wheredidtheybridge.com reads public blockchain data. This policy is about the much smaller amount of data that is yours — what we collect when you use the Service, why we need it, who else sees it, and how to get rid of it.
1.The short version
If you read nothing else
You can use Bridge Explorer without an account, and without us knowing who you are — a daily allowance of lookups is counted against an irreversible hash of your IP address, never the address itself.
We never ask for and never store a private key or seed phrase.
We use one cookie, and it exists only to keep you signed in. There are no advertising or analytics cookies and no third-party trackers.
We do not sell your personal information, and we never will.
We keep what an account needs to work — your sign-in identity, your usage counts, your payments — and a log of activity we use to prevent abuse and understand how the product is used.
You can delete your account yourself, whenever you like, from your account page. No email, no waiting on us.
The rest of this page is the detail behind those points.
2.Who we are
This policy covers wheredidtheybridge.com and everything we run under it: Bridge Explorer, the Bridge API, Decode Changer, and our Discord and Telegram bots (we, us). We operate from Canada. For anything in this policy, including a request about your data, contact support@wheredidtheybridge.com.
3.What we collect
Almost everything below exists because you chose to create an account. Browsing Bridge Explorer signed out involves far less, and is covered under Cookies and counting visitors.
Sign-in identity
Whichever you use: your email address, or your public wallet address and its chain. We record when each was verified or linked. There are no passwords — sign-in is a one-time email link or a wallet signature — so there is no password for us to store or lose.
Linked chat accounts
If you link Discord: your Discord user id, username, and avatar. If you link Telegram: your Telegram id, username, first name, and profile photo URL. Plus when the link was made. Only linked when you choose to link.
Sessions
A hashed session token, its expiry, an irreversible hash of the IP address that created the session, and the browser user-agent. We store only hashes, so the database never holds a token that could be used to sign in as you, nor the address you signed in from.
API keys
A hashed key, its prefix and last four characters so you can recognise it, the name you gave it, and when it was last used. We cannot recover a key after you create it — only you have the full value.
Plan and usage
Your tier, any plan grants or redemption codes applied, your decode credit balance, and per-period counts of Decode Changer searches and Bridge API calls. This is what enforces your quota.
Activity log
One record per meaningful action: what happened (sign-in, a bridge search, a decode search, a quota block, an API call), which surface it came from (web, API, Discord, Telegram), your tier at the time, the Discord server id if a bot command ran in one, an irreversible hash of your IP address, the time, and details of the lookup itself — typically the address, transaction hash, or chain you queried.
Payments
For each crypto order: what you bought, the USD price, the chain, token and amount quoted, the receiving address, the paying address you declared, the transaction hash once paid, and the order status. The on-chain parts are public; what is private is the link between them and your account.
Account-linking audit
When a Discord or Telegram identity is linked to an account or moved to a different one, we record the identity, the accounts involved, an irreversible hash of the IP address, the user-agent, and the time. We use this to detect one person farming many accounts for free quota.
Support messages
If you email us, we keep the correspondence and whatever you put in it, so we can help you and refer back to it later.
4.What we never collect
Private keys and seed phrases. We never ask for one and there is nowhere in the product to enter one. Anyone asking you for one in our name is attempting to defraud you.
Payment card details. We do not accept cards at all, so there is no card number, billing address, or card processor anywhere in the system.
Advertising and cross-site tracking data. No ad networks, no tracking pixels, no third-party analytics scripts, no fingerprinting, no data brokers.
Anything you were not asked for. We do not read your wallet balances for profiling, and signing in with a wallet gives us no ability to move your funds — a signature proves you hold the address, nothing more.
5.Cookies, and how we count visitors
We use exactly one cookie. It is called wdtb_session, it holds an opaque sign-in token, and it exists only so you stay signed in. It is HttpOnly, so scripts cannot read it, sent over HTTPS only in production, restricted to this site, and it expires after 30 days. Signing out deletes it. It is strictly necessary — without it you could not have an account — and it is not used for advertising or analysis.
