Section 8 now states that the originating IP address is removed from security logs after 90 days, rather than being kept for the full 24 months that applies to the rest of the log. Security logs record that an account analyzed a given address at a given time, and the IP is the field that turns that into a record of where the person was when they did it, which is the most sensitive thing WalletDNA holds about an investigation. The rest of the entry survives the full period, so what was analyzed and when remains auditable, and a customer's own audit trail is unaffected. Previously the IP was only removed as a side effect of deleting the last report held for an address, which meant it was kept indefinitely for anything nobody deleted. Published alongside the scheduled job that performs the removal, so the stated period is enforced rather than promised.
Changes to Our Legal Documents
Every material revision to the WalletDNA Terms of Use and Privacy Policy, dated and described in plain language.
This page records every material change to our Terms of Use & Disclaimer and Privacy Policy. Entries are appended chronologically and are never deleted or rewritten.
Most changes here accompany a new feature, or describe something we already did more precisely than the previous wording managed. Some correct something we got wrong. Each entry says which, because a record of changes that cannot be trusted about its own history is not worth publishing.
Each change is tracked in our source control, which is private. The commit reference is shown where one is recorded, so a specific revision can be produced on request. Minor edits such as typo and formatting fixes are not listed here.
Corrected the list of blockchain data providers in Section 5.1. Moralis was removed: WalletDNA no longer sends it anything, following a code change that replaced it with checks made directly against the blockchain. More consequentially, the previous list named eight providers and omitted thirteen others that do receive an analyzed address, among them the providers used for Bitcoin, XRP, Tron and Solana, which are four of the five most frequently analyzed chains. The entry now names every provider that receives an address and states which chain sends an address to which provider, so a reader can establish, before analyzing an address, which third parties will see it. It also names Chainabuse and Chainbase, which are queried for community scam reports and address labels. What is sent has not changed: providers receive the address being analyzed and nothing else, with no account information, name or email address, as the entry stated before and continues to state.
Named the operating company. WalletDNA is operated by Enbits Technologies, Inc., a California corporation, which is the contracting party and the data controller. Earlier revisions on this date described the operator first as a corporation that had not been registered, then as an unincorporated sole proprietorship; both were inaccurate. The Privacy Policy Summary and Section 1 now name the operating company and identify it as the data controller. The Terms of Use previously identified no contracting party at all, and now open by stating that they are a binding agreement between the user and the named company. Section 5.3 of the Privacy Policy continues to govern any future transfer of the business or its data to another entity.
Superseding the operator disclosure published earlier the same day. That version named the individual operating WalletDNA. The Summary and Section 1 now identify the operator by trading name and jurisdiction only, state that WalletDNA is not yet incorporated and currently operates as a sole proprietorship, and undertake to provide the operator's identity on request to any data subject, regulator, law enforcement agency, or counterparty with a legitimate need to know. No US privacy regime applicable to WalletDNA requires a natural person to be named in a published policy, and the earlier wording disclosed more than accuracy required. The correction of the inaccurate corporate claim it replaced still stands: no entity has been registered.
Corrected who operates WalletDNA. The Summary and Section 1 previously described the operator as "WalletDNA, Inc., a California corporation". No such entity has been registered. Both now state accurately that the Platform is operated by a named individual doing business as WalletDNA, as a sole proprietorship based in California, that a California entity is in formation, and that data controller responsibility rests with that individual. This will be updated again once the entity is registered.
Section 5.1 (Service providers) now names Neon (managed database hosting) and Clerk (authentication and multi-factor authentication), which were previously processing data without being listed, and adds the blockchain data providers that receive an address when it is analyzed. A new paragraph states plainly that analyzing an address transmits it to those providers, that they receive the address only, and that this is a limitation to account for if it matters that no third party learns which address was queried. Section 8 (Retention) now describes what deleting a report actually does: the report, its review share links and access records, ownership attestations and valuations are removed permanently and immediately; where it is the last report held for an address, that address, the originating IP and the risk score are stripped from security logs, and risk score history is deleted unless the address is still monitored. Added that these practices apply to every account on every plan, and that deletion may be suspended under a litigation hold or lawful preservation request. Published alongside the code change that made deletion permanent, replacing a prior implementation that marked reports hidden while retaining them. No customer report was affected: every report held under the previous behaviour belonged to a WalletDNA-owned account, and all of them have been removed.
Section 15 (Communications) updated ahead of the first product-update email. Replaced "we do not currently send marketing emails" with an accurate description: we occasionally send product update emails to account holders, every one states how to stop receiving them, opting out does not affect transactional email, and we neither sell email addresses nor carry third-party advertising.
Added Section 14A (Plans, Features, and Complimentary Programs): WalletDNA may add, change, limit, or discontinue plans, allowances, features, and complimentary access programs, including free Pro for government and military accounts, with at least 30 days' notice to accounts already enrolled in a complimentary program. States that complimentary access carries no ongoing entitlement, no cash value, and is not transferable, and that the notice requirement does not apply to access granted for a stated period such as a free trial, which ends on the date disclosed when it began. Added ahead of launching the .gov/.mil grant and the 14-day Pro trial, so the reservation predates enrolment rather than following it.
Initial publication of the WalletDNA Terms of Use & Disclaimer and Privacy Policy as standalone pages at /terms and /privacy. Replaces the legacy combined disclaimer modal.
This changelog is internal and is not linked from public pages. To request a copy of a specific historical version, contact us via the Contact Us form on the homepage.