Back to KEPTRA

Privacy Policy

Last updated: September 16, 2026

This policy explains, in plain terms, what personal data KEPTRA collects, why, who helps us process it, how long we keep it and how you can control it. We collect as little as the Service needs.

1. Who we are

KEPTRA (keptra.app) is operated by an independent developer based in Romania, who is the controller of the personal data described in this policy under the EU General Data Protection Regulation (“GDPR”).

For anything about your data, including the rights listed below, write to hello@keptra.app.

2. The data we collect

You can browse the public pages without an account. We then store nothing about you ourselves; our hosting provider keeps the standard technical logs described below.

When you create an account and use it, we collect:

  • Account data - your email address and, if you sign up with email, a password that our authentication provider stores only in hashed form; or the name, username, email and profile picture your sign-in provider shares when you use Google or X. X does not share an email address, so an account created with X may have none.
  • What you save - favorite chains, price and metric alert rules, notification settings (channels, quiet hours, time zone and any webhook URL you enter), portfolio transactions you record, saved chart layouts, your votes in chain sentiment polls, and the API keys you create. We keep only a cryptographic hash of each API key, never the key itself.
  • Notifications - the alerts we generate for you and whether each was delivered.
  • Product usage - while you are signed in, the pages you open and how long you spend on each chain's page. We use this to understand which features and chains are used and to improve them. It is tied to your account and not shared with anyone.
  • Subscription data - if you subscribe, your plan, billing interval, status, renewal and cancellation dates, and the customer and subscription identifiers our payment provider assigns. We never receive your card or bank details.
  • Messages - what you send us by email, and our replies.

Technical data. Like any website, our hosting provider processes your IP address, browser details and the pages requested, to deliver the site, keep it secure and investigate errors.

Wallet addresses you look up. Wallet Trace reads public blockchain data. For MultiversX your browser queries the public MultiversX API directly, so that service sees the request and your IP address. For chains read through Etherscan, the address you enter is sent to our server, which queries Etherscan for you. We do not store the addresses you look up in our database or keep a history of them; like any request, they can appear briefly in our hosting provider's logs.

3. Why we use it, and on what legal basis

  • To provide the Service you signed up for - your account, saved items, alerts, API keys and a Pro subscription. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
  • To keep the Service secure and working - preventing abuse, enforcing rate limits, investigating errors. Legal basis: our legitimate interest in running a secure service (Art. 6(1)(f)).
  • To improve the product - aggregate understanding of which pages and chains are used. Legal basis: our legitimate interest in improving the Service (Art. 6(1)(f)).
  • To meet legal obligations - for example keeping records needed for tax or to answer lawful requests. Legal basis: legal obligation (Art. 6(1)(c)).

4. What we do not do

  • We do not sell or rent your personal data.
  • We do not show advertising and do not use advertising or cross-site tracking cookies.
  • We do not use third-party analytics services; the usage data above stays in our own database.
  • We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

5. Who processes your data for us

We use a small number of service providers, each only for the purpose listed:

  • Supabase - database and authentication, including the account confirmation emails.
  • Vercel - hosting of the website and its server functions.
  • Google and X - only if you choose to sign in with them. They process your data under their own privacy policies.
  • Lemon Squeezy - checkout, payments, invoices, tax and the subscription customer portal. Lemon Squeezy is the merchant of record and processes your payment data as an independent controller under its own privacy policy.
  • Etherscan and MultiversX - public blockchain lookups for Wallet Trace, as described above.

If you add a webhook URL to your notification settings, we send your alerts to that address; the service behind it is chosen and controlled by you.

6. International transfers

Some of these providers are based in, or use infrastructure in, countries outside the European Economic Area, including the United States. Where that happens, the transfer is covered by an adequacy decision (such as the EU-US Data Privacy Framework, for certified providers) or by the European Commission's Standard Contractual Clauses.

7. How long we keep it

  • Account data, everything you saved, your notifications and your usage data are kept while your account exists, and are deleted together with the account.
  • Messages you send us are kept for as long as needed to deal with your request, and no longer than two years afterwards.
  • Payment and tax records are kept by Lemon Squeezy for the periods the law requires of it.
  • Hosting logs are kept for the short periods set by our hosting provider.

8. Cookies and local storage

We only use cookies and browser storage that the site needs to work, or that remember choices you make. None of them track you across other websites, so no consent banner is required.

  • Sign-in cookies - set by our authentication provider to keep you signed in.
  • Interface preferences - your light or dark theme, whether the side menu is collapsed and whether you dismissed the upgrade notice.
  • Local storage in your browser - recent searches, chart layouts, whether alert sounds are muted, and whether you have seen the follow-on-X card. This stays on your device and you can clear it at any time from your browser settings.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have inaccurate data corrected;
  • have your data deleted, including your whole account;
  • restrict or object to processing based on our legitimate interests;
  • receive the data you gave us in a portable, machine-readable format;
  • lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work.

To exercise any of these rights, email hello@keptra.app from the address linked to your account, or tell us how to identify the account if it has none. We reply within one month. There is no charge.

10. Security

Connections to the site are encrypted with HTTPS. Access to the database is restricted by row-level security, so each account can only read its own data, and API keys are stored only as hashes. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the competent authority where the law requires it.

11. Age limit

The Service is not intended for anyone under 18. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.

12. Changes to this policy

We will update this policy when what we collect or how we use it changes. The date at the top shows the latest version, and we will notify account holders of material changes by email or in the app. The Terms of Service explain the rest of our relationship with you.