This policy explains what personal data we process when you use radarcrypto.chat, why, for how long, who we share it with and how you can exercise your rights. It’s written to be understood, without hiding what our server can see.
In short
- No phone number, no email. Your identity is a 12-word key created on your device, and it’s never sent to our servers.
- We can’t read your conversations. Your 1:1 and group messages, your files and your calls are end-to-end encrypted. Public channels, on the other hand, are public.
- We do see some metadata: your IP address and Chat ID while you’re connected; who sends an encrypted envelope to whom, when and how big it is (for up to 7 days); and the URLs you request from our server, which stay in its logs for about 15 days.
- No ads, no third-party analytics, no trackers and no cookies. We don’t sell your data.
- Some features rely on third parties: Google’s STUN server sees your IP address, your browser’s push service receives encrypted notifications, and market data providers get your queries from our server, never with your IP address.
- Your rights: you can access, correct or delete your data, and more, by writing to info@radarcrypto.fun, and you can complain to the Spanish data protection authority (AEPD).
1. Who we are
The controller of your data is the owner of RadarCrypto (radarcrypto.chat), referred to in this policy as “RadarCrypto” or “we.” You can write to us about any privacy matter at info@radarcrypto.fun. We haven’t appointed a data protection officer: questions and requests are handled at that same address.
This policy applies to the website, to the RadarCrypto web app (including when you install it as an app) and to its test version, which handles data the same way. We are governed by Spanish law and by the EU General Data Protection Regulation (GDPR).
2. What data we process and why
RadarCrypto is designed so that your conversations live on your devices and on those of the people you talk to. Even so, our servers need to process some data to work. We don’t ask for your real name, phone number or email, but your Chat ID and your IP address are personal data, and we treat them as such. Here’s what we process and why, feature by feature; what’s stored only on your device is explained in section 8.
Account and Chat ID
When you create your account, your browser generates a 12-word key and, from it, your encryption keys. Your Chat ID is the public part of those keys: a 64-character code that identifies you on RadarCrypto. We only ask for a display name, which can be a nickname and stays on your device. Your 12-word key and your private keys are never sent to our servers.
When you open the app, your browser connects to our signaling server (the “relay”) and proves with your key, without revealing it, that you control your Chat ID. While you’re connected, the relay processes your Chat ID and your IP address to put you in touch with others and to enforce anti-abuse limits. It keeps them in memory and only writes your IP address to its log if you exceed one of those limits; separately, each connection is recorded in the web server’s access logs (see “Server logs”).
Profile
Your display name, photo and status are stored on your device and travel directly to your contacts and the members of your groups or, if they’re offline, inside encrypted envelopes. Our servers don’t store your profile, with two exceptions: the group call server receives the name you show when you join a call and keeps it in memory while the call lasts, to show who’s in it; and in channels, the Chat IDs of the owner, the admins and whoever posts are public.
1:1 messages
Your messages are end-to-end encrypted on your device and, if the other person is online, travel directly between your browsers (P2P). To open that direct connection, the browsers exchange some technical data through the relay, including your IP addresses. The relay doesn’t store it, but it sees who connects with whom and when. If your networks don’t allow a direct connection, the traffic goes through our TURN server, which forwards it without being able to decrypt it.
If the other person is offline, your message waits for them on our server as an encrypted envelope that we can’t open. Along with the envelope, we store the Chat IDs of the sender and the recipient, the time it arrived and its size. The envelope is deleted as soon as the recipient picks it up or, if they never do, after 7 days. The same goes for delivery and read receipts, reactions, edits and friend requests sent while the other person is offline.
Sync across your devices
It’s on by default. So that your conversations show up on every device where you use your 12-word key, your app leaves copies of your new messages, contacts and groups on our server, encrypted for you alone. They’re uploaded even if you only use one device. We can’t open them: we only see that they’re yours, when they were sent and how big they are. They expire after 7 days (sooner if many pile up). You can turn sync off in Settings (Ajustes); from then on, no new copies are created, and the existing ones expire within that period.
