Privacy policy
Vaultonaut works without an account and without a profile. This policy still states exactly what data travels where — including where that is awkward. This is a translation; the German version is authoritative.
1. Controller
Julian Pachernegg
Trading as: Vaultonaut
Johann-Schrey-Weg 260
8232 Grafendorf, Austria
Email: vaultonaut@proton.me — further details in the imprint.
2. What we do not do
There is no registration, no account and no user profile. We keep no database of addresses, amounts or analyses. We run no analytics or advertising tools of our own and pass nothing on for advertising purposes.
3. What stays in your browser
Your settings live in your browser's local storage and are not transmitted to us:
- vaultonaut.settings.v1 — currency, hidden balances, refresh interval, chain selection and the address last tracked
- vaultonaut.locale — a cookie holding “de” or “en”, set only when you switch language. It decides which language an address without a language prefix lands in.
- vaultonaut.taxpayer.v1 — only if you explicitly tick “remember” on the tax report: the name, address and tax number written into the PDF. Nothing is stored without that tick, and un-ticking it deletes what was stored. These details never leave your browser — the PDF is produced there.
The first two are technically necessary for the service you asked for, so no consent is collected for them (§ 165 (3) TKG 2021); the third is created only on your explicit instruction. You can clear all of them at any time through your browser settings; “Reset” on the settings page removes the local storage.
4. What reaches our server
When you analyse an address, that address is transmitted to our server, because it runs the queries on your behalf. A wallet address is a pseudonym; in an individual case it can identify a person. We do not store it permanently — it appears in the request and in a short-lived cache that expires within minutes.
Like any web server, ours also logs technical access data: IP address, timestamp, requested URL, status code, user agent and referrer. These logs serve operation and abuse prevention, are rotated daily and deleted after 14 days. The legal basis is our legitimate interest in a working, secure service (Art. 6(1)(f) GDPR).
5. What reaches third parties
To produce an analysis, our server queries the protocols it reports on and a few data services: Morpho (api.morpho.org), Accountable (yield.accountable.capital), Yuzu (app.yuzu.money and defi-point.yuzu.money), Merkl (api.merkl.xyz), CoinGecko (api.coingecko.com), and Ethereum nodes (rpc.mevblocker.io, falling back to eth.drpc.org) for reading the chain directly. Because the server does this rather than your browser, those services never learn your IP address — though they do learn the wallet address being queried, since there is no answer without it. Not every request reaches all of them: which services are contacted depends on the chains selected and on which vaults the address holds anything in.
Wallet connectivity is different. The Reown library (formerly WalletConnect) starts up with the page and calls api.web3modal.org for its configuration and pulse.walletconnect.org besides — before you click anything. These calls come from your browser, so Reown learns your IP address on every page view. What is sent is the public project identifier, not your wallet address.
If you additionally open the wallet dialog, its styling loads a font from fonts.googleapis.com, at which point Google learns your IP address. The site's own fonts are served from our server and load nothing externally.
Usage statistics are switched off for this project at Reown, so no usage events are recorded. The two calls themselves cannot be prevented from within the page — the first is how the library learns that setting in the first place.
Reown and Google are based in the United States. For those transfers the providers rely on the European Commission's standard contractual clauses and on the EU-US Data Privacy Framework respectively. If you would rather avoid even that, the site works without a wallet — typing an address into the bar at the top involves none of it; only a tracking blocker in your browser stops the calls made during page load.
6. Your rights
You have rights of access, rectification, erasure, restriction, portability and objection (Art. 15 to 21 GDPR). In practice they mostly come up empty, because we hold nothing about you that could be attributed to a person — apart from the last 14 days of server logs. An email to vaultonaut@proton.me is enough to make a request.
You may also lodge a complaint with the Austrian Data Protection Authority: dsb.gv.at.
7. Changes
If what flows where changes, this policy changes with it. The version published here applies; the date appears at the end.
Last updated: August 14, 2026