Privacy
onchain data bank · this edition: 17 August 2026
This page covers onchainbank.com and app.onchainbank.com. It is short because there is little to describe: the product is market data, its readers are analysts and machines, and neither the site nor the data behind it is built on knowing who you are.
The short version
- No advertising, no advertising networks, no third-party tracking scripts, no profiling.
- No account is needed to read the public pages, and no sign-up form exists on them.
- We do not store the IP address of a visit – see Traffic below.
- Nothing about you is sold, rented or shared for anyone else's marketing.
Cookies
Only what a page needs to work or what you yourself chose – which is why there is no consent banner here. Nothing below identifies a person or follows one across other sites.
| name | what it is for | how long |
|---|---|---|
| nav | which navigation the page should draw (public site or dashboard) | the browsing session |
| who | the initials and role shown in the corner when a session is signed in; empty and immediately expired for everyone else | the browsing session |
| theme, themev | the light or dark theme you picked with the switcher; written only after you press it | one year |
| session | the signed-in session of the dashboard – set by the door, and only for people who have an account with us | until sign-out |
| __cf_bm and the like | Cloudflare's security cookies, set by the network in front of the site to tell a browser from an attack | minutes to a day |
Your browser also keeps a few choices locally (local storage): the Mono switch, the last window you were looking at, the size of a list. They never leave the browser and are not read by us.
Traffic
We count visits ourselves, on the server, because the readers that matter most here are machines: an AI agent runs no scripts, so a counter living in a browser cannot see it at all. Each request for a page or for one of the machine-readable files is recorded as one row:
| stored | what it is |
|---|---|
| host, path | which page was served |
| referrer | the page that linked here, when the browser sends one |
| country | two letters, as named by Cloudflare |
| user agent | what the client calls itself, cut to 200 characters, plus our reading of it: a person, a search crawler, an AI agent, another machine |
| languages | the list your browser sends with every request – used only inside the fingerprint below, never stored on its own |
| visitor | sixteen characters of a salted hash – see below |
| rendered | whether a browser actually drew the page |
The address is not stored, and it is not even hashed. What goes into the one-way hash is the network BLOCK your request came from (the last part of an IPv4 address is dropped, and rather more of an IPv6 one), the languages your browser asks pages in, the user agent, the current thirty-day window and a secret salt. We keep sixteen characters of the result. It cannot be turned back into an address, it is useless for finding anyone, and when the window turns over the same reader becomes a new one. Rows are deleted after 90 days.
The block is deliberately coarse - it is shared by a whole neighbourhood - so this is a count and not an identity: two readers can still melt into one. The figure is a floor on how many read us, never a headcount.
Alongside it we use Cloudflare Web Analytics, which is cookieless and aggregate: page views, countries, referrers and loading speed, with no identifier of any kind.
If you have an account
Accounts exist only for the people who run this service. For them we keep a user name, a password hash and the times of sign-in – nothing else, and nothing derived from what they look at.
Who processes what for us
- Cloudflare – the network in front of both hosts: protection, caching and the cookieless analytics named above.
- Railway – where the services and the database run.
The market data itself comes from public exchange feeds and public data providers, and the model opinions published on this site are generated from that data. None of it contains anything about the people who read it.
Your rights
Under the GDPR you may ask what we hold about you, ask for a copy, ask for it to be corrected or deleted, and object to processing. Given the above the honest answer is usually "nothing that identifies you", and we will say so plainly rather than sending a form back.
Write to [email protected]. You may also complain to your national data protection authority.
Changes
The date at the top is the edition. The day this page has to say something new – a new tool, a new kind of data – it will say it here, and the date will move with it.