To count how many distinct people use the free Explorer, to enforce the daily allowance for signed-out visitors, and to rate-limit abuse, we need to tell visitors apart without identifying them. We do that without a cookie: we take your IP address and browser user-agent, combine them with a secret value and the current UTC date, and store only an irreversible hash of the result. The stored allowance counter works the same way — a hash and a number of lookups, with no address attached, swept once it is old enough to be useless.
What that design means in practice
The identifier changes every day and cannot be reversed back to your IP address. It lets us answer “how many people searched today”, “has this visitor used their free lookups”, and “is one visitor hammering the API”. It cannot be used to follow you from one day to the next, to build a profile, or to recognise you on any other website.
The account-level records listed in What we collect — sign-ins, activity events, identity links, code redemptions — are stamped the same way, with an irreversible hash rather than the address. That one is not rotated daily, because its purpose is to notice when many free accounts share a single origin, and a value that changed every night could not. So it is a durable label: it can tell us two accounts came from the same place, and it still cannot tell us, or anyone who obtained the database, where that place is.
We do not store your IP address anywhere. It is read from the request, used in memory to apply a rate limit or count an allowance, hashed, and discarded — no table, log, or backup in this system holds the address itself.
One third-party request is worth naming: our pages load fonts from Google Fonts, which means your browser contacts Google's servers and Google sees your IP address and user-agent. That is the only external asset we load, and we set no cookie through it.
6.Why we use it
Each purpose below maps to something in the list above. We do not repurpose data beyond these.
To run your account — sign you in, keep you signed in, show your plan, and let you reach the same account from Discord or Telegram.
To deliver the Service — perform the lookups you ask for and return results.
To meter and bill — count searches and API calls against your quota, apply credits and grants, verify a crypto payment on-chain and credit it to the right account.
To prevent abuse and fraud — rate-limit, detect quota evasion and multi-account farming, block identities that abuse the Service, and keep an audit trail of administrative actions.
To support you — answer your emails and investigate problems you report.
To understand the product — aggregate measures like active users, which features get used, and where people hit limits, so we know what to build and fix.
To meet legal obligations — keep financial records and respond to lawful requests.
Under Canadian privacy law (PIPEDA) we rely on your consent, given when you create an account and use the Service, together with the limited purposes above that are necessary to operate, secure, and account for it. You can withdraw consent by closing your account — see Your rights.
7.The searches you run, and the wallets you search
When you look up an address, we record that you did — including the address itself — in the activity log. On paid tiers this is also what powers your search history. We use it to meter your quota, to support you, and to detect abuse.
The wallets you look up usually belong to other people. We want to be plain about our position on that. The blockchain data we read is already public, published by the chains themselves; we do not create it, and we do not add off-chain identity to it — we do not attach names, emails, or real-world identities to the addresses we show. But an address can still be personal information when someone knows whose it is, and searching one tells us that you were interested in it.
What you do with a result is your responsibility. The Terms prohibit using the Service to harass, dox, or target anyone, and that restriction exists precisely because public data can be misused.
8.Who we share it with
We do not sell personal information, and we do not share it for advertising. We share only in these situations:
Providers who run parts of the Service
Our application host and managed database provider (which is where the data described above is stored), and our transactional email provider, which receives your email address in order to deliver sign-in links. They process data on our instructions.
Blockchain data sources
To answer a lookup, our servers query third-party APIs: a blockchain analytics provider used by Decode Changer, public block explorers and RPC endpoints, and the bridge protocols we aggregate. What reaches them is the address, transaction hash or chain being queried, plus our server’s IP — not your identity, your account, or your IP address.
Discord and Telegram
Only if you use those surfaces. Linking passes your identity on that platform to us; using a bot means your command travels through that platform, and in a shared server or group it may be visible to other people there. Their privacy policies govern their side.
Blockchains, when you pay
A crypto payment is a public transaction. The paying address, amount, and hash are permanently visible to anyone, by design and outside our control. We add the private link between that payment and your account; the transaction itself was already public.
Legal and safety
Where we are required by law, or where we reasonably believe disclosure is necessary to investigate fraud or abuse, to enforce our Terms, or to protect the rights and safety of users or the public.
A change of ownership
If the Service is ever sold or transferred, account data may transfer with it. We would tell you before your information became subject to a different privacy policy.
