wardcrest

Privacy Policy

Version 1 · in effect from 14 September 2026

Wardcrest is operated by the operator of Wardcrest, which is responsible for the personal data described here. We collect what the service needs to work and keep it no longer than necessary. Contact: support@wardcrest.com.

On this page

What we collect

  • Account: email address, optional name, a password hash (Argon2id), an encrypted two-factor secret and hashed recovery codes if you enable 2FA, and sign-in timestamps.
  • Sessions: a hash of the session token, your browser’s user-agent string, and when the session was created and last used.
  • Network data: we never store raw IP addresses. For rate limiting and the audit log we store a keyed hash of the address, which cannot be reversed without our secret key.
  • Workspace content: monitors and the addresses, contracts and extended public keys in them (extended keys encrypted), notification channel settings (encrypted), alerts and their delivery records, API key hashes, invitations and the audit log.
  • Crypto features you use while signed in: your watchlist, price, fee, gas and confirmation alerts, portfolios (the transactions you enter and the watch-only wallet addresses you add, with their synced balances), and investigations — case files, notes, private address tags, and bulk-screening lists with their results.
  • Public tools: what you type into a tool (an address, a transaction id, an invoice, an amount) is used to answer that request and is not stored with your identity. We keep only an anonymous daily count per tool. Several tools — the extended-public-key explorer, unit converters and most calculators — run entirely in your browser and send nothing to us.
  • Billing: the plan, amount and status of each invoice, the BTCPay invoice reference and payment details. Bitcoin payments are public on the blockchain by nature.
  • Email: copies of the account and alert emails we send, kept to diagnose delivery.

We do not use analytics or advertising trackers and do not sell or share personal data for marketing. We set two cookies: the strictly necessary session cookie when you sign in, and a preference cookie that remembers light or dark mode if you use the theme switch. Market data, coin logos and charts are fetched by our servers and served from our own domain, so browsing Wardcrest sends nothing to those providers.

Why we use it

To run the service you asked for (the contract with you), to keep it secure and prevent abuse (our legitimate interest), and to meet legal obligations such as accounting. We email you about your account, security events, alerts you configured and billing — never marketing unless you opt in.

Who else sees data

  • Blockchain data providers — the RPC services, Bitcoin explorers (mempool.space, Blockstream), EVM explorers (Blockscout) and the Safe Transaction Service we query — receive the public addresses and transaction ids being monitored or looked up, including addresses derived from an extended public key and those in your portfolio wallets, but not who you are. If keeping Bitcoin addresses unlinkable matters to you, weigh this before adding an xpub. A transaction you ask us to rebroadcast is sent to those networks, which is what broadcasting means.
  • Market data providers (CoinGecko, the European Central Bank, ExchangeRate-API, alternative.me) receive no personal data: our servers request market-wide figures and cache them.
  • Channels you configure — Slack, Discord, Telegram, PagerDuty, your email provider or your own webhook — receive the alerts you route to them.
  • Our network edge (Cloudflare) carries traffic to Wardcrest and processes connection data, including IP addresses, under its own privacy terms.
  • Payments are handled by our own BTCPay Server; no card processor or payment company receives your data. Email is sent from our own mail server.
  • Authorities, where the law compels us — we will tell you unless we are legally prevented.

How long we keep it

We delete data automatically when its period ends. This table is generated from the same schedule our deletion job runs on, so it shows the periods actually in force.

