Privacy
We collect almost nothing
No advertising networks, no third-party trackers, and no analytics scripts running in your browser. We do count page views, on our own server, with an identifier that cannot follow you from one day to the next. This page explains all of it.
Cookies
Four, all of them functional, none of them used to track you:
- cm_session — set when you sign in, so that you stay signed in. Deleted when you sign out.
- cm_in — set beside cm_session, holding only the number 1, so the menu can show “Account” instead of “Sign in” while you are signed in. It identifies nobody and signs nobody in. Deleted when you sign out.
- cm_csrf — a two-hour token proving a form was submitted from this site. It has to exist before you sign in, because the sign-in form itself needs protecting.
- a session cookie on the admin area, which only we can reach.
There is no consent banner because there is nothing here to consent to: these are the cookies a site is allowed to set without asking, and we set no others. No advertising cookie, no analytics cookie, no third-party cookie of any kind.
Two preferences are stored in your own browser's local storage — your light/dark theme and your display currency. They never leave your device and we cannot read them from our servers. Clearing your browser data removes them.
Analytics: ours, and only ours
We count page views. It happens on our own server after the page has already been sent to you — there is no script, no pixel and no beacon in the page, so nothing about this reaches anyone but us. We run no Google Analytics, no tag manager, no session recording and no advertising trackers.
Each page view is one row: the date, the page, and
- a visitor identifier that is rebuilt every day — a hash of your address and a secret, with the date mixed in. It lets us tell two page views apart today, and it is a different value tomorrow, so it cannot follow you across days. That is also why we report “visitor-days” rather than visitors: we genuinely cannot tell whether you are new.
- country, region and city — see the third parties section below;
- whether you are a browser or a crawler, and for a crawler, which one;
- the site you arrived from, host only, never the full address;
- mobile, tablet or desktop, worked out from your browser user-agent, which is read and then discarded rather than stored.
Your IP address is never written down, your user-agent is never written down, and none of it is attached to your account, your email or your name — not even while you are signed in. We do not build profiles of visitors, and we have no way to follow you to other sites.
What our web host records
Like any web server, our hosting provider records standard access logs — IP address, page requested, timestamp, browser user-agent — for security and diagnostics. These are generated by the hosting infrastructure, retained on a rolling basis, and are not combined with anything else or used for analytics.
When you use Sellability
Each check is recorded. This is deliberate: the accumulating record of how tokens' exit conditions change over time is the product, and it cannot be reconstructed after the fact. What we store:
- the chain, contract address and token symbol you checked;
- the position size you entered, and the resulting paper value, estimated proceeds and friction;
- a salted hash of your IP address — not the address itself.
The hash exists for one reason: to stop a single visitor exhausting the free public services the tool depends on. It is not reversible in any practical sense, is not linked to a name, email or account, and is never shared. The market data in each record is kept indefinitely as part of the historical series; it describes a token, not a person.
Sellability requires no wallet connection, and we never ask for a seed phrase, private key or exchange password.
When you buy a Realizable Value Statement
Everywhere else on this site, an address you look up is used to answer and is not stored. A statement is the exception, because a kept record is the thing you are buying. It is stored only because you asked for it. What we store, for a statement and nothing else:
- the address, and the chains it was read on;
- the record itself: each holding, its balance, its quoted value and what a sale would have returned, the totals, and the block heights at the moment it was taken;
- a fingerprint of that record, its reference, the time it was taken, and the account and order it belongs to.
For how long. Three years from the day it is taken, or longer if you extend it. If you order a statement for a future date, the address is held from the order until that date as well.
Deleting it. You can delete a statement from your account at any time. The address and the record are erased, not hidden. The same happens by itself when its time runs out. What remains is the reference, the fingerprint and the dates it was issued and erased: enough for someone holding a printed copy to be told it was once genuine, and nothing that says what was in it.
Who can read it. Anyone who has its link, which is how you share it; so give the link only to people who should read it. A statement is never listed, searchable or offered to search engines, and opening one is not recorded in our visitor statistics. Our web server’s own request log does record the address of every page fetched, the statement’s link included, as it does for the whole site; that log is kept for about two weeks for security and is not used for anything else. Our admin pages show that a statement exists, its date and its state, and not its address or figures.
A statement describes an address. Ordering one does not ask you to prove you control it, and we never ask for a wallet connection, a signature, a seed phrase or a private key.
