YONDER docs
Your piece lands at an address nobody told you about, so the site finds it for you. It reads the public ERC-5564 announcements and checks each one with your view key, right in your browser. Nothing about your keys is sent to a server.
Yonder stealth keys v1 | chain <chainId> | account <your wallet, lowercase>. From it, your browser derives your spending key and your view key.All of these live in page memory only. They are not written to browser storage and not sent to any server. Switching wallet account, switching chain or disconnecting clears them, and the next scan asks for the signature again.
To move a piece into an everyday wallet, the same signature rebuilds that stealth address's own private key in your browser. The move is its own transaction, so the stealth address needs a little ETH for gas. Funding it from your main wallet links the two addresses in public.
There is nothing to export or import for your pieces. Your keys are not stored anywhere, so they come back the same way they were made: open the site on the new device, connect the same wallet account on the same chain, sign the same message, and scan. Recovery needs the original wallet account, the same chain, and a wallet that signs the same message the same way every time.
If you lose access to the wallet you bought with, you lose the way back to its stealth keys. There is no email reset. Private token sends also create public recovery material you should save; see Make your $YONDER private.