Privacy Policy
What data we collect, why, how long we keep it, and how you can exercise your GDPR rights.
Privacy in 30 seconds
- 🪪 Accounts are optional. Browse fully without signing in.
- 📊 Google Analytics only after you click Accept.
- 🗒 Access logs (IP, path) kept ≤ 14 days, then deleted.
- 🚫 We don't sell data, run ads, or build profiles.
- 🌍 EEA infrastructure. GA transfers via DPF safeguards.
- 🔄 You can withdraw consent anytime — see manage below.
This Privacy Policy explains what personal data we collect when you use the Quantascan website (the “Site”), why we collect it, how long we keep it, who we share it with, and what rights you have. It applies to all visitors to the Site, including those who use our public API.
Section 01
Who is responsible
The Site is operated by an independent operator (the “Operator”, also “we”, “us”). For the purposes of the EU General Data Protection Regulation (GDPR), the Operator acts as data controller for the personal data described in this policy.
One contact channel for all privacy matters
We can be reached for all privacy matters — including data-access and erasure requests — by sending a message @12remember on the QRL Discord. Please allow up to one month for a reply, in line with GDPR Art. 12(3).
Section 02
What we collect and why
2.1 — Technical / server-log data
When you visit the Site or call our API, our servers automatically receive and log the following technical information:
- your IP address;
- the date and time of the request;
- the page or API endpoint requested;
- the HTTP status code and response size;
- your browser’s user-agent string and the referring URL;
- (where applicable) an API key if you are using the authenticated API.
Why: to operate the Service, detect and prevent abuse, debug errors, comply with rate limits and meet legal obligations. Legal basis (GDPR Art. 6(1)(f)): our legitimate interest in operating a secure, available Service. Retention: raw HTTP access logs are kept for a maximum of 14 days, after which they are deleted from our log aggregator. Aggregated, non-identifying metrics may be kept longer for capacity planning.
2.2 — Error monitoring
We may use a self-hosted or vendor-hosted error-monitoring tool (e.g. Sentry / GlitchTip) to capture uncaught errors so we can fix bugs. Error reports include the URL on which the error happened, a stack trace, and basic browser metadata.
2.3 — Analytics (Google Analytics 4)
We use Google Analytics 4 (operated by Google Ireland Ltd) to understand which pages are visited, on which devices, and via which navigation paths. We use it in privacy-preserving mode:
- Consent Mode v2— no analytics cookies or user-identifiers are set until you click “Accept”.
- IP anonymisation — the last octet of your IP is dropped by Google before any further processing.
- No Google Signals, no cross-device tracking, no advertising features, no remarketing audiences.
- Data retention set to the GA minimum of 2 months.
Legal basis (GDPR Art. 6(1)(a)): your explicit consent, given via the cookie banner. You can withdraw consent at any time via the link in Manage preferences below.
2.4 — Functional storage
We use a small number of strictly necessary entries in your browser’s localStorage and first-party cookies to remember:
- your light/dark theme;
- your language choice;
- your cookie-consent choice (so we do not show the banner on every page);
- your dismissal of UI hints (e.g. tooltips, banners).
Legal basis:these are “strictly necessary” for the functioning of the Site (ePrivacy Directive, Art. 5(3) exemption) and do not require consent. Retention: until you clear your browser storage.
2.5 — Blockchain data on the Site
Public on-chain data, not data about you
The Site displays public data read from the QRL and QRL2 blockchains, including addresses, balances, transactions and smart-contract source code. This is not personal data about you — it is public on-chain data available to anyone running a node. We act as a viewer, not a collector, of this data.
2.6 — Voluntary submissions
If you message us, submit an address label, report a token, file a DMCA notice or otherwise reach out, we keep your message and any attachments for as long as needed to resolve the matter (and, where required, to keep a record of compliance) — typically up to 24 months. We do not use these contact details for marketing.
2.7 — Account data (optional)
You can use the Site without an account. If you choose to create one, sign-in is handled by our authentication provider Supabase, optionally through a social login with GitHub or Discord (see §5). We store the following in our own database, keyed to your account identifier, for as long as your account exists:
- Identity — your email address and any display name and avatar supplied by your sign-in provider.
- Preferences — your notification, language, timezone and currency settings, and a record of your consent choices.
- Saved data — your watchlists, price and activity alerts, in-app notifications, and any private address labels, transaction notes or hidden-token choices you create. These are private to your account and never shown to anyone else.
- API keys — a label and a one-way hash of each key you create (never the key itself), plus per-day usage counts.
- Activity log — security-relevant account events (sign-ins, key and profile changes, exports). We store a hashed, non-reversible form of your IP address — never the raw address.
We use this strictly to operate your account and keep it secure (legal basis: performance of a contract and our legitimate interest in security). We never sell it or use it to build advertising profiles. Marketing email is off unless you explicitly opt in, and you can withdraw at any time in your account settings.
