Privacy policy

Effective October 3, 2026

This policy explains how personal data is processed when you use fmze.dev, its accounts and its API (the "Service"). "We", "us" and "our" mean the operator of fmze.dev. "You" means anyone who uses the Service.

1. Controller

The controller responsible for your personal data is the operator of fmze.dev, based in the European Union. You can reach us at any time through our contact form. We have not appointed a data protection officer, as the law does not require one for a service of this kind.

2. Data we process

The table below lists what we process, why, on which legal basis under Article 6(1) of the General Data Protection Regulation (GDPR), and how long we keep it. "Contract" means the processing is necessary to provide the Service you asked for (Article 6(1)(b)). "Legitimate interests" means our interest in operating a secure, reliable service and preventing abuse, which we have weighed against your rights (Article 6(1)(f)). "Legal obligation" refers to Article 6(1)(c).

DataPurposeLegal basisKept for
IP address, browser details, the page requested and the time (server request log)Running the site, finding faults, preventing abuseLegitimate interests14 days
IP address (rate limiting)Protecting the site from overload and abuseLegitimate interestsAbout one minute, in memory only
Technical error logsFinding and fixing faultsLegitimate interestsUp to one month
Email address, password hash and profile picture valueProviding your accountContractUntil you delete your account
Two-factor secret (encrypted) and recovery codes (hashed)Securing your account, if you turn two-factor onContractUntil you turn it off or delete your account
Session records: IP address, browser, timesKeeping you signed in and letting you review and end sessionsContractUntil you sign out, after 12 hours of inactivity, or after 7 days at most
Security log: sign-ins and account changes, with IP address and timeProtecting your account and investigating misuseLegitimate interests180 days
One-time email codesConfirming your email address and resetting your passwordContract10 minutes
API access request and the purpose you describeDeciding on and managing API accessContractUntil you delete your account
API request and webhook delivery logs: endpoint, result, response time, IP addressOperating the API, enforcing limits, preventing abuseContract and legitimate interests30 days
Wallet and watched-address records, for approved API keys onlyProviding wallet and webhook featuresContractFor as long as the feature is provided to you, then as long as the law requires
Contact form messages and any email address you giveAnswering you and handling requests about your rightsLegitimate interests; legal obligation for rights requests90 days after we have dealt with the message
Database backups (containing the account data above)Restoring the service after a failureLegitimate interests14 days

The blocks, transactions and addresses shown on the explorer are public data from the Litecoin blockchain. We do not connect that data to you, unless you give us an address through your account or an API key. Transactions recorded on the blockchain cannot be changed or deleted by anyone, including us.

We do not sell personal data, use it for advertising, use analytics or tracking tools, or make decisions about you based solely on automated processing, including profiling.

3. Whether you must provide data

You can use the explorer without giving us any personal data beyond what your browser sends with each request. To create an account, you must provide an email address and a password; without them we cannot create the account. Giving an email address in the contact form is optional, but without one we cannot reply.

4. Cookies

We set one cookie, __Host-fmze, and only when you sign in. It keeps you signed in and is deleted when you sign out or after 7 days at the latest. It is strictly necessary to provide the account you requested, so under Article 5(3) of the ePrivacy Directive it does not require your consent. We use no other cookies and no similar technologies for tracking.

5. Recipients

We use the following service providers, which process personal data on our behalf (Article 28):

  • Cloudflare, Inc. delivers the site, protects it against attacks and serves the icon font used on the pages.
  • Advin Servers hosts the server that runs the Service, located in the United States.
  • Resend sends our emails from its infrastructure in the European Union (Ireland).

We disclose personal data to authorities only where the law requires us to.

6. Transfers outside the European Economic Area

Some of these providers are established in, or process data in, the United States. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision, including the EU-US Data Privacy Framework for certified providers, or on the European Commission's Standard Contractual Clauses. You can ask for a copy of the relevant safeguards through our contact form.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Article 15);
  • have inaccurate data corrected (Article 16);
  • have your data erased (Article 17);
  • restrict our processing (Article 18);
  • receive your data in a portable format (Article 20).

You can delete your account at any time under Account, Security. For any other request, use our contact form. We may ask you to sign in or otherwise confirm your identity, and we respond within one month, as Article 12 requires.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State where you live, work or believe an infringement took place (Article 77).

8. Your right to object

Where we process your data on the basis of our legitimate interests, you have the right to object at any time, on grounds relating to your particular situation (Article 21). We will then stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.

9. Security

Connections are encrypted. Passwords are stored only as Argon2id hashes, two-factor secrets are encrypted, and access to the server is restricted. No system is completely secure, but we take appropriate technical and organisational measures for the risks involved (Article 32).

10. Children

The Service is not intended for children under 16, and we do not knowingly process their personal data.

11. Changes to this policy

We may update this policy when the Service or the law changes. The effective date at the top shows when it last changed. If a change materially affects account holders, we will tell them by email before it takes effect.