Last updated 18 August 2026
Privacy policy
This service is built to hold as little about you as possible. There is no account, no password and no email address — a wallet signature is the login, and a public wallet address is the identity.
This policy sets out what is collected, why, who else sees it and how long it is kept.
What we collect
There is no account in the usual sense. You do not give us a name, an email address or a password, and we do not ask for one. What we hold is the minimum needed to run a paid API.
- Your public wallet address. This is your identity on the service — it is how a payment is matched to access and how you sign in.
- Payment transactions. The chain, the transaction hash, the token and the amount, so a payment can be verified and credited. These are already public on the blockchain.
- API keys, stored only as a cryptographic hash. We cannot recover a key after it is shown to you once; we can only check whether one you present is valid, and revoke it.
- Usage records. Which tools were called and when, so quotas can be enforced and abuse can be identified. We do not store the content of your queries or the responses returned to you.
- A session cookie, set when you sign in, so you stay signed in between page loads.
- Basic technical data that any web server receives: IP address, user agent, and timestamps of requests.
What we do not collect
We do not collect your name, email address, postal address, phone number or date of birth. We do not build advertising or marketing profiles, we do not sell data to anyone, and we do not use your data to train models.
We never have custody of your funds and we never ask for a private key or a seed phrase. Signing in produces a signature that proves you control an address; it cannot move anything.
Why we hold it
To provide the service you have paid for: verifying payments, issuing and validating keys, enforcing quotas, and keeping the service secure and available. Where the law requires a legal basis, this is performance of a contract with you and our legitimate interest in operating and protecting the service.
Cookies and analytics
We set an encrypted session cookie that keeps you signed in after you sign a message with your wallet, and a first-party anonymous identifier used to connect activity before registration with the account created later. The anonymous identifier carries no advertising profile by itself.
We use Vercel Analytics and Google Analytics to count page views and understand which pages are read. Google Analytics may set first-party cookies on this site; we disable advertising-oriented features and do not use analytics data for advertising.
When available in a visit, we retain first-touch and last-touch campaign information such as UTM parameters, referrer, landing page and advertising click identifiers. First-touch information is not overwritten; last-touch information may change when you arrive through a new campaign.
Who else sees it
We share the minimum necessary with the infrastructure providers that run the service — hosting, the database and analytics — who process it on our instructions and are not permitted to use it for their own purposes.
Requests you make are answered using third-party market data providers. Those requests are sent as an anonymous query for market data; the provider does not receive your wallet address, your key, or anything that identifies you.
We will disclose data if we are legally required to. We do not sell it, and we do not share it for advertising.
Blockchain data is permanent
Payments happen on public blockchains. Those records are outside our control and cannot be edited, hidden or deleted by us or by you — that is a property of the blockchain itself, not a choice we made. Anything you send on-chain is public and permanent.
How long we keep it
Access and payment records are kept while your access is live and afterwards for as long as we need them for accounting and to resolve disputes. Usage records are kept for a limited period for quota enforcement and abuse detection. Revoked keys are kept as hashes so a revoked key cannot be reused.
Your rights
Depending on where you live, you may have the right to ask what we hold about you, to have it corrected or deleted, to object to or restrict how we use it, and to receive a copy. Contact us and we will action it.
Two limits are worth stating honestly. We cannot delete anything recorded on a public blockchain. And because your wallet address is the identity the whole service is built on, deleting it ends your access.
Security
Keys are stored only as hashes, sessions are encrypted, and everything travels over TLS. No system is perfectly secure, but the design deliberately holds as little as possible: there is no password to steal, and no stored key to leak.
Changes
If this policy changes, the date at the top of this page changes with it. Material changes will be noted on the home page.
Contact
Questions about this policy can be sent to @mcp_f1ow.