SCIENTER

Legal

Privacy Policy

What we collect, why we collect it, how long we keep it, and how to make us delete it. Written against what the code actually does rather than what a template assumes.

Last updated: 2026-09-01

1

The short version

We collect the minimum needed to run the service: an account if you make one, a billing reference if you pay, and server logs. We do not sell personal data, we run no advertising trackers, and we never ask for a private key or a seed phrase.

At the time of writing we run no third-party analytics at all — no Google Analytics, no PostHog, no advertising pixel — and the site sets no tracking cookies. If that changes, this page changes with it and the date at the top moves.

2

Who is responsible for your data

Scienter is operated by its founder, Iliya, as an individual based in Israel, who is the controller of personal data processed through it. No separate company has been incorporated for it. For privacy questions, requests or complaints, write to [email protected].

3

What we collect

  • Account data — your email address, and any name you choose to give us. Only if you create an account. Used to give you access and to email you about the service.
  • Billing data — a customer reference, the plan and its status, returned to us by the payment processor. Card numbers, bank details and billing addresses go to the processor and never reach our servers.
  • Wallet addresses you query — when you look up an address, that address is sent to our servers and to the chain-data providers in clause 4 in order to answer the query. Public blockchain addresses are public data; we treat them as personal data anyway where they are tied to an account, because in the hands of someone who can link an address to a person they behave like one.
  • A connected wallet — if you connect one for a feature that needs it, we see its public address. We never request, receive or store a private key or seed phrase, and we cannot move your funds.
  • Server and request logs — IP address, user agent, the URL requested, timestamps and error traces. Generated automatically by our hosting and CDN, and needed for security, abuse prevention and debugging.
  • Support correspondence — what you send us when you write to us, kept so we can answer.

Stored on your device, not on ours: your theme, sound and cursor preferences, your onboarding progress, your recent command-palette searches and a local count of which venue links you have clicked. These live in your browser’s local storage, never leave it, and are cleared when you clear site data.

Public blockchain addresses that merely appear in the product — the traders, vaults and contracts we grade — are public chain data. They are not collected from you and are not linked to your account.

4

Cookies and third-party services

Cookies. The site sets only strictly necessary cookies. Today that means preview switches (gc_role, gc_tier) that control which version of a gated page renders, plus any session cookie required once you are signed in. These carry no advertising identifier and are not used to profile you across sites. We run no analytics or advertising cookies, which is why you are not being asked to consent to any. If we ever add optional analytics, they will be off until you opt in, and this clause will say what they are.

Processors and third parties. A small number of vendors process data on our behalf or receive data in order to complete something you asked for:

  • Vercel — hosting and application delivery. Processes request data, including IP addresses, to serve the site.
  • Cloudflare — CDN, DNS and denial-of-service protection sitting in front of the application. Processes request metadata for delivery and security.
  • Whop and Lemon Squeezy — payments and subscription management. They collect your payment details directly under their own privacy notices and act as merchant of record where applicable; we receive a reference and a status. The Whop checkout embeds a script from their domain on the pages that offer it.
  • Helius, Etherscan, Alchemy, CoinGecko and Hyperliquid — public blockchain, block-explorer and market-data sources. We send them blockchain addresses, transaction hashes and asset identifiers in order to read public chain and market data. We do not send them your name, your email, your account identifier or any other personal detail, and they receive nothing that links an address to you.
  • Discord, Telegram, Slack and Microsoft Teams — only if you choose to connect one for alert delivery, and only the channel or chat identifier needed to deliver to it.

We do not sell or rent personal data, we do not share it with data brokers or advertisers, and we do not run third-party ad pixels.

5

Why we are allowed to process it

For readers in the EU, EEA and UK, our legal bases under the GDPR are: performing our contract with you (account, plan and access); legitimate interests (keeping the service secure and working, preventing abuse, understanding aggregate usage); legal obligation (tax, accounting and sanctions); and consent, for anything optional, which you can withdraw at any time.

Where we rely on legitimate interests you have the right to object, and we will stop unless we have grounds that override yours.

6

How long we keep it

  • Server and request logs — 90 days, then deleted or aggregated beyond re-identification.
  • Account data — for as long as your account exists, and deleted on request. See clause 7.
  • Billing records — kept for as long as tax and accounting law requires after the last transaction, typically seven years. This is the one category we cannot delete on request while the obligation runs.
  • Support correspondence — up to two years after the matter is closed.

7

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, restrict or object to processing, and withdraw consent. Readers in the EU, EEA and UK have all of these under the GDPR; readers elsewhere, including in Israel and in US states with their own privacy statutes, have equivalent rights under their own law.

To exercise any of them, email [email protected]. We answer within 30 days. We will not charge you for it and we will not make the service worse for you because you asked.

Two honest limits. First, entries published to the Alpha Ledger are written to a public chain and cannot be deleted by us or by anyone — those entries record market calls we made, not personal data about you. Second, public blockchain history is public and permanent; we can delete what we hold, but we cannot delete a chain.

If you think we have handled your data badly, tell us first — but you are entitled to complain to your local supervisory authority instead, and nothing here asks you to waive that.

8

Where your data goes

We are based in Israel, and our processors operate globally, so data is processed outside the country you are reading from. Israel holds an adequacy decision from the European Commission, and transfers to processors elsewhere rely on Standard Contractual Clauses or an equivalent safeguard under those processors’ own terms.

9

Security

Traffic is served over HTTPS. Access to production systems is limited to those who need it. Bearer tokens are sent in headers rather than in URLs, specifically so they do not end up in proxy logs, referrer headers or a pasted bug report.

No system is perfectly secure and we will not claim otherwise. If a breach affects your personal data and presents a risk to you, we will tell you and the relevant authority within the time the law requires.

10

Children

The service is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

11

Changes to this policy

We update this page when what we do changes — a new processor, a new category of data, a new retention period. The last updated date at the top moves with it, and material changes are notified by email or in the app before they take effect.

12

Contact

Privacy questions, access and deletion requests, and complaints: [email protected].