Privacy
We collect almost nothing
No advertising networks, no third-party trackers, and no analytics scripts running in your browser. We do count page views, on our own server, with an identifier that cannot follow you from one day to the next. This page explains all of it.
Cookies
Three, all of them functional, none of them used to track you:
- cm_session — set when you sign in, so that you stay signed in. Deleted when you sign out.
- cm_csrf — a two-hour token proving a form was submitted from this site. It has to exist before you sign in, because the sign-in form itself needs protecting.
- a session cookie on the admin area, which only we can reach.
There is no consent banner because there is nothing here to consent to: these are the cookies a site is allowed to set without asking, and we set no others. No advertising cookie, no analytics cookie, no third-party cookie of any kind.
Two preferences are stored in your own browser's local storage — your light/dark theme and your display currency. They never leave your device and we cannot read them from our servers. Clearing your browser data removes them.
Analytics: ours, and only ours
We count page views. It happens on our own server after the page has already been sent to you — there is no script, no pixel and no beacon in the page, so nothing about this reaches anyone but us. We run no Google Analytics, no tag manager, no session recording and no advertising trackers.
Each page view is one row: the date, the page, and
- a visitor identifier that is rebuilt every day — a hash of your address and a secret, with the date mixed in. It lets us tell two page views apart today, and it is a different value tomorrow, so it cannot follow you across days. That is also why we report “visitor-days” rather than visitors: we genuinely cannot tell whether you are new.
- country, region and city — see the third parties section below;
- whether you are a browser or a crawler, and for a crawler, which one;
- the site you arrived from, host only, never the full address;
- mobile, tablet or desktop, worked out from your browser user-agent, which is read and then discarded rather than stored.
Your IP address is never written down, your user-agent is never written down, and none of it is attached to your account, your email or your name — not even while you are signed in. We do not build profiles of visitors, and we have no way to follow you to other sites.
What our web host records
Like any web server, our hosting provider records standard access logs — IP address, page requested, timestamp, browser user-agent — for security and diagnostics. These are generated by the hosting infrastructure, retained on a rolling basis, and are not combined with anything else or used for analytics.
When you use Sellability
Each check is recorded. This is deliberate: the accumulating record of how tokens' exit conditions change over time is the product, and it cannot be reconstructed after the fact. What we store:
- the chain, contract address and token symbol you checked;
- the position size you entered, and the resulting paper value, estimated proceeds and friction;
- a salted hash of your IP address — not the address itself.
The hash exists for one reason: to stop a single visitor exhausting the free public services the tool depends on. It is not reversible in any practical sense, is not linked to a name, email or account, and is never shared. The market data in each record is kept indefinitely as part of the historical series; it describes a token, not a person.
Sellability requires no wallet connection, and we never ask for a seed phrase, private key or exchange password.
Third parties we query
To answer your request the server — not your browser — calls CoinGecko and GeckoTerminal for market data, KyberSwap and ParaSwap for routing quotes, and GoPlus for contract security checks. These requests come from our server, so your IP address and browser are never exposed to them.
One exception, and it is the one worth stating plainly. To label a page view with a country we ask ipwho.is, and that request contains your IP address. It is the only third party that ever sees it. We ask once per network rather than once per visitor — the answer is cached against a hash of your address block, so a whole office or a whole mobile carrier costs a single lookup — which means that for most people nothing is sent at all, because somebody nearby already triggered it.
If you email us
Mail sent to hello@cryptominium.com or security@cryptominium.com is received through Google Workspace and kept as long as needed to deal with your message. We do not add correspondents to any marketing list.
What we never do
- We do not sell, rent or trade personal data. There is no commercial data product here.
- We do not run advertising networks or share data with advertisers.
- We never take custody of assets, and we never request wallet credentials.
Your rights
Depending on where you live, you may have rights to access, correct or erase personal data we hold. Practically speaking we hold very little that could identify you, but if you want to ask, write to hello@cryptominium.com and we will answer.
Children
This site is not directed at anyone under 18 and we do not knowingly collect information from them.
Changes
If these practices change, this page is updated and says what changed. Adding tracking without saying so would contradict the reason this site exists.
9 September 2026 — corrected. This page previously said the site set no cookies and ran no analytics. Both had stopped being true: sign-in cookies arrived with member accounts, and server-side page-view counting started on 17 August 2026. The page should have been updated in the same release and was not. Nothing was ever shared with an advertiser or a tracking network, and no visitor profile has ever been built — but the page was wrong in our own favour, which is the direction that matters, so it is named here rather than quietly rewritten.
This page describes how the site actually behaves. It is a plain-language notice, not legal advice. Last reviewed September 2026.