Privacy
What we store
| what | why | kept |
|---|---|---|
| Server log — IP, page, referring page, browser type | abuse and debugging | 14 days, auto-deleted |
| Session cookie — random token (hashed on our side) + browser type | keeps you signed in | 30 days |
| Anonymous account — random ID + key hash. No email, no name | your keys and settings | until you delete it |
| Email account — email + salted password hash (Argon2), never the password | your login | until you delete it |
| Google sign-in — one-way hash of your Google ID; your email in plain text if Google shares it | your way back in | until you delete it |
| Activity log — sign-ins and key events; hashed IP on failed logins | security | deleted with the account |
| Launch-note signup — optional email + note, hashed IP, browser type | one email at launch | until launch, then deleted |
| Theme, calculator inputs, cached prices, last sign-in method | convenience | your browser only — never sent to us |
Keys are stored as SHA-256 hashes; only the last 4 characters stay readable so you can tell them apart. We cannot read a key back.
Third parties your browser talks to
Pages load fonts from Google Fonts. The dashboard fetches public chain data from mempool.space, litecoinspace.org and Blockchair, with Google Firestore as fallback — these retire as our own nodes take over. Two signal pages fetch price history from Binance's public data API. The account page loads Google's sign-in button when you open it. Each sees your IP. Password-reset and alert emails are delivered by Resend, which sees the recipient address and message.
Deletion
Self-serve on the account page: one button erases the account, its keys, its sessions and its activity log. Lose an anonymous key and no one, including us, can reach the account.
BasinTwo runs on our own server in Hillsboro, Oregon, USA (Hetzner). Data changes hands with no one. Run by one person — questions, or a copy of your data: platform@basintwo.com.
Updated 2026-09-19.