Denuo Web, LLC
HNS DANE Browser Privacy Policy
HNS DANE Browser is published by Denuo Web, LLC. For privacy questions or deletion requests, email info@denuoweb.com or use the developer contact listed in the app's store listing. Do not post personal information to the public project issue tracker.
Summary
HNS DANE Browser is a Handshake-first browser for local HNS proofs, authoritative DNS, optional requester-only HNS P2P DNS relay consumption, optional user-configured recursive HNS DoH recovery, DNSSEC, and DANE diagnostics. It also provides native controls to create or restore one device-local non-value HNS account identity and to open, unlock, or lock that local wallet, plus visible read-only rows for balance, receive target, transaction history, tracked names, and module status. It does not provision the required scoped loopback credential or indexed wallet backend, so those rows remain unavailable and make no wallet-specific network request. It cannot send funds, import or manage names, provide website-provider access, participate in HNSA or HNSR service roles, settle trades, provide exchange features, or expose P2P marketplaces. The requester-only P2P DNS relay is separate from HNSR and does not make the device a relay endpoint or output node. The app has no advertising SDKs, analytics SDKs, developer-operated accounts, or paid feature unlocks. The Android edition may show an optional external donation link that does not unlock functionality; the iOS app has no donation or payment flow.
The app stores browser and native wallet data locally on the device and sends network requests needed to load sites and keep HNS resolution data current.
Data stored locally
The app may store the following data on the device:
- Browsing history and navigation state: page URLs, page titles, visit times, or the current session's back-forward list, depending on the platform.
- Website data: cookies and other storage managed by Android WebView or Apple WebKit.
- Downloads: files saved at your request and platform-specific local records needed to complete or present those downloads. Android records may include the URL, file name, MIME type, DownloadManager ID, and queued time; iOS saves completed files in the app's local Documents/Downloads directory until you export or remove the app.
- HNS data: synced headers, peer records (including manually added relay-peer IP endpoints), verified resource values, resolver cache, and resolver diagnostics.
- Settings: homepage, cookie preference, optional HNS P2P DNS relay requester, optional user-configured recursive HNS DoH recovery URL, and related app preferences. Relay consumption and recursive recovery are independently off by default and require separate explicit choices. Upgrades erase the historical resolver key and never copy it into the new recovery setting or treat it as relay consent.
- Native wallet data: a network-scoped encrypted wallet database, one non-value HNS account identity, and the key material needed to reopen it. Android keeps the database under app-private no-backup storage and wraps its 32-byte database key with Android Keystore. iOS uses an app-private, backup-excluded database with complete file protection and a ThisDeviceOnly Keychain item requiring user presence. A newly generated recovery phrase is shown once for offline backup; restore input and the one-time display are cleared when the wallet screen leaves its protected lifecycle. If the screen closes before that display is confirmed, the app wipes its unconfirmed database-key buffer and deletes the incomplete wallet database. Swift/UIKit-managed text on iOS cannot be claimed to be deterministically zeroized, although app-owned mutable buffers are wiped. The app stores no scoped wallet-backend credential; its visible synchronized-read rows remain unavailable.
This local data is used only to provide browser functionality, native wallet controls, diagnostics, and HNS resolution. It is not sold. It is not sent to a Denuo Web analytics or advertising service.
Network requests
To provide browser functionality, HNS DANE Browser may connect to:
- Websites and web services that you choose to open.
- Handshake peers and DNS seed hosts for header sync, peer discovery, and proof retrieval.
- Relay-capable Handshake peers for recursive HNS DNS queries after local proof validation and authoritative DNS attempts fail, but only after the user opts into requester consumption. Upgrades preserve an independent relay choice and never convert a former public-DoH or compatibility choice into consent. A manual relay peer must be entered as an IP-literal endpoint and is stored only after its live HSD handshake advertises the relay capability. The browser does not become an output node.
- Authoritative DNS nameservers for delegated HNS names.
- Proof-bootstrapped or RFC 9461-discovered RFC 8484 authoritative DoH endpoints for delegated HNS names.
- A recursive HNS DNS-over-HTTPS endpoint entered explicitly by the user, but only after direct authoritative DNS, owner-published proof-anchored authoritative DoH, and any independently enabled P2P requester path fail because port 53 is intercepted or DNS transport is unavailable. Leaving the setting blank makes no request to such a service.
https://hnsdoh.com/dns-queryis an example only; it is never prefilled, selected automatically, or contacted unless the user enters it. - Security or reputation services exposed by the platform web engine. In particular, an installed Android WebView provider may check URLs with its Safe Browsing service and apply its own privacy policy. Apple WebKit and the operating system may apply their own browser-security protections. HNS DANE Browser does not operate those platform services.