A Position Statement asks for no address, so none is stored. It is of a token and an amount you type, and those two things are stored with the record, beside your account, for the same three years and erased in the same way when you delete it or its time runs out. The measurement taken for it is kept out of the log our free Sellability check writes, and our admin pages do not show the token or the amount.
When you paste a website into search
A web address pasted into search is compared by name with our list of projects’ official sites, to tell you whether it is one. That comparison happens on our server and nothing else: we do not visit the address, we send it to nobody, and we do not store it. The search log records only that a web address was searched, never which one.
Third parties we query
To answer your request the server — not your browser — calls CoinGecko and GeckoTerminal for market data, KyberSwap and ParaSwap for routing quotes, and GoPlus for contract security checks. These requests come from our server, so your IP address and browser are never exposed to them.
One exception, and it is the one worth stating plainly. To label a page view with a country we ask ipwho.is, and that request contains your IP address. It is the only third party that ever sees it. We ask once per network rather than once per visitor — the answer is cached against a hash of your address block, so a whole office or a whole mobile carrier costs a single lookup — which means that for most people nothing is sent at all, because somebody nearby already triggered it.
When an assistant uses Cryptominium (the MCP server)
Assistants such as Claude and ChatGPT can call Cryptominium directly through our MCP server at
/mcp (see developers). When they do, the request comes from
the assistant's servers, not from your browser, and carries whatever the assistant sends: a token
name, an address, an ENS name or a transaction hash.
- What we use it for: answering that one call. An address, name or hash is used and then dropped; it is not written to our database, logs we keep, or anything else.
- What we record: which tool was called, when, and what kind of input it was (for example “an EVM address” or “a ticker”) — never the input itself.
- Rate limiting: a salted hash of the calling connection, kept for two days and then deleted. It identifies the assistant's server, not you.
- Refused outright: anything that looks like a recovery phrase or private key is refused before any lookup and is not logged.
- Sharing: none. To answer, our server queries the public blockchain nodes and data sources listed above, with the address or hash but nothing about you.
- The assistant's side — what it keeps of your conversation — is governed by that assistant's own privacy policy, not this one.
Questions: [email protected].
When you use the Fair Price Check
The Fair Price Check compares what your app, exchange or Bitcoin ATM shows with the market price. You type a coin, an amount in dollars, an amount of coin and where you bought or sold.
- A free check is not stored. The figures are used to answer and then dropped. They are sent with the form rather than in the page address, so they do not end up in logs or your browser history.
- What we record: that a check ran, whether it was a purchase or a sale, and which way the answer went. Never the coin, the amounts or where. To count the three free checks a day, a keyed hash of your connection is kept for two days, the same one the wallet tool uses.
- With the Buyer’s Plan, a check is saved to your account only if you leave “save” ticked: the coin, the two amounts, where, the market price and the time. You can delete one or all of them at /account/fair-price. They stay if your plan ends, until you delete them.
- A Price Record keeps one check, as it was answered, for three years, like every statement. It holds no address and nothing about who you are; you can delete it from your account.
- The market price is read from Coinbase’s and Kraken’s public price feeds. We send them only the name of the coin, never your figures.
When you use Before You Buy
Before You Buy takes a coin and an amount, fills in what we measure about the coin, and checks what you write against the rules you set.
- A free decision is not stored. The coin, the amount, your answers and your rules are used to make the Decision Record and then dropped. They are sent with the form, never in the page address.
- What we record: that a decision was made, how many of your own rules it broke, and whether rules were set. Never the coin, the amount or anything you wrote. To count the free fact sheets a day, the same keyed hash of your connection as the Fair Price Check is kept for two days.
- With the Buyer’s Plan, a decision is saved only if you leave “save” ticked, and your rules only if you leave “keep these rules” ticked: the facts as they were read, what you wrote, your rules, and what you later mark (bought, passed, sold). Delete one or all of them, rules included, at /account/decisions.
- What selling it again would return is read from Coinbase’s and Kraken’s public order books. We send them only the name of the coin, never your amount or your words.
- Watch My Conditions (Buyer’s Plan) keeps each condition you set: the coin, what to watch for, the price, percentage or amount you typed, your note, and what we read when it happened. It is used only to check the condition and send you one email. Remove one or all of them at /account/conditions. Nothing is read from any wallet or exchange account.
