2) What data we process and why
A) Server access & security logging (stats.db)
When you visit this website, we process technical access data to operate the service and protect it against abuse.
The application logs:
timestamp, HTTP method, path, status code, user-agent, referer.
Your IP address is not stored in plain form; instead we store a salted SHA-256 hash (ip_hash) for approximate unique-visitor counting.
Legal basis: Art. 6(1)(f) GDPR (legitimate interests: operation, debugging, abuse prevention).
Retention: 30 days (then deleted).
B) Wallet lookup features
If you enter a wallet address or a .anyone domain, the server processes the input to fetch and display network-related information (e.g., consensus presence, bandwidth, flags, geo distribution).
Legal basis: Art. 6(1)(f) GDPR (legitimate interests: providing the requested information/service).
C) Operator profiles (optional user-submitted content)
You may create or edit an operator profile. The website may store:
wallet address (identifier), optional X handle, optional Telegram handle, a short bio, and an optional profile image you upload.
You can delete your profile, which also triggers best-effort deletion of the stored image file.
Legal basis: Art. 6(1)(b) GDPR (providing the requested profile feature) and/or Art. 6(1)(a) GDPR (where you voluntarily provide optional fields).
Retention: Until deletion by the user.
D) Authentication (Connect & Sign)
To protect profile management, we use an authentication flow where you sign a challenge with your wallet.
The server stores a short-lived nonce and sets an auth cookie (op_auth) to keep you logged in for a limited time.
Legal basis: Art. 6(1)(f) GDPR (security; preventing unauthorized profile changes).
Retention: nonce: minutes; auth cookie: typically up to ~30 minutes (or until you log out).
E) Embedded third-party content
Some pages can load third-party iframes (e.g., TradingView price chart, DepinHub explorer). When loaded, your browser connects to those providers and they may process personal data (e.g., IP address, device/browser information) under their own responsibility.
Depending on your browser settings, third-party cookies may be set by them.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest: providing useful embedded information). If you prefer, you can avoid loading embeds by not clicking “Load chart” and by blocking third-party resources in your browser.
3) Recipients
Data is processed on a virtual private server (VPS) located in Germany. No reverse proxies, CDNs, or external logging services are used.
Embedded third-party providers (if loaded) process data under their own responsibility.
4) Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18),
data portability (Art. 20), and objection (Art. 21) under the GDPR, where applicable.
You also have the right to lodge a complaint with a supervisory authority (Art. 77).