1. Who is responsible
Gliese Watch (gliese.io) is operated by Devcode Technology, which decides how and why personal data is processed for the Service and is therefore the “controller” in data-protection terms. You can reach us about anything in this policy at [email protected].
This policy covers the website, the public feed and contract pages, accounts, the Telegram bot, webhooks and email alerts, and any API we offer. It does not cover the wallets, networks, Telegram or other services you use alongside Gliese; each of those has its own policy.
2. What we collect
We collect as little as the Service needs. Depending on how you use it, that is:
- Wallet addresses. The address you sign in with and any others you link, plus the signed sign-in message itself (address, domain, one-time nonce, chain id, timestamp). We do not receive private keys or seed phrases and never ask for them.
- Telegram chat id and the username Telegram shows us when you link the bot, so alerts can reach your chat.
- Email address, only if you add one for email alerts (a paid-plan channel).
- Webhook URL, only if you add one, plus delivery results (status code, timing) so you can see whether it works.
- Your watchlist and settings: the contract addresses you watch, minimum severity per contract, an optional display name, theme choice. If you enable wallet auto-discovery, the contracts we resolve from your linked wallets’ on-chain positions.
- Payment records for paid plans: the paying wallet, network, token, amount, transaction hash, the quote you generated at checkout and the days credited. No card or bank details exist in our system.
- Alert history: which events were sent to which of your channels and whether delivery succeeded.
- Technical logs: IP address, browser user agent, requested URL, timestamp and status for requests to our servers, and error reports. These are ordinary web-server logs used for security and debugging.
- Analytics, only after you accept it in the cookie banner: pages viewed, referrer, approximate country or city, device and browser type, via Google Analytics 4. GA4 does not store IP addresses, and we have turned off Google Signals and ad personalisation.
- Support correspondence: whatever you send us by email or Telegram when you ask for help.
We do not collect your name (unless you put one in the display name field), government identifiers, payment cards or precise location, and we do not buy data about you from anyone.
3. Why we use it, and on what basis
In plain words, each use has a reason the law recognises:
- To run the Service you asked for — sign you in, keep your watchlist, resolve the contracts behind your wallets, send the alerts you configured, credit your payments. Basis: performing our contract with you (the Terms).
- To keep the Service secure and fair — detect abuse, rate-limit scrapers, investigate errors, protect the treasury from fraud. Basis: our legitimate interest in running a safe service, which we have balanced against your interests; server logs are the main tool here and are short-lived.
- To keep records we must keep — payment records for accounting and tax, responses to lawful requests. Basis: legal obligation.
- To understand which pages help — aggregated analytics. Basis: your consent, given in the cookie banner and withdrawable at any time.
- To answer you when you contact us. Basis: our legitimate interest in responding, or the contract if it is about your account.
We do not sell personal data, we do not show ads, and we do not build profiles of you for anyone. We do not make automated decisions about you with legal or similarly significant effects.
4. How long we keep it
- Notifications (records of which alert went to which channel, and delivery status): 90 days, then deleted.
- Setup-noise events (deployment-time events we tag as “init” and hide by default): 30 days, then deleted.
- Account data (wallets, channels, watchlist, settings): until you delete your account or ask us to delete it. Unlinking a wallet, Telegram, email or webhook removes that item straight away.
- Payment records: for as long as accounting and tax rules require after the payment, even if the account is deleted earlier; the on-chain transaction itself is public and permanent regardless.
- Server logs: rotated and kept for no longer than 30 days, except where an entry is needed for an ongoing security investigation.
- Analytics: event-level data in Google Analytics is kept for no longer than 14 months; aggregated reports may be kept longer but contain no identifiers.
- Real on-chain change events (the public feed) are records of public blockchain activity, not of you, and are kept as part of the Service.
7. Your rights and choices
Wherever you live, we will honour these requests; in the EU/EEA, the UK and a growing list of other places they are also legal rights:
- Access — ask what personal data we hold about your account and receive a copy in a common format.
- Correction — fix anything inaccurate; most fields you can edit yourself in settings.
- Deletion — ask us to delete your account and its data. We will do so within 30 days, keeping only what the law obliges us to keep (payment records).
- Objection and restriction — object to processing based on legitimate interest, or ask us to pause it while a dispute is resolved.
- Withdraw consent — change your analytics choice with “Cookie settings” in the footer. Withdrawing does not affect what happened before.
- Portability — receive the data you gave us in a machine-readable form.
- Complain — to the data-protection authority where you live, if you think we have handled your data badly. We would appreciate the chance to fix it first.
Self-service: you can unlink a wallet, unlink Telegram, remove an email or webhook, and remove contracts from your watchlist at any time in the app’s settings, and sign out to end your session.
To exercise a right, email [email protected]. Because accounts have no name or password, we will ask you to prove you control the linked wallet, usually by signing a short message; this protects your data from anyone who merely knows your address. We respond within 30 days.
8. Public blockchain data
Wallet and contract addresses, balances and transactions are recorded on public blockchains that anyone can read and that nobody, including us, can edit or erase. Our public pages display that data. When you link a wallet, you are telling us that a public address is yours; we keep that link private, we do not publish which addresses belong to which account, and deleting your account removes the link from our systems. It cannot remove anything from the chain itself.
9. International transfers
Devcode Technology is based in the Republic of Seychelles, and the providers listed above operate servers in the European Union, the United States and elsewhere. Your data may therefore be processed outside the country you live in. Where the law of your country requires safeguards for such transfers (for example in the EU/EEA and the UK), we rely on the providers’ standard contractual clauses and equivalent mechanisms, and we keep the data involved to a minimum, as described in this policy.
10. Security
All traffic is encrypted in transit (HTTPS). Sessions use an httpOnly cookie that scripts cannot read, there are no passwords to leak, and we never hold private keys. Access to production systems is limited to the people who run the Service. No system is perfectly secure; if you believe you have found a vulnerability, please tell us at [email protected] before disclosing it publicly.
11. Children
The Service is not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the Service changes; the current version is always at gliese.io/privacy with its “last updated” date. If a change materially affects how we use your data, we will make reasonable efforts to notify you in advance on the site or through a channel you gave us. Continued use after the effective date means you accept the updated policy.
13. Contact
Devcode Technology, operator of Gliese Watch, Republic of Seychelles. Email: [email protected]. Please mention the wallet address linked to your account so we can find it.