Groups
Group messages are end-to-end encrypted too. If the group is small (8 people or fewer) or the recipient is one of your contacts, and a direct connection is open, they can travel directly; otherwise they go through the relay as encrypted envelopes. For each envelope, the server sees who sends it, who it’s addressed to and a technical tag that is always the same for a given group, so it can tell which Chat IDs take part in the same group, though not the group’s name or what’s said in it. Envelopes are deleted when each recipient picks them up or, at the latest, after 7 days.
Files
Photos, videos, voice notes and documents are encrypted on your device (AES-256-GCM) before they leave it. If the other person is online, they go directly. If not, they’re uploaded, encrypted, to our file store, where they wait for up to 7 days; they’re deleted sooner once every recipient has them or if the sender withdraws them. We can’t see the file, its name or its type; we do know who uploads it, who it’s for, its size and when it’s uploaded and downloaded.
1:1 calls
Voice, video and screen-sharing calls between two people go directly between the browsers, encrypted with DTLS-SRTP, WebRTC’s mandatory encryption. The call notification and the connection data go through the relay, which sees who calls whom, when, whether it’s a video call and whether it’s accepted, declined or ended, but doesn’t store any of it. If there’s no direct route, the encrypted audio and video go through our TURN server, which sees both ends’ IP addresses, the time and the amount of data, but can’t decrypt them; its error logs may include IP addresses. We don’t record calls.
Group calls
Group calls go through our media server, which distributes the audio and video among the participants. Your browser encrypts them end to end before sending them, with a key our media server doesn’t have, so it passes them on without being able to see or hear them. If your browser can’t encrypt, it won’t let you join.
While the call lasts, that server keeps in memory the group’s identifier, the Chat IDs, the names you show, your IP addresses and when each person joins and leaves. Its logs keep a fragment of your Chat ID and a fragment of the group identifier, with the time (and your IP address, if you exceed a limit). Also, while you have a group open, the app checks every few seconds whether a call is in progress, and those requests are recorded in the access logs.
Presence
To show who’s online, your app sends the relay the list of Chat IDs of your contacts and your group mates. The relay keeps it only in memory while you’re connected and doesn’t store any “last seen.” Presence is mutual (you only see someone as online if they also have you) and, for now, it can’t be turned off. The “typing…” indicator only travels over the direct connection, and read receipts travel like any other message; you can turn both off in Settings → Privacy (Ajustes → Privacidad).
Public and private channels
A public channel is, as the name says, public: its name, description, photo and posts are stored on our server unencrypted, and anyone who has the link or finds it in “Descubrir” (the channel directory) can read them without following it. The Chat IDs of the owner, the admins and whoever signs each post are public too. If you create a channel or post in one, the public key you sign with is registered and linked to your Chat ID, and anyone can look it up.
In a private channel, the channel details and posts are encrypted with a key that only travels in the invite link and never reaches our server. Even so, the server sees the Chat IDs of the owner, the admins and the authors, and the dates, sizes and view counts of each post.
To follow a channel, react or vote in a poll, we don’t use your Chat ID but a pseudonymous identifier that’s different for each channel. If you turn on a channel’s notification bell, we do store the link between that channel and your Chat ID until you turn it off. When you use channels, your app asks our server for updates from your IP address: the list of channels you follow isn’t stored, but the channel you have open is recorded in the access logs along with your IP address.
Channels and their posts are kept for as long as they exist. The owner can delete a post (a marker remains with its author, dates and view count) or the whole channel, which deletes all its content. People who follow a channel may keep copies on their devices. The signing key linked to your Chat ID can’t be deleted from the app.
Channel reports
Anyone can report a channel or a post for scams, impersonation or spam. We store the channel, the post, the reason you write, the date and a fingerprint of your IP address. We keep reports so we can review them, and the fingerprint helps prevent abuse of the reporting system. We don’t store your Chat ID, but that fingerprint makes it possible to check whether a specific IP address filed a report, so reports aren’t fully anonymous. Reports aren’t currently deleted automatically.
