Privacy Policy
Last updated: September 2026
1. Who We Are
ChainHint ("we", "us", "our") is a blockchain analytics platform operated by an independent developer based in Ukraine. We provide informational tools for cryptocurrency incident response, fund tracing, and wallet reputation analysis at chainhint.com. For privacy enquiries, contact us via the contact form.
2. What Personal Data We Collect
We collect and process the following categories of personal data:
- Account data: email address and display name provided during registration or via OAuth (Google, GitHub).
- Authentication metadata: OAuth provider identifiers managed by Supabase Auth. We do not store passwords for OAuth users.
- Wallet addresses you submit: blockchain addresses entered for tracing or monitoring. These are public-chain data but are linked to your account.
- Hashed IP addresses: we store a one-way hash of your IP address for abuse prevention. We do not store raw IPs.
- Visitor intelligence data: when you visit public pages, we log your browser's user agent string, the referring URL, and your network's autonomous system number (ASN / ISP name) for security monitoring and abuse prevention. This data is not used for advertising or cross-site profiling and is automatically purged after 90 days. Processed under legitimate interest (GDPR Art. 6(1)(f)).
- Usage data: pages visited, features used, investigation metadata, and subscription status.
- Funnel step counts: when you open one of our account pages (sign-up, log-in, onboarding, dashboard, payment) — or when a checkout starts, is issued, is cancelled, confirms, fails or is refunded — we add 1 to a counter for that step and that calendar day. The stored record is the step name, the date and a number — no IP, no hashed IP, no account, no device, no browser, no referrer, no time of day. It tells us how many people reached each step, never which people, and it is not linked to anything else we hold. Processed under legitimate interest (GDPR Art. 6(1)(f)).
- Payment references: NOWPayments invoice IDs and transaction status. We do not store your wallet private keys or full payment wallet addresses.
- Error logs: de-identified error reports sent to Sentry for debugging.
- Free-access applications: if you apply on /for-investigators, we store the name, email, country, organization, links and description you enter, plus your browser's user agent and the referring URL, so the owner can review the application by hand. Processed on the basis of your request (GDPR Art. 6(1)(b)).
3. What We Do NOT Collect
We do not use advertising trackers or marketing cookies. We do not sell, rent, or share personal data with advertisers. We do not build user profiles for ad targeting. We do not process biometric data. The only third-party analytics we use is Google Analytics 4, and it runs only after you accept analytics cookies (see section 8).
4. Lawful Bases for Processing (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)): processing your account data, wallet submissions, and subscription data is necessary to provide the service.
- Legitimate interest (Art. 6(1)(f)): hashed IP storage, visitor intelligence (UA, referrer, ASN) for abuse prevention, error logging, and service improvement.
- Legal obligation (Art. 6(1)(c)): retaining transaction records as required by applicable tax/accounting law.
- Consent (Art. 6(1)(a)): analytics cookies (Google Analytics 4) and optional email notifications (subscription reminders). You may withdraw consent at any time — for analytics via "Cookie settings" in the footer.
5. AI Processing Disclosure
When you request an incident report, we send blockchain transaction data and entity labels to the Anthropic Claude API for automated analysis. The data sent consists of public blockchain information and entity labels — not your personal account data. Anthropic processes this data under their data processing terms and does not use it to train models. You have the right to request human review of any AI-generated output.
6. Third-Party Sub-Processors
We use the following third-party services to operate ChainHint:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, auth, edge functions | EU (Ireland) |
| Anthropic (Claude) | AI report generation | US |
| NOWPayments | Crypto payment processing | EU |
| Resend | Transactional email | EU (Ireland) |
| Sentry | Error tracking (de-identified) | EU (Germany) |
| Google (Analytics 4) | Aggregated usage statistics — only after you accept analytics cookies | US (EU–US DPF) |
| Cloudflare (Web Analytics) | Cookieless page-view statistics (no cookies, no identifiers) | US (EU–US DPF) |
| Moralis, Alchemy, Ankr | Blockchain data indexing | US/EU |
| Etherscan, GoPlus, Chainalysis | Entity labels, risk scoring, sanctions | US |
| DeFiLlama, CoinGecko | Hack data, pricing | US/EU |
| 1inch, TonAPI, Blockstream, TronGrid, TronScan | Chain-specific data | Various |
7. International Data Transfers
Our database is hosted in the EU (AWS eu-west-1, Ireland). Several of our sub-processors are US companies (see the Trust page), so your data may be accessed from or processed in the United States. These transfers rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or the EU-US Data Privacy Framework where applicable. We take reasonable steps to ensure adequate safeguards are in place.
8. Cookies
- Strictly necessary: authentication session tokens and UI preferences, including your cookie choice itself (kept in your browser's local storage). These need no consent.
- Analytics (optional): Google Analytics 4 sets the
_gaand_ga_*cookies (up to 2 years) to count visits, pages and referrers in aggregate. GA4 is loaded only after you click "Accept" in the cookie banner. If you decline or do nothing, no analytics script runs and no analytics cookie is set. GA4 does not store IP addresses; Google processes the data in the US under the EU–US Data Privacy Framework. - Cookieless analytics (always on): Cloudflare Web Analytics counts page views, referrers, countries and page-speed metrics for every visitor. It sets no cookie, uses no local storage and, per Cloudflare, does not fingerprint visitors by IP address or user agent, so it does not require consent. Our own visit log (section 2, "Visitor intelligence data") works the same way.
- Funnel step counts (always on, no cookie): the per-step, per-day counters described in section 2. They set no cookie, read no storage, and record nothing that could identify you or your device, so they need no consent and are unaffected by your cookie choice.
- Changing your mind: "Cookie settings" in the footer re-opens the banner at any time. Declining later stops further collection and removes the analytics cookies.
- Global Privacy Control: browsers that send the GPC signal are treated as "declined" and the banner is not shown.
- We do not use advertising or social-media cookies.
9. Data Retention
- Account data: retained for the lifetime of your account, deleted within 30 days of account deletion request.
- Investigation data: retained while your account exists. Soft-deleted investigations are permanently purged after 90 days.
- Payment records: retained for 7 years as required by EU tax/accounting obligations.
- Hashed IPs and error logs: automatically purged after 90 days.
- Free-access applications: automatically deleted 12 months after submission. To have yours deleted sooner, write to us (section 14).
10. Public Investigations
You may choose to make an investigation public via the share feature. Public investigations are accessible to anyone with the link and are indexed by the platform. Making an investigation public means the blockchain graph, entity labels, and AI report become viewable without authentication. You can revoke public access at any time.
11. Your Rights Under GDPR
As a data subject in the EU, you have the right to:
- Access — obtain a copy of all personal data we hold about you.
- Rectification — correct inaccurate personal data.
- Erasure — request deletion of your personal data ("right to be forgotten").
- Restriction — request restricted processing in certain circumstances.
- Data portability — receive your data in a structured, machine-readable format (JSON).
- Object — object to processing based on legitimate interest.
- Withdraw consent — where processing is based on consent.
- Lodge a complaint — with your local supervisory authority.
To exercise any of these rights, reach out via the contact form. We will respond within 30 days.
12. Children
ChainHint is not directed at individuals under 18. We do not knowingly collect data from minors. If we learn that we have collected personal data from a person under 18, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice at least 30 days before they take effect. Continued use of ChainHint after the effective date constitutes acceptance of the updated policy.
14. Contact
For any privacy-related questions or data requests, use the contact form.