Privacy

Last updated 26 September 2026

What is recorded, what is sent where, and what this cannot protect you from. Every claim below can be checked against the source.

Never sent anywhere

Your private key. It is held in the browser tab, derives your address, and signs transactions locally. It appears in no server route. It is kept in memory only and cleared when you disconnect or close the tab.

Recovery phrases for wallets generated here. Same: created in your browser, never uploaded, no copy kept.

Address labels and the observer lists attached to them, which live in your browser's own storage.

A wallet extension, if you use one. Connecting TronLink or a Bitcoin wallet leaves the key in that extension: it gives this page an address, and approves every payment in its own window. Nothing is stored here, and this site never sees the key.

One exception to the lookups below. When TronLink signs, it talks to its own Tron nodes from your connection rather than through this server, so those nodes see your address and your IP. Pasting a key keeps every chain call behind this server instead; signing in the extension trades that for never handing the key over. Paying a deposit address yourself avoids both.

Your destination address, for sanctions screening. A Bitcoin payout address is checked against the US Treasury's published sanctions list, and that check runs here: the list is downloaded to this server and the comparison is made locally. The address is never sent to Treasury, and never to a screening company — this site buys no such service and subscribes to no such service.

An exchange in progress. Its amounts, addresses, exchange id and plan are kept in this tab's session storage, so reloading the page returns to the same step and stage. That storage belongs to the one tab and is cleared when it closes. The private key is never written to it: after a reload the wallet has to be connected again.

What this site records

Each exchange is written down for fee accounting. A record holds:

time · amount · currencies · provider · fee rate and amount · payout address · transaction hash · a random browser handle

The handle is a random value generated in your browser so repeat exchanges can be grouped. It is not derived from anything about you and resets when you clear this site's data.

Country: each exchange also records the country your connection appears to come from, as a two-letter code supplied by the network in front of this site. It is approximate — a VPN or Tor changes it — and the IP address it is worked out from is not stored.

Recorded with every exchange: your IP address, your browser's user-agent and its language header. FixedFloat requires partners to retain this and to produce it on request, and exchanges here are created through such providers, so it is kept for at least a year and can be disclosed to them. This is personal data and it is not anonymous.

Google Analytics runs on every page. It is a script from Google that loads in your browser, sets cookies to tell one visit from the next, and reports to Google which pages you viewed, roughly where you are, and what brought you here. It runs on the exchange page too. This site used to promise no tracking script of any kind and no longer can: that sentence was true until analytics was added, and leaving it there would have been the easiest lie on the site to catch. A content blocker stops it, and nothing here breaks when it is blocked.

Still not recorded by this site: no account, no email, no browser fingerprint. Demo runs create no exchange record, since nobody pays for them — though Analytics sees those page views like any other.

What necessarily reaches other people

The exchange provider receives your payout address, the amount and the currency pair. An exchange cannot be quoted or created without them, and the provider sees the timing of the leg it handles. SideShift also receives your IP address: it asks integrations to forward the payer's address so its own checks see you rather than this server, and exchanges made through it do so.

Block explorers and price data. Balance lookups, transaction broadcasts and price checks are made by this server rather than by your browser, so those services see the server rather than you. The explorers are blockstream.info and mempool.space; dollar figures come from the public ticker endpoints of Binance, KuCoin, Gate and MEXC, which are read without any account or key and are sent nothing about you.

A Bitcoin destination address is looked up. When the payout is in Bitcoin, the address you entered is sent to a block explorer to read its public history for the linkability read-out shown beneath it. That request is made by this server, which hides who is asking — it does not hide which address was asked about, and an explorer still learns that somebody looked. No other payout chain is looked up at all.

Importing from a recovery phrase checks a few hundred addresses in one go, which tells the lookup service that those addresses were asked about together — again from this server, not from your connection. The phrase never leaves your browser; only the addresses derived from it are looked up.

A webhook, only if you paste one. Exchange status, amounts and payout address are relayed to whatever address you chose.

What this cannot protect you from

The blockchain is public. Every transaction made through this site is permanently visible to anyone. Splitting a transfer makes it harder to reassemble; it does not make it invisible.

Providers keep their own records. What they log, and for how long, is theirs — not something this site controls or can promise anything about.

The hosting platform sees requests. Render, and Cloudflare in front of it, handle traffic to this site and log requests, including IP addresses. That is inherent to being hosted, and it is separate from the record this site now keeps itself: both exist, and neither is invisible.

Your own machine. Browser extensions can read what is on a page, including a private key you have typed into it. A compromised device defeats everything described above.

This is not an anonymity service, and anyone selling you one is worth distrusting. What it does is avoid adding to what already leaks.

Retention

Exchange records are held for fee accounting and for the retention the exchange providers require of partners: at least one year for the IP address, user-agent and language header attached to each exchange. Ask and they will be deleted, unless a provider has an open request for them. Browser storage — labels, your handle, notification settings — lives on your device and is removed whenever you clear this site's data. The copy of an exchange in progress lives in the tab's session storage and goes when the tab closes.

Messages sent through Contact us are kept until they are pushed out. There is no expiry: the five thousand most recent are held and the oldest drops off beyond that, which on current volume is indefinitely. Each one stores what you wrote, its kind and status, anything written back to you, the two-letter country, the random handle your browser carries, and the page you sent it from. It does not store your IP address. A way to reply is optional and never required — a complaint about privacy should not cost you an address to make. Ask, quoting your reference, and the message and its replies will be deleted.

Cookies

Google Analytics sets cookies — the _ga pair, which distinguishes one visitor from another and one visit from the next. They are read by Google, not by this site, and they are what makes the visit counts on the other side of them possible. Blocking them costs you nothing here.

There are no advertising cookies, and nothing is sold or passed to an ad network. The only cookie this site sets itself is a session cookie for the administrator area, and only when someone signs into it.

Plan an exchange

No account, no sign-up, and nothing is held here — your browser pays each provider directly.

Questions about any of this? The source is the authority — everything described here can be checked against it.