Privacy Policy

Effective Date: June 2026

Data Collection

TrustSniffer processes deterministic, publicly available blockchain data (transaction hashes, wallet addresses, smart contract bytecode) and publicly accessible web content (DNS records, HTTP responses, DOM structure). This data is inherently non-personal.

Our Web Intelligence engine collects and analyzes publicly accessible website content including: rendered HTML/DOM structure, client-side JavaScript, HTTP response headers, SSL/TLS certificates, DNS records (A, MX, NS, TXT), WHOIS registration data, and visual page screenshots. We log URLs submitted for analysis and retain scan artifacts to improve phishing and scam detection models.

We collect limited account information when you register: email address, organization name, and API usage metadata. We do not collect or process personally identifiable information (PII) associated with wallet addresses unless you explicitly provide it. We do not extract or store end-user credentials, form inputs, or private session data from scanned websites.

GDPR & CCPA Compliance

GDPR (EU/EEA)

We process data under the legitimate interest legal basis for blockchain analytics (publicly available data). For account data, processing is based on contractual necessity. You have the right to access, rectify, erase, restrict processing, and data portability. Contact privacy@trustsniffer.com to exercise these rights.

CCPA (California)

We do not sell personal information. California residents may request disclosure of collected data categories and deletion of account data. We respond to verified requests within 45 days.

Data Retention

Analysis artifacts (risk verdicts, scan outputs) are retained for the duration of your subscription plus 90 days. Upon account deletion, all tenant-scoped data is purged within 30 days. Aggregated, anonymized analytics data may be retained indefinitely for service improvement.

Blockchain data indexed from public networks is not subject to deletion requests as it constitutes publicly available information not controlled by TrustSniffer.

Third-Party Subprocessors

We engage the following subprocessors to deliver our services:

ProviderPurposeLocation
HetznerInfrastructure hostingEU (Finland, Germany)
CloudflareCDN, DDoS protectionGlobal
PostmarkTransactional emailUS
Alchemy / InfuraBlockchain RPC nodesUS, EU

We maintain Data Processing Agreements (DPAs) with all subprocessors. The current subprocessor list is updated at least annually.

Cookies

TrustSniffer uses only essential cookies. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies, and we do not sell or share cookie data.

CookiePurposeType
SessionKeeps you signed in after you log in.Essential, first-party
SecurityProtects the site from abuse and automated attacks, set by our CDN (Cloudflare).Essential
Cookie noticeRemembers that you dismissed the cookie notice (stored locally in your browser).Essential, first-party

Because these are strictly necessary to sign you in and keep the site secure, they do not require consent. You can clear or block cookies in your browser settings at any time. Blocking the session cookie will sign you out and prevent you from logging in.

Contact

For privacy inquiries or to exercise your data rights: privacy@trustsniffer.com