How the session works
The site generates a pairing URI, your wallet reads it, and the two establish an end-to-end encrypted session through relay servers that cannot read the contents. The site learns the address and chain you approved for the session.
From then on the site can send requests: switch chain, sign a message, send a transaction. Each one surfaces in your wallet as a prompt you must explicitly accept.
What a connection reveals
Your public address and therefore your on-chain history and balances, which are public anyway. A site can read everything your address has ever done, because so can anybody with a block explorer.
It does not reveal your private key, your recovery phrase or any other account in the same wallet that you did not approve.
Where the real risk is
In the approval prompts. A malicious site connected over WalletConnect is exactly as dangerous as a malicious site in a browser extension wallet: it can request an unlimited allowance or a transfer, and it depends entirely on you reading the prompt.
Signature requests deserve the same care as transactions. An off-chain signature can authorise a token transfer under permit-style standards without any on-chain approval step.
Session hygiene
Disconnect sessions you are not using, from the wallet side. A long-lived session to a site you no longer visit costs nothing but adds a channel that can propose requests at any time.
FBT Swap uses WalletConnect for external wallets and shows the chain and the proposed transaction before anything reaches your wallet. The signature always happens in your wallet, never here.