Skip to main content
walletlink
Legal

Terms of service

Last updated 26 September 2026. walletlink.social is operated by Starl3xx Labs LLC. Write to help@walletlink.social about anything on this page; a person reads it.

The short version

These terms cover everything at walletlink.social: the website, the REST API, the MCP server and the onchain credit rail. They go with the privacy policy, which says what we hold and why.

Four sentences cover most of it. You buy credits once, and a credit is spent only on a match: a wallet resolved to an X or Farcaster account. Refunds are limited to the cases listed below, so try the free allowance first. You may use what you find to reach the holders of your own token or collection, and your own community. You may not use it to stalk, expose, track or profile anyone, and if you do, we may revoke your API keys and disconnect your applications.

Who this agreement is with

walletlink.social is operated by Starl3xx Labs LLC (“we”, “us”), a limited liability company organized in Wyoming. These terms are an agreement between us and whoever uses the service (“you”). The service is for business and professional use only. You use it on behalf of a business, even when that business is you alone, so “you” also means that business, and you confirm that you can bind it to these terms. If a consumer protection law that cannot be waived applies to you anyway, nothing in these terms takes away a right it gives you.

You accept these terms when you create an account, buy credits, create an API key, connect an application, pay for credits onchain, or use the service in any other way. When you buy credits, at checkout or onchain, you also confirm that you agree to them, and we record the time and the version of these terms with the purchase.

You must be at least 18 years old to use the service.

The privacy policy explains what we hold about you and about the people in the index, and for how long. Read it with these terms.

What the service does

We resolve wallet addresses on Ethereum and other EVM chains to the X and Farcaster accounts their owners published, and back again.

  • A forward lookup takes one address or a list and returns the social accounts attached to each, with the evidence behind every match.
  • A reverse lookup takes an X handle or a Farcaster username and returns the wallets attested to it, a page at a time. It returns only wallets whose recorded evidence is all attested, and it needs an account with an email address.
  • The web app runs both, saves your lookups, exports results as a CSV file or an X list, and can send direct messages on Farcaster from your own account.
  • The REST API and the MCP server do the same for your own software and for AI agents. They draw on the same balance as the app.
  • The onchain rail lets software buy credits with USDC on Base and receive an API key, with no card and no email.

An identity is attested when the wallet owner published the link themselves: a Farcaster verification, an onchain ENS record, an attested-social sign-in, or a manually verified record. Anything else is correlated, and labeled so. No link between a wallet and an account is inferred from a display name or a bio.

Our answers come from public and third-party sources. We keep them in a permanent index, which also answers other customers’ lookups. The privacy policy explains what that means for you and for the people in it.

We may change, add or remove features. Before we remove a paid feature, such as the API or reverse lookup, we will tell account holders by email at least 30 days ahead, and credits that have not expired stay usable on the rest of the service.

Accounts, keys and connected applications

Your account is an email address. You sign in with a link we send to it, and there is no password, so anyone who can read that inbox can use your account. Keep it secure, and tell us at once if you think someone else has used it.

API keys. Any signed-in account can create keys under API keys in the account menu. We show a key once and store only a hash of it, so nobody can show it to you again, including us. If you lose a key, create a new one and revoke the old one. A key spends your whole balance, so keep it on a server and never in code a browser downloads. You are responsible for every call made with your keys, and by the applications or agents you connect, until you revoke or disconnect them. A key you revoke stops working at once.

Connected applications. An AI client can connect over OAuth instead of using a key. A connection can resolve wallets in both directions, run a background job and read your balance. It cannot see your saved lookups, your billing details or your email address, and it cannot buy credits or change anything about your account. Its access lasts an hour and renews itself. To end it, open the account menu, then API keys, then Connected applications, and choose Disconnect. It stops working on the next call, not at the end of the hour.

Wallet accounts. Credits bought onchain belong to an account tied to the wallet that paid. That account has no inbox and cannot sign in to the website. To recover or revoke its keys, you sign with the same wallet, as described under paying onchain.

Each account is for one business. Do not share an account between businesses, and do not open more accounts to get more of the free allowance.

