Privacy Policy
Last updated: 7 September 2026
Scope and contact
This policy describes OnChainDiligence's free public MCP tools and the relevant data handling of the wider OCD service. Contact the OnChainDiligence operator at support@onchaindiligence.com with privacy questions or requests.
Free Plugin inputs and purposes
Payment inspection processes the public wallet addresses, network, token contract, amount, optional resource URL and policy constraints you supply to compute a deterministic comparison. Resource URLs are parsed, not fetched. Receipt retrieval uses an exact public receipt ID. Verification processes either a public receipt ID or the signed envelope you choose to provide, to check its structure and proof. Do not submit credentials, private keys, payment authorizations, private URL parameters or unrelated personal data.
These tools do not create accounts, operations, payments, receipts or webhooks. Inspection inputs and directly supplied verification envelopes are not written to OCD's business-record database by these tools. Verification does not echo the supplied envelope. Retrieval returns the complete existing public signed envelope so its proof remains checkable; public receipts can contain public addresses, transaction hashes, amounts and signed claims.
Infrastructure and recipients
Vercel hosts the website and MCP service; Neon/Postgres stores durable OCD records. Receipt verification reads OCD's public signing-key registry. Normal hosting/security processing may involve IP addresses, request timing, status and technical request metadata. The shared receipt resolver may log a structural-corruption diagnostic. This public MCP adapter does not add argument/result logging or persistent session storage.
When you use a client such as ChatGPT or Codex, the client provider handles your conversation and tool exchanges under its own terms and privacy policy. These tools send responses back to that client. Website fonts are loaded from Google Fonts, which receives browser connection information. Processing may occur outside your country; this page does not promise UK/EU-only residency.
Separate paid services can query their disclosed data providers, including public sanctions sources, Companies House and SEC EDGAR, and payment/RPC infrastructure where relevant. The free Plugin does not call these paid screening tools or a payment facilitator.
Wider product records and retention
Operations, lifecycle steps, signed receipts, execution bindings, chain observations, merchant-evidence records and webhook delivery metadata currently have no automatic deletion period. They remain in the current environment unless manually removed or a retention policy is introduced. No fixed deletion schedule is promised. Public signed receipts are designed for durable verification and may be copied by others; blockchain data and third-party copies cannot be erased by OCD.
Raw merchant response bodies are not accepted or stored by the merchant-evidence feature. It stores caller-reported digests, byte counts, status, content type and allowed header metadata, labelled CALLER_REPORTED, not verified delivery.
Keys and credentials
OCD does not request or store customer wallet private keys. Account API keys and operation recovery credentials are stored as hashes. The finalization authorization store uses capability hashes; an authenticated lifecycle recovery path also retains the raw finalization token in its lifecycle step so the same operation can resume. Webhook signing secrets are stored server-side because outbound signing requires the secret. None of these values are exposed through the free Plugin.
User controls
You can choose not to send an envelope or optional proposal data, and stop using or disconnect the Plugin in your client. Only public receipts are retrievable by ID; private and unknown IDs are indistinguishable. Wider-product customers can delete their own webhook endpoint, which removes its delivery history. There is no self-service account or operation deletion API today.
Contact support to request access, correction or deletion of personal data, or to raise an objection. We will assess requests under applicable law and explain relevant limitations; this is not a promise that immutable public records or third-party copies can be deleted. You may also contact your applicable data-protection authority. Do not email secrets as evidence of identity.
Support messages, logs and updates
If you contact support, we process your email address and the information you choose to send to respond and investigate the issue. No fixed automatic deletion period for support correspondence or hosting logs is promised here. The free MCP endpoint does not set a login cookie. Your client and hosting providers may perform their own security processing. Changes to this policy will be posted with a revised date.