Effective Date: September 6, 2026

Rug Munch Media LLC (“we,” “us,” “our”) is committed to privacy. This policy describes what data we collect — and more importantly, what we don’t.

This policy complies with the General Data Protection Regulation (GDPR) (EU 2016/679), the California Consumer Privacy Act (CCPA) (Cal. Civ. Code § 1798.100 et seq.), and the Wyoming Consumer Privacy Act (W.S. § 40-12-501 et seq.).


1. What We Don’t Collect

We built our products with a privacy-first philosophy:

  • No analytics. We don’t use Google Analytics, Mixpanel, Segment, or any third-party analytics service on cryptorugmunch.com.
  • No tracking cookies. We don’t set cookies for advertising, tracking, or profiling purposes.
  • No fingerprinting. We don’t collect device fingerprints, browser signatures, or behavioral data.
  • No personal data harvesting. We don’t buy, sell, or rent personal data.
  • No advertising networks. We don’t participate in any ad network or data broker ecosystem.

2. What We Do Collect (Minimal)

Website (cryptorugmunch.com)

  • Technical necessity only. The site may set functional preferences (e.g., preferred color scheme) stored locally in the browser. These contain no personal data and are not transmitted to us.
  • Server logs. Our CDN provider (Cloudflare) may collect standard server logs (IP address, user agent, timestamp) for security, DDoS protection, and performance. We do not routinely access, store, or analyze these logs. Cloudflare’s data practices are governed by their privacy policy.

RMI Telegram Bot (@rugmunchbot)

  • Scan queries. When you use /scan <address>, we process the token address to return risk data. We do not store your Telegram user ID or chat history beyond what is technically necessary to respond to your request.
  • No persistent profiles. We do not maintain user profiles or link scan queries to identity.

APIs

  • Rate limiting. We may track request counts per IP address to enforce rate limits. This data is temporary (retained for no more than 24 hours) and not linked to identity.
  • x402 payments. When using x402 pay-per-call, payment transactions are settled on-chain and are public by nature of the blockchain. We do not link on-chain payment addresses to off-chain identity.

Self-Hosted Git (git.rugmunch.io)

  • Account data. If you create an account on our self-hosted Forgejo instance, we store your username, email, and SSH public keys. We do not store passwords in plaintext (bcrypt hash only).
  • Commit data. Git commit metadata (author name, email, timestamp) is inherent to the Git protocol and is public.

3. Scan Data and Community Scam Detection

When you submit a token address, wallet address, or other query to our hosted products, the on-chain data and risk indicators from that scan may be used to improve our scam detection models, including our crypto-native RAG (retrieval-augmented generation) system.

This is for the good of the community, not for our private gain:

  • What we use: Risk indicators, contract patterns, and behavioral signals extracted from public blockchain data. These are on-chain facts, not personal data.
  • What we don’t use: Your Telegram user ID (beyond what’s technically necessary to respond), your off-chain identity, or any personal information. We do not link scan queries to individuals.
  • How the community benefits: Improved detection means better risk scores, more accurate honeypot detection, and stronger protection for every user of our products — including self-hosters running our open-source code. Improvements flow back through public methodology documentation and open-source code.
  • We don’t sell scan data. Scan-derived insights are never sold to third parties. They feed our detection models, which are shared with the community.
  • Your consent. By submitting a scan query to our hosted services, you consent to this use as described in our Terms of Service.
  • Opt out by self-hosting. If you prefer that your scan data not be used this way, you may self-host RMI or PryScraper under the applicable open-source license. No data reaches our servers when you self-host.

4. Blockchain Data

Our products analyze publicly available blockchain data. By design, blockchain data is public, immutable, and cannot be deleted. We do not control, delete, or modify on-chain data.

Under GDPR Article 4(1), blockchain addresses are not considered personal data unless linked to an identified or identifiable natural person. We do not link blockchain addresses to identity.

5. Legal Basis for Processing (GDPR Article 6)

Where we process personal data, our legal basis is:

  • Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, and service operation
  • Contract performance (Art. 6(1)(b)) — providing the services you request
  • Legal obligation (Art. 6(1)(c)) — compliance with applicable laws

We do not process personal data based on consent that can be withdrawn, because we do not collect data requiring consent. Scan data usage (Section 3) operates on legitimate interest — the community benefit of improved scam detection — and processes only on-chain public data, not personal data.