Credits and what they cost

walletlink.social is sold as credit packs, each a one-time payment. There is no subscription, and nothing renews.

  • Trial: $29 for 250 matches
  • Campaign: $99 for 1,500 matches
  • Scale: $299 for 6,000 matches
  • Index: $899 for 25,000 matches

The pricing page always shows the current packs. A price change never changes a pack you have already bought. Prices exclude taxes, and you pay any tax that applies to your purchase. Any promotion, such as bonus credits, is described where we offer it. Stripe takes card payments on its own pages, and card numbers never reach us.

What a credit buys. One credit pays for one match. A match is a wallet resolved to an X handle or a Farcaster account. Wallets that resolve to nothing, and wallets carrying only an ENS name, a Lens profile or a GitHub account, are never billed. Billing is per address, not per identity: an address carrying both an X handle and a Farcaster account costs one credit. A reverse lookup costs one credit per wallet it returns, and nothing when a handle has no wallets.

How long credits last. 365 days from the day you get them, whether you bought them or we granted them. We spend the credits that expire soonest first, and what is left at expiry is gone.

The free allowance. Every account created with an email gets 100 matches in a rolling 30-day window: each match becomes free again 30 days after you spent it. It is there to show you your real match rate before you pay. It does not apply while you hold any unexpired credits, bought or granted, and accounts created by paying onchain do not get it. Some features in the app, including reverse lookup, need a pack, and the free allowance does not unlock them.

Plans bought before credit packs. If you bought a plan before credit packs existed, it keeps what it was sold with, and nothing on this page reduces it. The old unlimited plan has one fair-use limit: at most 1,000,000 addresses submitted in any 24 hours, a level that only bulk copying of the index reaches.

Before you spend, know that:

  • an API or tool call that resolves more addresses than you have left still returns them all, and we refuse the next metered call;
  • a list may be at most 10 times your remaining matches, which stops junk lists and does not touch real ones;
  • when a lookup or a background job finds more matches than your balance covers, we deliver a margin of 10% of your remaining balance past it at no charge, and show the rest as locked rows, which you do not pay for;
  • a retried API call or tool call is a new call and bills again, unless you send an idempotency key to the REST batch endpoint;
  • an estimate is only an estimate, and you pay for what actually resolved.

Credits have no cash value. You cannot sell them, transfer them to another account, or exchange them for money.

Paying onchain

Software can buy credits with no account, no card and no email. A POST to /api/x402/buy answers with a payment request. When you pay it in USDC on Base, the response contains an API key, unless the paying wallet already holds as many active keys as it may, in which case the credits are added to its account and no new key is issued.

  • An Agent pack is $1 in USDC for 12 matches. One payment can buy from 1 to 25 packs, at the same price per pack.
  • The credits are the same credits a card buys. We meter them the same way, and they last 365 days.
  • The account the payment creates does not get the free allowance.
  • We show the key once. If you lose it, sign a challenge with the wallet that paid, and we issue a new key against the same credits. One signature can also revoke all of that wallet’s keys and issue a single new one.
  • A payment that carries an existing key adds its credits to that key’s account and creates no new key.
  • We cannot charge you twice for the same signed payment: if you replay it, the response shows the credits it already bought.
  • An OAuth connection cannot buy credits.

A key bought this way resolves addresses on the REST API and the MCP server: the single, batch and job lookups, the estimate, and the free reads. The reverse lookups, from a handle to the wallets behind it, need an account with an email address. They refuse this key, because that direction can find a person, so somebody has to answer for the search.

Onchain payments are final. We cannot reverse a transaction on the chain, and the refund rule below applies to onchain payments as it does to card payments. If a payment settles and we do not record the credits, the error contains a settlement reference. Send it to help@walletlink.social and we will issue the pack by hand. We cannot issue it twice. A payment facilitator settles these payments. It sees the paying address and the amount, which are already public on the chain.

Refunds

We do not refund credits, used, unused or expired, except where the law requires it or this page says so. Check first instead: the free allowance shows your list’s real match rate before you spend anything, and a wallet that resolves to nothing costs nothing either way.

