The Harbor Crew · Privacy
Privacy & data handling
Last updated: 30 September 2026. This notice describes data handling for the public EVM report page and its MCP report tools. It is an operational notice, not legal advice.
What the report service receives
To generate a report, the service processes one to five public EVM addresses and queries public blockchain RPC endpoints for their current code. To redeem a paid report, it also receives the selected payment rail, transaction hash, payer's public wallet address, and a wallet signature that authorizes the report request. The signature does not authorize or perform a transfer.
Do not submit seed phrases, private keys, passwords, or other secrets. The service does not need them.
What is stored
The report service stores a network-scoped payment transaction hash, a keyed fingerprint of the normalized address batch, and a creation timestamp. These records prevent a payment from being reused for a different batch. The raw address batch, wallet signature, and generated report are not stored in the service database. The application does not currently publish a fixed deletion schedule for redemption records.
Who receives data
- Public RPC providers receive the public addresses needed to read code on the selected report networks.
- The hosting and CDN provider processes ordinary connection and request metadata to deliver and protect the website and API.
- Payment transactions are recorded on the selected public blockchain. Blockchain records are public and cannot be removed by this service.
- Explorer links open third-party websites under their own privacy practices.
The application source does not include an advertising pixel or behavioral analytics integration.
Payments and wallet use
The checkout page can ask the browser wallet for the public account, request a network switch, and open the wallet's confirmation screen for the exact token transfer after the customer selects a rail and presses the payment button. The wallet provider submits a transaction only after the customer confirms it. Payment goes directly to the operator's published address; the service does not custody assets, store card details, create token allowances, or sign for a customer. After payment, the page may request a separate personal signature binding the report request to the payment and address batch; that signature does not transfer funds.
Questions or privacy requests
Contact the project through its public GitHub repository. Do not include private keys, seed phrases, private wallet data, or sensitive personal information in a public issue.