Push notifications
They’re off by default. If you turn them on in Settings → Notifications (Ajustes → Notificaciones), your browser creates a subscription with its push service (Google’s, Mozilla’s, Apple’s or Microsoft’s, depending on the browser), and we store it with your Chat ID so we can notify you when the app isn’t open. The notification is encrypted all the way to your browser and doesn’t say who it’s from or what it says: the push service only sees when it’s sent and what type it is (message, call or channel).
The subscription doesn’t expire: it’s deleted when you turn notifications off in the app or when your browser’s service tells us it’s no longer valid. Logging out doesn’t delete it: if you want it gone, turn notifications off first. Separately, while the app is open, the notifications your own browser shows may include the beginning of a message; that doesn’t go through our server, and you can turn it off in Settings (Ajustes).
Link previews
By default, the app doesn’t generate previews: it shows you a “Ver vista previa” (“See preview”) button. If you tap it, or if you turn on automatic previews in Settings → Privacy (Ajustes → Privacidad), our server visits the link for you to build the card. That way, the destination website sees our server’s IP address instead of yours, but we know which link you previewed, whether you sent it or received it. The result is cached in memory for up to an hour, and the request, including the link, stays in the access logs for about 15 days.
Market features
Prices and risk analysis. When you ask for a price or a risk analysis, or when the app automatically shows the price of a “$SYMBOL” that appears in a message, your app asks our server. The server sees the symbol or the token address, not the conversation or who wrote it, and queries market data providers from its own IP address. The request is recorded in the access logs with your IP address. You can turn off automatic lookups in the “Cripto” panel.
Alerts and watches. To notify you, we store with your Chat ID each alert (coin, condition, value, time window, name, dates and number of notices sent) and each token watch (the token, the conditions and a snapshot of its data at that moment). Fixed-price alerts are deleted when they trigger; percentage-change alerts and watches are deleted when you remove them. Notices from “Radarcrypto Bot” reach you as encrypted envelopes, just like a message.
Predictions. Games don’t store who created them and are deleted 30 days after they close. Your vote is stored with its direction, its time and a fingerprint of your Chat ID (pseudonymous, not anonymous, data), and is deleted about 24 hours after the game closes. Predictions are just a game: there’s no money, no betting and no prizes.
Portfolio and Terminal
Portfolio. You can connect Phantom or Solflare just to see your balance (the app reads your public address and doesn’t sign anything), or follow any address. To calculate the balance, your address is sent to our server, which looks it up with Helius (on Solana) or with Etherscan and publicnode (on EVM networks). It doesn’t store the address on disk: it only keeps it in memory for a while to avoid repeating the lookup. On a phone without the extension, the connect button opens RadarCrypto inside the Phantom or Solflare app, which receives the URL of the page you were on.
If you share your portfolio with the /cartera command, the address goes in the request URL and stays in the access logs with your IP address. The card sent to the chat is encrypted, but anyone who receives it and taps “Actualizar” (“Refresh”) will also look up that address through our server.
Terminal. To quote and prepare a memecoin buy or sell, our server requests the data from Jupiter and other providers. When the trade is prepared, Jupiter receives your wallet address, the token and the amount, and returns the unsigned transaction to us; your wallet signs it and sends it to the Solana network. While the Terminal is open, we also look up your balance with Helius. To track the trade we use its signature, which stays in the access logs along with your IP address; since Solana transactions are public, that makes it possible to link that IP address to your wallet for as long as the logs are kept.
RadarCrypto doesn’t hold funds, doesn’t have your wallet’s keys and doesn’t charge trading fees. The Terminal’s conditions and risks are explained in the Terms of Service and in the Risk Disclosure.