A payment that went wrong is different, and we will put it right. If you paid and received no credits, write to help@walletlink.social with your receipt or the settlement reference, and we will issue them. If you were charged twice for one purchase, we refund the duplicate payment to the card or wallet it came from once we have confirmed it.

If you dispute a card payment with your bank or card issuer, we remove the credits that payment bought, and we may revoke your API keys while the dispute is open.

Rate limits

The API and the MCP server limit how fast you can call, in three windows at once: per minute, per day and per month. When you go over any one of them, we refuse calls until that window resets. The limits count units, not credits: one per single lookup, one per address in a batch or an estimate, two per reverse lookup, one per job submission, and none for a status poll. The daily and monthly limits count every key on the account together. All three follow the largest pack your account holds that has not expired:

  • Free allowance, Trial, Campaign, Agent and granted credits: 60 units a minute, 5,000 a day and 50,000 a month, and batches of up to 50 addresses
  • Scale: 300 units a minute, 50,000 a day and 500,000 a month, and batches of up to 200 addresses
  • Index: 1,000 units a minute, no daily or monthly ceiling, and batches of up to 1,000 addresses

An account on a plan bought before credit packs existed keeps the limits that plan carries. Through the API and the MCP server, one background job may be active per account at a time, counting jobs started on the website.

The website has its own limits. Without signing in, a lookup takes up to 500 addresses and opens at most 50 matches, each IP address can start 3 lookups an hour, and each IP address can open at most 50 matches a day across all its lookups. The free tools on the website, such as the handle check and the single-address lookup, are capped per IP address, so they stay a lookup rather than a data feed.

The limits are part of what you buy. If you need more, write to help@walletlink.social. Do not work around them.

What you may not do

walletlink.social exists to help projects reach their own community, the people who hold their own token or collection, to check whether an account holds your token (for example before a partnership, an allowlist or an airdrop), and to study wallets in aggregate. It is not for spam, or for targeting people who have no relationship to your token. It links wallets to people, so some uses of it would harm the people in the index. You may not use the service, or anything it returns, to:

  • stalk, harass, threaten or intimidate anyone;
  • target, rob, extort, threaten or physically locate anyone because of what they hold;
  • dox or expose a person: publish or share a link between a wallet and a person, or what that person holds, to embarrass, endanger, pressure or shame them;
  • monitor an individual: repeat lookups of the same person to follow what they hold, buy or sell over time, or alert on their wallets or accounts;
  • build a profile or dossier of a private person, or combine our results with other data to identify someone who has not made the link public themselves;
  • infer a person’s health, religion, politics, sexuality or any other sensitive trait from what they hold;
  • find, contact or profile anyone below the minimum age above;
  • send spam: bulk messages to people outside your own token, collection or community, messages to anyone who has asked you to stop, or anything the next section forbids;
  • discriminate against anyone unlawfully, or use our results to decide a person’s eligibility for credit, employment, housing, insurance or any similar decision about them;
  • defraud anyone: phishing, impersonation, fake airdrops or claims, or any message that tries to get a person to connect a wallet, sign something or send funds under false pretenses;
  • get around a rate limit, the free allowance or a credit check, for example by rotating accounts, keys, wallets or IP addresses, or by splitting one job across several accounts;
  • resell, sublicense, publish or redistribute our results in bulk, or use them to build or improve a competing dataset, index or service;
  • scrape, crawl or systematically query the website, the API or the MCP server to copy the index, or reach it any way other than through the documented interfaces within their limits;
  • probe, test or attack the service’s security, or interfere with its operation or with other customers;
  • break any law or regulation, including privacy, data protection, anti-spam, consumer protection and sanctions law, or the rules of X, Farcaster or any other platform you use to act on our results.

Sanctions. You confirm that you are not a person or organization that the sanctions laws we are subject to forbid us to deal with, and that you will not pay us from a wallet or an account that belongs to one. We may refuse or end service to anyone we believe is.

