Legal
Privacy policy
Plain English, kept short. HoodRugCheck reads public blockchain data — that part needs no personal information at all. What follows is what we collect about you as a visitor or account holder, and what we deliberately don't.
What we collect
Wallet address — if you sign in, we store the public address you signed in with. That's it; signing in is a signature, never a password or a key.
Account email — signing in with a wallet creates an account email tied to that wallet so our auth system has something to key on; it is not a real inbox we message. If you ever sign in with an email instead, we store that email.
Scan history — the tokens you (or your session) scan, the score, and when, so we can enforce free-tier limits, show your recent scans, and keep the public "recently scanned" ticker.
Hashed IP and a device id — used only to count anonymous scans against the free daily limit. The IP is salted and hashed before it touches a database; we never store it in the clear, and the hash can't be reversed back to an address.
Payment records — if you go Pro, the on-chain transaction hash, amount, and resulting Pro expiry. We never see or store card numbers, bank details, or anything off-chain, because there aren't any — payment is a transaction you send from your own wallet.
API key — if you generate a public API key, we store a one-way hash of it, never the key itself. The plaintext key is shown to you exactly once, at creation.
What we don't collect
No private keys or seed phrases — we never ask for one, and would never store one if you tried to give it to us.
No custody of funds — we never hold, move, or have the ability to move your assets. Payments are you sending a transaction, not us pulling one.
We don't sell, rent, or trade your data to anyone, for any reason.
No third-party ad trackers or cross-site analytics pixels.
Who processes it
Three infrastructure providers run HoodRugCheck, each acting as a processor for the data above, never an owner of it:
- Supabase — accounts, sessions, scan history, payment and API key records.
- Vercel — hosting, and standard web server request logs (IP, user agent) kept only as long as their platform default retention.
- Alchemy — reads public Robinhood Chain data on our behalf; it sees the RPC calls a scan makes, not who you are.
Your choices
Everything above is tied to an account or a browser session. Don't sign in, and we hold only a hashed IP and a device id, both used solely for the free-tier counter.
To ask about or remove data we hold on your account, email support@hoodrugcheck.com.
Changes
If this policy changes in a way that matters, we'll update this page. Material changes get a note on the homepage.