Privacy policy

Last updated 23 September 2026 · Version 1.4

The short version. Everything you record is saved in your own browser. If you create an account, a copy is also kept in our database so your portfolio follows you between devices — your email address, your transactions, your settings, your watchlists, and, only if you turn them on, your price alerts and notification settings. We don't sell anything to anyone, we run no advertising or analytics trackers, and we never hold your cryptocurrency.

Who we are

Tokemetrics is operated by Davinchi Limited, a company registered in New Zealand (NZBN 9429049300529), trading as Tokemetrics, from Christchurch, New Zealand. Davinchi Limited is the agency responsible for the personal information described here. You can reach us at hello@tokemetrics.com about anything in this policy.

This policy is written to meet the New Zealand Privacy Act 2020 and its information privacy principles, and the Australian Privacy Principles under the Privacy Act 1988 (Cth), so that people in either country know where they stand.

What we collect, and why

If you join the waitlist: your email address, the exact wording of the consent you ticked, the date and time, the network (IP) address the signup came from, and the browser's user agent string. The address and user agent are kept as evidence that the consent was real, because the spam laws below expect us to be able to show it. We use the email address for one thing — to tell you when the product launches.

If you use the app without an account: nothing reaches us from the app itself. Your transactions, holdings, settings, watchlists, saved wallet addresses and the last prices you were shown are stored by your own web browser, on your own device, under this site's own storage. They are not transmitted to us and we cannot see them. Clearing your browser data deletes them, which is why the app lets you export a copy.

If you create an account, we hold:

We hold these so your portfolio follows you between your phone and your computer, and so it survives a lost device. We do not collect your name, address, date of birth or any identity document, because tracking what you own does not require knowing who you are.

Your password. Accounts are run for us by Supabase. Your password goes from your browser to Supabase and is stored there as a hash — a one-way scramble. It does not pass through our own server, and neither we nor anyone else can read it back. The same is true when you confirm your password before deleting something.

Notifications. Nothing in this section exists until you switch notifications on. When you do, your browser creates a subscription with its own push service — the one run by whoever makes your browser — and we store that subscription so we can send to it. We also store your time zone, because "8am" means nothing to a server otherwise. A daily summary contains the value of your portfolio and how it has moved; an alert names a coin and a price. Those messages are encrypted for your device before they leave our server, so the push service passes them on without being able to read them — but it does know that a message was sent to your device, and when. Turning notifications off removes the subscription. Deleting an alert removes it.

Exchange connections. If you connect an exchange, the API key you give us must be read-only — we never ask for permission to trade or withdraw, and you should never grant it to us or to anyone claiming to act for us. The key is encrypted on our server before it is stored, and it is written to a table that no signed-in browser session can read, including yours. There is deliberately no way to ask for a key back. Our sync worker decrypts it only to fetch your trades, which are then saved as ordinary transactions on your account.

Wallet addresses. If you add a public wallet address, it is kept on your device rather than in your account. To show a balance, the address is sent to our server, which asks a public block explorer or a public node for that chain. Those services see the address and our server, not you. A public address reveals only what any block explorer already shows anyone who asks.

Automatically: our hosting provider records standard technical information such as IP addresses and request logs, for security and to keep the site running. Our own functions count requests per network address, in memory and briefly, to stop a script running up the bill. We don't use analytics or advertising trackers, we don't set cookies for either purpose, and there is no third-party measurement code on any page.

We never hold your cryptocurrency, and we cannot move it.

What stays on your device

The browser copy is not a cache of the account — it is where the app actually works from, which is why it keeps working offline. Signing out does not erase it. It switches to a separate record used when nobody is signed in, and leaves the account's record in the browser where it was.

Anything stored by a browser is readable by anything else running on the same site, and by anyone with the unlocked device. If you share a computer, sign out and clear the site's data when you're done.

Who can see it

Other people using Tokemetrics cannot see your data. That is enforced by the database itself, which refuses any request for another person's rows, rather than by our code remembering to check. Every table holding account data works that way, including alerts, watchlists and notification settings.

