Legal
Privacy Policy
This explains what we collect, why, and what you can do about it. We are the data controller for the information described here, under the UK GDPR and the Data Protection Act 2018.
What we collect
You give us
- Email address, and name if you provide one.
- A password, stored only as a bcrypt hash — we cannot read it, and neither can anyone who obtains the database.
- Your Telegram chat ID, only if you enable Telegram alerts.
- Anything you type into the contact form.
We generate
- Which token addresses you scan, and when. This enforces plan limits and is used in aggregate to improve the engine.
- Your watchlists and alert rules.
- Basic security logs, including IP address, retained for 30 days.
We never collect
- Your wallet's private keys or seed phrase. There is no field for them anywhere and we would never ask.
- Card numbers. Payments go directly to Stripe; we store only a customer reference and invoice metadata.
- Any link between your HoneyRug account and a wallet you own, unless you explicitly connect one.
Why we're allowed to hold it
- Contract — account, scans, watchlists, alerts and billing. Without these we cannot provide the service.
- Legitimate interests — security logging, abuse prevention and aggregate product analytics, balanced against your rights.
- Legal obligation — retaining transaction records for tax and accounting purposes.
- Consent — marketing email, if you opt in. You can withdraw it at any time without affecting your account.
Who processes it
We use a small number of processors, each bound by a data processing agreement: Vercel (hosting), our managed PostgreSQL provider (database), Upstash (cache and rate limiting), Stripe (payments, a controller in its own right for fraud prevention), and Telegram (only if you enable alerts). Token analysis requests are sent to GMGN; these contain contract addresses, never anything about you.
We do not sell your data, and we do not share it for advertising.
How long we keep it
- Account data: while your account exists, then 30 days.
- Scan history: 12 months, then aggregated and de-identified.
- Billing records: 7 years, as UK tax law requires.
- Security logs: 30 days.
Your rights
You have the right to access, correct, delete, restrict or object to our processing, and to receive your data in a portable format. Delete your account from Settings and the deletion runs immediately; email us through the contact page for anything else. We respond within 30 days and do not charge for it.
If you think we have handled your data badly, please tell us first — but you can complain to the Information Commissioner's Office at any point.
Cookies
We set one strictly necessary cookie to keep you signed in. There are no advertising cookies, no third-party trackers and no cross-site profiling, which is why you are not looking at a consent banner.
Transfers outside the UK
Some processors operate outside the UK. Where they do, transfers are covered by UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
Changes
We will notify you by email before any material change takes effect.
Last updated: 2026 · Add your registered company name, address and ICO registration number before launch, and have this reviewed by a data protection adviser.