Privacy Policy
Last updated October 2026
1. What we collect
Account data: your email address and a password hash. We never store your password in plaintext.
Subscription data: your plan, expiry, and on-chain payment records (transaction hash and matched amount).
Telegram (optional): if you connect the SAD group bot, we store your Telegram user id and membership status to apply the member discount.
2. On-chain data
The security tools read public blockchains. Any address you submit is looked up on public indexers (Blockscout, GeckoTerminal, and others). We do not associate submitted addresses with your account, and we do not store them beyond a short-lived cache.
Public on-chain data is not personal data we control. We cannot delete what is already public on a blockchain.
3. How we use it
To authenticate you, to deliver the subscription you paid for, to apply the member discount, and to prevent abuse (rate limiting, fraud detection).
We do not sell your data. We do not share it with third parties except the providers needed to operate the service (database, email, payment verification).
4. Cookies and storage
We use an httpOnly session cookie to keep you signed in. We use local storage to remember your language preference.
We do not run advertising or cross-site tracking.
5. Retention
Account data is kept while your account exists. Password-reset tokens are single-use and expire after one hour. Rate-limit counters roll over automatically.
6. Security
Passwords are hashed with PBKDF2-SHA256. Sessions are stored as hashed tokens. Payment data is limited to the public on-chain record.
No system is perfectly secure. If you believe there has been a breach, contact support immediately.
7. Your rights
Depending on your jurisdiction you may have additional rights (e.g. GDPR, PDP). We will honor them to the extent they apply.
8. Contact
For privacy or data requests, email supportanydisruption@gmail.com.