Privacy
Last updated: September 20, 2026
Address lookups
When you look up a Bitcoin address, the request passes through Cloudflare and our own web and API services. The address appears in the request path, so it can be recorded in service logs together with the query string and information about your browser.
Our web-server logs mask IP addresses to network prefixes. Our Bitcoin-data API access logs replace the client-IP field with a fixed redaction marker for satoshis.watch requests. These logs can still contain requested Bitcoin addresses and browser information; masking or removing an IP address does not make all the remaining data anonymous.
If our own history source cannot supply the requested history, the service may ask mempool.space for an address summary and transaction pages. Those requests can include the Bitcoin address and, when paging through results, a transaction ID. We do not control mempool.space's logging, retention, or deletion practices. Cloudflare also processes requests under its own policies.
We do not use lookup activity to build advertising profiles or provide lookup queries to advertisers. Bitcoin addresses and transactions are public, but an address can still be sensitive when it is connected to a person.
Privacy mode hides balances and related values on your screen. It does not stop network requests or change how service logs are handled.
Browser data
The site can store display, theme, tab, and address-specific preferences in your browser. You can remove this data through your browser's storage controls.
Watch accounts
For Watch and Watch+ accounts, we store your username, password hash, settings, saved Bitcoin addresses and their names, colors and display settings, entitlements, and session records. Session and security records can include hashed network and browser information.
When we issue a Watch Key, its plaintext secret is shown to your authenticated browser once. The service stores a password-style hash rather than the plaintext secret. When you unlock with a Watch Key, the key is sent to the service for verification.
Deleting an account revokes access and removes it from normal use. Security, payment, operational, and backup records may remain.
Payments
Watch+ checkout records can include the account, payment method and status, timestamps, payment address or invoice, transaction identifiers, and confirmation state. USDC recovery records can also include a possible payer address. The Watch+ checkout does not ask for a name, email address, mailing address, or card number. Payment providers and networks may keep their own records under their own policies.
Contact messages
When you contact us, we store your message, any email address you choose to provide, the page URL, a timestamp, the source host, and a masked network prefix. A successful submission means the message was received and stored; it does not guarantee email delivery, a reply, or a review time.
Retention
Our web-server request logs are configured to rotate daily and keep three rotated files alongside the current log. Our Bitcoin-data API access logs are configured to keep 365 daily rotations, approximately a year, alongside the current log. These settings do not establish a maximum retention period for backups or other operational copies.
Network and browser hashes in account audit records are scheduled for deletion after 72 hours. Account sessions normally have a 30-day lifetime that can be extended by use. Those periods do not set the retention of account, Contact, or payment records, which are handled separately. Deleting an account or clearing browser storage does not guarantee deletion of all server records or backups.
Terms
Use of satoshis.watch is governed by our Terms of use.