CryptRing
Legal

Privacy Policy

Last updated 16 July 2026

Your privacy in plain language: CryptRing never connects to your wallet, runs no ad trackers and no analytics you have not accepted, and asks our data providers for token information from our own servers — so they never see you. We collect the minimum needed to run scans and accounts, and we don't sell your data.

Draft — not yet in force

CryptRing does not yet have a registered legal entity, so the operator details below are placeholders and this text is not a binding agreement. It takes effect once the entity is registered and those details are filled in.

Contents

1. Who is responsible for your data

The controller of your personal data is [COMPANY LEGAL NAME] S.R.L., registered in Romania under [TRADE REGISTER NUMBER], VAT/fiscal code [CUI / VAT ID], registered office [REGISTERED ADDRESS], Romania.

For anything about your data — questions, requests, complaints — email privacy@cryptring.com. We are not required to appoint a Data Protection Officer and have not appointed one; that address reaches the people who actually handle this.

This policy explains what we collect on cryptring.com and why. It sits alongside our Terms of Service.

2. The short version

We never ask you to connect a wallet. No wallet connection, no transaction signing, no seed phrases, no private keys — there is nothing for you to approve and no way for us to touch your funds.

Four things that are true of CryptRing and unusually rare on the web:

  • No ad trackers. We run no pixels, no advertising SDKs, no session recording, and no third-party tag except the one below.
  • Analytics you can refuse. We use Google Analytics to count pages and a handful of actions. It starts switched off: nothing is stored on your device and no analytics cookie is set unless you accept. Refusing costs you nothing on this site.
  • Our servers do the asking, not your browser. When we fetch token data, the request comes from us — your IP address is never disclosed to our data providers. Even token images are fetched by our server, so image hosts never see you either.
  • Fonts are served from our domain. Your browser never contacts Google Fonts or any CDN.

We do not sell your personal data, and we never will.

3. What we collect

If you create an account:

  • Your email address.
  • A display name — we don't ask you for one, we derive it automatically from the part of your email address before the @ symbol.
  • Your password, stored only as a cryptographic hash — we cannot read it, and neither can anyone who obtains the database.
  • Whether you have confirmed your email address.
  • Your scan history: which token addresses you scanned, the score and verdict at the time, and when. This is also how we count your daily allowance.

When you are signed in:

  • A session record containing your IP address and browser User-Agent, created when you sign in. We keep this to secure the account. We record it; we don’t currently monitor or alert on it.

If you subscribe to Pro:

  • Your Stripe customer, subscription and price identifiers, which plan you're on, your subscription status including any pending cancellation, and when the current period ends.
  • We do not receive or store your card number, expiry, or CVC. Those go directly to Stripe.

From everyone, signed in or not:

  • Your IP address, used to apply rate limits and the anonymous scan allowance, and to protect the service from abuse.
  • Standard server logs — the pages requested and when. These include the URL, which matters for wallet lookups (see section 5).

4. Token addresses you scan

Solana mint addresses are public blockchain identifiers. They identify a token, not you.

If you're signed in, we store the addresses you scan against your account, so we can show you your history and count your allowance. That record does link you to the tokens you looked at and when — it is a behavioural record, and we treat it as personal data even though the addresses themselves are public.

If you're not signed in, your scan history is kept only in your own browser's local storage (up to 30 entries) and never reaches our database. Clearing your browser data deletes it, and we have no copy.

Token report pages are public and indexed by search engines. The page shows the token, not who scanned it — we never publish, expose, or share who looked up what.

5. Wallet addresses you look up

The portfolio tracker works from an address you paste in. There is no wallet connection.

When you look one up, we send that address to Helius, our Solana data provider, to read what it holds. We keep the result in the server's memory for about a minute so a refresh doesn't re-fetch it; after that we stop using it and fetch fresh data instead. It is never written to our database, never linked to your account, and the in-memory copy is discarded when the server restarts.

The address appears in the page URL. That means it lands in your browser history, in our server logs, and in the Referer header if you click an outbound link from that page. If you don’t want an address associated with you, be careful about sharing that link.

You can look up any address, including someone else's. Everything shown is already public on-chain, but see section 13 of our Terms for how to use that responsibly.

6. Why we're allowed to use it

Under the GDPR we need a legal basis for each purpose. Ours are:

  • Running your account and Pro — creating your account, signing you in, saving your history, counting your allowance, taking payment. Basis: performance of our contract with you.
  • Keeping the service up and honest — rate limiting by IP, the anonymous scan allowance, blocking abuse and fraud. Basis: our legitimate interest in a service that stays available and isn’t drained by bots. We use the least identifying thing that works — an IP address — and keep it briefly.
  • Security — the IP and User-Agent on your session, so you and we can tell your sign-ins from someone else’s. Basis: our legitimate interest in protecting accounts.
  • Billing records — keeping invoices and subscription history. Basis: our legal obligation.

Consent is used for exactly one thing: analytics. Everything else here runs on contract, legitimate interests or legal obligation — no marketing profiling, no ad targeting. Refusing analytics leaves every feature working.

7. Cookies

We set exactly one cookie without asking, and only once you sign in: a session cookie that keeps you signed in. It is strictly necessary — without it you could not stay logged in.

  • Name: better-auth.session_token (__Secure-better-auth.session_token over HTTPS).
  • Lifetime: 7 days, extended while you keep using the site.
  • Settings: HttpOnly (JavaScript can’t read it), SameSite=Lax, and Secure in production.

No advertising cookies and no third-party cookies. Signing out deletes it; so does clearing your site data.

Google Analytics sets its own cookies, and only if you accept it. Your answer is remembered on this device — in local storage, not in a cookie — and you can change it at any time, as easily as you gave it.

