Privacy Policy
This explains what StalkChain Data collects about you, why we hold it, who else processes it, and how to get it removed.
1. What we collect
Account data. Your email address. If you sign in with X, which does not share an email, your X username instead, plus any email you choose to add for receipts and alerts. Sign-in is handled by Privy; we store the identifier they return plus your email. If you answer the optional question about what you use StalkChain for, we keep your answers to improve the product.
Credentials. API keys are stored only as a hash, so we cannot show you a key again after it is created. Sessions are stored as a hash of the cookie value.
Usage. For each call: which tool was used, when, how long it took, whether it succeeded, the credits it cost, and a short summary of the arguments. This is what your balance and the usage charts are built from.
Payments. Card details never reach us. Stripe processes payments and returns an identifier, an amount and a status, which we store against your purchase.
Agent wallets. If you create an agent wallet, its addresses, the trading limits you set, and a record of each trade it makes (token, amounts, fee and transaction signature). The wallet's keys are held by Privy, never by us.
Technical. IP address and request headers, used for rate limiting and abuse prevention, and kept only briefly.
2. Why we hold it
To run your account and authenticate you, to meter credits and show you what you spent, to take payment, to prevent abuse and keep the service up, and to answer you when you contact support. We also use aggregate figures to understand which tools are worth improving.
We do not sell personal data, and we do not use your queries to build a profile of your trading.
3. Who processes it
We use a small number of providers, each handling only what their job needs:
- Privy for sign-in and wallet linking
- Stripe for payments
- Neon for the database and Vercel for hosting
- Upstash for caching and rate limiting, where enabled
- PostHog for product analytics, where enabled
- Upstream market-data providers, which receive the token or trader you asked about but nothing that identifies you
4. How long we keep it
Sessions expire after 30 days. Expired sign-in links, authorization codes and revoked tokens are deleted by a daily job. Usage and purchase records are kept while your account exists, because they are your billing history. Deleting your account removes your email, wallet addresses, keys and sessions; purchase records are retained only as long as tax and accounting rules require.
5. Your choices
You can see your usage and revoke API keys and connected applications from the dashboard at any time. Write to support@stalkchain.com to request a copy of your data, a correction, or deletion of your account. We answer within 30 days.
Depending on where you live, you may have rights to access, correct, delete, export or object to the processing of your data. Exercising them is free.
6. Cookies
We set one cookie, the session cookie that keeps you signed in. It is required for the site to work and is not used for advertising. Where product analytics is enabled it may set its own cookie to count visits; no advertising or cross-site tracking cookies are used.
7. Security
Traffic is served over HTTPS. Keys and session values are stored hashed, never in plain text. Access to the production database is restricted. No system is perfectly secure, so tell us at support@stalkchain.com if you believe an account has been compromised and we will revoke its credentials.
8. Public blockchain data
The market data we return describes public blockchain activity and public posts by trading accounts. It is not collected from you, and it is not personal data about you. If you are a trader who appears in that data and you want to discuss it, contact us.
9. Using StalkChain from an AI assistant
When you connect StalkChain to Claude, ChatGPT or another AI assistant, the assistant sends us only the name of the tool it wants to run and that tool's arguments, such as a token address or a trader handle. We never receive your conversation, your other messages, or anything else from the assistant, and we do not ask for them.
What we send back is the market data listed in section 8: trader handles and display names, their public wallet addresses, holdings, positions, trades and profit, public posts and comments they wrote about trades, follower counts, and token, price, liquidity and DeFi data. None of it is about you.
The version listed in the Claude and ChatGPT directories cannot trade, move funds or sign anything. The one thing it can change is your own alerts: when you ask, it creates, lists or deletes price and smart-money alerts on your account, and an alert that fires sends one notification to the email address or webhook you chose for it.
10. Changes and contact
We will update this page when our processing changes, and the date at the top will change with it. Questions go to support@stalkchain.com. See also our Terms of Service.