Last updated: 7 September 2026
1. Scope and applicability
This Privacy Policy applies to information processed through the WalletScope website, application interfaces, report-generation workflows, payment-related flows, administrative interfaces where applicable, and associated application programming interfaces and infrastructure operated for the WalletScope service. It is intended to explain the categories, purposes, technical pathways, retention characteristics, and disclosure circumstances applicable to information handled by the service, without purporting to eliminate rights or obligations that cannot lawfully be excluded under mandatory applicable law.
2. Nature of the service
WalletScope is a non-custodial blockchain-information and analytical reporting service. The service may accept a publicly observable Bitcoin or Ethereum wallet address and, depending on the package selected, process blockchain-derived information and selected third-party search results to produce a report. WalletScope does not require possession of a private key, seed phrase, recovery phrase, password, signing key, or other credential capable of controlling the referenced blockchain address.
Because blockchain networks are public, decentralized, replicated data systems, submitting a public wallet address should not be interpreted as causing WalletScope to make that address private. The address, its on-chain activity, and information already publicly observable on the relevant network may remain accessible independently of WalletScope and may be indexed, cached, replicated, or analyzed by third parties outside our control.
3. Categories of information processed
Depending on how the service is used, WalletScope may process the following categories of information:
- Request data: blockchain network selection, wallet address, selected report package, coupon code when supplied, and technical request metadata.
- Order data: an internal order identifier, order token, selected package, price before and after any applicable discount, payment status, report status, timestamps, and provider payment identifiers.
- Blockchain-derived data: transaction identifiers, timestamps, amounts, inputs, outputs, contract or transfer information, balances or related values, and other data returned by supported blockchain data providers.
- External-source results: for packages that include external search functionality, search-result metadata, publicly accessible references, snippets, URLs, and GitHub-related public references returned by the configured providers.
- Security and operational data: rate-limit state, request timestamps, service-status information, error classifications, abuse-prevention signals, and infrastructure logs to the extent generated or made available by the hosting and service stack.
- Payment-flow data: information necessary to create, reconcile, verify, and associate a payment with an order, including provider-generated identifiers and webhook/IPN information.
4. Information we do not request for ordinary report generation
WalletScope is not designed to require private blockchain credentials for the ordinary operation of its report-generation service. You should never submit a private key, seed phrase, recovery phrase, wallet password, exchange password, authentication token, or other secret credential into a report request, support message, coupon field, or any other WalletScope interface. Such information is unnecessary for the service and should be treated as confidential regardless of whether a particular interface appears capable of accepting it.
5. Public blockchain information and the distinction between personal data and public data
A blockchain address may be pseudonymous rather than inherently anonymous. Although a protocol-level address may not directly contain a conventional civil identity, transactions and associated metadata can sometimes be correlated with information published elsewhere by the address owner, counterparties, exchanges, applications, repositories, websites, or other actors. WalletScope may process such publicly available information as part of generating an analytical report; however, the presence of a correlation, search result, username, repository, or other external reference does not by itself establish that the referenced person is the legal or beneficial owner of a blockchain address.
6. Purposes of processing
Information may be processed for the purposes of validating a request, determining package eligibility, applying a coupon, creating and reconciling an order, initiating and verifying payment, retrieving blockchain information, querying configured external sources where the purchased package includes such functionality, generating the requested report, providing report access, detecting malformed or abusive requests, enforcing technical limits, maintaining service integrity, diagnosing failures, preventing fraud or unauthorized use, and maintaining auditable operational state necessary for the functioning of the service.
7. Blockchain data providers and third-party dependencies
WalletScope may rely upon third-party infrastructure and data providers for blockchain retrieval and external-source enrichment. For Bitcoin, the service may use Mempool.space; for Ethereum, it may use Alchemy; external search and repository references may be obtained from configured third-party services such as Tavily and GitHub. These providers operate independently and may apply their own privacy policies, retention practices, rate limits, availability constraints, and technical controls. WalletScope cannot guarantee the completeness, timeliness, persistence, or uninterrupted availability of information supplied by an external provider.
8. Payment processing
Paid orders may be processed through NOWPayments or another payment mechanism expressly presented at checkout. WalletScope uses provider-generated payment information to associate a payment event with an order and to determine whether the order may proceed to report generation. Payment providers may process information under their own terms and privacy documentation. WalletScope does not need to receive or retain your private blockchain credentials merely because a cryptocurrency payment is used.
9. Webhooks, IPN messages, and payment verification
Payment status may be communicated to WalletScope through provider callbacks, webhooks, or IPN-style notifications. The application may validate the authenticity and integrity of such notifications using provider-defined cryptographic signature mechanisms before changing payment state. Receipt of a network callback does not necessarily mean that the underlying payment is irrevocable, final, or immune from provider-side reconciliation; WalletScope may therefore maintain internal payment states and transition an order to report generation only after the conditions configured for that payment flow are satisfied.
