There are no accounts, no tracking cookies, and no analytics beacons on this site. We keep short lived server logs and a transient rate limit counter. A transaction ID is public data on a public ledger, so submitting one tells us nothing private about you.
1. The short version
Most privacy policies in this category run to a few hundred words and say nothing. This one is longer because it says specifically what happens, and you should be able to check every claim in it against what your browser is actually doing.
What we do not do
No user accounts. No login. No tracking cookies. No advertising network. No analytics script. No fingerprinting. No selling or sharing of anything with a data broker. No email list you did not ask to join, because there is no email list.
2. A transaction ID is not personal data
This is worth explaining properly, because it is the single most common worry people have before pasting one.
A Bitcoin transaction ID is a public identifier for a record already published on a public ledger. Anyone in the world can look it up on any block explorer without your permission or knowledge. It is not linked to your name, your email, or your identity, and giving it to us does not give us any control over the coins. It is closer to a public tracking number than to a password.
What a transaction ID does reveal is the addresses and amounts in that transaction, which were already visible to everybody. If you would prefer not to associate your network address with a lookup, the site works normally over a VPN or Tor and we place no obstacles in the way of either.
3. What we collect
Server logs
Our web server records a line for each request, in the standard format any web server uses: the requesting network address, the time, the path requested, the response code, the number of bytes sent, the referring page if the browser sends one, and the user agent string. This is operational data. It is what lets us see that the site is up, that a page is not returning errors, and that we are not being attacked.
These logs rotate and are deleted on a rolling basis. We do not build profiles from them, do not join them to anything else, and do not share them, except where we are legally compelled to.
The transaction you submit
When you submit a transaction ID or raw hex, it is used to perform the lookup and the relay, and it appears in the request log like any other request path. We do not maintain a separate database of submitted transactions, and we do not link submissions to each other or to a person.
The rate limit counter
To protect the volunteer run public nodes we relay to, we count broadcast requests per network address over a rolling window. That counter holds a network address and a count, nothing else, and it expires by itself once the window passes. It is a throttle, not a record.
The daily measurement job
A scheduled job re-measures Bitcoin network statistics each morning and writes them to a public file. It reads the network, not you. Nothing about any visitor appears in /data/facts.json, which you can open and read yourself.
4. Cookies and local storage
We set no cookies for tracking, advertising, or analytics. The site works with cookies disabled entirely. If a preference is ever stored, it will be stored in your own browser, will exist only to make the site behave the way you asked, and will be named in this section before it ships.
5. Third parties your browser contacts
Being honest about this matters, because a site can promise not to track you while quietly loading four services that do.
| Third party | When | What it can see |
|---|---|---|
| Google Fonts | Every page | Your network address and browser, when fetching the typefaces |
| mempool.space | Every page, for the live figures in the header and footer | Your network address and that a fee or block height was requested |
| Public Bitcoin nodes and explorers | Only when you submit a transaction | The transaction, relayed from our server rather than from your browser |
| Formspree | Only when you send the contact form | What you typed into the form, including your email address |
| Our hosting provider | Every request | The traffic reaching the server, as any host necessarily does |
Each of these operates under its own privacy policy, which we do not control. The relay itself runs server side, so the public nodes see our server rather than you.
6. The relay, and what broadcasting means
When you ask us to rebroadcast, your signed transaction is sent to a set of independent public Bitcoin nodes. That is the entire purpose of the request, and it cannot be done privately, because broadcasting a transaction means telling the network about it.
This is inherent to Bitcoin rather than a choice we made. A transaction that nobody knows about cannot be mined. The nodes we relay to are named on the homepage so that you know in advance exactly who receives it.
7. The contact form
The contact form is handled by Formspree, which receives what you type and forwards it to us by email. Send us what is needed to answer your question and no more. In particular, never send a seed phrase or a private key to us or to anybody else, under any circumstances.
Messages are kept while the matter is open and for a reasonable period afterwards so we can pick up a thread you return to. Ask us to delete a message and we will.
8. What we never do with data
- We do not sell, rent, or trade anything to anybody.
- We do not share data with advertisers or data brokers, because we run no advertising.
- We do not attempt to identify you, or to connect submissions to a person.
- We do not use your data to train anything.
- We do not send marketing email. There is no list.
9. Security
The site is served over HTTPS with a strict transport policy, so browsers refuse to load it unencrypted. Security headers restrict what the page is allowed to load. Secrets live outside the web root with restricted file permissions. There is no user database to breach, because there are no user accounts, which is the strongest privacy measure available to any site: not holding the data in the first place.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the use of personal data about you, to object to its processing, and to complain to a regulator. Under the GDPR in the UK and EU those rights are explicit. Under the CCPA in California you additionally have the right not to be discriminated against for exercising them, and we do not sell personal information as that law defines selling.
Because we hold no accounts and build no profiles, there is usually very little to act on. Write to [email protected] and we will respond honestly about what we do and do not hold, rather than sending you a form letter.
Where the GDPR applies, our lawful basis is legitimate interest: keeping the service available, secure, and not overloaded. That basis covers server logs and the rate limit counter, and nothing broader.
11. Children
This site is not directed at children under 13, and we do not knowingly collect data from them. There is nothing here to sign up for.
12. International visitors
The server is in the European Union, so a request from elsewhere is processed there. Using the site means you accept that the request travels to the server handling it, which is true of every website.
13. Changes to this policy
Changes are recorded below with the date they took effect. If we ever add analytics, advertising, or anything that watches you, it will appear in this table before it appears on the site.
| Version | Effective | What changed |
|---|---|---|
| 1.0 | 29 August 2026 | First published. |
14. Contact
Privacy questions, deletion requests, and security disclosures go to [email protected] or through the contact form. We answer them ourselves.
Never send us a seed phrase
Not by email, not through the form, not to anybody claiming to be us. We have no use for one and would delete it immediately. Anyone who asks for yours is trying to take your coins.