Privacy Policy
Last updated: September 2026
1. No Account System
TNT House has no user accounts, no passwords, and no login. Most of the Service is usable anonymously. Where identity matters at all (free-tier limits, paid credits, API keys), it is tracked by the minimal signal needed — described below — not by a profile.
2. What We Collect
- Token addresses you submit for audit or listing — already-public on-chain data.
- Wallet address and transaction signature when you pay via Solana Pay, to verify and credit your payment.
- IP address and a random httpOnly fingerprint cookie, used only to enforce free-tier daily limits and to reduce abuse (see lib/quick-check-limit.ts). The cookie carries no personal profile — just a rate-limit counter.
- API key and, if you provide one, an email, if you sign up for Risk-Data API access — used for authentication, usage/billing tracking, and service notices.
- Aggregate usage analytics (page views, general traffic patterns) via Vercel Analytics.
3. What We Do Not Collect
We never see or store your private keys or seed phrase — payments are signed entirely inside your own wallet extension. We do not run KYC and do not collect government ID.
4. How We Use It
To deliver the Service (run your audit, verify your payment, list your token, authenticate your API calls), enforce free-tier and rate limits fairly, detect abuse, and understand aggregate traffic. We do not sell personal data.
5. Third-Party Services
We rely on the following infrastructure and data providers, each under its own privacy policy:
- Supabase (database), Vercel (hosting, analytics), Upstash (rate-limit storage)
- Helius, Solana Tracker, RugCheck, and DexScreener (on-chain and market data)
- Telegram Bot API (internal alerts to our team — not for marketing to you unless you message our bot yourself)
6. Cookies
A single httpOnly fingerprint cookie is set for Quick Check rate limiting. It is not used for advertising or cross-site tracking.
7. Data Retention
Payment and usage logs are kept as long as needed for billing accuracy, abuse prevention, and legal/accounting requirements. Rate-limit counters reset automatically (daily for free-tier counts).
8. Your Rights
Since there is no account system, most of what we hold is either public on-chain data or minimal rate-limit/billing records. To ask what we hold tied to your API key or wallet address, or to request deletion where we are able to, contact us on Telegram (below).
9. Children
The Service is not directed at, and is not intended for use by, anyone under 18.
10. Changes to This Policy
We may update this policy as the Service evolves. The "Last updated" date above reflects the most recent revision.