Legal

Privacy Policy

Last updated October 2026

1. What we collect

Account data: your email address and a password hash. We never store your password in plaintext.

Subscription data: your plan, expiry, and on-chain payment records (transaction hash and matched amount).

Telegram (optional): if you connect the SAD group bot, we store your Telegram user id and membership status to apply the member discount.

2. On-chain data

The security tools read public blockchains. Any address you submit is looked up on public indexers (Blockscout, GeckoTerminal, and others). We do not associate submitted addresses with your account, and we do not store them beyond a short-lived cache.

Public on-chain data is not personal data we control. We cannot delete what is already public on a blockchain.

3. How we use it

To authenticate you, to deliver the subscription you paid for, to apply the member discount, and to prevent abuse (rate limiting, fraud detection).

We do not sell your data. We do not share it with third parties except the providers needed to operate the service (database, email, payment verification).

4. Cookies and storage

We use an httpOnly session cookie to keep you signed in. We use local storage to remember your language preference.

We do not run advertising or cross-site tracking.

5. Retention

Account data is kept while your account exists. Password-reset tokens are single-use and expire after one hour. Rate-limit counters roll over automatically.

6. Security

Passwords are hashed with PBKDF2-SHA256. Sessions are stored as hashed tokens. Payment data is limited to the public on-chain record.

No system is perfectly secure. If you believe there has been a breach, contact support immediately.

7. Your rights

Depending on your jurisdiction you may have additional rights (e.g. GDPR, PDP). We will honor them to the extent they apply.

8. Contact

For privacy or data requests, email supportanydisruption@gmail.com.