- The non-routable
192.0.2.1TEST-NET DNS sentinel after delegated DNS failure; a matching reply confirms transparent outbound port 53 interception, while no reply is reported only as not detected. - Cloudflare's DNS-over-HTTPS service at
cloudflare-dns.com(bootstrapped through the documented1.1.1.1addresses) for ordinary internet DNS resolution. - Platform download services and the destination you choose when you download or export a file.
The app contains a bounded read-only wallet projection, but provisions no scoped loopback credential or indexed wallet backend. The visible balance, receive, history, tracked-name, and status rows therefore remain unavailable, and the native wallet makes no wallet-specific network request. It cannot send a transaction, contact a website wallet provider, or settle a trade; its available account controls are device-local.
These network endpoints may receive technical information that is normal for network communication, such as your IP address, the requested host or URL, protocol metadata, and any data you submit to websites. Cloudflare controls its own resolver logging, retention, and privacy practices; Denuo Web does not operate that service. In particular, an HNS relay peer or a user-configured recursive HNS DoH operator can observe queried DNS names and record types, request timing, and the source IP address. An ordinary Handshake TCP connection is not query-confidential; encrypted peer transport should be preferred where available. Relay and configured-recursive responses are still validated locally through the app's Handshake proof, DNSSEC, TLSA, and DANE checks; neither a peer's DNS authenticated-data bit nor a resolver's trust assertion is accepted as proof.
The app has no automatic or default recursive HNS resolver. If the user explicitly configures a recovery endpoint, the app validates its bounded HTTPS URL, resolves its hostname only through validating ICANN DoH, connects only to public addresses with WebPKI, and still validates HNS answers locally. Bogus DNSSEC, invalid DNS, DNS response codes, and stale or missing HNS proof state remain terminal instead of activating recovery. HNS WebPKI fallback remains prohibited. Every complete DNS hostname is also resolved through bounded validating ICANN DoH for dual-root classification; ICANN WebPKI is allowed only after authenticated TLSA denial or a proven unsigned zone.
HTTPS, DNSSEC, and DANE are used where applicable. If you intentionally open a cleartext http:// site, that site connection is not encrypted by HTTPS.
Cookies and website data
Websites may set cookies or use platform web-engine storage. Android provides settings controls to block third-party cookies and delete cookies plus WebView origin storage. iOS uses a persistent WebKit profile and provides a settings action that deletes its cookies and website data. Remaining website data is removed when the app is uninstalled. Websites are responsible for their own privacy practices.
Data sharing
Denuo Web does not sell personal or sensitive user data. HNS DANE Browser shares data only as necessary for user-requested browser functionality, such as loading a website, syncing HNS data, resolving a name, or downloading a file. The app does not send native wallet databases, recovery phrases, device-bound database keys, account identities, or wallet read data to Denuo Web, websites, analytics services, or a wallet provider.
Retention and deletion
Local browser data remains on the device until you clear it using an available platform or app control, or uninstall the app. Android provides controls for clearing cookies and WebView origin storage, browsing history, download records, gateway diagnostics, and the HNS resolver cache; Android system settings can also clear all app storage. iOS provides controls for clearing cookies and WebKit website data, browsing history, download-list records, locally stored gateway diagnostics, and the HNS resolver cache. Clearing the iOS download list does not delete the downloaded files themselves; those app-local files remain until the app is uninstalled. Files you export to another location are then controlled by that destination.
An unconfirmed newly created wallet is automatically removed when its protected recovery screen closes: the app wipes its unconfirmed database-key buffer and deletes the incomplete database. There is no in-app delete control for a confirmed native wallet. On Android, clearing all app storage or uninstalling the app removes its private wallet database and wrapped-key records. On iOS, uninstalling removes the app-container database; the operating system may retain the ThisDeviceOnly Keychain item under normal Keychain semantics. If the database is absent when the wallet screen is later opened, the app reconciles and deletes that orphaned item. Save the recovery phrase before clearing storage or uninstalling, because the app cannot show it again and cannot recover the wallet for you.
HNS DANE Browser does not create developer-operated user accounts, so there is no app account deletion flow.
Children
HNS DANE Browser is not directed to children. Because it is a general-purpose browser, websites opened by users may contain third-party content outside Denuo Web's control.
Changes
This policy may be updated as the app changes. Material privacy changes should be reflected on this page, in the in-app privacy text, Google Play's Data safety form, and Apple's App Privacy answers as applicable.