Legal

Privacy policy

What we collect, why we collect it, how long we keep it and who else sees it. Written against what the code actually does.

In effect 12 August 2026 · English is the authoritative version

1. Controller

Cabal Hunter is a business name used by a sole trader established in Ireland. We are the data controller for the processing described here. Contact [email protected] for any privacy question, or to exercise the rights in section 7.

We have not appointed a Data Protection Officer; we are not required to.

2. The short version

No advertising, no tracking cookies, no data sold, ever. The only cookie we set is an owner/administrator login cookie that ordinary visitors never receive. Most analytics we keep are stored against a salted hash of your IP address rather than the address itself. The two places we keep a raw IP are free-tier metering and abuse prevention, because the free allowance is counted per address.

3. What we collect and why

DataWhyLegal basisKept for
IP address (raw) — free-scan and map usage countersMetering the free allowance and preventing quota abuse; the free tier is counted per addressLegitimate interests; performance of a contract13 months
Hashed IP (SHA-256, salted, truncated) — page and API visits, country, referrer, path, response statusUnderstanding usage, diagnosing faults, distinguishing served scans from rejected onesLegitimate interests13 months
Token mint addresses you scanProducing and caching the result you asked forPerformance of a contract13 months
Email address, if you request an API keyDelivering the key, service notices, billingPerformance of a contractUntil you ask us to delete it
Marketing consent flagOnly set if you opt in; defaults to offConsentUntil withdrawn
Purchase records — transaction reference, amount, credits, timestampIssuing credits, support, accountingLegal obligation (tax); contract6 years (Revenue)
Help-assistant questions — the text you type into the on-page assistant, with page, locale, country and hashed IPAnswering the question and improving the answersLegitimate interests13 months
IP classification — IP address, country, network operator, and whether it belongs to a hosting providerTelling automated traffic from people, which is what the free allowance and the abuse limits depend onLegitimate interests13 months
Feedback you send us — your message and, if you give one, your email addressReading it and replyingLegitimate interests24 months
Owner/admin cookie (ch_owner)Keeps the operator logged in to internal pagesLegitimate interests1 year

Those periods are enforced by a job, not by good intentions. A nightly task deletes rows once they pass the retention period above. A published retention period with nothing behind it would be a claim rather than a policy.

We do not ask for, and do not want, your name, your postal address, your wallet's private keys or any special-category data. Do not send them to us.

4. Cookies

We set one cookie, ch_owner, and only for the operator of the site after authenticating at an internal URL. It is HttpOnly, Secure, SameSite=Lax and lasts one year. It carries no personal data beyond an authentication token.

There are no analytics cookies, no advertising cookies and no third-party trackers, which is why you are not being shown a cookie banner. If that ever changes, consent will be requested before anything is set.

5. Who else processes your data

We keep this list short on purpose. Each of these receives only what it needs:

ProcessorWhat it receivesWhere
Amazon Web Services — hostingEverything, at rest on the serverEU (Frankfurt)
Cloudflare — CDN, TLS and abuse protectionRequest metadata including IPGlobal edge; EU-first routing
Helius — Solana RPCThe mint and wallet addresses being analysed. Not your identity.United States
Dexscreener — market dataThe mint address being analysedUnited States
Stripe — card paymentsPayment and billing details. We never see or store your card number.United States / EU
Anthropic — the on-page help assistantThe question text you type into the assistantUnited States
ip-api.com — country lookupYour IP address, to resolve a country codeUnited States

Transfers outside the EEA rely on the European Commission's standard contractual clauses or an equivalent safeguard offered by the provider.

On-chain payments are public by design. If you pay in USDC on Solana, that transaction — its amount, timing and the wallets involved — is permanently public on the blockchain. Neither we nor anyone else can delete or amend it.

6. What we do not do

  • We do not sell, rent or trade personal data.
  • We do not link the addresses you scan to your identity, and we do not build behavioural profiles of visitors.
  • We do not use your data to train machine-learning models.
  • We do not run advertising or share data with ad networks.

7. Your rights

Under the GDPR you can ask us to: give you a copy of your data; correct it; erase it; restrict or object to how we use it; or send it to you in a portable format. Where processing relies on consent, you can withdraw consent at any time — withdrawing it does not affect what was lawful before.

Email [email protected]. We will respond within one month. There is no charge unless a request is manifestly excessive. We may need to verify that a request relates to data that is actually yours — for a key, that normally means sending the request from the email on the account.

Two practical limits, stated plainly rather than buried: we cannot erase records we are legally required to keep for tax purposes until that period expires, and we cannot alter the public blockchain.

If you are unhappy with how we have handled your data you can complain to the Irish Data Protection Commission (dataprotection.ie), or to the supervisory authority in your own EU country.

8. Security

The site is served over TLS. Administrative routes are authenticated, rate-limited and fail closed. Data is held on an encrypted volume in the EU with restricted access. No system is perfect: if you find a vulnerability, report it to [email protected] — see security.txt. We will not pursue researchers who act in good faith and give us a reasonable chance to fix the issue.

9. Children

The service is not intended for anyone under 18, and we do not knowingly collect data from children.

10. Changes

Material changes will be published here with a new effective date, and sent to paid customers by email.