Privacy Policy
Last updated: September 2026
Short version: nothing runs until you give us permission. The files you upload are read in memory and not kept. The results of a wallet analysis are kept for about 30 days so you can download them again. We keep a record of payments, because we have to. We have no ads and no tracking, and we sell nothing to anybody.
1. Your permission comes first
Before you can upload a file or analyze a wallet, the terms window asks you to agree to the terms and, separately, to tick a box giving us permission to process the personal information in what you provide. Until that box is ticked, our server refuses to take in a file or an address. We record that you gave permission (see section 3, "What we keep"). You can withdraw it at any time by clearing this site's cookies and not using the tool; anything already processed is dropped when your session ends.
2. What you give us, and what happens to it
- A public wallet address to analyze. We read that address's public transactions from the blockchain. The resulting export is saved on our server for about 30 days, tied to a Job ID, so you can download it again from My Jobs. Results older than 30 days are removed by an automatic clean-up.
- Your Coinbase transaction CSV. Read in the server's memory for your session. It is not written to disk and not kept. A session ends when you remove the file (it is dropped at once), or three hours after you last used it. Coinbase prints your name and Coinbase user ID at the top of this file; we use the name only to label your workbook, and keep neither.
- Coinbase statement PDFs (optional, for reconciliation). Written to a temporary file for the moment it takes to read, then deleted. The balances read from it stay in memory for your session only. See section 5 for the one case where the statement's text can leave our server, and only if you say yes.
- The Excel workbook. Built in memory and sent to you. We do not keep a copy.
- Private keys and seed phrases. Never requested, never needed. Anyone asking for one in our name is not us.
3. What we keep
- Payment records. The wallet that paid, the transaction signature, the amount, the credits it bought, and when they expire (365 days). These are needed to give you what you paid for, and the payment itself is on a public blockchain permanently.
- Job records. For each wallet analysis: the Job ID, the wallet that ran it, the address analyzed, when it ran, how many transactions, its status, and the results file described above. Kept about 30 days.
- A record that you accepted the terms and gave permission. The version you accepted, the time, that you ticked the permission box, the first 100 characters of your browser's identification string, and a shortened hash of your IP address made with a secret key only our server holds. We do not store the IP address itself in this record.
- Technical logs. Error messages and run logs used to fix problems. They can include a shortened public address being analyzed and a Job ID. They record counts (how many assets, how many lots), not your balances, your name, or the contents of your files.
- Caches of public data. Token prices, token names, and transactions already fetched for an address, so the same public data is not fetched twice. None of it is private; all of it is on a public blockchain or a public price feed.
We do not ask for, and do not keep, your name, email address, tax ID, or anything else that says who you are. A wallet address is not a name, but it is permanent and public, and everything that address has done can be looked up by anyone.
4. Your IP address
Your IP address is used, in memory, to limit how fast one visitor can send requests. It is not written to a database. Like any website, the company hosting our server may keep ordinary connection logs.
5. Other services involved
To do its job the server asks outside services about the public address you are analyzing. Those requests come from our server, not your browser, and carry the blockchain address only.
- Helius, with the Solana Foundation's public endpoint as a backup: Solana transactions. For a coin with no DefiLlama price, Helius is also asked for the public trades in that coin's pool just before your send or receive; that asks about the pool, not your wallet.
- Blockscout: Ethereum transactions.
- DefiLlama: historical and current token prices. Our server asks it for a coin's price at a time; it is never told whose wallet the coin is in.
- Google Fonts: your browser loads the site's typeface from Google, so Google sees your IP address when it does, as with most websites.
- Anthropic, in one case only, and only if you say yes. Statement PDFs are read by code on our own server. If that reader cannot understand a statement (for example, one that is not from Coinbase), nothing is sent: the page tells you, and asks whether you want the text extracted from that statement sent to Anthropic's API so its AI can pick out the balances. That text includes your balances and may include your name and account details as printed on the statement. If you say yes, it is sent for that one statement, for that purpose only, and handled by Anthropic under its own terms. If you say no, the statement is skipped; reconciliation is optional and everything else works without it.
We do not sell, rent or share your data with anyone for advertising or marketing. There is none of either here.
6. Cookies and tracking
No advertising cookies, no analytics, no tracking pixels, no fingerprinting. The site sets only cookies it needs to work, each signed or random so it cannot be forged:
- yt_consent - that you accepted the terms and gave permission. Lasts a year, or until the terms change.
- yt_pass - a pass you paid for, if you did. Lasts as long as the pass.
- yt_wallet - the wallet you signed in with, when you sign in. Lasts 24 hours.
Signing in is a wallet signature rather than an account, and preferences such as having accepted the terms are also remembered in your own browser's storage.
7. How long
- Uploaded CSVs and statements: the length of your session, three hours idle at most.
- Wallet analysis results and job records: about 30 days.
- Payment records, and the record of your terms acceptance and permission: kept, as a business and legal record.
- Anything on a blockchain, including your payment: permanent, and outside anyone's power to delete.
8. Your choices
You can decline the permission box, in which case nothing is processed. You can use Manual Payment so that you never connect a wallet. You can skip statement uploads entirely, and you can say no when asked about sending a statement to Anthropic. You can see, download and delete what we hold for your wallet yourself: on My Jobs, sign in with the wallet (a signature, so only its owner can) and use "Download my data" or "Delete my data". Deleting removes your jobs and their results, your run history and the cached transactions of the addresses you analyzed, at once. Payment records, and the pass or credits you paid for, are kept (see section 3). Removing an uploaded file on the calculator page deletes it from our server straight away. A job you ran without a wallet (Manual Payment) can be deleted by sending its Job ID through the contact page. We cannot remove anything from a blockchain.
9. Children
YerTaxes is not for anyone under 18.
10. Changes
If what we collect or keep changes, this page changes first, and the date at the top changes with it.
10. Contact
Privacy questions and deletion requests: abuse@yertoken.fun, or the contact page.