Privacy policy
Last updated: 20 July 2026
1. Data controller
The controller for the processing described on this page is SolHealth, which operates solhealth.io.
Privacy contact: gacanga@gmail.com
2. What we process
The table below is exhaustive as of the date at the top of this page. It is derived from the application code, not from a template.
| Data | Where | Retention | Purpose & legal basis |
|---|---|---|---|
| Solana wallet address (scanned) | Upstash Redis cache | 60 seconds | Serving a scan without re-querying the blockchain. Legitimate interest (providing the requested service). |
| Scan results (aggregated amounts and counts) | Upstash Redis cache | 60 seconds | Same as above. No individual account addresses are stored, only totals per category. |
| IP address | Upstash Redis (rate-limit counter) | 60 seconds | Preventing abuse of the free scan endpoint. Legitimate interest (security and service availability). |
| Wallet address, referral code, tier, commission rate | Neon PostgreSQL | Until you request erasure | Operating the referral program. Legitimate interest / performance of the service you requested. |
| Referrer ↔ referred wallet link, referral code used, locked commission rate | Neon PostgreSQL | Until you request erasure | Attributing referral commissions correctly and permanently. Same basis. |
| Transaction signature, wallet addresses, commission amount | Neon PostgreSQL | Until you request erasure | Recording commissions actually paid on-chain to a referrer. Same basis. |
| Transaction signature, wallet address, reclaimed amount, protocol fee, number of accounts | Neon PostgreSQL | Until you request erasure | Public leaderboard (wallet addresses are shown truncated) and eligibility for the Founding referral tier. Same basis. |
| Referral code (8 characters) | The URL by default. Stored in a cookie only if you explicitly consent. | 30 days if you consent, otherwise not retained | Crediting the person who referred you, at the moment you connect a wallet. Consent (Art. 6(1)(a) GDPR) for the cookie. See section 4. |
| Page views, approximate location, device and browser type | Vercel Web Analytics | Per Vercel's retention policy | Aggregated audience measurement. Vercel Web Analytics does not use cookies and does not build cross-site profiles. |
| Technical logs (wallet addresses, transaction signatures, errors) | Vercel runtime logs | Per Vercel's retention policy | Diagnosing failures. Legitimate interest (operating and securing the service). |
We do not collect: your name, postal address, phone number, date of birth, payment card, government ID, seed phrase or private key. There is no account and no password.
3. Wallet addresses as personal data
A Solana wallet address is pseudonymous, not anonymous. On its own it does not name you, but it can become indirectly identifying as soon as it is combined with another element — an email address, a social media handle, or an on-chain interaction that is publicly attributed to you. We therefore treat wallet addresses as personal data and apply the rights described in section 7 to them.
This matters most for the pairing described in section 5: an email address linked to a wallet address is unambiguously personal data. If you ever create such a pairing with us, you can have both sides of it deleted, and deletion means the row is removed from the database — not marked as inactive.
4. Cookies and local storage
Referral attribution normally works through the URL alone. If you arrive through a referral link containing a ?ref= parameter, that code stays in the address bar as you move around the site and is sent to our server only at the moment you connect a wallet, so the person who referred you can be credited.
That approach has one weakness we would rather be upfront about: some mobile wallet apps open websites in their own built-in browser starting from a clean address, which drops the parameter and loses the attribution. So if — and only if — you arrive through a referral link, we show a small prompt asking whether we may remember the code:
- If you choose “Remember”, we set a single first-party cookie named
solhealth_ref_consented. It contains nothing but the 8-character referral code.SameSite=Lax, 30-day lifetime. - If you choose “No thanks”, nothing at all is written to your device, and we do not ask again on that page. The scan and the cleanup work exactly the same either way.
If you never arrive through a referral link, you will never see the prompt and no cookie is ever set. That is the case for the vast majority of visits.
Changing your mind. The choice is revocable at any time: delete the solhealth_ref_consented cookie in your browser settings (Chrome and Edge: Settings → Privacy → Third-party cookies → See all site data; Firefox: Settings → Privacy → Cookies and Site Data → Manage Data; Safari: Settings → Privacy → Manage Website Data). Clearing cookies for solhealth.io removes it, and we will simply fall back to the URL-only behaviour.
Earlier versions of this site set a cookie named solhealth_ref automatically, without asking. That is no longer the case: it is never set again, it is never read, and if your browser still holds one from a previous visit it is actively expired the next time you load any page here.
We use no advertising cookies, no third-party trackers, no fingerprinting and no cross-site profiling.
5. Email alerts
As of the date at the top of this page, SolHealth does not collect email addresses at all. A reclaim-alert feature is planned. If and when it ships, the following applies — and only to people who explicitly opt in:
- Data: your email address and the wallet address you want to be alerted about.
- Purpose: notifying you when that wallet has accumulated reclaimable SOL again.
- Legal basis: your consent, given by opting in. You can withdraw it at any time, and every email will contain a one-click unsubscribe link.
- Retention: until you unsubscribe or ask for erasure, after which the record is deleted.
- Processor: the email provider will be named on this page before the feature launches, and no address will be collected until it is.
Opting in to alerts will never be a condition of using the scan or the cleanup.
6. Processors and international transfers
We rely on the following providers. Each acts as a processor on our instructions, except Helius, which you also contact directly from your own browser (see below).
- Vercel Inc. (United States) — hosting, runtime logs and Web Analytics.
- Neon — managed PostgreSQL database.
- Upstash — managed Redis, used for the 60-second scan cache and IP rate limiting.
- Helius — Solana RPC provider. Note that the RPC endpoint is also used directly by your browser through the wallet adapter in order to broadcast your signed transaction, which means Helius receives your IP address and the wallet address being queried.
Some of these providers are established in, or process data in, the United States. Such transfers rely on the appropriate safeguards provided for in Chapter V of the GDPR, in particular the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
7. Your rights
Under the GDPR you have the right to access your data, to have it rectified, to have it erased, to receive it in a portable format, to object to processing based on legitimate interest, to request restriction of processing, and to withdraw your consent at any time where processing is based on consent.
How to exercise them
Write to gacanga@gmail.com and include the wallet address concerned. Because there is no account, the wallet address is the only identifier we hold — we may ask you to prove control of it (for example by signing a short message with that wallet) before acting on a request, so that nobody can request erasure of someone else's data.
Erasure requests result in the deletion of the corresponding database rows. As explained in section 3, on-chain transactions cannot be deleted by anyone, including us.
8. Complaints
If you believe your data protection rights have not been respected, you may lodge a complaint with the French supervisory authority:
Commission Nationale de l'Informatique et des Libertés (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — cnil.fr
9. Changes to this policy
Any change to what we collect will be reflected on this page, with an updated date at the top. Material changes affecting processing based on your consent will be notified to you before they take effect.