Server logs
Like almost any website, our web server records every request it receives: your IP address, the date and time, the requested URL with its parameters, the response, the referring page and your browser’s identifier (User-Agent). Those URLs may contain data such as the link you preview, the channel you read, what you search for in channels or in the Terminal, the token or wallet address you look up, or a trade’s signature. These access logs are kept for about 15 days and then deleted automatically. The content of what you send, such as your encrypted envelopes or your alerts, isn’t logged.
Our services also log how they’re running and any errors. Those entries may include your IP address (if you exceed a limit, or in some TURN server errors) and a fragment of your Chat ID (when you join or leave a group call), and they’re kept for up to about 5 weeks. We use all these logs to keep the service running, detect faults and abuse and protect it; we don’t use them for advertising or profiling.
Aggregate statistics
To understand how the service is used, we produce aggregate statistics, for example how many people connect each day or how many messages and calls go through the server. To count distinct people without storing who is who, the relay uses fingerprints of the connected Chat IDs, computed with a random key that exists only in memory and is then discarded; only numbers, with no identifiers, are written to disk. We also count requests by type, without IP addresses or URLs. Hourly figures are kept for 90 days and daily totals indefinitely, since they don’t identify anyone. When you open certain screens, the app uses your key to check whether your Chat ID belongs to an administrator; the statistics service doesn’t store it.
3. What your contacts can see
When you chat or call over a direct connection, the other person’s browser receives your IP address, because that’s how a P2P connection works, and someone with technical knowledge can see it. This happens even if the connection ends up going through our TURN server. Members of your groups see your name and your Chat ID.
In addition, anyone who knows your Chat ID, even if you haven’t accepted them as a friend, can send you a friend request and call you and, if you’re online, open a direct connection with you and so see your IP address, name, photo and status. Their messages don’t reach you until you accept their request. For now, the app doesn’t let you block a person.
4. Legal bases
We only process your data when we have a legal basis to do so. Here’s the basis for each purpose:
| Purpose | Legal basis |
|---|---|
| Providing RadarCrypto as you request it: your account, messages and their encrypted envelopes, sync, groups, files, calls, presence, channels, market features, alerts, watches, predictions, the portfolio and the Terminal | Performance of a contract (Art. 6(1)(b) GDPR): without this data we can’t provide the service you accept in the Terms of Service |
| Sending you push notifications when the app isn’t open | Your consent (Art. 6(1)(a) GDPR), which you give by turning them on and withdraw by turning them off |
| Generating link previews | Your consent (Art. 6(1)(a) GDPR), which you give by tapping “Ver vista previa” or turning on automatic previews, and withdraw by turning them off |
| Protecting the service: anti-abuse limits, fraud prevention and server logs | Our legitimate interest (Art. 6(1)(f) GDPR) in keeping the service secure and available to everyone |
| Reviewing channel reports and preventing abuse of reporting | Our legitimate interest (Art. 6(1)(f) GDPR) in fighting scams and abuse in channels |
| Producing aggregate usage statistics | Our legitimate interest (Art. 6(1)(f) GDPR) in understanding how the service is used so we can improve it, with figures that don’t identify anyone |
| Handling your rights requests and meeting our legal obligations | Compliance with a legal obligation (Art. 6(1)(c) GDPR) |
Where we rely on legitimate interest, you can object to the processing (see section 9). You don’t need to give us any identifying data to use RadarCrypto, we don’t make automated decisions that have legal effects on you or similarly significantly affect you, and we don’t profile you for advertising.
