Privacy Policy
What we collect, why we collect it, who else sees it, and how to make us delete it. Written against what the code actually does, not against a template.
Last updated 25 August 2026
1. What we collect
From your account:
- Your name, email address, profile image and account identifier, received from Google when you sign in. We do not receive your Google password.
- A session record, so that staying signed in works. The cookie in your browser holds only an opaque token; the session itself lives in our database.
- Your subscription tier, Stripe customer and subscription identifiers, subscription status and renewal date.
From your use of the product:
- Token contract addresses you analyse, watch, or track as positions — along with the position details you enter yourself: size, entry price, and any note you add.
- Every analysis the engine runs for you, retained as a permanent record. This is what the public track record is built from.
- Public wallet addresses you paste into the wallet scanner, and the holdings it reads back.
- A count of how many analyses you have run today, to enforce the daily quota on your plan.
- If you connect Telegram: your Telegram chat identifier and username, so alerts have somewhere to go.
- For Apex API keys: a cryptographic hash of the key, the first characters for display, and when it was last used. The key itself is never stored and cannot be recovered.
From visitors who are not signed in:
- A salted, one-way hash of your IP address paired with the current date, and a count of free analyses run. This exists solely to stop one person consuming unlimited free analyses. We do not store the IP address itself, and the hash cannot be reversed back into one.
We do not run advertising networks, third-party analytics, session recording, or cross-site tracking, and we do not build advertising profiles.
2. Why we are allowed to hold it
Where the UK/EU GDPR applies, our lawful bases are: performance of a contract for the data needed to give you the product you signed up for (your account, your positions, your analyses, your alerts); legitimate interests for keeping the service secure and preventing quota abuse — a purpose we pursue with a one-way hash precisely so it costs you as little privacy as possible; and legal obligation for keeping payment and tax records. Where we ever rely on consent, we will ask for it plainly and you can withdraw it.
4. How long we keep it
- Account, positions, watches and alert settings: until you delete your account.
- Anonymous quota hashes: 30 days, then deleted. They have no value after the day they gate.
- Payment records: as long as tax and accounting law requires us to keep them, typically six to seven years, regardless of account deletion.
- Analyses recorded in the public track record: retained permanently and in anonymised form — the token, the call, the timestamp and the outcome, with no link to the account that ran it. A track record that could be quietly pruned would be worthless as evidence, which is the entire point of publishing it.
5. Your rights
Wherever you live, you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong.
- Delete your account and the personal data attached to it.
- Export your data in a portable format.
- Object to or restrict a particular use, including our legitimate-interests processing.
Email clujkeebs@aol.com and we will respond within 30 days. We will not charge you for it, and we will not make the service worse for you because you asked.
If you are in the EEA or UK and think we have handled your data badly, you may complain to your national data protection authority. If you are in California, we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and exercising your rights will not result in discriminatory treatment.
6. International transfers
The service is operated from, and your data is stored in, the United States. If you use it from the EEA or the UK, your data is transferred there. Where required, our processors rely on Standard Contractual Clauses or an equivalent transfer mechanism for those transfers.
7. Security
Traffic is encrypted in transit. API keys are stored only as SHA-256 hashes, so a database dump does not hand anyone a working key. Anonymous rate-limit records hold a salted hash rather than an IP address. Payment card data never reaches our servers at all.
No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your personal data, we will notify affected users and the relevant regulator as the law requires.
8. Children
The service is not for anyone under 18. We do not knowingly collect data from children, and we will delete any account we find to belong to one.
10. Changes
If we change how we use your data in a way that materially affects you, we will give notice in the app or by email before the change takes effect. The date at the top of this page always reflects the current version.