::
i see your concerns and i think they are valid. this is why i did not create an account nor did i create a wallet using the Ellipal app.
i used [Ian Coleman’s Mnemonic Generator](https://iancoleman.io/bip39/) offline to give me my seed phrases. then, i used the „restore wallet“ option on the Titan (again, air-gapped/offline & therefore secure) to create the BTC address.
then i used the QR feature with the app to push the wallet address to the blockchain.
my only concern is that if my signing password is included (in plain-text) in the QR code, would that give Ellipal staff (and subsequently, the CCP) the opportunity to decode the QR and reveal my signing password?
i do not know the answer to this question.
same with opening an account on the app. i do not know what information is stored on their servers, and with the auto-signing features on their hot wallet, this is cause for concern.
i wish we could have Ellipal’s Security Team make a statement about this.