5. How long we keep data
These are the actual retention periods for what we keep. Everything is stored on our server, hosted in the EU.
| Data | How long |
|---|---|
| 1:1 and group message envelopes, with sender, recipients, time and size | Until each recipient picks them up; 7 days at most |
| Sync envelopes between your devices | 7 days at most (sooner if many pile up) |
| Encrypted files for offline recipients, with sender, recipients, size and times | Until every recipient picks them up or they’re withdrawn; 7 days at most |
| Notices from “Radarcrypto Bot” | Like any envelope: 7 days at most |
| Push notification subscription, with your Chat ID | No expiry: until you turn notifications off or your browser’s service invalidates it. Logging out doesn’t delete it |
| Channels, posts and images, with the Chat IDs of the owner, the admins and the authors | For as long as they exist, until the owner deletes them. A deleted post leaves a marker with its author, dates and view count until the channel is deleted |
| Channel followers, reactions and votes (pseudonymous) | Until you remove them or the channel is deleted |
| A channel’s notification bell (channel and Chat ID) | Until you turn it off, leave the channel or it’s deleted |
| Public post-signing key, linked to your Chat ID | No set period; for now it can’t be deleted from the app (you can ask us to) |
| Channel reports, with the IP fingerprint | No set period; for now they aren’t deleted automatically |
| Price alerts, with your Chat ID | Fixed-price alerts, until they trigger or you remove them; percentage-change alerts, until you remove them |
| Token watches, with your Chat ID | Until you remove them |
| Prediction votes | About 24 hours after the game closes |
| Prediction games (with no creator) | 30 days after they close |
| Web server access and error logs (IP address, URL and User-Agent) | About 15 days |
| Service logs (IP address in some cases, and Chat ID fragments) | Up to about 5 weeks |
| Aggregate statistics (no identifiers) | Hourly figures, 90 days; daily totals, indefinitely |
| Data held only in memory: connections, presence, ongoing calls, previews, portfolio lookups and sessions | While the connection or call lasts, or for a short time afterwards; some caches are only cleared when they fill up or the server restarts. Fingerprints for statistics, up to 30 days |
6. Who we share your data with
We don’t sell your data, we don’t show ads and we don’t use third-party analytics or trackers: the website and the app only load code from our own domain. Even so, some features need other providers. Here’s what each one receives:
| Who | What they receive | When |
|---|---|---|
| Hostinger (Hostinger International Ltd and HOSTINGER operations, UAB), our data processor | Hosts our server in the EU (France), with all the data and logs described in this policy; a security scanner from the provider itself also runs on it. It’s also our domain registrar and DNS provider | Always |
| Google, STUN servers | Your public IP address and port, which your browser asks it for so it can connect directly | When opening direct chat connections and when calling |
| Your browser’s push service (Google, Mozilla, Apple or Microsoft) | Your subscription address, an encrypted notification it can’t read, its type (message, call or channel) and the time | If you turn notifications on and the app isn’t open |
| Websites of the links you preview | The URL we visit, from our server’s IP address; they don’t get your IP address | When you request a preview |
| Market and blockchain data providers: Helius, Jupiter, DexScreener, GeckoTerminal, pump.fun, Etherscan, publicnode, honeypot.is, CoinGecko, alternative.me and frankfurter.dev, plus the websites we get logos and news from | What you look up: symbols, token and pool addresses, Terminal searches, transaction signatures and hashes and, for the portfolio and the Terminal, your wallet address. Always from our server: they never get your IP address, browser or Chat ID. Logo and news requests include nothing about you | Prices, risk analysis, alerts, watches, portfolio, Terminal and commands |
| Your wallet (Phantom or Solflare) | The connection request and, when you trade, the unsigned transaction, which your wallet signs and sends. On a phone without the extension, the URL of the page you were on | When you connect and when you trade. What your wallet does with its own servers is governed by its own privacy policy |
| The Solana network | Your signed transaction, which is public on the blockchain | When you trade; your wallet sends it |
| External websites you open from the app (explorers, DEXs, social networks) | Whatever the link contains, plus your IP address, like any website you visit | Only if you tap the link |
| Authorities | The data the law requires us to provide | Only when there’s a legal obligation |
Hostinger processes the data on our behalf, as a data processor. The others receive only what’s needed for the feature you use and handle that data under their own policies.