Analytics is your call on every device. .

8. Who else touches your data

We use a small number of providers to run the service. Each gets only what it needs to do its job.

Providers that receive personal data:

  • Stripe (payments) — your email address and your CryptRing user id when you go to checkout, plus the card and billing details you give Stripe directly. United States and Ireland.
  • Resend (email) — your email address and the verification or password-reset link, when we send you one. United States.
  • Google Analytics (audience measurement) — the pages you view and a few actions, plus a truncated IP address, and only after you accept analytics. Never your email, wallet or the mints you scan. United States.
  • Upstash (rate limiting) — your IP address, as a short-lived key. Only where enabled; it expires automatically, at most 48 hours. United States.
  • Helius (Solana data) — a wallet address, when you use the portfolio tracker. Never your identity, your email, or your IP. United States.
  • Our hosting and database providers — they store and serve everything above on our instructions.

Providers that receive no personal data at all:

  • DexScreener, Jupiter and GeckoTerminal (market data) — our server makes these calls, so they don’t see you, your IP, or that it was you who asked. They see the token address being looked up and, in Jupiter’s case, the text you type into the search box, which we pass on to match against its token list. We send them nothing that identifies you.

Everyone above acts as our processor under a contract, except Stripe, which is also a controller for its own payment and anti-fraud purposes.

We may also disclose data if the law requires it, to establish or defend a legal claim, or to protect the rights and safety of our users. If our business is sold or reorganised, data may transfer to the buyer under this same policy.

9. Sending data outside the EEA

Some of the providers above are based in the United States, so your data may be processed there.

Where a provider is certified under the EU–US Data Privacy Framework, that certification covers the transfer. Otherwise we rely on the European Commission's Standard Contractual Clauses. Either way, the provider is contractually bound to protect your data to European standards.

Ask us at privacy@cryptring.com if you want the detail for a specific provider.

10. How long we keep it

  • Account data (email, password hash, display name) — for as long as your account exists, and up to 30 days after you ask us to delete it.
  • Scan history — for as long as your account exists, and removed within 30 days when you ask us to delete the account.
  • Sessions (IP, User-Agent) — a session expires 7 days after you last use it, and each use restarts that window, so a session you keep using stays alive while you keep using it. We delete the record as soon as you sign out or reset your password; otherwise it is removed when your account is deleted.
  • Rate-limit records (IP) — expire automatically: the abuse and burst counters within a couple of minutes, and the anonymous free-scan counter within 48 hours (a 24-hour window, plus the further window the limiter has to keep in order to measure it).
  • Email verification and reset tokens — 1 hour, then deleted automatically.
  • Billing and invoice records — 10 years, because accounting and tax law requires it. This one outlives a deletion request; see section 11.
  • Anonymous scan history in your browser — until you clear your site data. We never have it.

Aggregate token statistics we compute — holder counts, concentration percentages, launch analysis — are about tokens, not people, and contain no personal data. We keep those indefinitely.

11. Your rights

If you're in the EU or EEA, the GDPR gives you the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted.
  • Restriction — have us pause processing while a dispute is sorted out.
  • Portability — get your data in a machine-readable format.
  • Objection — object to processing based on our legitimate interests, including the rate limiting and session security described in section 6.

To use any of them, email privacy@cryptring.com from the address on your account. We answer within 30 days, and it’s free. We may need to check you are who you say you are before we act.

One honest limit on erasure: if you have ever paid us, we must keep the invoice for 10 years under tax law. We delete everything else and strip the invoice record back to the legal minimum.

We don't do automated decision-making that produces legal effects about you. The RingScore is an automated assessment of a token, not of any person.

12. Deleting your account

You can delete your account yourself, at any time, from the My scans page — scroll to “Delete account”. It asks for your password and then removes your account, your saved credentials, your sessions and your scan history immediately, subject to the invoice-retention rule in section 11. There is nothing to wait for and no one to ask.

If you would rather we did it for you, email privacy@cryptring.com from your account address and we’ll do it within 30 days.

We delete the whole account rather than parts of it — your scan history is what counts your daily allowance, so deleting the history on its own would just hand out a fresh allowance. If you want the history gone, the account goes with it.

If you have an active Pro subscription, cancel it first — otherwise Stripe would keep billing a subscription for an account that no longer exists.

Public blockchain data is not ours and we cannot erase it. Nothing on-chain identifies you as a CryptRing user.

13. Security

Passwords are hashed, never stored in readable form. The site is served over HTTPS. The session cookie can't be read by JavaScript. Card data never reaches our servers. Each active session records the IP address and browser it was created from, and resetting your password kills every existing session.

No system is perfectly secure, and we won't pretend otherwise. If we ever suffer a breach that puts your rights at risk, we'll tell you and the supervisory authority as the law requires.

Found a security problem? Email hello@cryptring.com. We welcome it and we won’t pursue anyone who reports a genuine issue in good faith.

14. Children

CryptRing is for adults — you must be 18 or older to use it. We don’t knowingly collect data from children. If you believe a child has given us personal data, email privacy@cryptring.com and we’ll delete it.

15. Changes to this policy

We'll update this policy as the product changes. The date at the top tells you when we last did.

If a change materially affects how we handle your data and you have an account, we'll email you at least 30 days before it takes effect. If we ever add error monitoring or another third-party tag, it'll appear in section 8 before it goes live — not after.

16. Complaints

If you think we’ve mishandled your data, please tell us first at privacy@cryptring.com — we’d rather fix it than have you fight for it.

You also have the right to complain to a data-protection supervisory authority — in Romania that is ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), and you can go to the authority in the EU country where you live or work instead.

Questions about this document? Email hello@cryptring.com.
Back to scanner