6. Third-Party Services

We use these service providers for infrastructure:

Provider Purpose Data Accessed GDPR Status
Cloudflare DNS, CDN, DDoS protection IP address, user agent DPA available
Self-hosted Forgejo Git hosting Username, email, SSH keys Controller
Telegram Bot platform Scan queries Third-party processor
Self-hosted docker-mailserver Email (mail.rugmunch.io) Email content Controller — no third-party access
Netcup Server hosting (EU, Germany) Server logs EU-based

We select providers with strong privacy commitments and minimize data sharing to what’s technically necessary. Data Processing Agreements (DPAs) are in place where required by GDPR Article 28. Our email is fully self-hosted (docker-mailserver on our own infrastructure) — no third-party email provider has access to our communications.

7. Telegram Stars Payment Data

Premium tiers of RugMunchBot are paid through Telegram Stars. Payment processing is handled entirely by Telegram. We do not receive, store, or process your payment credentials, billing information, or Stars transaction details. Telegram’s processing of Stars payments is governed by Telegram’s own privacy policy and terms.

8. Data Retention

  • Server logs: Not routinely stored beyond 7 days
  • Rate limiting data: Deleted within 24 hours
  • Git account data: Retained until account deletion is requested
  • Scan queries: Not retained after response is delivered; on-chain risk indicators extracted from scans may persist as part of detection models (these are public blockchain patterns, not personal data)
  • On-chain data: Immutable — cannot be deleted (see Section 4)

9. Data Security

We implement reasonable technical and organizational security measures including:

  • Encryption at rest: AES-256-GCM
  • Transport encryption: TLS 1.3
  • Access controls: Role-based, least-privilege
  • Secrets management: Gopass (no secrets in code or git)
  • Regular security audits: Internal + automated (gitleaks, semgrep, bandit)
  • Open-source code: Every line is public and community-reviewable

However, no system is perfectly secure. In the event of a data breach affecting personal data, we will notify affected users within 72 hours as required by GDPR Article 33, and in accordance with applicable U.S. state breach notification laws.

We do not voluntarily share personal data with law enforcement or government agencies. If compelled by valid legal process (subpoena, court order, or other lawful order), we may disclose the minimal data we hold. We will challenge overly broad requests and notify affected users where legally permitted. Because we collect minimal data, our ability to disclose is inherently limited.

11. Your Rights

GDPR Rights (EU/EEA Residents)

Under GDPR, you have the right to:

  • Access (Art. 15) — request a copy of your personal data
  • Rectification (Art. 16) — request correction of inaccurate data
  • Erasure (Art. 17) — request deletion of your personal data (“right to be forgotten”)
  • Restriction (Art. 18) — request limitation of processing
  • Portability (Art. 20) — receive your data in a machine-readable format
  • Objection (Art. 21) — object to processing based on legitimate interest
  • No automated decisions (Art. 22) — we do not make automated decisions with legal effects

CCPA Rights (California Residents)

Under CCPA, you have the right to:

  • Know — what personal information we collect, use, and disclose
  • Delete — request deletion of your personal information
  • Opt-out — of the “sale” of personal information (we do not sell personal information)
  • Non-discrimination — equal service regardless of privacy rights exercised

Wyoming Consumer Privacy Act Rights

Under W.S. § 40-12-501 et seq., Wyoming residents have rights similar to CCPA including access, correction, deletion, and opt-out of targeted advertising.

Exercising Your Rights

Contact privacy@cryptorugmunch.com to exercise any of these rights. We will respond within 30 days (GDPR) or 45 days (CCPA).

Since we collect minimal data, most requests can be fulfilled immediately.

12. Children’s Privacy

Our products are not directed at children under 13 (COPPA) or 16 (GDPR). We do not knowingly collect data from children. If you believe a child has provided us with data, contact us for immediate deletion.

13. International Data Transfers

Our servers are located in the European Union (Germany) and the United States. Data may be transferred between these jurisdictions under the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs).

14. Cookies

We do not use advertising, tracking, or analytics cookies. Any cookies set are strictly necessary for site functionality and do not contain personal data. No cookie consent banner is required because we do not use cookies that require consent under GDPR Article 5(3) or ePrivacy Directive Article 5(3).

15. Data Protection Officer

We have not appointed a formal Data Protection Officer as we do not engage in large-scale processing of special category data (GDPR Article 37). For privacy inquiries, contact privacy@cryptorugmunch.com.

16. Changes to This Policy

We may update this policy. Material changes will be posted on this page with an updated effective date.

17. Contact

Privacy inquiries: privacy@cryptorugmunch.com

Legal inquiries: legal@cryptorugmunch.com

Rug Munch Media LLC Cheyenne, Wyoming, USA