Skip to content

Privacy Policy

Last updated: 2026-09-29

This Privacy Policy explains how BlockVectra collects, uses, shares and protects your personal information when you use the JSON-RPC API, the Data API, the Console and the related websites and documentation, and what rights you have.

Please read it together with the Terms of Service. Terms such as "Credits", "API key", "Console", "Contact email" and "compute unit (CU)" have the same meaning here as in the Terms of Service.

1. Who we are

Under applicable data protection laws, the controller of the personal information described in this Policy (called the "personal information processor" under China's Personal Information Protection Law) is the operator of the BlockVectra service ("BlockVectra", "we", "us" or "our"), which is your contracting party under the Terms of Service.

For privacy matters, write to the contact email ([email protected]).

2. Scope

This Policy applies to the JSON-RPC API, the Data API and the Console that we provide, our website, documentation site and status page, and your communications with us, for example by writing to the contact email.

This Policy does not apply to services provided by third parties, including sign-in services such as GitHub and Google, the wallet and wallet provider you use, and the blockchain networks themselves. They handle information under their own policies.

This Policy replaces any other privacy policy or privacy notice previously published for the Service.

3. Information we collect

We collect only what we need to provide the Service. When you sign in, we do not collect your email address, name or profile picture. The information we collect is described below by source:

  • Sign-in information. If you sign in with a wallet signature (only externally owned accounts, i.e. EOA wallets, are supported; the sign-in page lists the supported wallet types), we store your wallet address; you only sign a sign-in message, the signature is not submitted to any blockchain and costs no fee, and we never ask you to sign a transaction. If you sign in with GitHub, we store the numeric ID and username of your GitHub account; we request no additional permissions from GitHub and do not read your email. If you sign in with Google, we store the unique identifier (subject ID) of your Google account; we request only the basic permission used to identify you, and do not read your email, name or profile picture. Different sign-in methods correspond to different Accounts, and we do not merge Accounts by email or by any other information.
  • Account and API key information. Your Account number, the identifier and name of each API key you create, and records of creating, renaming, rotating and revoking keys. The secret of an API key is shown only once, when it is created or rotated, and we store only a hash of it.
  • API usage records. When you call the JSON-RPC API or the Data API, we record the API key identifier, the method, the network, the time, the number of calls and the CU consumed. These records are used for metering, billing and showing your usage in the Console.
  • Console audit records. When you open an Account, sign in, sign out, manage sign-in methods, or create, rename, rotate or revoke an API key in the Console, we record the type of action, the time and your IP address, for security auditing. The IP address is cleared automatically after 180 days; the rest of the record is kept.
  • Server and network logs. The service that serves our API (JSON-RPC API and Data API) does not record client IP addresses; rate limits are applied per API key and Account, and API usage records contain no IP address. The access log of the Console website records the IP address, time, request method, path (without query string), status code and bytes sent, and may include browser information (User-Agent); it is rotated daily and kept for 14 days. To prevent abuse, sign-up and sign-in endpoints count requests per IP address (IPv6 per /64 range) to limit their frequency; these counters are held in memory only and are never written to disk. In addition, all our domains are proxied by Cloudflare, which as the edge network processes client IP addresses for security protection and statistics, and keeps them under its own policy.
  • Billing and top-up records. Charge records, top-up records (amount, currency, time and type) and your Credits balance. You can view these records in the Console.
  • Information you provide when you contact us or top up. Top-ups are currently handled by email. We keep: the email address you write from, the content of your emails and any attachments; the sign-in identity or Account number you give us to identify your Account; payment details such as currency, amount, payment address, transaction hash or proof of receipt; the receiving-account details needed to process a refund and, if you have lost every sign-in method, materials showing that you control the original source of payment; and, where the law or our compliance requirements call for it, information about your identity and source of funds.

4. Purposes and legal bases

We use your personal information only for the purposes below. Where data protection laws of the EU, the UK or similar regions apply, our bases are performance of a contract, compliance with a legal obligation, our legitimate interests and, where the law requires it, your consent; where the Personal Information Protection Law of the People's Republic of China applies, these correspond to what is necessary to conclude or perform a contract, what is necessary to comply with a legal obligation and, where the law requires it, your consent; the legitimate-interests basis listed in this Policy applies only in the EU, the UK and similar regions.

