Cookies & privacy
Optional cookies support analytics and advertising on content pages. You can accept or reject them. Privacy Policy.
Skip to content
Jjepeta.
SecurityToolsGuidesResearchScanner
Scan a token
TRUST / PRIVACY

Privacy Policy

How Jepeta Risk Guard handles browser-session data, scan telemetry, support and commerce records.

Last updated: October 6, 2026
AboutPrivacyTermsRisk disclaimerAccessibilityContact

Scope

This policy describes data handling for jepeta.dev, the free Base token scanner, Jepeta's public web surfaces, and related support or paid-report flows. Jepeta Risk Guard is the service name used on this site.

Jepeta is read-only on the web: the scanner does not connect to a wallet, request a wallet signature, or execute a trade.

Data we process

  • Browser telemetry context: a random browser-journey identifier, first-touch campaign parameters, a public publication/attribution code when present, and the external referrer hostname. These are kept in this tab’s sessionStorage for an absolute 30-minute window so navigation between the scanner, docs and app retains the same source. Owner, test and browser-automation markers help exclude internal activity; a browser journey is not a verified person.
  • Product telemetry: events such as page view, scan start/success/error, visible report offers, checkout preparation, outbound report clicks, status code, duration, and the scanned token contract address when relevant.
  • Security and abuse prevention: request metadata needed to rate-limit abuse. The analytics endpoint derives a one-way hash from the requesting IP for rate limiting; Jepeta does not intentionally store the raw IP in its funnel event record.
  • Telegram and paid-report records: if you use the Telegram bot or a paid rail, the service may process Telegram user/chat identifiers, invoice/payment state, report-delivery state, support events and transaction references required to deliver or support that service.
  • Public blockchain or token data: contract addresses and risk observations are not treated as identifying a natural person merely because they are public blockchain data.

Why we process it

We use this data to provide scans and reports, preserve source attribution, measure whether the product works, diagnose failures, prevent abuse, support users, and maintain payment/report records where a paid service is used.

Telegram checkout attribution

Preparing a report checkout creates a short attribution code that connects the current token, browser journey and acquisition source to the bot flow. Browser events alone do not identify a Telegram user. If you open the attributed bot link or purchase a report, server-side records can associate that code and journey with your Telegram user/chat identifiers and invoice or purchase records. This supports delivery, support and source-to-purchase measurement. The 30-minute browser expiry is separate from server retention: operational funnel records may be retained for 90 days, and payment records follow the retention rules below.

Browser storage and cookies

Intelligence pages use a random localStorage identifier for up to 14 days to measure return visits during the pilot. The identifier does not itself contain your name or Telegram account. If the same browser journey later opens an attributed Telegram link or checkout, existing attribution records may associate that journey with a Telegram account. Owner, test and known automated traffic is excluded from the pilot metrics. Blocked storage produces incomplete visitor counts rather than inferred identities.

Jepeta uses sessionStorage for the per-tab browser journey described above. Its absolute 30-minute expiry is not extended by activity; expired values are discarded on the next access, and the browser normally clears sessionStorage when the tab closes. If this storage is blocked, the journey stays in page memory and may not survive navigation.

For visits attributed to the October 6 tax-tools experiment, Jepeta also stores a random first-party visitor identifier and owner/test exclusion marker in localStorage for an absolute seven-day window. Activity does not extend that window; expired values are discarded on the next experiment access. The identifier joins that campaign's page, engagement and outbound-link events across tabs and sessions in the same browser. If localStorage is unavailable, visitor identity is unavailable and measurements may count only the current session. Clearing site data or using another browser changes the identifier. Jepeta's first-party experiment measurement does not use cookies or browser fingerprinting.

