Privacy Policy
The short version: Xcertify does not collect, store, or sell any personal information. When you check a wallet address or describe a situation, that content is sent to our API to generate a risk assessment. We don't know who you are, and we don't try to find out.
Who we are
Xcertify ("we", "us", "our") is a crypto address risk scoring service operated at xcertify.io. Our product includes a web application, a Telegram bot (@XcertifyBot), and a Chrome browser extension that analyse wallet addresses and suspicious situations, and return risk assessments based on publicly available on-chain data, sanctions databases, and scam intelligence.
What data we process
When you use Xcertify — via the website, the Telegram bot, or the browser extension — the following data is processed:
- Wallet addresses you submit or that are detected on the page you're viewing. These are sent to our API to retrieve a risk score.
- Situation descriptions you submit to the "Check a situation" feature (on the website or by messaging the Telegram bot). This text is analysed in real time to detect scam patterns and is not stored by us — see "How situation analysis works" below.
- Blockchain data retrieved from third-party APIs on your behalf. This data is publicly available on-chain.
- Sanctions data cross-referenced from the publicly available U.S. Treasury OFAC sanctions list.
Apart from an email address you voluntarily provide to join our extension waitlist (see "Data retention"), we do not collect names, email addresses, browser fingerprints, or any other information for the purpose of identifying you as an individual. We do not use analytics or tracking of any kind.
How situation analysis works
The "Check a situation" feature lets you describe a suspicious situation, or paste messages you have received, to check them against known scam patterns. When you use it:
- Your text is sent to our API and forwarded to Anthropic's Claude API, which classifies it against known scam patterns. Anthropic processes this text to generate the analysis; under Anthropic's commercial API terms, it is not used to train their models.
- Any wallet addresses found in your text are checked using the same services as an ordinary address check.
- We do not store the text you submit. After analysis, we record only anonymous, pattern-level metadata (for example: which scam pattern was matched, the confidence level, and how many addresses were found) to improve scam detection. This metadata contains none of your text.
Please avoid including personal information about yourself or others (names, phone numbers, account details) in situation descriptions — it is not needed for the analysis.
How the Telegram bot works
@XcertifyBot runs on the Telegram Bot API. When you message the bot, Telegram delivers your message (and its associated chat ID) to our service so we can reply. Wallet addresses and situation text sent to the bot are processed exactly as described above. We use the chat ID only to send the reply and to apply per-user rate limits — we do not build profiles of bot users or store message history. Telegram itself processes your messages under its own privacy policy.
How the browser extension works
The Xcertify Chrome extension scans the text content of pages you visit to detect crypto wallet addresses. Detected addresses are sent to the xcertify.io API to retrieve risk scores. The extension does not:
- Record or transmit your browsing history
- Read page content beyond detecting wallet address patterns
- Store any data on our servers linked to your identity
- Execute any remotely hosted code
Risk scores are cached locally in your browser for 30 minutes to avoid redundant API calls. This cache is stored only on your device and is never transmitted to us.
Third-party services
To generate risk assessments, we query the following third-party APIs. When a wallet address or situation is checked, the relevant data is sent to these services:
- MistTrack (SlowMist) — AML and illicit-address intelligence (misttrack.io). Wallet addresses being checked are sent to this service.
- Chainabuse — scam report database (chainabuse.com)
- Etherscan — Ethereum and EVM-compatible chain data (etherscan.io)
- Tron Grid — Tron blockchain data (trongrid.io)
- Helius — Solana blockchain data (helius.dev)
- Blockstream — Bitcoin blockchain data (blockstream.info)
- XRP Ledger public API — XRP blockchain data
- Anthropic — Claude API for scam-pattern analysis of situation descriptions (anthropic.com)
- Telegram — bot messaging platform, if you use @XcertifyBot (telegram.org)
- U.S. Treasury OFAC — sanctions screening via the publicly available SDN list
These services have their own privacy policies. We only transmit the content being checked — we do not attach names, emails, or other identifying information to these requests.
Data retention
We do not maintain a database of users or their activity. Wallet addresses and situation text passed through our API are used solely to generate and return an assessment in real time. We do not log or store this content in a way that is linked to any individual user.
Four narrow exceptions exist for operating the service:
- Rate limiting. To prevent abuse, we keep a temporary counter keyed to your IP address (or, for the Telegram bot, your chat ID) for up to one hour. This counter contains no content — only a number of requests.
- Pattern-level analytics. For situation analyses, we record which scam pattern was matched and its confidence level, without any of the submitted text, to track scam trends and improve detection.
- Waitlist signups. If you join the extension waitlist, we store the email address you provide, solely to notify you when the extension is available. Email hello@xcertify.io at any time to have it removed.
- Scam-intelligence records. When our analysis identifies an address as high-risk — through scam-pattern detection, user reports, or unusual checking activity — we retain that address and the risk evidence in our scam-intelligence database. These records are keyed to addresses only: they never contain information about who performed a check or submitted a report.
Infrastructure logs
We do not use analytics and we do not attempt to identify our users. However, like almost every internet service, the infrastructure we run on (our hosting provider, Vercel, and the third-party APIs listed above) may generate short-lived technical logs — which can include IP addresses — as a normal part of operating, securing, and debugging their platforms. These logs are governed by those providers' retention policies. We do not use them to identify users, and we do not combine them with the content of your checks.
Cookies and tracking
Xcertify does not use cookies, tracking pixels, analytics scripts, or any third-party advertising technology. We do not track how you use the product across sessions.
Children's privacy
Xcertify is not directed at children under 16. We do not knowingly collect any information from children.
Changes to this policy
If we make material changes to this privacy policy, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically. Continued use of Xcertify after changes are posted constitutes acceptance of the updated policy.
Questions?
If you have any questions about this privacy policy or how we handle data, contact us at hello@xcertify.io.