We do not sell your personal information, do not use it for advertising and do not use it for purposes unrelated to those below.

  • Providing and operating the Service. Creating Accounts and signing you in, issuing and managing API keys, routing requests and enforcing limits, metering, billing and settlement, and showing usage and balance. Basis: performance of a contract.
  • Handling top-ups, refunds and billing disputes. Checking payments and processing refunds to the extent permitted by law and Section 11 of the Terms of Service, handling metering disputes, dealing with payments that are reversed or charged back, and verifying who owns an Account when you have lost every sign-in method. Basis: performance of a contract; our legitimate interests.
  • Security, abuse prevention and enforcing the Terms. Security auditing, rate limiting and limits on account opening, detecting and dealing with leaked API keys, preventing abuse of Free Credits (including deactivating surplus Accounts created automatically by the same person), protecting the Service and other users, and enforcing the Terms of Service. Basis: our legitimate interests; performance of a contract.
  • Legal compliance. Sanctions screening, verifying identity and source of funds where necessary, keeping accounting and tax records, and responding to lawful requests from courts and authorities. Basis: compliance with a legal obligation; our legitimate interests.
  • Communications and notices. Replying to your emails and sending you service-related notices, including email notices of price changes and material changes to the Terms that are adverse to you (see Section 30 of the Terms of Service). Basis: performance of a contract; compliance with a legal obligation; our legitimate interests.
  • Operations and improvement. Troubleshooting, capacity planning and improving the Service. Basis: our legitimate interests.

5. Public nature of on-chain data

Transactions you submit to blockchain networks through the Service are broadcast to public networks, can be viewed by anyone and cannot be changed or deleted, and we cannot delete them for you.

Wallet addresses are publicly visible on the blockchain by their nature.

If more than one sign-in method (for example, a wallet and a GitHub or Google account) is linked to your Account, we will know that these identities belong to the same Account.

6. Local storage and cookies

The Console stores your sign-in session credential and the sign-in method you last used in your browser's local storage, only to keep you signed in and make your next sign-in easier. A session is valid for at most 7 days, expires after 24 hours of continuous inactivity, and also ends when you sign out. You can clear local storage in your browser at any time.

We do not set advertising or analytics cookies on our own website or in the Console and do not use third-party tracking tools; the providers that supply network acceleration and security protection may set strictly necessary technical cookies for their services. If we introduce such tools in the future, we will first update this Policy and, where the law requires, obtain your consent.

7. Sharing and recipients

We do not sell your personal information. We share the necessary information only in the following cases, with the following categories of recipients:

  • Infrastructure providers. Providers of hosting, storage and backup, and Cloudflare, which provides network acceleration (CDN) and security protection; they process information for us.
  • Sign-in providers. If you sign in with GitHub or Google, they handle your sign-in process and process the related information under their own policies; we exchange with them only what is needed to complete the sign-in.
  • Banks, payment channels and compliance service providers. To process top-ups and refunds, verify payments and carry out sanctions screening.
  • Blockchain networks. Transactions you submit through the Service are broadcast to public networks (see Section 5).
  • Authorities, courts and professional advisers. Where the law requires it, or where it is necessary to establish, exercise or defend legal claims, we disclose information to courts, regulators and law enforcement; we disclose to lawyers, auditors and other professional advisers under a duty of confidentiality.
  • Successors to the business. If the Service is transferred or reorganized between us and an affiliate or a successor to the Service, information moves with the business to the successor; the successor will remain bound by this Policy, or we will notify you separately and obtain your consent as the law requires.

8. International transfers

The Service is delivered over a global network. We and the providers above may process your personal information outside the country or region where you live, where the level of data protection may differ from that where you live.

Where the law requires it, we put appropriate safeguards in place, such as standard contractual clauses, security assessments or certifications, as applicable, and, as required, tell you about the recipients and obtain your separate consent.

You can ask us about the safeguards we use by writing to the contact email.

