Privacy Policy
Last updated: May 2026 · PrivaScan collects minimal data and never sells it.
Email addresses submitted during API key generation. API request logs (endpoint, timestamp, anonymised IP) for rate limiting and abuse prevention. No personal browsing data, no tracking pixels, no third-party analytics.
We do not track which contract addresses you scan. We do not store wallet addresses, transaction histories, or any on-chain data linked to your identity. We do not use cookies for tracking.
Email addresses are stored to associate API keys with a point of contact. They are never sold, shared with third parties, or used for marketing without explicit opt-in. API logs are retained for 30 days for rate limit enforcement and deleted automatically.
Raw API keys are shown once at generation and never stored. We store only the SHA-256 hash of each key. If you lose your key, generate a new one — we cannot recover the original.
Email addresses associated with active API keys are retained until you request deletion. Keys that have been inactive for 12 months are purged. Score reports and analysis results contain no user-identifying information.
PrivaScan queries Etherscan, Alchemy, DefiLlama, and Dune Analytics for on-chain data. We also screen against the OFAC consolidated SDN list. These services have their own privacy policies.
You may request deletion of your email and associated API keys at any time by emailing privacy@privascan.xyz. We will process requests within 14 days.
For privacy-related requests: privacy@privascan.xyz. For general support: support@privascan.xyz or Telegram @privascan.