DeFadeDeFade
Scan Pricing API

Privacy Policy

Last updated: June 25, 2026

DeFade ("we", "us", "our") is operated by DeFade Ltd, a company registered in England and Wales (Company No. 17136143). This policy explains how we collect, use, and protect information when you use DeFade via our website at defade.org, iOS app, Android app, Chrome extension, Telegram bot, or public REST API.

DeFade Ltd is the data controller for personal data collected through these services. We are subject to the UK GDPR and the Data Protection Act 2018.

1. Information We Collect

Account Information: When you register for a DeFade account, we collect your email address and a hashed password. This is used to authenticate you and manage your subscription.

Payment Information: Subscription payments are processed either by Stripe (card) or directly on the Solana blockchain (USDC). DeFade Ltd does not store your card details. For USDC payments, your public Solana wallet address is received as part of the on-chain transaction record. This is publicly visible blockchain data and is associated with your account for the purpose of confirming payment. We retain records of your subscription tier, billing status, and transaction references for accounting and dispute resolution purposes.

API Keys: If you generate a DeFade API key, the key and associated usage metadata (call counts, endpoints accessed, timestamps) are stored server-side linked to your account.

Usage Logs: We log API requests and scan activity including IP addresses, endpoints called, timestamps, and country (derived from Cloudflare's cf-ipcountry header). These logs are used for rate limiting, abuse detection, security, and resolving billing disputes.

Blockchain Data: When you scan a token or connect a wallet, we query publicly available Solana blockchain data through third-party APIs (Helius, DexScreener, Jupiter, Birdeye, Moralis). This data is publicly accessible on the blockchain and is not private information.

Wallet Addresses: If you connect your wallet, your public wallet address is used to display your holdings and facilitate swaps. We do not store your wallet address on our servers.

Analytics: We use Cloudflare Web Analytics to collect anonymous, aggregated usage data (page views, country-level location, referrer). This does not use cookies and does not track individual users.

Email Communications: If you subscribe to our newsletter or transactional emails, your email address is stored with our email provider (Resend). You may unsubscribe at any time.

2. Information We Do Not Collect

  • We never collect, store, or have access to your private keys or seed phrases
  • We do not use tracking cookies or advertising pixels
  • We do not sell, share, or rent personal data to third parties for marketing purposes
  • We do not store your wallet address, transaction history, or on-chain portfolio data on our servers
  • We do not collect personal information from users who use DeFade without creating an account

3. Wallet Connection & Swaps

When you connect a wallet (Phantom, Solflare, or Backpack), the connection is established directly between your browser and the wallet extension or app. All swap transactions are executed through Jupiter Aggregator — we do not custody, hold, or have access to your funds at any point. Transaction signing occurs entirely within your wallet.

4. Third-Party Services

DeFade uses the following third-party services to provide its functionality:

  • Helius — Solana RPC and blockchain data (subject to Helius Privacy Policy)
  • Jupiter — Swap execution and price quotes (subject to Jupiter Terms)
  • Moralis — Deep holder data
  • DexScreener — Token price and market data
  • Cloudflare — CDN, analytics, security, and WAF
  • Stripe — Payment processing and subscription management (subject to Stripe Privacy Policy)
  • Resend — Transactional and newsletter email delivery
  • Railway — Backend hosting and Postgres database
  • Apple App Store / Google Play — Mobile app distribution

Each third-party service has its own privacy policy. We encourage you to review them.

5. Data Storage & Security

Account data (email, hashed password, subscription status, API keys, and usage logs) is stored in a Postgres database hosted on Railway in the EU. Token analysis results are temporarily cached for performance (typically 5 to 15 minutes) and contain only publicly available blockchain data.

We use industry-standard security measures including HTTPS encryption, secure HTTP headers, Cloudflare WAF, CORS restrictions, and input validation on all API endpoints. Passwords are never stored in plaintext.

We retain account data for as long as your account is active. Usage logs are retained for up to 12 months. If you delete your account, your personal data is removed within 30 days except where retention is required by law (e.g. financial records for tax purposes).

6. Lawful Basis for Processing (UK GDPR)

Where we process personal data, we do so on the following lawful bases:

  • Contract: Processing your email address, subscription data, and API keys is necessary to provide the service you have signed up for
  • Legitimate interests: Usage logs and IP data are processed to protect the platform from abuse, enforce rate limits, and resolve disputes
  • Consent: Newsletter emails are sent only where you have opted in. You may withdraw consent at any time by unsubscribing
  • Legal obligation: We may retain billing records to comply with tax and accounting obligations

7. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access: You may request a copy of the personal data we hold about you
  • Right to rectification: You may request correction of inaccurate data
  • Right to erasure: You may request deletion of your personal data, subject to legal retention requirements
  • Right to restriction: You may request that we limit processing of your data in certain circumstances
  • Right to data portability: You may request your data in a machine-readable format
  • Right to object: You may object to processing based on legitimate interests

To exercise any of these rights, contact us at info@defade.org. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Children's Privacy

DeFade is not intended for use by anyone under the age of 18. We do not knowingly collect information from minors.

9. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of DeFade after changes constitutes acceptance of the updated policy.

10. Contact

For privacy-related questions, contact us at:

DeFade Ltd · Company No. 17136143 · Registered in England & Wales
Email: info@defade.org
Website: defade.org

Terms of Service Privacy Policy DeFade App
DeFade Ltd · Company No. 17136143 · Registered in England & Wales