We collect as little as the service can function with. There is no account system in the conventional sense: there is no name, no password and no email address required to use the API. Identity is a wallet signature, and credentials are stored only as one-way hashes.
The individual operator of M2M Sentinel is the controller for the processing described in this policy and can be reached at contact@m2msentinel.com.
| Data | Why | Retention |
|---|---|---|
| Wallet address | Proves entitlement to a key, enforces one free key per wallet, and is the address a refund is paid to. | For the life of the key record, then 180 days. |
| SHA-256 digest of your API key | Authentication. The plaintext key is never written to storage or to a log. | Until revoked or expired, then 180 days. |
| Transaction hash and settlement record | Prevents a payment being redeemed twice, and supports refunds and accounting. | The detailed settlement record is retained for 180 days. A minimal transaction-hash replay marker is retained indefinitely to prevent double redemption. |
| Request counters | Rate limiting and monthly credit metering, keyed by key digest, not by identity. | Rate windows: minutes. Monthly usage counters: 62 days. |
| Server logs | Operating the service and investigating abuse and errors. Written by our hosting provider. | Per the hosting provider's retention policy. |
| Queried contract addresses and symbols | Present in the request path so the request can be served. Not retained in a profile. | Only in provider logs, as above. |
The website stores your API key in your browser's localStorage under the key
m2m_api_key, so the inspector and sandbox pages can call the API on your behalf. This never
leaves your device except as an x-api-key request header to our API. Clear it at any time with
"Forget stored key" on the API Keys page. We do not use cookies for tracking.
Blockchain transactions are public and permanent. We cannot edit, hide or delete anything recorded on Base — including the payment you send us and the address you sent it from. That data is outside our control and outside the scope of any deletion request.
These providers receive only what is needed to perform their function. We do not send them your API key.
We do not rely on consent for any processing, and we do not carry out automated decision-making that produces legal effects concerning you.
Depending on where you live, you may have the right to access, correct, delete, restrict or port your data, and to object to processing. Because we hold so little, most requests resolve quickly.
POST /v1/keys/revoke, then email
contact@m2msentinel.com from a channel you control. We
cannot delete on-chain records, and we may retain settlement records where tax law requires.
GET /v1/keys/self.
We aim to respond within 30 days. You may also complain to your local supervisory authority.
No system is perfectly secure. If you believe you have found a vulnerability, report it to contact@m2msentinel.com. We will acknowledge within 5 business days and will not pursue legal action against good-faith research that follows the Acceptable Use Policy.
If a breach affecting your data occurs, we will notify affected users without undue delay, and regulators where legally required, describing what happened, what data was involved and what you should do.
Our infrastructure providers operate globally, so your data may be processed outside your country.
The service is not directed at children and is not intended for anyone under 18.
Material changes will be announced in the changelog, and the version and effective date above will change.
Privacy requests: contact@m2msentinel.com · Security: contact@m2msentinel.com