9.Where it is processed
We operate from Canada, but our providers and the data sources we query may store or process data outside it, including in the United States and the European Union. While data is in another country it is subject to that country's laws, and may be accessible to its courts and authorities under them. We use providers that offer appropriate protection and, where required, contractual safeguards for transfers.
10.How long we keep it
Account data — for as long as your account exists, and deleted when you close it, subject to the exceptions below.
Sessions, sign-in links, and linking tokens — until they expire, then removed on a routine basis. Sign-in links are single-use and short-lived.
Anonymous visitor identifiers — meaningless after 24 hours by design, since the hash changes daily and cannot be reversed.
Payment and financial records — retained as long as tax and accounting rules require, typically several years, even after an account closes.
Activity, identity-linking, and administrative audit logs — retained beyond account deletion, in the form described next.
What deletion actually does, and what survives it
Deleting your account strips every identifying detail from it — email, wallet address, Discord and Telegram identity — and destroys every credential: sessions, API keys, and any unused sign-in links. What is left is a stub with no identity attached, which nobody can ever sign in as.
That stub is kept rather than dropped, on purpose. Your payment records hang off it and we are required to keep those; so does the record of which single-use codes have been redeemed, which is what stops a code being used twice by deleting and re-registering. Activity records, identity-link history, and the log of administrative actions are stored separately and survive on their own — they are what let us spot one person farming accounts for free quota, and what stops historic usage figures from silently rewriting themselves.
All of it keeps an internal account identifier that no longer resolves to a person. Chat platform identifiers stay in the link history for the anti-abuse purpose above. If you want to know exactly what would remain in your case, ask us before you delete.
11.Your rights
You can ask us to:
Tell you what personal information we hold about you and how it has been used.
Correct anything inaccurate.
Delete your account and the personal information attached to it.
Withdraw your consent and stop processing, which in practice means closing your account.
Explain a decision or a data practice you do not understand.
Deleting your account takes about ten seconds
Go to your account page, choose Delete account, and type the confirmation word. It happens immediately — you do not have to email us, wait for us, or explain why. Because you are already signed in, there is nothing for us to verify. Before you confirm, the page lists exactly what you are giving up, including any remaining paid time and decode credits, which are not refunded.
Deletion removes your email address, wallet address, and any linked Discord or Telegram account, deletes every session and API key, and permanently disables the account. It cannot be undone and we cannot restore an account afterwards. You are free to sign up again, but it will be a new account starting from nothing.
Deletion is refused in three situations, and the page will tell you which one applies: the account is suspended (email us — we will not let deletion be a way around a suspension), a crypto payment is still in flight (wait for it to land or expire, so money you have already sent is not lost), or the account is an administrator of the Service.
For anything else — access, correction, or a question about your data — email support@wheredidtheybridge.com from the address on your account, or tell us the wallet address you sign in with. We aim to respond within 30 days, and may need to verify that the request really comes from you.
Two limits on deletion worth stating plainly:
We cannot delete anything from a blockchain. Transactions, including a payment you made to us, are permanent public records held by the network, not by us. Nobody can remove them.
We keep the audit records described above. Retaining them is necessary for fraud and abuse prevention, and for our own financial records.
If you are not satisfied with how we handle a request, you can complain to the Office of the Privacy Commissioner of Canada, or to the privacy regulator where you live. We would rather you told us first so we can put it right.
12.Security
Traffic is served over HTTPS. Every credential we hold is stored as an irreversible hash rather than in a usable form — session tokens, sign-in links, account-linking tokens, and API keys — so a copy of our database would not let someone sign in as you or spend your quota. There are no passwords in the system to be reused or leaked. Administrative access is restricted to a named allow-list, and every administrative action is logged.
No system is perfectly secure, and we will not pretend otherwise. If you believe your account has been accessed without your permission, or you have found a security problem, email support@wheredidtheybridge.com and we will take it seriously.
13.Children
The Service is not intended for anyone under 18 and we do not knowingly collect information from children. If you believe a child has given us personal information, email support@wheredidtheybridge.com and we will delete it.
14.Changes to this policy
We will update this page as the product changes. The date at the top shows when it last changed. If a change materially affects how we handle your information, we will make reasonable efforts to tell you in the product or by email before it takes effect.