Vaultonaut

Privacy policy

Vaultonaut works without an account and without a profile. This policy still states exactly what data travels where — including where that is awkward. This is a translation; the German version is authoritative.

1. Controller

Julian Pachernegg
Project: Vaultonaut
Grafendorf bei Hartberg, Austria

Email: vaultonaut@proton.me — further details in the imprint.

2. What we do not do

There is no registration, no account and no user profile. We keep no database of addresses, amounts or analyses. We run no analytics or advertising tools of our own and pass nothing on for advertising purposes.

3. What stays in your browser

Your settings live in your browser's local storage and are not transmitted to us:

  • vaultonaut.settings.v1 — currency, hidden balances, refresh interval, chain selection and the address last tracked
  • vaultonaut.locale — a cookie holding “de” or “en”, set only when you switch language. It decides which language an address without a language prefix lands in.
  • vaultonaut.taxpayer.v1 — only if you explicitly tick “remember” on the tax report: the name, address and tax number written into the PDF. Nothing is stored without that tick, and un-ticking it deletes what was stored. These details never leave your browser — the PDF is produced there.

The first two are technically necessary for the service you asked for, so no consent is collected for them (§ 165 (3) TKG 2021); the third is created only on your explicit instruction. You can clear all of them at any time through your browser settings; “Reset” on the settings page removes the local storage.

4. What reaches our server

When you analyse an address, that address is transmitted to our server, because it runs the queries on your behalf. A wallet address is a pseudonym; in an individual case it can identify a person. We do not store it permanently — it appears in the request and in a short-lived cache that expires within minutes. The legal basis is our legitimate interest in providing the service you are actively requesting at that moment (Art. 6(1)(f) GDPR) — there is no account and no contract for Art. 6(1)(b) GDPR to attach to.

Like any web server, ours also logs technical access data: IP address, timestamp, requested URL, status code, user agent and referrer. These logs serve operation and abuse prevention, are rotated daily and deleted after 14 days. The legal basis is our legitimate interest in a working, secure service (Art. 6(1)(f) GDPR).

5. What reaches third parties

To produce an analysis, our server queries the protocols it reports on and a few data services: Morpho (api.morpho.org), Accountable (yield.accountable.capital), Yuzu (app.yuzu.money and defi-point.yuzu.money), Ember (vaults.api.prod.ember.so), Merkl (api.merkl.xyz), CoinGecko (api.coingecko.com), and public blockchain nodes for reading the chain directly (for Ethereum rpc.mevblocker.io, falling back to eth.api.onfinality.io; for Pharos rpc.pharos.xyz; for the other chains their public default nodes). The event logs of Ember's vaults are fetched from Routescan (api.routescan.io, Ethereum) and Blockscout (base.blockscout.com, Base) — by vault address only, never with the wallet address being queried. Because the server does this rather than your browser, those services never learn your IP address — though they do learn the wallet address being queried, since there is no answer without it. Not every request reaches all of them: which services are contacted depends on the chains selected and on which vaults the address holds anything in. The legal basis is the same legitimate interest as in section 4: without these requests, the analysis you asked for does not exist (Art. 6(1)(f) GDPR).

Wallet connectivity is different, and where you are on the site decides what happens. The landing page, the methodology page and these legal documents do not load the wallet library at all; on those pages not a single request goes out to a third party.

The wallet dialog itself loads nothing: its styling uses your system's own fonts. The site's fonts are served from our server as well. Nothing goes to Google.

The one exception: click “Connect wallet” on any application screen — dashboard, vaults, income, rewards, analytics, tax report or settings — and only then does the Reown library (formerly WalletConnect) start up and immediately call api.web3modal.org for its configuration and pulse.walletconnect.org for technical telemetry. Simply opening an application screen or typing in an address no longer triggers this. Here too the legal basis is our legitimate interest in providing the feature you explicitly requested with that click (Art. 6(1)(f) GDPR).

If you then pick WalletConnect as the connection method and actually establish a connection to a wallet, further Reown/WalletConnect infrastructure gets involved — in particular the relay service that carries the connection itself, and a verify service that checks the request. Exactly which hosts those are depends on the package version in use; at present they include, among others, services under relay.walletconnect.org and verify.walletconnect.org, plus further subdomains of walletconnect.com, walletconnect.org and web3modal.org. This list is deliberately not a closed catalogue we could keep in sync with every library update — it describes what the calls are for. The calls come from your browser, so Reown learns your IP address along with technical device and connection information; it also receives the public project identifier and, once a wallet responds, that wallet's public address — never a private key or seed phrase, which never leave the wallet app and reach neither Reown nor Vaultonaut.

Usage statistics are switched off for this project at Reown, so no usage events are recorded. Once you click the connect button, the first of these calls cannot be prevented — it is how the library learns that setting in the first place. Without that click, none of the calls described above happen at all.

Reown is based in the United States. According to Reown's own privacy policy, a transfer there may rely on the European Commission's standard contractual clauses or, depending on the destination country, on an adequacy decision — we checked this against what Reown publishes, but cannot vouch for Reown's future practice. Further information about the safeguards in place, and a copy of the clauses actually used, can be requested through the contact address given above. To avoid the transfer entirely, simply do not click “Connect wallet” — opening any application screen and typing in an address will not trigger these calls on their own.

6. Your rights

You have rights of access, rectification, erasure, restriction, portability and objection (Art. 15 to 21 GDPR). In practice they mostly come up empty, because we hold nothing about you that could be attributed to a person — apart from the last 14 days of server logs. An email to vaultonaut@proton.me is enough to make a request.

You may also lodge a complaint with the Austrian Data Protection Authority: dsb.gv.at.

7. Changes

If what flows where changes, this policy changes with it. The version published here applies; the date appears at the end.

Last updated: September 28, 2026