Privacy Policy
Last updated: September 2026
1. What we collect
- Wallet addresses — when you check a transaction, connect a wallet, buy deep-check credits, or submit a threat report. Addresses are pseudonymous, public on-chain data.
- Payment data — when you buy Pro credits, we record the paying wallet address, amount, and on-chain transaction hash (itself public on Base) to credit your balance and for the audit log described in Section 4. We do not collect card numbers, bank details, or run identity/KYC verification today.
- Email address — if you submit a threat report at /report (to send a one-time confirmation link; we store a one-way hash of it as your reporter identity once confirmed, not the raw address), or if you subscribe to updates via the footer or the wallet-connect consent step. Newsletters and important product/security communications are sent to subscribed addresses; every email includes an unsubscribe link, and you can unsubscribe at any time.
- Transaction/signature data you submit — to analyze it. This is processed to produce a verdict and is not sold or used for advertising.
- Consent records — when you connect a wallet, install the Snap, or authorize the Snap's deep checks, we log that a specific address (where available) accepted a specific version of these Terms/this Policy, so we can demonstrate consent was given.
- Basic request metadata (IP address, timestamps) for rate-limiting and abuse prevention, and for our security/audit logs (see below).
2. What we don't collect
We never see or request your private keys, seed phrase, or wallet password. We do not track your browsing activity outside GENESIS, and we do not sell personal data to third parties.
3. Third-party processors
Data may pass through the following providers as part of running the Service. We don't control these providers and are not responsible for their independent handling of your data beyond what's described here; see our Integrations & Partners page for what each one does.
- Resend — sends the report-confirmation email (sees your email address).
- Cloudflare Turnstile — bot-check on the report form.
- GoPlus Security, ChainAbuse (TRM Labs), Blockaid — receive addresses/origins you check, to look up threat intelligence. These providers, and we, may compare addresses against public sanctions and law-enforcement watchlists as part of that lookup.
- Reown/WalletConnect — powers the "Connect wallet" flow.
- Neon (PostgreSQL) — hosts our database (threat intel, credit balances, audit logs).
- Render, Vercel — host our backend and website.
4. Audit & security logs
We keep internal records of deep-check credit spending, security-relevant flags (e.g. a known-malicious address or phishing site detected), and integration failures, to operate the Service reliably and investigate abuse. These logs are keyed by wallet address, not by real-world identity.
5. Retention
We retain the data above for as long as needed to operate the Service (e.g. credit balances persist until spent; audit logs are retained for security investigation purposes). We have not yet finalized a formal deletion schedule — see the draft notice above.
6. Your rights
Depending on where you live, you may have rights to access, correct, or delete personal data we hold about you (e.g. under GDPR or CCPA). Contact security@sadhutech.com to make a request.
7. Changes
We may update this Privacy Policy from time to time. Material changes will be noted on this page.
8. Contact
security@sadhutech.com. See also our Terms of Service.