OceanAltOceanAlt

Privacy Policy

Document version V0.4Legal set V0.4Effective 2026-09-12business@oceanalt.com

This is the bilingual V0.4 publication copy of the OceanAlt legal documents. OceanAlt is at an early stage and has not yet designated a single formal legal operating entity; these documents use a transitional operating arrangement and do not fabricate any legal-entity details.

Core reminder: no risk signal found ≠ safe. Pre-payment screening does not replace your own authorisation, transaction monitoring, legal judgement or necessary human review.

OceanAlt provides pre-payment screening with no registration and minimal data wherever possible. Looking up an address or URL does not mean OceanAlt knows who owns it, and we do not bind a query target to a real identity. The retention periods, cookies and bot fields described here were checked against the actual code and server configuration.

1. Core principle

We do not sell personal data; we do not use query targets for advertising profiles or sell them to advertisers; and we build no advertising profile of anonymous visitors.

2. Data we may process

Website and API: request time, endpoint name, IP address, browser/User-Agent, basic access logs, page-view/read/share events, and the address, domain, transaction parameters or other input you submit to complete a query.

Account and admin (only if you register or use the admin area): email, account identifier, password hash (no plaintext passwords), security logs, and any Agent, mandate or partnership details you configure.

Telegram bot: to provide subscriptions and address watching we store the chat id, subscription toggles, language preference and the addresses you ask us to watch; we do not store message content or usernames.

Discord bot: only when you use a slash command does Discord send OceanAlt the data needed to complete it. Per command we record only: endpoint name, time, source IP, client identifier, caller class and the command name (for example check or help). We do not store the Discord user ID, server/guild/channel ID, the query target in the command, or the raw interaction payload; the user ID is used in memory only for per-minute rate limiting and is not persisted. The Discord bot does not passively read any channel history.

Wallet and on-chain data: wallet address, network, asset and public blockchain data you choose to connect or submit. We do not collect or store seed phrases or private keys.

Browser extension (once listed): processes only content you paste or select and explicitly ask to check; it keeps only your most recent query text locally and does not read browsing history or page content.

API keys (only if you request one): the email address you provide, the name you give the key, and that key's call count and last-used time. Of the key itself we store only a sha256 hash, never the key — it appears once, in the email we send you, and we cannot read it back.

API key restrictions (only if you set them): the scopes, source-IP allowlist (IP addresses or CIDR ranges) and expiry you set for a key. The allowlist is something you enter yourself and is kept with that key's record; if you ask for a restriction to be loosened, the requested change is held until you confirm it.

Communications: emails, questions, complaints, partnership and support requests you send us.

3. How we use data

Only to: provide queries and decisions; produce necessary evidence and audit records; prevent abuse and attacks; measure service usage; debug and maintain; improve the product; and meet applicable legal requirements.

4. Query content versus statistics

A. Query content: the address, URL or parameters you actually query, processed only to complete that query and for necessary security/evidence functions.

B. Query statistics: endpoint name, time, IP, client identifier, page-view/read/share events; these do not include the specific address/URL you queried, unless the record is one you chose to save (such as a watched address), a risk event, compliance evidence, or a record we must keep by law.

5. Retention (as actually enforced)

Server access logs: 30 days (rotated daily, 30 files kept).

Query statistics: 366 days (API call statistics, page-view, read and share events). 366 days allows a same-month year-over-year comparison and stops one day past a full year.

Source IP inside call records: blanked after 181 days; the record and its counts stay until 366 days. An IP is a personal identifier and the year-over-year comparison does not need it.

Compliance-evidence records: 2 years (730 days): block records, payment verdict records and the admin action trail, so that a dispute can reconstruct why a payment was blocked or allowed.

Rate-limit counter windows: 7 days.

Idempotency records (a copy of the first response to a payment request, so a retry after a network failure is safe): deleted after 2 days (no longer used after 24 hours).

Webhook delivery records (each attempt to reach the webhook URL you configured: event type, message body, status code, duration, error summary): 30 days.

API keys: a key that was never activated and never used is deleted after 30 days together with its record (email, key hash, name) — we never had a use for that address. A key in actual use is kept while it is in use, and you can ask us to revoke or delete it at any time. Restrictions you set on a key (scopes, source-IP allowlist, expiry) are kept with that key's record and go when the key is deleted or revoked.

Pending requests to loosen an API key's limits (the requested scopes, source-IP allowlist and expiry): cleared after 2 days (the confirmation link itself stops working after 24 hours, and confirming or cancelling clears it immediately).

Account data is kept while the account is active and then deleted or de-identified within a reasonable period subject to law, security, disputes and backups. Newsletter email is kept until you unsubscribe or request deletion.

These periods are enforced by a daily job that actually deletes; they are not a documentation-only claim. A machine-readable version is exposed as the data_retention field of GET /api/pay. Where law requires longer, you request deletion, or a security incident or dispute needs separate handling, we record the exception and its period.

Not subject to automatic deletion: risk address lists and entity labels (public-source intelligence, not anyone's behavioural record); published content and rating profiles (public records governed by the editorial process); control-baseline attestations (explicit one-year validity with withdrawal). Public blockchain records are outside OceanAlt's control and cannot be removed by deleting an account.

6. Public blockchain data

Wallet addresses, on-chain transactions, amounts and paths may already be public. OceanAlt's analysis of public on-chain data does not make the blockchain private. Do not send unnecessary sensitive personal information to OceanAlt via memos or query parameters.

7. Third-party platforms and processors

OceanAlt relies on hosting and infrastructure, Discord, Telegram, blockchain RPCs, data sources, facilitators, and email or security services, which may process data under their own privacy policies. Real mainnet x402 settlement currently uses the third-party Coinbase CDP facilitator under its own terms; OceanAlt makes no representations on behalf of third parties.

We disclose only the data necessary to those vendors, and may also disclose where required by law, to protect rights and safety, to investigate abuse, or in a business reorganisation. Enterprise customers may request the subprocessor list.

8. International processing

Because OceanAlt serves the global internet and blockchains, data may be processed outside your country. The production server is currently located in Hong Kong; encrypted backups are stored in Cloudflare R2 (the specific storage region is to be confirmed before formal publication); the applicable cross-border mechanism will be added once a formal entity is designated. We will update this Policy on any material change to storage locations, vendors or transfer mechanisms.

9. Your rights

Subject to applicable law you may have rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a regulator. Send requests to business@oceanalt.com; we may verify identity and will reply within a lawful period. Withdrawal does not affect prior lawful processing.

10. Children

Services requiring an account, wallet, real mainnet payment or professional developer features are intended for users aged 18 or over. If we learn we collected a minor's data without lawful authority, we will take reasonable steps to delete it.

11. Automated judgements

OceanAlt's APIs may return machine-executable risk judgements, but these are OceanAlt's own service-admission signals or signals supplied to integrators; they are not government decisions, credit scores or legal identity determinations about a natural person. Integrators must decide whether human review is needed and whether local automated-decision laws apply.

12. Security and updates

We use HTTPS, one-way password hashing, access controls, audit logs, rate limits, offline-verifiable decision signatures and other reasonable safeguards; no internet or blockchain system is absolutely secure. Material updates are notified through the site or another reasonable channel.

Other documents: Legal centre →