This policy explains how personal data is processed when you use fmze.dev, its accounts and its API (the "Service"). "We", "us" and "our" mean the operator of fmze.dev. "You" means anyone who uses the Service.
1. Controller
The controller responsible for your personal data is the operator of fmze.dev, based in the European Union. You can reach us at any time through our contact form. We have not appointed a data protection officer, as the law does not require one for a service of this kind.
2. Data we process
The table below lists what we process, why, on which legal basis under Article 6(1) of the General Data Protection Regulation (GDPR), and how long we keep it. "Contract" means the processing is necessary to provide the Service you asked for (Article 6(1)(b)). "Legitimate interests" means our interest in operating a secure, reliable service and preventing abuse, which we have weighed against your rights (Article 6(1)(f)). "Legal obligation" refers to Article 6(1)(c).
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| IP address, browser details, the page requested and the time (server request log) | Running the site, finding faults, preventing abuse | Legitimate interests | 14 days |
| IP address (rate limiting) | Protecting the site from overload and abuse | Legitimate interests | About one minute, in memory only |
| Technical error logs | Finding and fixing faults | Legitimate interests | Up to one month |
| Email address, password hash and profile picture value | Providing your account | Contract | Until you delete your account |
| Two-factor secret (encrypted) and recovery codes (hashed) | Securing your account, if you turn two-factor on | Contract | Until you turn it off or delete your account |
| Session records: IP address, browser, times | Keeping you signed in and letting you review and end sessions | Contract | Until you sign out, after 12 hours of inactivity, or after 7 days at most |
| Security log: sign-ins and account changes, with IP address and time | Protecting your account and investigating misuse | Legitimate interests | 180 days |
| One-time email codes | Confirming your email address and resetting your password | Contract | 10 minutes |
| API access request and the purpose you describe | Deciding on and managing API access | Contract | Until you delete your account |
| API request and webhook delivery logs: endpoint, result, response time, IP address | Operating the API, enforcing limits, preventing abuse | Contract and legitimate interests | 30 days |
| Wallet and watched-address records, for approved API keys only | Providing wallet and webhook features | Contract | For as long as the feature is provided to you, then as long as the law requires |
| Contact form messages and any email address you give | Answering you and handling requests about your rights | Legitimate interests; legal obligation for rights requests | 90 days after we have dealt with the message |
| Database backups (containing the account data above) | Restoring the service after a failure | Legitimate interests | 14 days |
The blocks, transactions and addresses shown on the explorer are public data from the Litecoin blockchain. We do not connect that data to you, unless you give us an address through your account or an API key. Transactions recorded on the blockchain cannot be changed or deleted by anyone, including us.
We do not sell personal data, use it for advertising, use analytics or tracking tools, or make decisions about you based solely on automated processing, including profiling.
3. Whether you must provide data
You can use the explorer without giving us any personal data beyond what your browser sends with each request. To create an account, you must provide an email address and a password; without them we cannot create the account. Giving an email address in the contact form is optional, but without one we cannot reply.
4. Cookies
We set one cookie, __Host-fmze, and only when you sign in. It keeps you signed in and is deleted when you sign out or after 7 days at the latest. It is strictly necessary to provide the account you requested, so under Article 5(3) of the ePrivacy Directive it does not require your consent. We use no other cookies and no similar technologies for tracking.
5. Recipients
We use the following service providers, which process personal data on our behalf (Article 28):
- Cloudflare, Inc. delivers the site, protects it against attacks and serves the icon font used on the pages.
- Advin Servers hosts the server that runs the Service, located in the United States.
- Resend sends our emails from its infrastructure in the European Union (Ireland).
We disclose personal data to authorities only where the law requires us to.
6. Transfers outside the European Economic Area
Some of these providers are established in, or process data in, the United States. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision, including the EU-US Data Privacy Framework for certified providers, or on the European Commission's Standard Contractual Clauses. You can ask for a copy of the relevant safeguards through our contact form.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- restrict our processing (Article 18);
- receive your data in a portable format (Article 20).
You can delete your account at any time under Account, Security. For any other request, use our contact form. We may ask you to sign in or otherwise confirm your identity, and we respond within one month, as Article 12 requires.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State where you live, work or believe an infringement took place (Article 77).
8. Your right to object
Where we process your data on the basis of our legitimate interests, you have the right to object at any time, on grounds relating to your particular situation (Article 21). We will then stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
9. Security
Connections are encrypted. Passwords are stored only as Argon2id hashes, two-factor secrets are encrypted, and access to the server is restricted. No system is completely secure, but we take appropriate technical and organisational measures for the risks involved (Article 32).
10. Children
The Service is not intended for children under 16, and we do not knowingly process their personal data.
11. Changes to this policy
We may update this policy when the Service or the law changes. The effective date at the top shows when it last changed. If a change materially affects account holders, we will tell them by email before it takes effect.