9. Retention

We keep personal information only as long as needed for the purposes above and delete or de-identify it when that period ends, unless the law requires or allows a longer period, or retention is necessary for security auditing, abuse prevention or dispute handling. Closing an Account does not mean all data is deleted immediately (see Section 25 of the Terms of Service). In detail:

  • IP addresses in Console audit records: cleared automatically after 180 days; the rest of the record (time, Account, type of action) is kept.
  • Sign-in sessions: valid for at most 7 days and expire after 24 hours of continuous inactivity.
  • Console website access log: kept for 14 days; the API service does not record IP addresses. Information processed by Cloudflare is kept under its own policy.
  • API usage records: kept while your Account exists, for metering, billing and showing your usage; after the Account is closed, kept until the end of the period needed for legal, financial or dispute-handling purposes.
  • API key records: kept for security auditing, abuse prevention and dispute handling, during your Account's existence and afterwards for as long as needed for those purposes, and not deleted immediately when an Account is closed; these records currently have no automatic deletion period.
  • Billing, charge and top-up records: kept for reconciliation, accounting and tax purposes during your Account's existence and afterwards for as long as needed, and not deleted immediately when an Account is closed.
  • Emails to us and contact email addresses: kept while we handle your request, and afterwards for as long as needed for verification, refunds, dispute handling and sending you service-related notices.
  • Backup copies: daily database backups include the audit records, so backups may contain IP addresses up to 180 days old; backups are kept for a limited period and deleted on rotation; we keep the seven most recent copies locally for disaster recovery.

10. Security

We take reasonable technical and organizational measures to protect your personal information. For example: the secret of an API key is shown only once, when it is created or rotated, and we store only a hash of it; sign-in sessions have an expiry and an inactivity timeout; and audit records are append-only and are not modified, other than clearing IP addresses on schedule.

No system is completely secure. If a security incident affects your personal information, we will notify you and the competent authorities as applicable law requires. Please also keep your wallet, sign-in credentials and API keys safe (see Section 6 of the Terms of Service).

11. Your rights

Under applicable data protection laws, you may have the rights below. These rights are not absolute in every situation; for example, records we must keep because of legal or financial obligations, the legitimate interests of others, and data that is already public on a blockchain may limit how a right can be exercised.

  • to access your personal information, obtain a copy and learn how we process it;
  • to have inaccurate or incomplete personal information corrected;
  • to ask for your personal information to be deleted;
  • to ask us to restrict processing, or to object to processing that we carry out on the basis of our legitimate interests;
  • to receive the personal information you provided to us in a commonly used, structured and machine-readable format, or have it transferred to another party (data portability);
  • to withdraw your consent (withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn);
  • to lodge a complaint with the data protection authority where you live.

12. How to exercise your rights

Write to the contact email, saying which right you want to exercise and what your request covers. The Service currently has no self-service deletion or export: you can view your own usage, charges and top-up records in the Console, and we handle other requests manually by email.

To protect Accounts, we may ask you for information that shows you control the Account concerned (for example, the identity you sign in with and your top-up receipts) before we act on a request.

We will respond to your request without undue delay. If we refuse a request, we will explain why. We generally do not charge a fee, but where a request is manifestly unfounded or excessive we may, where the law allows, charge a reasonable fee or decline to act on it.

Records we cannot delete because of legal or financial obligations are mainly billing, charge and top-up records; API key records are kept for security auditing, abuse prevention and dispute handling and currently have no automatic deletion period; backup copies cannot be deleted individually before they expire; and we cannot delete data on a blockchain. For these records we will tell you why, and will use them only to the extent needed for the purposes described in Section 4.

13. Children

The Service is for people aged 18 or over and is not directed at anyone under 18 (see Section 3 of the Terms of Service). We do not knowingly collect personal information from anyone under 18.

If we find that we have collected personal information from someone under 18, we will take steps to close the Account concerned and handle the information as the law requires. If you believe we may have collected such information, please tell us at the contact email.

14. Changes to this Policy and notices

We may change this Policy from time to time. We will post the revised Policy on this page, update the "Last updated" date and, where reasonably practicable, summarize the main changes.

Material changes that are adverse to you (for example, collecting new categories of information, expanding the purposes of use or adding recipients) take effect 30 days after they are announced; in addition to announcing them on our website, we will email each Account that has requested a top-up by email, at the address used for that request. Other changes, and changes required immediately to comply with law, take effect when posted. Where the law requires your consent, we will obtain it separately. This is consistent with Sections 29 and 30 of the Terms of Service.

This Policy is available in Chinese and English. If the two versions differ, the English version prevails, except where applicable law requires another language version to prevail.

15. Contact us

If you have any questions about this Policy or your personal information, contact us through the Contact Us page or the contact email ([email protected]), and we will reply by email.