Security and data boundaries
RelaxView's security design follows one principle: data we do not need to touch, we do not touch. Market data flows directly from your device to the source, exchange keys never pass through our servers, and the app neither executes trades nor custodies assets.
Market data and keys
- Market source configurations contain only public market endpoints—no API keys, secrets or trading permissions; third-party data connects directly from your device to the source.
- If you add a source of your own that requires a key, the key stays on your computer and is never uploaded to the RelaxView website or servers.
- RelaxView does not execute trades, does not place orders on your behalf and does not custody any assets.
Installation and updates
- Installers are provided only through the official website and official release channels; do not install builds of unknown origin or third-party modified programs.
- The built-in updater accepts only signature-verified update packages; the signing private key is not kept on any server.
- Every release ships with a SHA-256 checksum you can verify yourself.
Website and accounts
- Website accounts are used for membership entitlements and payment confirmation; the scope and retention of collected data are described in the Privacy Policy.
- The Mac release notice records only your email, used for a one-time notification; contact us at any time to cancel.
- Admin, account and payment pages are not open to search engine indexing.
Reporting a security issue
Found a security issue? Email [email protected] with reproduction steps; we will reply with the handling status once confirmed.
FAQ
Do I have to give you my exchange API keys to use RelaxView?
No. Public market source configurations contain no keys; if you add a source that needs a key, it stays on your computer.
Which servers does RelaxView connect to?
Market data goes directly from your device to the third-party sources you choose; RelaxView servers handle only updates, membership entitlements and website services such as On-Chain Radar.
How can I confirm the installer has not been tampered with?
Download only from the official website and check the release's SHA-256; the built-in updater verifies update signatures automatically.