Privacy Policy
Last updated: 22 September 2026
Draft for legal review. CryptoPreflight is in testing and this document has not been reviewed by an attorney. Do not rely on it as a final privacy notice.
What we never ask for
CryptoPreflight never asks for wallet or exchange passwords, credentials or recovery information — including seed phrases, recovery phrases, private keys and two-factor codes. It never connects to a wallet, never holds funds and never signs, sends, cancels or reverses a transaction. If any page ever appears to ask for those, stop and contact us.
What an account stores
Separately from the above: saving records requires your own CryptoPreflight account. You sign in with an email address and a password you choose here, or with Google. That password belongs to this site only. We store your account identifier, your email address, and the preflights you create.
A saved preflight holds the details you entered:
- asset, amount, and the networks instructed and selected;
- the sending and destination platforms you named;
- the destination address and any memo or destination tag;
- the check results, their sources and the time each was recorded;
- your acknowledgements, any test-transaction hash, and your receipts.
Rows are isolated per account by database access rules: another signed-in user cannot read, change or delete your preflights.
Confirmation links you send to someone else
When you ask a recipient to confirm their details, we create a single-use link. Only a hash of the link token is stored, so the link cannot be reconstructed from our database. The link expires after 72 hours, stops working once answered, and can be revoked by you at any time. The recipient is never shown your entries — not on the page and not in the data that page receives, before or after they answer. They type the asset, network, address and any memo or destination tag themselves, and the comparison happens on our server. After submitting, the recipient sees only which of their fields matched. You see which fields matched, whether all of them matched, and any note they wrote. The values the recipient typed are stored against your preflight in our database but are not shown back to either side; they are deleted with the preflight.
Public blockchain lookups
When you submit a test-transaction hash, we query free public blockchain sources to read what is already published on-chain. Those requests carry the transaction hash and no account information. We do not use scam databases, sanctions lists or paid risk providers, and we do not claim to.
Usage measurement
Product-usage events are recorded in your browser session only. Addresses, memos, amounts and email addresses are removed before an event is recorded. No third-party analytics service is connected.
Retention and deletion
A preflight is kept until you delete it. Deleting a preflight removes its details, checks, confirmation links, recipient responses, test transactions, acknowledgements and receipts from the live database. Copies may remain in our database platform's routine backups for a short period until those backups roll over; we do not restore deleted records into the product. Early-access sign-ups are kept until you ask for removal. Write to hello@cryptopreflight.app for account deletion or any privacy request.
Not yet settled
Encryption at rest beyond the database platform's own defaults, exact retention periods, a list of sub-processors, and the legal bases for processing under GDPR, UK GDPR and CCPA are all still to be confirmed with counsel. We will not publish claims about them until they are verified against what is actually running.