TRUST / PRIVACY
Privacy notice
A concise account of the data processed to deliver and secure this read-only service.
EFFECTIVE 1 AUGUST 2026 · COUNSEL REVIEW NOT CLAIMED
Privacy notice
Public evidence pages remain available without an account. When the default-off free-account feature is enabled, Google or GitHub sign-in is optional for account-only API keys and dashboard preferences. Scrolld OÜ operates the service. Standard request metadata may be processed by Cloudflare to deliver, secure, cache, and monitor it.
Minimal free-account data
CHAIN4663 retains one normalized verified email as the account identifier, the provider name (Google or GitHub), and a keyed hash of the provider subject. It does not retain your username, avatar, organization, access token, refresh token, password, device hint, city, country, Robinhood credential, wallet, position, order, or balance. Google and GitHub process the OAuth request under their own notices; provider tokens are used only to complete sign-in and are discarded.
Session, CSRF, provider-link, OAuth-state, and API-key secrets are represented server-side only by hashes or keyed hashes. API-key plaintext is shown once in the authenticated dashboard and is not accepted in URLs. CHAIN4663 sends no welcome, transactional, lifecycle, or marketing email; account and key delivery stays in the dashboard.
Purpose and legal-basis review
Account identity and preferences are processed to provide the free workspace the user requests; technical protection and bounded abuse controls are processed to secure that service. The current processing map treats those purposes as contract-related service delivery and legitimate-interest security respectively, subject to qualified-counsel confirmation before activation. No account data is sold, used for advertising, or used to build a cross-service profile.
Retention and deletion
OAuth attempts expire after 10 minutes, sessions after 12 hours, revoked API-key hashes remain only until account deletion, and account identity and preferences remain until self-service deletion. Provider-managed recovery copies may persist temporarily under the infrastructure recovery policy. Deleting the account removes its identity, provider link, sessions, active or revoked keys, and preferences from the live database. This free release creates no payment record.
Privacy-safe service measurement
The website records aggregate page counts and Core Web Vitals in hourly buckets by canonical path and two-letter country code. The first-party measurement does not store IP addresses, referrers, query strings, user agents, advertising identifiers, or analytics cookies. Web Vitals are stored only as good, needs-improvement, or poor counters rather than individual measurements.
Telegram bot data
The separately optional Telegram bot stores Telegram chat and user IDs, username, first name, chat type, optional deep-link source, ticker watchlist, update IDs, and delivery receipts to provide requested bot features. Use /delete to remove that profile, watchlist, and receipts. Telegram data is not joined to a website account.
Public-chain and contact data
Public blockchain addresses, transactions, logs, and contract state are public records and are not presented as identified customer profiles. If you contact the service, the message and details you provide are used to respond or investigate. Contact contact@chain4663.com to request access, correction, deletion, restriction, portability, or objection where applicable. This behavior notice records the released data flow; it is not a claim of legal certification.