Privacy Policy
1. Summary
We collect as little as the service can function with. There is no account system in the conventional sense: there is no name, no password and no email address required to use the API. Identity is a wallet signature, and credentials are stored only as one-way hashes.
Akselis is the controller for the processing described in this policy and can be reached at [email protected].
2. What we process
| Data | Why | Retention |
|---|---|---|
| Wallet address | Proves entitlement to a key, enforces one free key per wallet, and is the address a refund is paid to. | For the life of the key record, then 180 days. |
| SHA-256 digest of your API key | Authentication. The plaintext key is never written to storage or to a log. | Until revoked or expired, then 180 days. |
| Transaction hash and settlement record | Prevents a payment being redeemed twice, and supports refunds and accounting. | The detailed settlement record is retained for 180 days. A minimal transaction-hash replay marker is retained indefinitely to prevent double redemption. |
| Request counters | Rate limiting and monthly credit metering, keyed by key digest, not by identity. | Rate windows: minutes. Monthly usage counters: 62 days. |
| Server logs | Operating the service and investigating abuse and errors. Written by our hosting provider. | Per the hosting provider's retention policy. |
| Queried contract addresses and symbols | Present in the request path so the request can be served. Not retained in a profile. | Only in provider logs, as above. |
What we do not do
- We do not ask for your name, email address, postal address or phone number to use the API.
- We do not set advertising cookies and we do not run third-party analytics or tracking pixels.
- We do not sell, rent or share personal data with data brokers.
- We do not take custody of funds and never have access to your private keys.
- We never place your API key in a URL, and we reject requests that do — precisely so your key does not end up in logs and browser history.
3. Browser storage
The website stores your API key in your browser's localStorage under the key
m2m_api_key, so the inspector and sandbox pages can call the API on your behalf. This never
leaves your device except as an x-api-key request header to our API. Clear it at any time with
"Forget stored key" on the API Keys page. We do not use cookies for tracking.
4. Public blockchain data
Blockchain transactions are public and permanent. We cannot edit, hide or delete anything recorded on Base — including the payment you send us and the address you sent it from. That data is outside our control and outside the scope of any deletion request.
5. Third parties we send data to
- Hosting / edge network — serves requests and writes access logs.
- Managed Redis provider — stores key digests, usage counters and settlement records, over TLS.
- Base RPC providers — receive the contract addresses you query, in order to answer them.
- DexScreener — receives token addresses when market data is requested.
- x402 facilitator — receives payment payloads when you settle a per-call payment.
These providers receive only what is needed to perform their function. We do not send them your API key.
6. Lawful basis (UK/EU users)
- Contract — issuing and authenticating keys, metering usage, settling payments.
- Legitimate interests — securing the service, preventing abuse, and debugging faults.
- Legal obligation — retaining financial records where required.
We do not rely on consent for any processing, and we do not carry out automated decision-making that produces legal effects concerning you.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or port your data, and to object to processing. Because we hold so little, most requests resolve quickly.
-
Deletion. Revoke your key at
POST /v1/keys/revoke, then email [email protected] from a channel you control. We cannot delete on-chain records, and we may retain settlement records where tax law requires. -
Access. Your key metadata is available to you at any time at
GET /v1/keys/self. - Verification. Since identity here is a wallet, we may ask you to sign a challenge with the wallet in question before acting on a request.
We aim to respond within 30 days. You may also complain to your local supervisory authority.
8. Security
- API keys are stored only as SHA-256 digests and compared in constant time.
- Redis connections require TLS; a plaintext connection to a remote host is refused at boot.
- Credentials are refused in query strings so they cannot leak into logs or history.
- If storage is unreachable, protected routes fail closed with HTTP 503 rather than falling back to a weaker check.
- Secrets live only in the hosting provider's encrypted environment store, never in tracked configuration.
No system is perfectly secure. If you believe you have found a vulnerability, report it to [email protected]. We will acknowledge within 5 business days and will not pursue legal action against good-faith research that follows the Acceptable Use Policy.
9. Breach notification
If a breach affecting your data occurs, we will notify affected users without undue delay, and regulators where legally required, describing what happened, what data was involved and what you should do.
10. International transfers
Our infrastructure providers operate globally, so your data may be processed outside your country.
11. Children
The service is not directed at children and is not intended for anyone under 18.
12. Changes
Material changes will be announced in the changelog, and the version and effective date above will change.
13. Contact
Privacy requests: [email protected] · Security: [email protected]