DataHow long we keep it
Your account and what you create: profile, workspaces, monitors, channels, watchlist, price alerts, portfolios, cases, address tags and API keysUntil you delete it, delete its workspace, or delete your account.
Sign-in sessionsDeleted as soon as they expire, 30 days after last use (signing out ends a session at once).
One-time email links (email confirmation, password reset, data download); we store only a hash of each link7 days after the link expires.
Views of a shared case file link: when it was opened, and a visitor hash keyed per workspace, never an IP address90 days after the view.
Data exports (“Download my data”)Not stored: the file is built at the moment you download it, and the emailed link works once, within 24 hours.
Rate-limit counters (a keyed hash of a network address, an email address or an account id, with a count)2 days after the counting window starts.
Records of requests a rate limit refused: a keyed hash of the network address, email address, account or API key, which limit, and how often30 days after the hour counted.
Failed sign-ins and API key use by network, to spot credential stuffing and leaked keys (keyed hashes only, never an address or email)2 days after they are recorded.
Temporary blocks on a network, an account or an API key, with the reason90 days after the block ends.
Abuse incidents: what our detectors saw (counts and keyed network hashes) and how it was handled180 days after the incident is closed.
Security audit log2 years after the event.When an account is deleted, its entries stay but no longer say who acted.
Alerts and their delivery recordsThe workspace plan’s history period: 7 days on Free, 30 days on Plus, 90 days on Pro, 1 year on Team, 2 years on Business.
Bulk screening runs and their resultsThe workspace plan’s history period: 7 days on Free, 30 days on Plus, 90 days on Pro, 1 year on Team, 2 years on Business.
Copies of the emails we send, to diagnose delivery90 days after sending.
Emails with a data-download link, and notices about a deleted account7 days after sending.
Your email opt-outs (weekly digests and reports)Until you delete your account.
Entries in your notification centre: account notices, alerts and announcements90 days after they are created.
Your notification choices: which categories reach you by email or TelegramUntil you delete your account.
Records of the announcements we emailed you or sent to a Telegram chat you connected90 days after the email or message is sent.
Your watchlist and portfolio update settings: movement rules, where notices go, the digest schedule, your time zone and quiet hoursUntil you delete your account.
Watchlist and portfolio notices we sent you: coin moves, wallet activity and daily profit and loss90 days after they are created.
Records of the digests we sent you, and where each went90 days after the digest is sent.
Your signal rules: the coins each watches, the rise and volume it waits for, its cooldown and channels, and which coins it fired onUntil you delete the rule or your account.
Team invitations, with the invited email address30 days after they expire or are revoked.
Error logs30 days after the error.
Cached answers from data providers (charts, address histories)7 days after they expire.
Anonymous daily counts of public-tool use (nothing about you)1 year after the day counted.
Daily balances of monitored addresses, for monthly reports2 years after the day recorded.
Invoices10 years after the invoice date.Paid invoices are kept for this period even after the workspace or account is deleted, because accounting law requires it. Unpaid invoices of a deleted workspace are deleted after 30 days.
Database backups30 days after the backup is made.Anything deleted from Wardcrest is gone from every backup once this period has passed.

When you delete your account we delete your personal data at once, except what this table says we keep: paid invoices, and audit log entries that no longer identify you. Deleted data then leaves our backups as they roll over.

Your rights

Data-protection law (the UK GDPR, and the GDPR in the EU and EEA) gives you these rights. You can use them wherever you live.

  • See and take a copy of your data (access and portability). Under Settings → Your account → Download my data, we email you a link to a ZIP file with your data as JSON, plus CSV tables. The link works once, within 24 hours, and only while you are signed in. It covers your account, the workspaces you own with their alerts, price alerts, portfolios and cases, your watchlist, and your audit history. Secrets such as password hashes and webhook keys are never included.
  • Correct it. Change your name, password and workspace content in the app at any time.
  • Delete it (erasure). Under Settings → Your account → Delete account, confirmed with your password and, if you use two-factor authentication, a code. We delete your account and personal data at once and email you a confirmation. Workspaces only you use are deleted with it. If you are the only owner of a workspace other people use, make one of them an owner first; the other members of a workspace you leave are told. We keep only what the table above lists.
  • Object, or restrict processing. You can object to processing based on our legitimate interests, or ask us to limit it while a question about your data is resolved.
  • By email. If you cannot sign in, write to support@wardcrest.com from the address on your account. To protect your data we confirm requests through that address — a copy of your data is sent as a link to it — and may ask for more if we cannot be sure the request is yours. What we do for you is recorded in our audit log. We answer within one month.
  • Complain. You can complain to a data-protection authority, such as the ICO in the UK or the authority where you live in the EU.

Security

How we protect data is described on the security page. If a breach affects your personal data, we will tell you and the relevant authority without undue delay.

Changes

We will email account holders about material changes before they take effect. The date at the top shows the latest revision.