Google measurement and consent: Jepeta loads Google Tag Manager and Google Analytics (measurement ID G-6XDWJP30Z4) with Google Consent Mode v2. Optional analytics and advertising-related storage is denied by default. If you accept optional measurement, the site updates analytics_storage, ad_storage, ad_user_data and ad_personalization to granted, and Google may use cookies or similar storage according to its policies. If you reject, those consent states remain denied; Google tags may still send limited cookieless measurement signals. Jepeta stores only your consent choice in first-party localStorage so it can be applied on later pages. You can reopen the choice from Privacy choices.

Advertising and affiliate links: Published editorial articles may display Google AdSense ads after you accept advertising cookies. Previous analytics-only choices do not enable advertising. Google may process cookies, device information and IP addresses to serve and measure ads; see How Google uses information. Where applicable, Google's certified consent message asks for regional advertising choices. You can reject optional cookies or change your choice through Privacy choices. Scanner, risk reports, evidence pages, documentation and payment surfaces do not load AdSense. Relevant articles may contain disclosed affiliate links. Jepeta records visible affiliate offers and outbound clicks with partner, source page and campaign attribution; destinations are checked against an approved registry. Affiliate commission does not affect editorial conclusions. Pending commission is not received revenue.

Microsoft Clarity: Jepeta uses Microsoft Clarity through Google Tag Manager to understand how public pages are used through behavioral metrics, heatmaps and session replay. Clarity follows the site's Google Consent Mode signals: when analytics or ad storage is denied, Clarity operates with the corresponding restricted or cookieless behavior; when consent is granted, Microsoft may use cookies or similar technologies for the enabled purposes. Sensitive input fields are not intentionally collected by Jepeta through Clarity. Microsoft processes Clarity data under its own privacy terms; see the Microsoft Privacy Statement.

Article engagement records at least 30 seconds of visible, focused reading time with recent browser-trusted input and at least 50% article depth. Raw key values, pointer coordinates and input contents are not collected. This is a browser activity proxy, not verification of a person. Campaign visitor and session identifiers accompany Jepeta's affiliate redirects and Telegram invitation requests. Telegram joins are attributed only to the invitation's article, category and campaign cohort; join records are not attributed to a browser visitor or session. No wallet credentials, Telegram identifiers, invoice details or payment secrets are stored in this browser journey. Third-party destinations you choose to open may apply their own storage or privacy practices.

Service providers and external sources

Jepeta relies on infrastructure and data providers including GitHub Pages, Supabase, GoPlus Security, DEX Screener, Google Tag Manager, Google Analytics and Microsoft Clarity. GitHub states that visitor IP addresses are logged for security when GitHub Pages sites are visited. Optional support or commerce flows may involve Telegram and Virtuals ACP. Those providers process data under their own terms and privacy practices when applicable.

Retention

Jepeta applies automatic minimization to operational data. Browser funnel and Telegram product-event telemetry is retained for up to 90 days; request and edge-failure telemetry for up to 30 days; hashed rate-limit keys for up to 2 days; processed Telegram update-deduplication records for up to 30 days; delivered report payloads and resolved support requests for up to 180 days. Expired attribution codes are removed after a short grace period. Payment ledger and terms-acceptance records are kept separately and are not automatically purged by this operational cleanup because mandatory accounting or legal retention may apply.

International processing

Jepeta is an internet service and its infrastructure or service providers may process data in more than one country. Applicable privacy rights are not waived because processing is international.

Your choices and rights

Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal data. To make a privacy request, use the contact channel below and identify the request as a privacy matter. We may need enough information to verify that the request relates to you. You can also reopen and change the Google measurement choice at Privacy choices.

Sale of personal data

Jepeta does not operate a business model that sells personal data to advertisers or data brokers.

Contact

Use Jepeta_bot on Telegram and send /support. Do not post secrets, seed phrases, private keys or sensitive personal information in public GitHub issues.

jepeta.

Clarity before the transaction.

ScannerDocumentationTelegram
Jepeta Risk Guard · Base / 8453

Heuristic screening only. Not a smart-contract audit, safety guarantee, or investment recommendation.

AboutPrivacyTermsRisk disclaimerAccessibilityContact