Privacy Policy
Last updated: September 7, 2026
1. Who we are
The cryptoalert.report service (the “Service”) is operated by KYT GROUP LIMITED, a company incorporated in Hong Kong (Business Registration Number: 76814411), registered address: Unit 2A, 17/F Glenealy Tower, No.1 Glenealy, Central, Hong Kong (the “Operator”, “we”).
The Operator is the data controller of users' personal data under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong and, for users located in the EU and the UK, under the GDPR / UK GDPR.
2. Privacy contact
For any question relating to the processing of your personal data (access, rectification, erasure, complaints), please email [email protected]. We respond within 30 days.
3. What data we collect
We collect only the minimum data required to operate the Service:
- Email sign-up — your email address (used to send magic-link logins and security notifications).
- Google / GitHub sign-in — email, name and the provider's stable user identifier (returned by the OAuth provider with your consent). We never see or store your Google or GitHub password.
- Technical information — IP address, User-Agent string, timestamp. Used for abuse protection, rate-limiting and session handling.
- Session cookie — a strictly necessary cookie ca_session, HttpOnly + Secure, 30-day TTL. Without it sign-in cannot work.
- Public-page visit data — page address, referrer, device type, browser characteristics (aggregate Cloudflare and Yandex.Metrica statistics), plus the _gcl_au cookie from Google Ads and _ym_* from Metrica. See section 8 for details.
- Content you create in the Service — the list of blockchain addresses you choose to watch (watchlist), your labels and alert settings. Public blockchain addresses are not personal data on their own, but when linked to your account we treat them as personal data.
- Telegram chat ID — only if and when you link a Telegram bot to your account (upcoming feature). We store only the numeric identifier, never chat contents.
- Payment data — when paid plans launch, we will use an external processor (planned: CryptoCloud). We do not store crypto-wallet details of payers; we only receive the fact of payment, amount and a transaction identifier.
4. Why we process data
- Authentication and session maintenance.
- Transactional email (magic links, account security).
- Providing Service features (watchlist alerts, analytics, API).
- Abuse protection: rate-limiting, detection of suspicious activity.
- Compliance with applicable legal obligations.
Legal bases (for users under GDPR): performance of a contract (Art. 6(1)(b) GDPR) — to operate the Service; legitimate interest (Art. 6(1)(f)) — for abuse protection and security; consent (Art. 6(1)(a)) — for any marketing messages (we currently send none).
5. Whom we share data with
We do not sell your data. We share the minimum necessary with the following processors:
- Resend (Resend, Inc., USA; processing in eu-west-1, Ireland) — email delivery for magic links. We pass: email address, message contents.
- Google and GitHub — OAuth sign-in providers. They see the fact of a sign-in request from our domain; we receive a verified email and name (only upon your explicit consent on the OAuth screen).
- Google Ads (Google LLC, USA) — measures how our advertising performs. A tag on public pages reports a visit and a sign-up to Google, together with the advertising cookie _gcl_au (see section 8). Your email and watchlist contents are not shared with it.
- Cloudflare, Inc. (USA) — DNS, TLS termination, DDoS protection for part of our domains. Sees IP address and HTTP request metadata. Cloudflare Web Analytics also runs on our pages — aggregate visit statistics, no cookies.
- Yandex (Yandex LLC, Russia) — Metrica: visit statistics for the public pages, and faster crawling of the site by its search robot. Receives page address, referrer, browser characteristics and IP address. Your email, watchlist and dashboard data are not shared with it.
- QuickNode, Inc. (USA) — Ethereum and TRON RPC provider. We do not pass personal data; we only consume public on-chain data.
- MVPS.net (VPS hosting, Bulgaria) — hosts Service servers. Sees traffic as part of normal network operation.
- CryptoCloud (upon launch of paid plans) — crypto payment processor. Will receive: email, amount, plan identifier.
We maintain standard contractual safeguards with all processors. When data is transferred outside the EEA, recognised mechanisms (Standard Contractual Clauses or equivalent) are used.
6. Retention periods
- Login magic tokens: 15 minutes; deleted on use.
- Sessions: 30 days from last activity; deleted thereafter.
- Account data (email, OAuth identities, watchlist): retained while the account is active. Deleted upon your request or after 24 months of full inactivity.
- Request logs (IP, User-Agent, endpoint): 90 days, then anonymised or deleted.
- Financial records (once paid plans launch): retained in accordance with Hong Kong bookkeeping requirements (7 years).
7. Your rights
Regardless of your location, upon request to [email protected] you may:
- receive a copy of your personal data;
- request rectification of inaccurate data;
- request deletion of your account and related data (right to be forgotten);
- export your data in a machine-readable format (data portability);
- restrict or object to certain kinds of processing;
- withdraw previously given consent.
If you believe we violate your rights, you may also file a complaint with the PCPD (Hong Kong) or with your national supervisory authority (if applicable).
8. Cookies and statistics
A small, ordinary set: one cookie to keep you signed in, plus the standard web statistics the search services provide. We do not sell data and we do not record what visitors do on a page.
- ca_session — keeps you signed in. HttpOnly, Secure, SameSite=Lax. The Service does not work without it.
- _ym_uid, _ym_d, _ym_isad and other Yandex.Metrica service cookies (counter 112337986): how many people visit and which pages they read, and faster crawling of the site by the search robot. Session recording (Webvisor) and click mapping are off.
- _gcl_au — Google Ads: helps us tell whether a sign-up came from one of our ads. Stored for up to 90 days.
- Cloudflare Web Analytics — aggregate visit statistics, uses no cookies.
Neither the statistics nor the advertising tag is loaded in the Telegram Mini App. We do not use Google Analytics, Facebook Pixel or similar behavioural trackers.
If you would rather your browser did not keep these cookies, you can turn them off: Google settings, Yandex's opt-out add-on, an ad blocker, or private browsing. None of it affects how the Service works.
9. Security
- All traffic travels over HTTPS (TLS 1.2+, automatic certificate renewal).
- We do not store passwords — login is via magic link or OAuth only.
- Session cookies are HttpOnly, Secure, SameSite=Lax.
- Magic tokens are single-use with a 15-minute TTL.
- The database runs on an isolated Docker internal network, unreachable from the public internet.
10. Children
The Service is not intended for persons under 18. We do not knowingly collect data from minors. If you believe a minor has provided us with data, write to [email protected] and we will delete it.
11. Changes to this policy
We may update this policy. Material changes will be announced on the website and emailed to registered users at least 7 days before taking effect. The last-updated date is shown at the top of this document.
12. Governing law
This policy is governed by the laws of Hong Kong. Disputes arising out of the processing of personal data shall be resolved by the competent courts of Hong Kong, unless mandatory rules of the law of your country of residence provide otherwise.