We check the paying address of every onchain payment against the US Treasury’s list of Specially Designated Nationals before we accept it, and we refuse the payment if the address is on the list or if we cannot check it. We do not sell to buyers whose connection comes from a country or region under comprehensive US sanctions. If an address that paid us is added to the list later, we suspend the account the payment was for: its keys stop working, its credits are held, and we deal with them as the law requires. If you believe a suspension is a mistake, write to help@walletlink.social.

If the law gives you duties for personal data you get from us, those duties are yours. You receive our results as an independent controller: you decide what to do with them, and you need your own lawful basis for doing it. We do not process personal data on your behalf, so there is no data processing agreement.

Two purposes may go beyond these rules, and only after you write to help@walletlink.social first and tell us what you plan: security research and fraud investigation. There is no exception for law enforcement through an account. We answer the authorities only when a request comes through legal process.

Messaging the people you find

The product is for reaching your own holders, and this is also where it is easiest to do harm. When you contact anyone you found through us:

  • write only to people who hold your own token or collection or belong to your own community, about your own project, and never to the holders of another project’s token;
  • say who you are and who you speak for;
  • stop when someone asks you to, and do not contact them again from another account;
  • never ask anyone to send funds or approve a token transfer in a first message, and when you ask them to connect a wallet or sign something, link only to your project’s own domain;
  • follow the rules of the platform you send on, including its limits on automated and bulk messages.

Direct messages sent from the app, and X lists built from it, go out from your own Farcaster or X account, with your own credentials. They are your messages: you are responsible for what they say and who receives them, and the platform may act against your account.

What we do about misuse

If we believe you have broken these terms, we may do any of the following:

  • revoke some or all of your API keys;
  • disconnect your connected applications;
  • hand over data to the authorities where the law requires it, and tell you unless we are forbidden to.

We will not wait to warn you when a person may be harmed. In other cases, where we can, we will tell you what we did and why. If the breach is serious, your remaining credits are forfeited. You can appeal any of this by writing to help@walletlink.social, and a person will answer within 14 days.

How to report misuse. If someone is using walletlink.social to harass, track or expose you or anyone else, write to help@walletlink.social. Tell us what happened, and include any handle, wallet address or message involved. A person reads every report. If you only want your own address or handle out of the index, you do not need to report anything or prove anything: see the section below on being in the index.

What the data is, and what it is not

Every match carries the evidence behind it. An attested match is one the wallet owner published. A correlated match is weaker, and the evidence we return with it says so. A reverse lookup returns only wallets whose recorded evidence is all attested; a single-wallet lookup still shows correlated matches, with their evidence. An owner-published name record can name any X handle, and nobody checks that the handle’s owner agreed.

A match records what was true when the owner made the link, and it can stop being true. An X handle can be renamed, suspended, or given up and taken by somebody else. A checked X handle carries one of four states: live, suspended, unclaimed, or reassigned. A handle can be attested by its owner and suspended today, so a handle is not a promise that anyone is behind it. A field that is absent was not measured. Absent is not false: a missing reachability means the handle was not checked, never that nobody is behind it. Records can also go stale, and we flag the ones we have not confirmed again recently.

So treat a match as evidence, not as proof of who someone is. Check it before you act on it in a way that matters. Never rely on a match alone to identify, accuse or make a decision about a person. A missing match means we found nothing, not that there is nothing.

Match rates, coverage figures and cost estimates are measurements and forecasts. They change as the index grows, and your own list decides your own number. You pay for what actually resolved, never for an estimate.

If you are in the index

You may be in the index without ever having used walletlink.social. The privacy policy tells you how to get out of it, and these terms do not narrow it:

  • Write to help@walletlink.social and name each address or handle you want removed. We do not ask you to prove ownership first. A person runs the removal by hand. We delete each identifier from the index and add it to a suppression list that every write path checks, so a later sweep cannot put it back. It stays there until you ask us to undo the removal, and we keep a copy for 30 days only so a removal made in error can be undone, as the privacy policy explains. We complete a removal within 30 days.
  • If you can sign for the address, Claim your address lets you fill in or confirm the X account we hold for it, or withdraw the address from the index and stop us collecting it again. You do it yourself. Confirming the account we hold, or withdrawing, takes effect at once. If we hold a different account, we record your disagreement and keep the old one until it stops reaching anyone. You can withdraw a claim later from the same page, with the same wallet.