7. International transfers
Our server is in the European Union. Some of the third parties in the previous section are outside the European Economic Area (EEA), for example in the United States. When using their services involves transferring your data outside the EEA, the transfer relies on a European Commission adequacy decision (for example, the EU-U.S. Data Privacy Framework, for companies that participate in it) or, where there isn’t one, on the transfer being necessary to provide the feature you ask us for (Art. 49(1)(b) GDPR).
To keep what leaves the EEA to a minimum, market lookups are made from our server, without your IP address or Chat ID.
8. Data on your device
Most of your data isn’t on our servers but in the browser on your device: your 12-word key, your contacts, your messages, the files you send and receive, your groups and their keys, the channels you follow, your settings and your Terminal preferences. They’re kept in the browser’s local storage, not in cookies, and we list them in detail in the Cookie Policy.
That storage isn’t encrypted. If you turn on the PIN, your 12-word key is encrypted, but your messages and files aren’t: someone with technical access to your browser could read them. Protect your device with a screen lock.
To really delete your data:
- First of all, make sure you have your 12-word key written down if you want to use your account again.
- Turn off notifications in Settings → Notifications (Ajustes → Notificaciones): this deletes your subscription from our server.
- Remove your alerts and watches from their panels.
- If you want, delete the channels you created and turn off the bells of the ones you follow.
- Delete the site data for radarcrypto.chat in your browser settings; we explain how in the Cookie Policy.
If you downloaded your key as a text file (which isn’t encrypted) or made .rcbak backups, they’re outside the browser: delete them yourself if you no longer need them. Anything still on our server linked to your Chat ID, we can delete if you ask us (section 9).
9. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time. Where we process your data based on your consent, you can withdraw it whenever you like, without affecting the processing carried out before.
How to exercise them
Write to us at info@radarcrypto.fun saying which right you want to exercise. Since we don’t ask for your name, phone number or email, the only way to find your data is your Chat ID, so please include it. To make sure the account is yours, we may ask for proof that you control it, such as a message signed from the app or the answer to a challenge. If we can’t verify it, we may not be able to act on the request. We’ll reply within one month, which may be extended by two more months if the request is complex; if so, we’ll let you know.
What you can already do in the app
- Change your name, photo and status.
- Take your conversations, contacts and groups with you in an encrypted backup (
.rcbak). - Turn off sync, read receipts, “typing…”, automatic previews and automatic price lookups.
- Turn off push notifications, which deletes your subscription from our server.
- Remove your alerts and watches, unfollow channels, turn off their bells and delete your channels and posts.
- Leave a group, clear or delete chats, clear stored files and the local activity log, and disconnect your wallet.
Deleting your account
There’s no “delete account” button for now: your account is your 12-word key, and our servers don’t keep a profile of you to delete. Envelopes, files and sync data expire on their own within 7 days at most; you can delete the rest yourself by following the steps in section 8.
If you ask us, with your Chat ID and proof that the account is yours, we’ll delete whatever is still linked to your Chat ID on our server: your notification subscription, your alerts and watches, channel bells, your post-signing key and, if you want, the channels you created along with their posts. We can’t delete what’s on your devices or other people’s, such as messages you already sent them, or anything not linked to your Chat ID, such as IP-based logs, which are deleted automatically within the periods in section 5.
Complaints
If you think we haven’t handled your data properly, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the data protection authority in your EU country. We’d appreciate it if you wrote to us first so we can try to sort it out.
10. Minors
RadarCrypto is only for people aged 18 or over. We don’t knowingly process data from minors. Since we don’t ask for identity details, we can’t check anyone’s age; if you know a minor is using the service, write to us and we’ll delete whatever we can identify.
11. Security
We protect your data with end-to-end encryption for conversations, encrypted connections to our server, isolated services and anti-abuse limits. No system is 100% secure: on our Security page we explain in detail what we do, its limits and what’s up to you.
12. Changes to this policy
We may update this policy when the service or the law changes. We’ll publish the new version here with its date and, if the change is significant, we’ll announce it visibly on the website or in the app before it takes effect.
13. Contact
For any question about this policy or your data, write to us at info@radarcrypto.fun.