10. Report generation and derived information
A report may contain a mixture of directly retrieved blockchain data, normalized fields, calculated summaries, search-derived references, and analytical observations. The generated report is therefore a derived informational artifact rather than a raw blockchain record. Analytical or contextual statements may depend on the quality, scope, indexing state, and temporal freshness of upstream data and should not be interpreted as an independently verified identification of a person or organization.
11. Data minimization and internal identifiers
Where practical, WalletScope uses internal identifiers and non-human-readable order tokens rather than exposing database identifiers as the primary report-access mechanism. Report-access credentials may be represented in hashed form for storage so that possession of the persistent database representation does not itself constitute possession of the original access token. These controls are intended as defense-in-depth measures and do not constitute an absolute guarantee against compromise.
12. Caching and performance optimization
To reduce redundant provider requests and improve response performance, WalletScope may cache selected blockchain-derived information for a limited operational period. Cached information is subject to expiration and may become stale relative to the underlying blockchain or provider index. Cache invalidation and expiration mechanisms are operational controls, not a promise that every report will reflect a particular block height or an exact real-time state.
13. Cookies and similar technologies
The core report workflow is designed to operate without requiring advertising cookies. Nevertheless, hosting infrastructure, security mechanisms, analytics systems, or third-party integrations, if introduced or enabled, may employ cookies, local storage, request identifiers, or similar technical mechanisms. Where such technologies are used, their purpose should be understood from the relevant interface and applicable notices.
14. Security measures
WalletScope uses reasonable technical and organizational measures appropriate to a small cloud-native application, which may include HTTPS transport, access controls, environment-based secret configuration, cryptographic verification of payment callbacks, input validation, rate limiting, non-custodial architecture, restricted administrative endpoints, hashed report-token storage, and separation of application concerns. Security controls are necessarily subject to implementation limits, provider dependencies, configuration errors, zero-day vulnerabilities, credential compromise, and other risks inherent to Internet-connected systems.
15. Retention
Different categories of information may be retained for different periods according to operational necessity. Order and payment state may be retained for reconciliation, fraud prevention, accounting, service integrity, dispute handling, and legal obligations. Report data and cached data may be retained according to the service's implementation and lifecycle policies. Security records may be retained for a period reasonably necessary to investigate abuse, maintain system integrity, or satisfy applicable obligations. Data that is no longer required may be deleted, anonymized, aggregated, or rendered operationally inaccessible where technically and legally appropriate.
16. International processing
Because WalletScope relies on globally distributed cloud infrastructure and third-party service providers, information may be processed in jurisdictions other than the country in which the user is located. Where applicable law imposes requirements concerning international transfers, WalletScope intends to use legally recognized mechanisms appropriate to the circumstances; however, the exact processing location may vary as infrastructure providers and service dependencies change.
17. Disclosure to service providers
Information may be disclosed or made technically accessible to infrastructure, hosting, payment, blockchain-data, search, repository, security, and operational service providers to the extent reasonably necessary to provide the requested functionality. Such providers are not thereby authorized to transform WalletScope's service into a custodial wallet or to receive private wallet credentials that WalletScope does not require.
18. Legal, security, and abuse-related disclosures
WalletScope may disclose information where reasonably necessary to comply with a binding legal obligation, respond to a valid governmental or judicial request, investigate suspected fraud or abuse, protect the security or integrity of the service, enforce applicable terms, or protect rights, property, or safety. Such disclosures are intended to be limited to information reasonably relevant to the stated purpose, subject to applicable law.
19. User rights and requests
Depending on the user's jurisdiction and the applicable legal framework, a user may have rights concerning access, correction, deletion, restriction, objection, portability, or other forms of control over personal information. Because WalletScope may process information that is publicly available on decentralized networks and may not be able to alter third-party or blockchain records, a request directed to WalletScope cannot necessarily cause an underlying blockchain record or independently published third-party content to be erased.
20. Third-party websites and references
Reports may contain links or references to third-party websites, public repositories, blockchain explorers, search results, or other external resources. Following such a reference moves the user into an environment governed by the third party's own policies. WalletScope does not control third-party content, availability, accuracy, security posture, or subsequent changes to an external resource.
21. Children
WalletScope is not intentionally designed as a service for children. Users should not provide unnecessary personal information through the service, and guardians should ensure that use of the service is consistent with applicable age and contractual requirements.
22. Changes to this Privacy Policy
This Privacy Policy may be revised when the service architecture, provider dependency chain, legal requirements, security controls, or data-processing practices materially change. The updated version will identify a revised effective or update date. Continued use after an update may be subject to the revised policy to the extent permitted by applicable law.
23. No absolute security guarantee
No Internet service, database, cloud environment, API integration, cryptographic system, or transmission channel can be represented as mathematically or operationally immune from compromise. Accordingly, WalletScope does not represent that unauthorized access, data loss, service interruption, provider failure, malicious traffic, software defects, or other security incidents are impossible; the service instead applies reasonable controls intended to reduce the probability and impact of such events.
24. Contact
For privacy-related questions, requests, or notices, use the contact channel made available by WalletScope on its current website or service interface. A request should contain enough information to identify the relevant issue without unnecessarily including private keys, passwords, seed phrases, payment credentials, or other sensitive secrets.