Legal

Privacy Policy

Last updated: 28 July 2026

This Privacy Policy explains what information ChainProof processes when you visit this website or run an AML risk check, why we process it, and what rights you have over it. It is maintained by the operator of ChainProof and may be updated as the service changes.

What we collect

We aim to collect as little as possible. In practice the data falls into three groups:

  • Screening input: wallet addresses, transaction hashes and network identifiers you submit for a check. These are public blockchain identifiers, not personal documents.
  • Technical data: IP address, browser and device type, language, and timestamps of requests, collected automatically by the hosting layer for security and abuse prevention.
  • Contact data: only if you write to us — your email address and the content of your message.

What we do not collect

  • We never ask for private keys, seed phrases or wallet passwords. Nobody legitimate ever will.
  • We do not require an identity document to view informational pages on this site.
  • We do not sell personal data and do not share it with advertising networks.

Why we process it

  • To deliver the AML risk report you requested.
  • To keep the service secure: rate limiting, fraud and abuse detection.
  • To improve accuracy of risk scoring using aggregated, non-identifying statistics.
  • To comply with legal obligations that apply to the operator.

Legal bases

Where the GDPR applies, we rely on performance of a contract (providing the check you asked for), our legitimate interest (security, service quality) and legal obligation. Where consent is required — for example for non-essential analytics — we ask for it and you can withdraw it at any time.

Cookies and analytics

Essential cookies keep the interface working, remember your language and protect forms. Any analytics we use is configured to avoid cross-site tracking and profiling. You can block cookies in your browser; essential functions will still work.

Retention

Screening inputs and generated reports are kept only as long as needed to deliver and re-open your report, then deleted or aggregated. Technical logs are kept for a short security window. Correspondence is kept until the question is resolved plus a reasonable archive period.

Sharing

We share data only with infrastructure providers acting on our instructions (hosting, blockchain data sources, error monitoring), and only to the extent needed to run the service. Every provider is bound by confidentiality and data-protection terms.

Your rights

  • Access a copy of the data we hold about you.
  • Correct inaccurate data.
  • Request deletion of data we are not required to keep.
  • Object to or restrict certain processing.
  • Receive your data in a portable format.
  • Complain to your local data-protection authority.

Security

Traffic is encrypted in transit, access to production systems is limited to a small number of authorised people, and secrets are stored outside of application code. No system is perfectly secure, so we also limit what we store in the first place.

Children

The service is not intended for people under 18 and we do not knowingly process their data.

Changes

If this policy changes materially we will update the date at the top of the page and, where appropriate, highlight the change in the interface.

Contact

For privacy questions or to exercise your rights, contact the site operator through the contact details published on this website. We answer requests within 30 days.