Privacy Policy
Last updated: September 26, 2026
This policy explains what data XCA collects, why, and what you can do about it. We collect as little as we need to run the service.
What we collect
Account data: the email address you sign in with, or the public addresses of wallets you connect. We never ask for private keys or seed phrases.
Session and security data: a session token stored in a cookie, the IP address and browser of active sessions, and sign-in attempts to prevent abuse.
Product data: your watchlist, alert rules, API keys (stored only as hashes), a linked Telegram chat if you connect one, usage counters and payment records, including on-chain transaction signatures.
Cookies
We use a session cookie to keep you signed in and a language cookie to remember your language. We do not use advertising or cross-site tracking cookies.
How we use data
To provide the service: sign you in, run scans, apply your plan, deliver alerts and verify payments.
To keep it safe: rate limiting, fraud prevention and investigating abuse. We do not sell personal data.
Service providers
We rely on a small number of processors: an email delivery provider for sign-in codes and receipts, an optional wallet sign-in provider, our hosting and CDN providers, and blockchain data providers. They process data only to provide their service to us.
Public blockchain data
Token holders, trades and wallet histories are public on the blockchain. XCA analyses this public data; wallet addresses shown in reports are not linked to your account unless you connect them yourself.
Retention and your rights
Expired sessions and sign-in codes are deleted automatically. Account data is kept while your account exists; payment records may be kept longer where required by law.
You can review and remove sign-in methods in your account, disconnect Telegram, revoke API keys and ask us to delete your account.
Contact
Reach us through the community links at the bottom of this page.