AnyScan Extension Privacy Policy
Effective August 1, 2026 · Applies to the AnyScan browser extension
The short version
The extension reads the pages you browse locally, finds token mentions (cashtags like $BONK and Solana addresses), and asks the AnyScan API for safety verdicts on those mentions. The matched ticker or address is the only page-derived data that ever leaves your browser.
What is sent
Requests to the AnyScan API contain a list of detected mentions, each exactly two fields: a kind (ticker or address) and the matched value (e.g. BONK or a base58 mint address). Requests are sent without cookies or credentials. Standard connection metadata (your IP address, as with any HTTPS request) is visible to our servers and is used only for rate limiting.
What is never sent
- Page content, posts, or the text around a mention
- URLs of pages you visit, or your browsing history
- Anything you type — editors and compose boxes are never scanned
- Your identity: no accounts, no cookies, no identifiers
- Wallet contents — the extension never touches a wallet
What is stored
Verdicts are cached briefly inside your browser's extension storage so repeated mentions don't re-query. The options page stores one setting (a custom API endpoint, for developers). Nothing is stored server-side about you: the API sees anonymous ticker/address lookups, retained only in aggregate query caches keyed by the token — never by you.
What we will never do
- Sell or share data with third parties — there is none to sell
- Accept payment from token projects to alter a verdict
- Inject ads, referral links, or sponsored placements
These claims are enforced by the extension's architecture and checked by its automated test suite; the extension's source is publicly auditable.
Contact
Questions: privacy@anyscan.io. Material changes to this policy will be dated at the top of this page.