Skip to content
Gladpaid

Help · Getting connected

Why we never ask for keys or recovery phrases

Gladpaid refuses private keys and recovery phrases everywhere, never logs them, and never needs them.

Updated

Gladpaid is read-only. It records payments; it never moves them. Reading a public address needs nothing secret, so there is no screen, form, upload or support request where a key could be required.

What the key guard detects

  • Recovery phrases of 12, 15, 18, 21 or 24 words from the standard word list.
  • Raw private keys, such as a 64-character hex string.
  • Wallet export formats, including extended private keys (xprv, zprv) and Solana secret keys.

The guard runs on every text field and every upload, including remittance PDFs and statement files.

What happens if you paste one

  1. 01

    Refused before it is sent

    The field is rejected in your browser before anything is submitted.

  2. 02

    Refused again on our servers

    If anything gets past the browser, the server refuses it too.

  3. 03

    Never written down

    It is not saved, not logged, and scrubbed from error reports and analytics.

  4. 04

    You are told why

    A plain message explains what happened and that we never need it.

If the phrase or key was exposed anywhere else

Gladpaid discards it, but if you have pasted the same phrase or key into any other site, email or document, treat that wallet as compromised. Create a new wallet with your wallet provider, move the funds to it, and update the receiving address on your invoices. Then add the new address in Gladpaid (see Adding a receiving address).

More on how the product is built around this rule: Security & custody.

Did this not answer it? Write to support@gladpaid.com with the business name and the item. Please never include a recovery phrase or private key; we will never ask for one.