A customer who exported a result before you asked still has their copy, and we cannot reach it. These terms forbid them to use it against you. If they do, report it to us.

Your lists and your results

What you upload stays yours. We use it to run your lookups and keep it as the privacy policy describes, and no customer can see another customer’s lists.

When you look up an address, we write what we learn about it to the index, and it answers other customers’ lookups of the same address. We share what the sources said about the address, as the privacy policy lists it. We never share that you ran the lookup, what else was on your list, or what it was for. The one exception is the anonymous count of large recent lookups on our home page, which the privacy policy describes.

We license the results we return to you for your own use: outreach to your own community, research and running your project. You may share them inside your organization and with people who work for you. An agency may use results for a client, for outreach to that client’s own community, under these same rules. You may not resell or redistribute them in bulk. The license does not end when your credits expire. If we tell you that a person in your results has asked us to remove them, you must delete that person’s results from your copies.

No warranty

This page and our documentation say exactly how our data can be wrong. BEYOND THAT, WE PROVIDE THE SERVICE AND EVERYTHING IT RETURNS AS IS AND AS AVAILABLE. TO THE EXTENT THE LAW ALLOWS, WE MAKE NO PROMISE THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE OR FREE OF ERRORS, THAT ANY MATCH IS CORRECT, COMPLETE OR CURRENT, OR THAT THE SERVICE FITS ANY PARTICULAR PURPOSE.

Limits on our liability

To the extent the law allows:

  • we are not liable for indirect, incidental, special, consequential or punitive losses, or for lost profits, revenue, data or goodwill;
  • we are not liable for what you do with our results, or for how the people you contact respond to you;
  • our total liability for all claims about the service is limited to what you paid us in the 12 months before the claim arose, or $100 if that is greater.

Nothing here limits a liability that the law does not let us limit.

If someone brings a claim against us because you broke these terms, or because of how you used our results, you will cover what that claim costs us, including reasonable legal fees.

Ending this agreement

You can stop using the service at any time. Revoke your keys and disconnect your applications from the account menu. To delete your account, write to help@walletlink.social; the privacy policy says what we keep afterwards, such as payment records, and why. Your credits end with the account, and we do not refund them.

We can act on a breach of these terms as described under what we do about misuse. We may also close your account for any other reason, with 30 days’ notice by email, and then we refund what you paid for the credits you have not used and that have not expired. If we stop offering the service altogether, we will give at least 60 days’ notice, and then refund the unused part of any paid credits that have not expired, in proportion to what is left.

These parts continue after this agreement ends: what you may not do with results you already hold, the disclaimers, the limits on liability and the indemnity.

Changes to these terms

When these terms change, the date at the top changes with it, and we record the change in the public changelog. For a change that materially affects you, we will email every account holder at least 30 days before it takes effect, including accounts that have turned off product email, because this is a legal notice and not marketing. Accounts created by paying onchain have no inbox, so for them the date at the top and the changelog are the notice. If you continue to use the service after a change takes effect, you accept the new terms.

A change to these terms never takes away credits you have already bought or shortens their life.

Governing law and disputes

The laws of the State of Wyoming govern these terms, without regard to its rules on conflicts of law. Any dispute about these terms or the service is heard only in the state or federal courts located in Wyoming, and you and we both agree to their jurisdiction. Disputes go to court, not to arbitration.

You and we each bring claims only on our own behalf, never as a plaintiff or a class member in a class or representative action.

Before you start any formal dispute, write to help@walletlink.social and give us 30 days to try to resolve it.

The rest

These terms and the privacy policy are the whole agreement between you and us about the service. If a court finds part of them unenforceable, the rest still applies. If we do not enforce a term at once, we have not given it up. You may not transfer this agreement without our written consent. If the business is sold, this agreement and what we hold go with it, as the privacy policy says.

Contact

help@walletlink.social, for a question about these terms, a report of misuse, a removal request or a billing problem. It reaches a person rather than a queue. walletlink.social is operated by Starl3xx Labs LLC, a limited liability company organized in Wyoming.