What you can check yourself
You do not have an account, because there is nothing to sign in to
The scanner, the tool pages and the public feed need no registration, no email and no password. You paste a public address, the same one visible on any block explorer, and get a result.
We never ask for a private key, a seed phrase or a wallet connection
There is nothing to sign and nothing that can move your funds. Any page or message claiming to be Veriql and asking for a seed phrase is a scam. This is the one promise worth checking against the behaviour of the site itself.
No advertising trackers, no analytics vendor, no profile of you
There is no Google Analytics, no Meta pixel, no advertising SDK and no third-party session recorder. The counting is our own, it is aggregate, and it is described in full below.
What a visit records
1. Aggregate counters, not events about you
A page view increments a small number of daily counters: that a view happened, a two-letter country code, whether the device is a phone or a desktop, which page was viewed (from a fixed list of known pages), and which site referred you (the referring domain only, from a bounded list). These are counts in a table. They are not rows about a person and they cannot be reassembled into one.
2. A daily, salted visitor hash
To count unique visitors without identifying anyone, a one-way hash is derived from request data together with a secret salt that changes every day. It cannot be reversed to an IP address, and because the salt rotates, the same person on two different days produces two unrelated values. The hash is what is stored; the input is not.
3. What is not stored, ever
No raw IP address, no full User-Agent string, no full referring URL, no page-by-page history, no browser fingerprint, no cross-site identifier, and nothing that can be joined back to a person or a wallet.
4. IP addresses, used and not kept
Your IP is necessarily visible to any server you connect to. We use it transiently for abuse control: per-minute limits on the free scanners and per-day limits on free key issuance, held as short-lived counters that are pruned automatically. It is used to count, never to profile, and it is not stored alongside any of the analytics above.
5. Machines are counted separately
Crawlers, uptime pingers, link-preview fetchers and scripted clients are detected and contribute exactly one counter ("a robot visited"). They never reach the country, device, page or referrer figures, so those describe people rather than software.
The addresses you paste
6. The address goes to our data providers
To check a wallet, token or contract we query public data sources with the address you entered, principally GoPlus Security for risk data, DexScreener for prices, GeckoTerminal for new and trending pools, and mempool.space for Bitcoin. Those providers receive the address and their own privacy terms apply to them.
7. Scan outcomes are recorded, unlinked to you
We record that a scan happened, on which chain, of what kind, and what the engine concluded. This is the feedback loop that improves the scoring and powers the public threat feed. A public address is public data by design; it is not connected to a visitor, a session or an identity, because we hold no identity to connect it to.
8. Trade-link clicks
If you use a "trade safely" link, we record the day, the token, the chain and which page you clicked from, so we can see which checks lead somewhere useful. The destination is a third-party trading service with its own terms; we record the click, and we never see your trade, your balance or your wallet.
Three, and none of them track you
9. The full list
A theme preference stored in your browser so the site remembers light or dark. An owner session cookie, set only if someone signs in to the private operator dashboard. An owner opt-out cookie, which exists so the operator's own browsing is excluded from the site's own figures. That is all of them. There are no advertising or cross-site cookies, and nothing is shared with a marketing network.
10. No consent banner, on purpose
We do not set marketing or profiling cookies, so there is nothing to ask permission for. A banner would imply we were doing something we are not.
What the Guardian extension does
11. It reads the request you are about to approve
The extension inspects transaction and signature requests a site asks your wallet to approve, so it can decode them and warn you before you sign. It runs locally in your browser. It is read-only: it cannot sign, cannot move funds, and never sees a private key or seed phrase.
12. It stores nothing
The extension keeps no local database and no browser storage. Nothing about the pages you visit is saved, and no browsing history is collected or transmitted.
13. The only server it talks to
To look up a token or address it queries the GoPlus Security API, and nothing else. It sends the address being checked. It does not send the page you are on, your browsing history, or any identifier.
14. Why it asks for broad site access
A drainer can be on any website, so a warning that only worked on a list of known sites would fail exactly when it mattered. The permission is broad because the threat is; what it does with that access is narrow, and is described above.
Who else is involved
15. Infrastructure
The site is served through a content delivery network and an application host, and its data lives in a managed database. Those providers handle traffic on our behalf and can see connection data such as IP addresses, as any host must.
16. Fonts
Typefaces load from Google Fonts, which means Google's servers see the request. If you would rather they did not, a content blocker will stop it and the site remains fully usable in a fallback face.
17. Payments
If you buy something, payment is handled by a third-party crypto payment processor. The payment happens on their systems under their privacy terms; we receive a confirmation that an order was paid. We never see or hold a card number, and no card is involved.
18. Telegram
If you use the Telegram bot, Telegram's own terms and privacy policy apply to that conversation. For an account that saves wallets to monitor, we store the Telegram account id, the public addresses you asked us to watch, and the alerts sent to you.
Keeping, deleting, asking
19. How long things are kept
Abuse-control counters are short-lived and pruned automatically. Daily visitor hashes are meaningful only for the day they belong to, because the salt rotates. Aggregate counters and scan outcomes are kept as history, and contain no personal data to begin with.
20. Deletion
There is no account to delete, because there is no account. If you use the Telegram bot, removing a saved wallet removes what we hold about it; you can remove them all. For anything else, the honest answer is that we hold nothing tied to you to delete.
21. Children
The Service is not directed at children and is not intended for use by anyone under the age required to use crypto services where they live.
22. Changes, and how to reach us
If this policy changes, the revised version replaces this one from the moment it is posted. Questions about privacy can be sent through the contact options on the website.
In plain English: there is no account, no wallet connection and no advertising tracker anywhere in Veriql. We count how many people visit and what gets scanned, in aggregate, and we do not build a profile of you because we do not hold the pieces to build one from. Read the terms · More about what we do · Run a free scan