Privacy Policy
Last updated: August 17, 2026
CryptoAML.ai ("we", "us", "our") provides AML screening for cryptocurrency wallet addresses. Contact: [email protected]. This Privacy Policy explains what data we collect, how we use it, and how we protect it.
1. Information We Collect
When you use our service, we may collect:
- Wallet addresses — addresses you submit for screening (publicly visible on-chain data).
- Usage data — browser type, pages visited, referral source, and approximate location (country/region via IP).
- Contact information — name and email address if you submit our contact form or purchase an API plan.
- Payment information — handled entirely by our payment processors (Creem, Whop). We do not store payment card details.
2. How We Use Your Information
- To provide and improve the AML screening service.
- To process API plan subscriptions and send service-related emails.
- To analyse aggregate usage patterns and optimise the product.
- To comply with applicable laws and prevent fraud or abuse.
3. Cookies & Analytics
Google Analytics 4 (measurement ID G-0S6MY365BZ) and Yandex Metrica (counter 109775698) record pages, referrers, device type and approximate country. Both start only after you accept cookies. Decline keeps them off. You can also block them in the browser or with the opt-out tools Google and Yandex publish.
Microsoft Clarity
CryptoAML.ai uses Microsoft Clarity (project y3xr1b7t96) for session intelligence: clicks, cursor movement and scroll on the pages you open. Clarity is not a camera feed. Microsoft stores the data on Azure. Playback recordings stay available for 30 days. Heatmaps and starred sessions stay up to 9 months, then Microsoft deletes them from its servers. Microsoft states Clarity is GDPR-compliant as a data controller. Visitors in the EU contract with Microsoft Ireland Operations Limited; transfers to Microsoft Corporation in the United States use Standard Contractual Clauses. See Microsoft's Privacy Statement and Clarity's Privacy Policy.
Cookie consent
The banner on cryptoaml.ai writes your choice to the first-party localStorage key aml_cookie_consent and keeps it for 365 days. Accept sets analytics to true and calls initAnalytics() in /static/js/analytics.js?v=5. That function is the only place this site loads Clarity, from https://www.clarity.ms/tag/y3xr1b7t96. A clean profile never loads that script. Decline writes analytics false and skips the load. After 365 days the banner asks again.
Masking and excluded data
This project's masking mode is Strict: Clarity masks all on-page text before it leaves the browser. We do not send payment card numbers, checkout wallet addresses, AML report bodies, session tokens, API keys or login passwords to Clarity. Addresses you paste into the checker, invoice fields and the account login form stay masked. If a field still needs a tighter rule, email [email protected].
4. Data Sharing
We do not sell your personal data. We may share it with:
- Payment processors — Creem.io and Whop for billing purposes.
- Analytics providers — Google Analytics, Yandex Metrica, Microsoft Clarity.
- Law enforcement — if required by applicable law or valid legal process.
5. Data Retention
We retain usage logs for up to 12 months. Contact form submissions are kept for up to 24 months. You can request deletion at any time by emailing [email protected].
6. Your Rights
Depending on your jurisdiction you may have the right to access, correct, or delete your personal data. To exercise any of these rights, contact us at [email protected].
7. Security
We apply reasonable technical and organisational measures to protect your data. Wallet addresses submitted for screening are processed over HTTPS and are not stored long-term.
8. Third-Party Links
Our service links to Telegram bots and external resources. We are not responsible for the privacy practices of third-party services.
9. GDPR — Additional Rights for EU/EEA Residents
If you are located in the European Union or European Economic Area, the following rights apply to you under the General Data Protection Regulation (GDPR):
- Lawful basis. We process personal data on the basis of: (a) legitimate interest, providing a publicly accessible compliance tool; (b) contractual necessity, processing API plan subscriptions; (c) consent, Google Analytics, Yandex Metrica and Microsoft Clarity after you accept the cookie banner; (d) legal obligation, responding to lawful enforcement requests.
- Right of access. You may request a copy of the personal data we hold about you.
- Right to rectification. You may ask us to correct inaccurate data.
- Right to erasure ("right to be forgotten"). You may request deletion of your personal data, subject to our legal obligations.
- Right to data portability. You may request your data in a structured, machine-readable format.
- Right to object. You may object to processing based on legitimate interest.
- Right to lodge a complaint. You may lodge a complaint with your national data protection authority.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
10. Changes to This Policy
We may update this policy. The "Last updated" date at the top reflects the most recent revision. Continued use of the service after changes constitutes acceptance.
11. Contact
Questions about this policy? Email us at [email protected] or use the contact form.