Privacy policy
Last updated 25 August 2026. walletlink.social is operated by Starl3xx Labs LLC. Write to help@walletlink.social about anything on this page; a person reads it.
The short version
We resolve wallet addresses to the social accounts attached to them. To do that we hold your email address, what you have paid, what you have looked up, and enough technical data to keep the service standing up.
We do not sell your data, we do not run advertising, and we do not share your lookups with anyone. We do keep the wallet-to-identity mappings a lookup discovers, and the section on addresses you look up explains exactly what that means, because it is the one thing here a reader would not guess.
What we hold, and why
Your account. An email address, which is the whole account: there is no password and no profile. It exists so a sign-in link can reach you and so credits can belong to somebody. An account created by paying onchain has a wallet address instead, and no working inbox behind it.
What you paid. For a card payment, the customer and payment references our payment processor returns, and the date. Card numbers never reach us: the payment happens on the processor’s own pages. For an onchain payment, the paying address and the settlement reference, both of which are already public on the chain.
What you looked up. The addresses you submitted, the results, and a count. Saved lookups keep the full result set so you can open them again.
How the service is used. Page views and product events (an upload started, a checkout reached, a limit hit), each carrying a browser identifier and sometimes your email address. Also the number of requests an API key made, so rate limits and credits can be counted.
Technical data. Your IP address, held only as a counter against an hourly bucket so an endpoint cannot be scraped, and the browser string attached to a sign-in session so you can recognise your own sessions. Our host keeps its own request logs, which we do not control.
Addresses you look up
This is the part worth reading twice, because it is how the product works rather than an aside.
When you look up an address, we ask several public and third-party sources who is behind it. The answer is written to a permanent index, and that index then answers other people’s lookups of the same address. An address that resolves to nobody is recorded as such too, so we do not re-ask about it for 30 days.
What is shared this way is the mapping only: this address belongs to this X handle or this Farcaster account. Those facts came from public sources, and they are what we sell.
What is never shared is anything about you: that you ran the lookup, which addresses you submitted together, what your list was for, or what any of it told you. Your lists are yours, and no customer can see another customer’s.
Raw results are also cached for 7 days so a repeated lookup costs you nothing.
If you are in the index
You may be in it without ever having used the service. Every mapping we hold came from somewhere public: a profile you attested onchain, a record you published against your own name, a link you made yourself between an account and a wallet. We collect nothing from a private source and we hold no wallet balances, no transaction history and no contact details for anyone in the index.
Write to help@walletlink.social with the address or handle and we will remove it and suppress it from being re-collected. We do not require you to prove ownership first, because the alternative is asking a stranger for more information than we already hold about them.
Who else sees it
We use other companies to run the service. Each holds only what its job needs, and none of them may use it for anything else.
- Vercel hosts the site and provides its page-view analytics.
- Neon hosts the database.
- Stripe takes card payments and holds the card details we never see.
- Resend sends sign-in links and account mail.
- Cloudflare serves the domain, forwards mail sent to us, and runs the assistant on the documentation site, which sees the questions typed into it.
- Mintlify hosts the documentation site.
- A payment facilitator settles onchain payments. It sees the paying address and the amount, both already public on the chain.
- Third-party identity data providers receive the addresses and handles we resolve. They are named by category rather than individually, which is what a controller is permitted to do and what keeps our sourcing from being a public price list for anyone copying the product.
We will also hand over data where the law requires it, and we would tell you unless we were forbidden to. If the business is ever sold, what we hold moves with it and this policy travels with it too.
How long we keep it
A cleanup job runs daily and enforces every period in this table. Where something has no expiry, it says so rather than implying one.
| What | Kept for |
|---|---|
| Your account and credits | Until you ask us to delete it |
| Saved lookups | Until you delete them, or the account |
| Wallet-to-identity mappings | Indefinitely. This is the index |
| Cached raw results | 7 days |
| Product and page-view events | 400 days |
| IP rate-limit counters | 24 hours |
| Sign-in links | Usable for 15 minutes, once. The record goes after 24 hours |
| Sign-in sessions | 30 days, or until you sign out |
| Connected applications | Until you disconnect them. Their access renews hourly |
| API keys | Until you revoke them. Stored only as a hash |
| Payment records | Seven years, for tax and accounting |
Your rights
Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to stop using it, or ask for it in a portable form. Depending on where you live, some of those are rights rather than requests; we do not distinguish, because answering everyone the same way is simpler than deciding who is entitled to what.
Write to help@walletlink.social. We answer within 30 days, and we do not charge for it. If you are in the UK or the EU and we have not resolved something, you can complain to your data protection authority.
Some things we cannot delete. Payment records are kept for the period tax law requires. Deleting your account does not remove a wallet-to-identity mapping from the index, because that mapping is not about you unless the wallet is yours, in which case the section above is the one that applies.
How it is protected
Everything travels over HTTPS. API keys and sign-in tokens are stored as SHA-256 hashes, never as the value itself, which is why a key is shown exactly once and cannot be recovered afterwards. An application connected through OAuth holds an access token that expires every hour and can be cut off from your account at any moment. The database is reached by roles with only the access each one needs.
No system is perfect. If something goes wrong that affects you, we will tell you, and we will tell the relevant authority where we are required to.
Children
This is a product for businesses and developers, and it is not for anyone under 16. We do not knowingly hold data about a child. If you believe we do, write to help@walletlink.social and it will be removed.
Changes
When this changes, the date at the top changes with it, and the change is recorded in the public changelog like everything else. For anything that materially affects what we do with data we already hold, we will email account holders before it takes effect.
Contact
help@walletlink.social, for a question, a request, or a complaint. It reaches a person rather than a queue.