Privacy Policy
How Jepeta Risk Guard handles browser-session data, scan telemetry, support and commerce records.
Scope
This policy describes data handling for jepeta.dev, the free Base token scanner, Jepeta's public web surfaces, and related support or paid-report flows. Jepeta Risk Guard is the service name used on this site.
Data we process
- Browser telemetry context: a random page-lifetime identifier, attribution parameters present in the URL, and the external referrer host when available. Jepeta does not persist these analytics identifiers in cookies or Web Storage.
- Product telemetry: events such as page view, scan start/success/error, outbound report clicks, status code, duration, and the scanned token contract address when relevant.
- Security and abuse prevention: request metadata needed to rate-limit abuse. The analytics endpoint derives a one-way hash from the requesting IP for rate limiting; Jepeta does not intentionally store the raw IP in its funnel event record.
- Telegram and paid-report records: if you use the Telegram bot or a paid rail, the service may process Telegram user/chat identifiers, invoice/payment state, report-delivery state, support events and transaction references required to deliver or support that service.
- Public blockchain or token data: contract addresses and risk observations are not treated as identifying a natural person merely because they are public blockchain data.
Why we process it
We use this data to provide scans and reports, preserve source attribution, measure whether the product works, diagnose failures, prevent abuse, support users, and maintain payment/report records where a paid service is used.
Browser storage and cookies
Jepeta's public web pages do not intentionally set cookies, localStorage or sessionStorage for analytics. A random telemetry identifier is held in memory for the lifetime of the current page only and is discarded on navigation or reload. Third-party destinations you choose to open may apply their own storage or privacy practices.
Service providers and external sources
Jepeta relies on infrastructure and data providers including GitHub Pages, Supabase, GoPlus Security and DEX Screener. GitHub states that visitor IP addresses are logged for security when GitHub Pages sites are visited. Optional support or commerce flows may involve Telegram and Virtuals ACP. Those providers process data under their own terms and privacy practices when applicable.
Retention
Jepeta applies automatic minimization to operational data. Browser funnel and Telegram product-event telemetry is retained for up to 90 days; request and edge-failure telemetry for up to 30 days; hashed rate-limit keys for up to 2 days; processed Telegram update-deduplication records for up to 30 days; delivered report payloads and resolved support requests for up to 180 days. Expired attribution codes are removed after a short grace period. Payment ledger and terms-acceptance records are kept separately and are not automatically purged by this operational cleanup because mandatory accounting or legal retention may apply.
International processing
Jepeta is an internet service and its infrastructure or service providers may process data in more than one country. Applicable privacy rights are not waived because processing is international.
Your choices and rights
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal data. To make a privacy request, use the contact channel below and identify the request as a privacy matter. We may need enough information to verify that the request relates to you.
Sale of personal data
Jepeta does not operate a business model that sells personal data to advertisers or data brokers.
Contact
Use Jepeta_bot on Telegram and send /support. Do not post secrets, seed phrases, private keys or sensitive personal information in public GitHub issues.