Privacy policy

Effective 8 October 2026

This policy explains what Clearlist (legal entity to be stated on incorporation) (“Clearlist”) does with personal data. There are two kinds of people it concerns: the people who use our dashboard and API (our customers), and the people our customers screen (their end users). The security page describes how the data is protected.

Customers: people with an account

We store your name, email address, organisation name and a hashed password or sign-in token, so that you can log in and we can contact you about the service. We keep usage records (which keys made which requests, when) for billing, rate limiting and security. We send transactional email: a weekly digest of list changes and your monitors, billing notices and security notices. The digest can be turned off in the dashboard; security and billing notices cannot.

We do not sell this data, use it for advertising, or share it beyond the processors below.

End users: people our customers screen

When a customer screens a name, they may send a name, date of birth, nationality or identifier. When they screen an address, country or transaction, no personal data is involved unless the customer attaches it as metadata. The customer is the controller of this data and we are its processor: we process it only to produce the decision they asked for, to keep the record of that decision, to rescreen it if they enrol it for monitoring, and for nothing else.

A screening decision is a record that a check was made and what it matched. It is not a judgement about the person. If a decision concerns you and you believe it is wrong, contact the organisation that screened you; they hold the record and the policy that produced it, and they can clear it. We cannot identify you from a name alone and will not act on a request about a specific record without the customer, except where the law requires us to.

Retention

  • Decisions on the Free plan: deleted after 30 days.
  • Decisions on paid plans: kept while the account is open, deleted within thirty days of closure.
  • Counterparty exposure results: cached for six hours, then discarded.
  • The public address checker: nothing is stored; the query is not logged.
  • Account and billing records: kept while the account is open and for as long as tax and accounting law requires after.
  • Server logs: thirty days.

Processors

Hosting and compute: Vercel. Database: a managed Postgres provider. Email: a transactional email provider. Payments: Stripe, which receives billing details directly; we do not see card numbers. Chain data providers (Solana RPC, Helius, Etherscan) receive the public address being screened and nothing else. We will update this list when it changes and name each provider on request.

Where data is processed

Data is processed in the United States and, through the providers above, in the regions they operate in. Where a transfer mechanism is required we rely on the provider's standard contractual clauses.

Your rights

Depending on where you live you may have the right to access, correct, delete or export your personal data, to object to or restrict processing, and to complain to a supervisory authority. Customers can do most of this from the dashboard. For anything else, or if you are an end user, write to support@clearlist.xyz.

Cookies

The dashboard uses one session cookie to keep you signed in. The public site sets no cookies and runs no third-party analytics or trackers.

Changes

We will post changes here and, for material changes, email customers at least thirty days before they apply.