🔒 Privacy

Privacy Policy

Effective Date: 14 April 2026  ·  CryptMax47 Blockchain Intelligence Platform

Your privacy matters to us. This policy explains what data we collect, why we collect it, how it is stored, and the rights you have over it.

Section 01

Overview

CryptMax47 ("we", "us", "our") operates a blockchain wallet intelligence platform accessible at cryptmax47.online. This Privacy Policy applies to all data collected through our website, dashboard application, and API services.

📌 We do not sell, rent, or broker your personal data to any third party for marketing or commercial purposes.

By using CryptMax47, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the Service.

Section 02

Data We Collect

We collect data in the following categories:

Category Examples Basis
Account Data Username, email address, hashed password, 2FA system password (hashed) Contract performance
Payment Data Razorpay / Stripe subscription IDs, payment IDs (no raw card data stored) Contract performance
Usage Data Wallet addresses analysed, API endpoints called, timestamps, response times Legitimate interest
Device Data IP address (geolocation for payment routing), browser type, session token Legitimate interest
Alert Data Watched wallet addresses, BTC threshold values, email for alerts Consent

We do not collect biometric data, government IDs, or sensitive personal categories as defined by GDPR Article 9.

Section 03

How We Use Your Data

Your data is used exclusively for the following purposes:

  • Service Delivery: Authenticating your session, running wallet analysis, delivering risk scores, and processing API requests.
  • Billing & Subscriptions: Processing payments, managing plan limits, and sending transaction confirmations via Razorpay/Stripe.
  • Security: Detecting fraudulent logins (login-lock mechanism), enforcing rate limits, and auditing suspicious API usage.
  • Service Improvement: Anonymised usage statistics to understand which features are most valuable and to improve AI analysis accuracy.
  • Alerts: Sending email alerts when a watched wallet's BTC balance crosses a user-defined threshold.
  • Legal Compliance: Retaining records as required by applicable law, including financial regulations.
✅ We do not use your data for advertising, profiling for third parties, or automated decision-making that produces legal effects.
Section 04

Third-Party Services & APIs

CryptMax47 integrates with the following third-party services. Each operates under its own privacy policy:

  • Blockstream API: Used to fetch Bitcoin wallet data and transaction history. Your queried wallet addresses are transmitted to Blockstream's public API.
  • Etherscan API: Used to fetch Ethereum wallet data. Queried addresses are transmitted to Etherscan.
  • Anthropic Claude API: Wallet payload data (address, transaction summary, flow data) is sent to Anthropic for AI risk scoring. No personally identifiable information is included in this payload.
  • CoinGecko API: Used to fetch live BTC/ETH price data. No user data is transmitted.
  • open.er-api.com: Used for live FX exchange rates. No user data is transmitted.
  • Razorpay: Payment processing for Indian users. Card and bank data is handled entirely by Razorpay and never stored by us.
  • EmailJS: Used to deliver OTP emails for password reset. Your email address is transmitted to EmailJS to send the message.
  • ipapi.co: Used to detect your country for payment provider routing. Only your IP address is transmitted, and no data is stored by us from this call.
  • Redis (Railway): Used for server-side caching of analysis results. Cached data includes wallet addresses and analysis output but not personal account information.
Section 05

Cookies & Local Storage

We use browser localStorage (not third-party cookies) to persist your session. The following keys are stored locally in your browser:

  • cm_token: JWT authentication token for your session.
  • cm_session_email / cm_session_username: Your account identifiers for session continuity.
  • cm_sub_id / cm_subscribed_email: Razorpay subscription state to avoid repeated server lookups.
  • cm_api_key: Your current active API key (if any).
  • cm_session_expiry: Timestamp used to enforce the 15-minute session timeout.
  • cm_portfolio: Portfolio wallet addresses you have saved locally.
ℹ All localStorage data is stored exclusively in your own browser and is cleared on logout. We do not use third-party tracking cookies or analytics cookies.
Section 06

Data Retention

  • Account data is retained for as long as your account is active, plus up to 90 days after account deletion (to comply with financial record obligations).
  • Analysis cache (wallet data cached in Redis) expires automatically within a configurable TTL (typically 5–60 minutes) and is not stored permanently.
  • Payment records (subscription IDs, payment IDs) are retained for 7 years as required by Indian tax regulations and general financial compliance standards.
  • Server access logs containing IP addresses and endpoint activity are retained for up to 30 days for security and debugging purposes.

You may request early deletion of your account data by contacting us at admin@cryptmax47.online.

Section 07

Security Measures

We implement the following measures to protect your data:

  • Passwords are stored as bcrypt hashes. Plain-text passwords are never stored or logged.
  • API keys are stored as SHA-256 hashes. The raw key is only shown once at generation time.
  • JWT tokens are short-lived and validated server-side on every request.
  • 2FA is enforced on every login using a secondary system password.
  • Login lockout is applied after repeated failed login attempts.
  • TLS/HTTPS is enforced for all connections via Railway's infrastructure.
  • Rate limiting is applied per IP and per API key to prevent abuse.
⚠ No system is 100% secure. In the event of a data breach affecting personal data, we will notify affected users within 72 hours as required by applicable law.
Section 08

Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right of Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your account and associated data.
  • Right to Restrict Processing: Ask us to limit how we use your data in certain circumstances.
  • Right to Data Portability: Receive your data in a machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.

To exercise any of these rights, contact us at admin@cryptmax47.online. We will respond within 30 days.

Section 09

Children's Privacy

CryptMax47 is not intended for users under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us immediately and we will delete it promptly.

Section 10

International Data Transfers

CryptMax47 is operated primarily from India. By using the Service, you acknowledge that your data may be processed on servers located in India and, for certain third-party integrations (Anthropic, EmailJS, CoinGecko), in the United States or other jurisdictions.

Where data is transferred internationally, we ensure it is subject to appropriate safeguards consistent with applicable data protection laws.

Section 11

Changes to This Policy

We may update this Privacy Policy from time to time. The Effective Date at the top of this page will always reflect the date of the most recent revision. We will notify registered users of material changes via email or in-app notification at least 14 days before the changes take effect.

Continued use of CryptMax47 after the revised policy takes effect constitutes your acceptance of the updated terms.

12. Contact Us

For privacy-related requests, API calls, priority support, data deletion enquiries, or any questions about this policy, please reach out to our team.

📧 admin@cryptmax47.online