← HOME
// PRIVACY

Privacy Policy

Last updated: May 2026 · PrivaScan collects minimal data and never sells it.

What we collect

Email addresses submitted during API key generation. API request logs (endpoint, timestamp, anonymised IP) for rate limiting and abuse prevention. No personal browsing data, no tracking pixels, no third-party analytics.

What we do not collect

We do not track which contract addresses you scan. We do not store wallet addresses, transaction histories, or any on-chain data linked to your identity. We do not use cookies for tracking.

How data is used

Email addresses are stored to associate API keys with a point of contact. They are never sold, shared with third parties, or used for marketing without explicit opt-in. API logs are retained for 30 days for rate limit enforcement and deleted automatically.

API key security

Raw API keys are shown once at generation and never stored. We store only the SHA-256 hash of each key. If you lose your key, generate a new one — we cannot recover the original.

Data retention

Email addresses associated with active API keys are retained until you request deletion. Keys that have been inactive for 12 months are purged. Score reports and analysis results contain no user-identifying information.

Third-party services

PrivaScan queries Etherscan, Alchemy, DefiLlama, and Dune Analytics for on-chain data. We also screen against the OFAC consolidated SDN list. These services have their own privacy policies.

Your rights

You may request deletion of your email and associated API keys at any time by emailing privacy@privascan.xyz. We will process requests within 14 days.

Contact

For privacy-related requests: privacy@privascan.xyz. For general support: support@privascan.xyz or Telegram @privascan.