What we keep, and why.
What we store
- Account — your wallet address (if you sign in with a wallet) or your email and an Argon2 hash of your password (never the password itself). One session cookie, HttpOnly, seven days, plus a non-secret cookie that only says "signed in" so the landing page can skip the sign-in flow.
- Preferences — risk profile, network, simulation size, the public wallet you asked us to monitor, your Telegram chat ID if you set one, and whether alerts are on.
- Watchlist — pool ids you starred.
- Verdict log — every rotation verdict we showed you: position id, verdict, the alternative pool, our predictions and your position's fee total at that moment. This is how the track record is computed.
- Alert state — what the alert loop last saw per position, so it only messages you on changes.
- Rate-limit counters — hashed keys with request counts per window.
What we do not store
Private keys or seed phrases (never asked for), transaction signatures beyond the one-time sign-in message (verified, then discarded), IP addresses in the database (only a hashed, short-lived rate-limit key), advertising identifiers, or third-party tracking cookies. There are no ads. Page views are counted with Vercel Web Analytics: cookieless, aggregate (pages, referrers, countries, devices), never tied to an account or wallet.
Where data goes
- Krystal and DexScreener receive the public wallet address or pool ids needed to answer a request. They never see your account.
- Telegram receives alert messages for the chat ID you entered.
- The public track record is an aggregate: counts, medians and rates. No wallet, position, pool or account is published.
- Nothing is sold or shared with anyone else.
Browser storage
Your browser keeps a per-tab cache of the last data it fetched (cleared on sign-out), your page size and a few display preferences. None of it leaves your device.
Retention and deletion
Data stays while your account exists. Signing out deletes the session. To delete the account and everything attached to it, ask via the source repository; deletion removes the account, preferences, watchlist, verdict log and alert state. Aggregate track-record numbers already published are not affected, as they contain nothing identifying.
Security
Passwords are hashed with Argon2, sessions are random tokens stored hashed, sign-in messages are bound to this site and a single-use nonce, and every outbound error has secrets scrubbed before it is logged. If you find a problem, report it through the source repository before disclosing it.
Changes
The date above is the current version of this policy.
See also Terms of service and Privacy policy.