When you use the Telegram bot
The Cryptominium bot on Telegram (see /telegram) answers questions such as
/exit PEPE. Telegram delivers each message addressed to the bot to our server, with the
chat it came from and the account that sent it.
- What we use: the text of the command, to answer it. An address, ENS name or transaction hash is used and then dropped, exactly as on the site.
- What we record: which command ran, what kind of input it was, and whether it came from a private chat, a group or inline mode. For groups only, a keyed hash of the group's id, so we can count how many groups use the bot. Never your Telegram id, name, username or message.
- Rate limiting: a keyed hash of the chat (or, in inline mode, of the account), kept for two days and then deleted.
- In groups the bot runs in Telegram's privacy mode: it receives only commands addressed to it, not the group's conversation.
- Refused outright: anything that looks like a recovery phrase or private key is refused before any lookup, never repeated back and never logged.
- Telegram's side — what Telegram keeps of your chats — is governed by Telegram's privacy policy, not this one.
If we write to you (reporters, partners and others)
Sometimes we write to people who never signed up — mostly journalists who cover crypto markets, and organisations we might work with — to share our published figures. For that we keep a short contact list, written by hand.
- What we keep: your name, your work email address, your publication or organisation, and a note on why we thought our data was relevant to you (usually a link to something you published). We take these only from what you or your employer publish, such as an author page.
- What we send: one email at a time, addressed to you, never a mass mailing. Every one has a link that stops all further email from us with one click.
- What we record: when we wrote to you and whether it was delivered. Not whether you opened it or clicked anything — our emails carry no tracking pixels or tracked links.
- Sharing: none. The list is not sold, rented or shared. Email is sent through Google Workspace.
- Removal: after you use the stop link we keep only the fact that you asked, so we never write again. To be deleted entirely, write to [email protected].
- People who sign up on the site, and people who email us, are not added to this list.
If you email us
Mail sent to [email protected] or [email protected] is received through Google Workspace and kept as long as needed to deal with your message. We do not add correspondents to any marketing list.
What we never do
- We do not sell, rent or trade personal data. There is no commercial data product here.
- We do not run advertising networks or share data with advertisers.
- We never take custody of assets, and we never request wallet credentials.
Your rights
Depending on where you live, you may have rights to access, correct or erase personal data we hold. Practically speaking we hold very little that could identify you, but if you want to ask, write to [email protected] and we will answer.
Children
This site is not directed at anyone under 18 and we do not knowingly collect information from them.
Changes
If these practices change, this page is updated and says what changed. Adding tracking without saying so would contradict the reason this site exists.
5 October 2026 — added. Watch My Conditions: what is kept for each condition a Buyer’s Plan member sets, what it is used for, and where to remove it.
4 October 2026 — added. A section on Before You Buy: a free decision is not stored, a plan member’s decisions and rules are saved only if they choose, and the order books are read without sending anyone your amount. The Fair Price Plan is now called the Buyer’s Plan.
3 October 2026 — added. A section on the Fair Price Check: a free check is not stored, a plan member's check is saved only if they choose, and the market price is read without sending anyone your figures.
3 October 2026 — added. A fourth cookie, cm_in, which tells the menu you are signed in so it can show Account rather than Sign in and Sign up. It holds only the number 1 and is set and deleted with the sign-in cookie.
30 September 2026 — added. A section on pasting a website into search: it is compared by name with our project list, and is not visited, stored or sent anywhere.
30 September 2026 — added. A section on the Telegram bot: what Telegram sends us, what we record (the command and the kind of input, never who asked or what they sent), and the keyed group hash used to count groups.
30 September 2026 — added. A section on the contact list we keep for writing to reporters and partners: what is on it, where it comes from, the one-click stop link in every email, and how to be deleted.
30 September 2026 — added. A section on the MCP server, which lets assistants call Cryptominium directly: what an assistant sends, what we record (the tool and the kind of input, never the input), and the two-day rate-limit hash.
9 September 2026 — corrected. This page previously said the site set no cookies and ran no analytics. Both had stopped being true: sign-in cookies arrived with member accounts, and server-side page-view counting started on 17 August 2026. The page should have been updated in the same release and was not. Nothing was ever shared with an advertiser or a tracking network, and no visitor profile has ever been built — but the page was wrong in our own favour, which is the direction that matters, so it is named here rather than quietly rewritten.
This page describes how the site actually behaves. It is a plain-language notice, not legal advice, and it forms part of our Terms of service. Last reviewed October 2026.