Privacy policy · updated 19 September 2026

What we keep, and why.

What we store

What we do not store

Private keys or seed phrases (never asked for), transaction signatures beyond the one-time sign-in message (verified, then discarded), IP addresses in the database (only a hashed, short-lived rate-limit key), advertising identifiers, or third-party tracking cookies. There are no ads. Page views are counted with Vercel Web Analytics: cookieless, aggregate (pages, referrers, countries, devices), never tied to an account or wallet.

Where data goes

Browser storage

Your browser keeps a per-tab cache of the last data it fetched (cleared on sign-out), your page size and a few display preferences. None of it leaves your device.

Retention and deletion

Data stays while your account exists. Signing out deletes the session. To delete the account and everything attached to it, ask via the source repository; deletion removes the account, preferences, watchlist, verdict log and alert state. Aggregate track-record numbers already published are not affected, as they contain nothing identifying.

Security

Passwords are hashed with Argon2, sessions are random tokens stored hashed, sign-in messages are bound to this site and a single-use nonce, and every outbound error has secrets scrubbed before it is logged. If you find a problem, report it through the source repository before disclosing it.

Changes

The date above is the current version of this policy.

See also Terms of service and Privacy policy.