Self-service: export or delete your account data
Signed-in users can download all of their account data as a JSON file, and delete their account (a 30-day grace period applies, after which the data is permanently erased) — both directly from Account → Privacy & data, no request needed. Public on-chain data is unaffected by account deletion.
Section 03
Cookies and similar technologies
A cookie is a small file stored on your device. localStorage is browser-built-in storage with similar characteristics. The Site uses the following:
| Name | Category | Purpose | Set by | Expiry |
|---|---|---|---|---|
| sb-* (auth) | Strictly necessary | Keeps you signed in (only set once you log in) | Supabase / Quantascan | Session |
| qs_locale | Strictly necessary | Remember your language choice | Quantascan | 12 months |
| theme * | Strictly necessary | Remember light/dark theme | Quantascan | Until cleared |
| qs:consent * | Strictly necessary | Stores your cookie choice | Quantascan | Until cleared |
| _ga, _ga_* | Analytics | Distinguish unique visitors | Google Analytics 4 | Up to 2 years |
* Stored in your browser’s localStorage rather than in a cookie. It never leaves your device and is not sent to our servers, but we list it here for full transparency. All entries above except _ga / _ga_* are strictly necessary and set without consent; the analytics cookies load only after you accept.
Section 04
Manage your cookie preferences
You can change or withdraw your analytics-cookie consent at any time:
You can also block or delete cookies directly via your browser settings. Blocking strictly necessary cookies may break parts of the Site (e.g. theme switching).
Section 05
Who we share data with
We share data only with the following categories of recipients, each acting as a data processor (or independent controller, where noted) on a documented legal footing:
- Hosting and infrastructure — netcup GmbH, Germany (EU), which stores and processes all site data on our behalf;
- Supabase (Germany, EU) — our authentication provider. Only if you create an account, Supabase stores your sign-in identity (email and any linked social-login identities) on infrastructure within the EEA. The rest of your account data lives in our own database, not with Supabase;
- GitHub and Discord — only if you choose to sign in with one of them. The login handshake is brokered through Supabase and returns your email, username and avatar to create your account;
- Google Ireland Ltd — only if you have consented to analytics — for the analytics processing described in §2.3;
- Sentry / GlitchTip error-monitoring providers (if used; personal data is disabled — see §2.2);
- Authorities and courts where we are required to disclose data by binding law or legal process.
A current, itemised list of our sub-processors — with each provider’s role, location and safeguards — is kept in our data-processing register and available on request via the contact channel in §11.
Section 06
International transfers
Our primary infrastructure — hosting, database and authentication — is located in the European Economic Area. Personal data is transferred outside the EEA only in these cases:
- Analytics — to Google in the United States, and only with your consent (§2.3);
- Social login — if you sign in via GitHub or Discord, the OAuth exchange involves those providers in the United States.
For these transfers we rely on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses, together with additional technical safeguards (IP anonymisation and Consent Mode for analytics), to provide an adequate level of protection. If you never consent to analytics and never use a social login, your personal data stays within the EEA.
Section 07
Your rights under GDPR
If you are in the EEA, UK, Switzerland or another GDPR-aligned jurisdiction, you have the following rights with respect to your personal data:
- Right of access — to obtain a copy of personal data we hold about you;
- Right to rectification — to ask us to correct inaccurate or incomplete data;
- Right to erasure(“right to be forgotten”) — subject to the limits described below;
- Right to restriction of processing;
- Right to data portability for data you have provided to us;
- Right to object to processing based on legitimate interests;
- Right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- Right to lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
To exercise any of these rights, message @12remember on the QRL Discord. We will respond within one month, as required by GDPR. We may ask you to verify your identity before we act on a request.
Account holders: instant self-service
If you have an account, you can exercise your rights of access and portability (download your data) and erasure (delete your account) immediately and without a request, under Account → Privacy & data. You can also correct your display name and withdraw marketing consent in your account settings.
Caveat: blockchain data
On-chain transactions, balances, addresses and smart-contract code are recorded by the public QRL and QRL2 networks. We do not control those networks and cannot delete on-chain data. Your right of erasure is limited to data that we hold (server logs, analytics, contact correspondence, address labels we have assigned), not the underlying chain.
Section 08
Security
We apply industry-standard technical and organisational measures to protect personal data, including TLS encryption in transit, rate-limiting, structured access controls, principle-of-least-privilege database accounts, log rotation, and least-collection by design. No system is perfectly secure; if we become aware of a breach affecting personal data, we will notify supervisory authorities and affected users where required by law.
Section 09
Children
The Site is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please message @12remember on the QRL Discord so we can delete it.
Section 10
Changes to this policy
We may update this policy from time to time. The latest version is always posted on this page with a revised “Last updated” date. If we make a material change (for example, adding a new processor or a new category of data), we will surface a notice on the Site for a reasonable period.
Section 11
Contact
For any privacy question or to exercise your rights, please message @12remember on the QRL Discord. This is the only public contact channel for the Operator.
See also our Terms of Service.