Privacy Policy
Last updated 10 August 2026
Version 2.0 · effective 10 August 2026
This Privacy Policy explains how CryptoDoctor.ai ("CryptoDoctor", "we", "us") processes personal data in connection with CryptoDoctor.ai.
CryptoDoctor is designed to minimise identity data. A user can use core diagnostic functionality without giving CryptoDoctor a real-world identity, but some technical identifiers and optional information can still constitute or become personal data.
1. Controller
The controller responsible for CryptoDoctor.ai is CryptoDoctor.ai.
Privacy contact: [email protected]
2. Data we process
Depending on how the Service is used, we may process the following categories.
2.1 Public blockchain and diagnostic data
- wallet addresses and token contract addresses submitted for analysis;
- public balances, transfers, approvals and other on-chain activity associated with those addresses;
- public smart-contract and token data;
- third-party security, liquidity, holder and market-data fields used by the diagnostic pipeline;
- report scores, technical findings, snapshot time, coverage status and generated report content.
Blockchain data is public by design, but a wallet address may in some circumstances be linked to an identifiable person. We therefore treat wallet-related data as potentially personal where it is linked or reasonably linkable to an individual.
Submitting an address does not prove ownership of that address.
2.2 Account and authentication data
Depending on the authentication options enabled and selected, we may process:
- pseudonymous account identifiers;
- passkey/public-key credential identifiers and related authentication metadata;
- wallet address used for sign-in and cryptographic-signature authentication records;
- email address, only where the user chooses an email-based feature, such as email sign-in, recovery, report delivery, notifications or support correspondence;
- account settings and notification preferences.
We do not need a user's legal name for ordinary CryptoDoctor diagnostic functionality unless a law or a specific support process requires it.
2.3 Order and payment metadata
We may process:
- order/reference ID;
- service purchased;
- amount and displayed currency;
- payment status;
- the transaction hash and paying address observed on-chain, used to reconcile the payment against the order;
- refund and dispute status.
Payments are settled directly on-chain. We do not operate a payment gateway, do not receive card or bank details, and do not collect payment-provider identity-verification data.
2.4 Technical, security and anti-abuse data
We may process:
- a one-way salted hash derived from the IP address, used for rate limiting, abuse prevention and security;
- browser/device and request metadata;
- timestamps;
- server, application, error and security logs;
- fraud/abuse flags generated by our systems.
Identifiers used only for rate limiting are stored hashed with a secret salt rather than in raw form, and are not used to build advertising profiles. We do not log request bodies.
2.5 Support, complaint and feedback data
If a user contacts us, we may process the information the user provides, including email address, order/report ID, message content, attachments, complaint history and feedback/rating.
3. What we do not request
For Wallet Checkup and Token Screening, CryptoDoctor does not request and users must not provide:
- private keys;
- seed phrases;
- wallet passwords;
- exchange passwords; or
- credentials that allow CryptoDoctor to control Virtual Assets.
4. Why we process data
We process data for purposes including:
- providing the report or diagnostic feature requested by the user;
- calculating deterministic technical findings and displaying report history;
- authenticating accounts and maintaining optional account functionality;
- providing email login, recovery, delivery or notifications where the user chooses them;
- processing and reconciling orders and payments;
- preventing duplicate use, abuse, fraud and security incidents;
- troubleshooting, maintaining and improving the Service;
- responding to support requests, complaints and data-rights requests;
- maintaining accounting, legal, security and dispute records; and
- sending marketing communications only where permitted and, where required, after separate consent or a valid expression of interest.
We do not use a CryptoDoctor report to make decisions about credit, employment, insurance eligibility or other decisions intended to produce comparable legal effects concerning a person.
5. Optional email and marketing
Providing an email address for login, recovery, report delivery or operational notifications does not automatically subscribe the user to marketing.
If marketing emails are offered, the marketing choice is separate, optional and not pre-selected. A user can withdraw from marketing communications at any time without losing core account functionality.
Operational messages necessary to deliver a selected service, such as a requested login link, report-delivery email, security notice or payment/complaint update, are not treated as optional marketing messages.
6. AI processing
For report generation, structured findings and selected report data may be sent to an AI service provider to generate explanatory text.
The product architecture is that AI explains supplied machine-computed findings and does not independently decide the numerical score or create new findings.
We minimise the data sent to AI providers to what is reasonably necessary for the requested function. We do not send private keys, seed phrases or wallet credentials to AI providers.
7. Service providers and recipients
We may disclose data to service providers necessary to operate CryptoDoctor, such as:
- hosting and infrastructure providers;
- blockchain node, explorer and on-chain data providers;
- token-security and market-data providers;
- AI model providers;
- email-delivery providers;
- security, logging and monitoring providers; and
- professional advisers, courts, regulators or authorities where disclosure is legally required.
We do not sell personal data to advertisers.
Material provider categories are described in this Privacy Policy. If a separate subprocessor page is published later, it will be linked from this section.
8. International processing and transfers
CryptoDoctor is an online service. Our infrastructure and providers may process data in countries other than your own.
Where personal data is transferred internationally, we will use the transfer basis, contractual measures or other safeguards required by the data-protection law applicable to that transfer.
9. Retention
We retain data only for as long as reasonably necessary for the purposes described in this Policy and for applicable legal, accounting, security, fraud-prevention and dispute-resolution obligations.
Different data categories may have different retention periods. In particular:
- temporary rate-limit and anti-abuse data is kept for the shortest period reasonably necessary for that purpose;
- account data may be kept while the account remains active and for an appropriate period afterwards where needed for security, disputes or legal obligations;
- order, payment, refund and accounting records may need to be kept longer to meet legal and financial record-keeping obligations;
- report data may remain available while the user retains access to a report or account, subject to product settings and legal retention requirements.
If a report has been intentionally made public or shared, deletion from our systems cannot delete copies independently retained by third parties.
10. Public blockchains cannot be erased by CryptoDoctor
Public blockchain networks are operated by independent participants and are not controlled by CryptoDoctor.
We cannot delete or change information recorded on an underlying public blockchain. Where applicable, a data-rights request can address copies, account links or other information held in CryptoDoctor-controlled systems.
11. Rights
Subject to applicable law and lawful exceptions, a person may have rights to:
- obtain information about processing and access personal data;
- request correction of inaccurate personal data;
- request deletion where legal conditions are met;
- request restriction or cessation of certain processing;
- object to certain processing where applicable;
- receive or transfer certain personal data in a structured format where applicable; and
- withdraw consent where processing is based on consent, without affecting prior lawful processing.
Requests can be sent to [email protected]. We may need to verify that the requester is entitled to exercise the requested right before acting on the request.
12. Security
We use reasonable technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure and destruction.
No online system is completely secure.
CryptoDoctor will not request a private key or seed phrase for Wallet Checkup or Token Screening. Anyone asking for one while claiming to be CryptoDoctor should be treated as suspicious.
13. Cookies, local storage and analytics
CryptoDoctor uses only technologies reasonably necessary for security, authentication, preferences and core Service functionality.
CryptoDoctor does not use advertising cookies, behavioural advertising pixels or non-essential analytics trackers unless this Policy and the site’s consent controls are updated before they are activated.
Strictly necessary session cookies, local storage or similar technologies may be used where needed for account/session/security functionality.
14. Children
The Service is intended for adults and is not offered to persons under 18.
We do not knowingly provide paid Virtual Asset analytics services to children.
15. Changes
We may update this Privacy Policy. The current version and effective date are published on this page.
Where a material change requires notification or consent under applicable law, we will provide it as required.
16. Contact
Privacy questions and rights requests: [email protected]
General support: [email protected]