Privacy Policy
Last updated 2026-06-03
CitrateScan is a public block explorer for the Citrate Network. This policy explains what we store, why, and your rights. Citrate is experimental testnet software.
What we store
- Login session — handled by our authentication seam (OIDC). We read your subject id and wallet address from a signed token only to scope your data.
- Settings — end-to-end encrypted with a key derived in your browser from a wallet signature. We store only ciphertext we cannot read.
- API keys you issue — stored as a salted hash; the key itself is shown once and is never recoverable.
- Third-party provider keys you add for the agent — encrypted at rest with a per-user key, used only to run tools on your behalf.
- Watchlist and chat threads — scoped to your account; message bodies are encrypted.
- Audit log — the read-only tools the AI agent called on your behalf, kept for your transparency.
- Local storage — your login session, theme, and cookie-consent choice.
We do not use advertising, cross-site tracking, or sell or share your personal information. We do not currently run analytics; if we add it, it will be opt-in and disclosed in the consent banner.
On-chain data is public and permanent
Blocks, transactions, and addresses you view are public on the Citrate Network and are not controlled by us. We cannot edit or erase on-chain data, and neither can anyone else — that is the point of a blockchain.
Your rights
- Access & portability — export everything we store about you via
GET /api/account/export(Settings → Privacy & Data → Export my data). - Erasure — delete your account-scoped data via
DELETE /api/account(Settings → Privacy & Data → Delete account). On-chain data is unaffected. - Withdraw consent — change your cookie/storage choices any time via “Cookie settings” in the footer.
Contact
Privacy questions: privacy@citrate.ai. Security reports: see security.txt.
See also our Cookie Policy and Terms of Use.