Skip to content

Privacy

What Lockinfy keeps, and where.

Lockinfy works with public wallet addresses and keeps your settings in your own browser. Its server keeps records about you only once you start monitoring a wallet, which is optional: what they are, and for how long, is set out below.

Updated October 2026

In short

  • No name, email or password is collected. Without Monitor there is no Lockinfy account; starting it creates an anonymous monitoring account.
  • Your wallet shares a public address, nothing else. Lockinfy never asks for a recovery phrase or private key, and never asks your wallet to sign anything.
  • Your settings live in this browser’s local storage. Once you start monitoring a wallet, Lockinfy’s server also keeps your addresses, rules and monitor records until you stop it; your notification settings stay with your monitoring account.
  • Addresses reach Lockinfy’s server to look up balances; that lookup is not logged, cached or written to a database. Monitor stores the addresses it watches until you stop it.
  • Lockinfy does not sell your data, and the site runs no advertising or analytics trackers.

Stored in your browser

These items are saved in local storage on this device so the app remembers you between visits. They never leave the device except as described under the next headings.

Session
Tracked public addresses, the wallet type used to connect them, your strategy settings, the date you activated the simulation, your onboarding answers and display preferences such as Hide balances.
Wallet connection
Connection state kept by the wallet library, so a connected wallet reconnects on your next visit.
Set-aside session
If you open the demo while tracking a wallet, your wallet session is kept aside on this device so you can return to it.
Monitoring
Whether monitoring is on, the state of your rules, the protection triggers they raised and what you did with each, and whether you allowed browser notifications.
Monitoring session
Only once you start monitoring: the sign-in session of your anonymous monitoring account and a note of when this browser started it.
Visit counter
How many times the overview has opened for the current simulation, used to time a one-off message.

Disconnecting a wallet in Settings removes it from the session. Clearing this site’s data in your browser removes everything above.

Sent to Lockinfy’s server

When you track a wallet, your browser sends its public addresses (up to five) to Lockinfy’s server, which reads their balances and prices and sends the result back. The server keeps nothing from that request: addresses are not logged or stored, and responses are marked private so they are not cached along the way.

The strategy simulation and the demo run in your browser. When you start monitoring your wallets, Lockinfy’s server checks your rules on a schedule (next section).

The demo portfolio is generated in your browser. Using it sends no wallet data at all.

Like any website, the servers that deliver Lockinfy’s pages handle standard request data, such as your IP address and browser type, in order to respond.

When you start monitoring

Monitor is optional and read-only. Starting it on your wallets creates a monitoring account with Supabase, which hosts Lockinfy’s database and sign-in: anonymous (no name, email or password needed). Lockinfy’s server then checks your rules about every 5 minutes, also while your browser is closed, with the same public wallet data and prices as the app. It keeps:

Wallet addresses
The public addresses the monitor reads, and their network, to look up their balances at each check.
Protection policy
Your rules, a fingerprint that identifies that version of them, and where each rule stands: for example the current lock level and the portfolio high it tracks.
Monitor status
Check times and health, whether the monitor is active or paused and why, and when you last opened Monitor in Lockinfy, recorded at most once an hour: a monitor nobody has opened for 30 days and that can’t send you an alert is paused. A random stop token, which can only turn its alerts off or pause it.
Portfolio snapshots
One per check: total value and, per asset, quantity and price. No addresses. Every check is kept for 2 days, then one per hour up to 30 days; older ones are deleted.
Protection triggers
Each trigger, the rules and data quality it was based on, and what you did with it.
Notifications
Your alert settings, the browser push registrations you turn on (each one’s push service address and encryption keys), and a record of each push sent (channel, status, attempts).

These records are kept at most until you stop monitoring (Settings → Monitoring), which deletes the monitor with its addresses, protection policy, status, snapshots, triggers and delivery records. Snapshots are thinned and deleted sooner, as above. Disconnecting your last wallet or clearing local data in Lockinfy deletes it too. The monitoring account, your notification settings and push registrations stay after you stop: they hold no wallet data, and deleting them from the app is not available yet in the beta.

A monitor can be stopped from the browser that started it. It can’t be reached from any other browser: stop it in Lockinfy before clearing this site’s data in your browser settings; otherwise it keeps running with no way to reach it from Lockinfy.

Services Lockinfy relies on

Blockchain RPC providers
Lockinfy’s server asks RPC providers for the token balances of the addresses you track, and of the addresses a monitor watches at each check. They see the addresses queried, coming from Lockinfy’s server rather than from you.
CoinGecko
Current and daily historical prices. CoinGecko receives asset identifiers only, never your address.
Supabase
Only once you start monitoring: hosts Lockinfy’s database and its sign-in (anonymous), and stores what is listed under “When you start monitoring”.
Cloudflare Turnstile
Only when Lockinfy shows its sign-in check (starting monitoring in a browser without a monitoring session): Cloudflare’s script loads in your browser and checks, from browser and device characteristics, that a person is there. Lockinfy receives only a one-time pass token, which goes to the sign-in provider.
Browser push services
Only if you turn on browser push: your browser’s push service (from Google, Mozilla, Microsoft or Apple) delivers each notification. It says which rule triggered, with amounts unless you hide them.
Your wallet
MetaMask, Phantom or another wallet you connect handles the connection request on your device under its own privacy terms.
WalletConnect
When it is available, connecting through WalletConnect passes the connection through its relay service.
X (Twitter)
Only if you choose to share: the share button opens X with suggested text and a link. The shared page and image contain no address, holdings or amounts.

Your controls

  • Track an address without connecting a wallet, or explore the demo without any address.
  • Disconnect a tracked wallet in Settings. Disconnecting the last one signs you out and clears the session.
  • Turn on Hide balances to mask dollar amounts and quantities on screen.
  • Stop monitoring in Settings → Monitoring at any time; its records are deleted from Lockinfy’s server, except the account and settings listed above.
  • Turn on Hide balances in notifications to leave dollar amounts out of push alerts. Turning on Hide balances in the app turns it on too.
  • Clear this site’s data in your browser to remove everything Lockinfy stored on this device.

Changes

Lockinfy is in beta. Features such as live protection or syncing across devices would change what is stored. This page will be updated before any such change ships, and the date above will change with it.

See alsoRisk disclosureSecurity