help // and its boundaries
Support without custody
StellarKey can help explain the software, but no operator holds your keys, vault password, passkey, transactions, or browser-local merchant records.
Effective 28 August 2026 · Legal text version 1.1
- No legitimate support request requires your recovery phrase, private key, password, passkey output, decrypted backup, or remote device access.
- Support can troubleshoot the interface and public ledger behavior, but cannot recover a wallet, reverse a transaction, or restore local data that was never backed up.
- Use a public GitHub issue for sanitized product defects and the private Security channel for suspected vulnerabilities.
Start safely
Lock the wallet before sharing a screen or screenshot. Do not install remote-access software, run code from an unsolicited message, import a recovery phrase into a support form, or move funds to an address presented as “verification.” StellarKey maintainers will not contact you first to repair, upgrade, synchronize, or validate a wallet.
For an unexpected payment or balance, first confirm the selected network and public account address. Then compare the transaction hash and operations with a Stellar explorer you trust. A public ledger entry is authoritative even when a local interface is delayed.
Checks you can make
- Confirm that the site origin is exactly stellarkey.io and is using HTTPS.
- Open About and compare the full release commit with the published source release.
- Check the active account, mainnet or testnet selection, and configured Horizon or RPC endpoint.
- Reload once, then retry a read-only action before repeating anything that could sign or submit.
- Check the transaction hash on the authoritative network before sending a second payment.
- Use a fresh, unfunded testnet wallet to reproduce a defect whenever possible.
Safe diagnostic details
The following is normally safe to include after checking it contains no customer data:
- StellarKey release 1.0.0 and commit a52011004b480694addd7196bb038cc41ea3603f;
- device model, operating-system version, browser name and version, and install mode;
- mainnet or testnet, the affected route, expected result, and exact sequence of actions;
- a public account address or transaction hash only when it is essential and already public;
- a redacted screenshot or copied error message with all secrets and personal records removed; and
- whether the issue also occurs with a fresh testnet wallet in the latest supported release.
Never send secrets
Support never needs a recovery phrase, private key, wallet password, passkey output, encrypted or decrypted backup, raw signed transaction, one-time code, customer or merchant archive, complete browser-storage export, or remote access to your device. Do not paste secrets into a public issue, email, screenshot, form, chat, or AI assistant. If you believe a secret was exposed, move assets to a newly generated recovery path from a clean device; a password change cannot revoke a leaked Stellar signing key.
Support boundaries
Support can
- explain documented wallet, backup, network, asset, and merchant behavior;
- help distinguish an interface problem from confirmed public ledger state;
- triage a sanitized, reproducible software defect; and
- direct a security report into the private disclosure process.
Support cannot
Because StellarKey is self-custodial and backend-free, support cannot recover lost keys, unlock a vault, restore data that was not backed up, reverse a Stellar transaction, freeze an asset, issue a refund, alter a ledger record, monitor a suspended app, access local merchant data, or resolve an issuer, hardware-wallet, merchant, customer, or counterparty dispute. Support also cannot provide financial, tax, legal, accounting, or regulatory advice.
Choose the right channel
- Public software defects and feature requests: search existing reports, then open a sanitized GitHub issue with safe reproduction steps.
- Suspected vulnerability: do not open a public issue. Follow the private process on the Security page.
- Asset, redemption, or issuer dispute: contact the asset issuer through a verified official channel. StellarKey does not represent the issuer.
- General product question: use the protected support action below.
Response expectations
StellarKey is free software and general product support has no guaranteed response time, service level, fix deadline, or individual recovery service. Clear, minimal, reproducible reports are easier to investigate. A reply, workaround, planned change, or issue label is not a warranty that a defect will be fixed or that a transaction or local record can be recovered.
Contact support
The contact address is assembled only after you activate the button, keeping it out of the static page markup and reducing basic automated harvesting. Your email provider and the recipient will process the message, so include only what is necessary.