We can see it, in the sense that any service operator can: with direct access to the database, your transactions are readable. We don't look at individual accounts, and we don't build anything from your data. Two exceptions are worth naming — your password, which is stored only as a hash, and your exchange API keys, which are encrypted with a secret that is not in the database, so a copy of the database alone would not reveal them.

If you would rather we could not see it at all, don't create an account. The app is fully usable without one, and in that case your records never leave your device.

What we don't do

Cookies and browser storage

We set no advertising or analytics cookies. The app uses your browser's own local storage for your records and settings, and, if you are signed in, for the session that keeps you signed in between visits. If you were given a beta access code, the pass issued for it is kept there too. All of it stays on your device until you clear the site's data.

Consent, and taking it back

Joining the waitlist requires you to tick a box that is not ticked for you. That is your express consent to receive a launch email, as required by the Unsolicited Electronic Messages Act 2007 in New Zealand and the Spam Act 2003 in Australia.

Every email we send will identify us and include a working unsubscribe link. You can also withdraw consent at any time by emailing us, and we will remove your address.

Where it is stored, and who else is involved

The site is hosted by Cloudflare. Accounts, transactions, watchlists, alerts and notification settings are stored by Supabase, in a database hosted in Sydney, Australia. Waitlist emails are sent through Resend, which is given your address for that purpose.

Market prices come from Binance, coin information and artwork from CoinGecko, currency conversion rates from public rate services, and headlines from the published feeds of CoinDesk, Cointelegraph, The Block and Bitcoin Magazine. Wallet balances come from public block explorers and public nodes for each chain.

In the ordinary case those requests are made by our server, never by your browser. Binance and CoinGecko are asked what a coin is worth, not who is asking. They receive no account, no email address and no device identifier, and nothing about how much of anything you hold. Responses are cached and shared between everyone using the app, so a request is usually serving several people at once — though we won't pretend an unusual combination of coins isn't still an unusual request.

One exception, said plainly. If our own price service can't be reached, the app falls back to asking CoinGecko directly from your browser rather than leaving you with no figures at all. When that happens, CoinGecko sees your device's network address, the same as any website you visit does, along with the list of coins being asked about. It still never sees your amounts, your account or your email address.

Some of these providers operate outside New Zealand, including in the United States, so your information may be stored or processed overseas.

We only use providers that are subject to comparable privacy obligations, as required by information privacy principle 12 of the Privacy Act 2020 and Australian Privacy Principle 8.

How long we keep it

Waitlist addresses, and the consent records that go with them, are kept until the launch email has been sent, and then for up to twelve months in case of follow-up, unless you ask us to remove yours sooner.

Account data is kept while your account is open, and goes when you delete it. A price alert that has fired is kept, marked with when and at what price, so the list can tell you what happened instead of it silently vanishing; deleting the alert removes that record. A push subscription is removed when you turn notifications off, and also when the push service tells us the device is no longer reachable.

We don't keep personal information for longer than we need it.

Getting a copy

You can export your transactions as a CSV file at any time from Settings, and from the transactions list. It is a plain file you can open in a spreadsheet, keep, or load into something else. Do it before you delete anything, and do it occasionally regardless — browser storage is not a backup.

You can also ask us in writing for a copy of what we hold about you, under the sections below.

Deleting your data

You can delete everything you have recorded at any time from within the app — Settings, Your data, Delete everything. You will be asked for your password first. While you are signed in, this removes your transactions, your watchlist and named lists, your price alerts, your notification settings, your push subscriptions and any exchange connections (and with them the encrypted keys) from our database, and resets your settings to their defaults. Deletion is immediate and permanent, and we cannot restore it afterwards, so export a copy before you do it.

You can also delete the account itself — Settings, Account, Delete my account. You will be asked for your password and to type the word DELETE. That removes everything listed above, your settings record, and your sign-in record, so we no longer hold your email address at all. If the sign-in record cannot be removed for some reason, the app will tell you so rather than report success, and we will finish it by hand if you email us.

What deletion does not reach. Deleting clears your transactions from this device as well, but the browser's own record may still hold other things it saved — your watchlists, saved wallet addresses, theme and currency, and any records kept for other accounts or for signed-out use on the same browser. Only clearing this site's data in your browser removes those. Waitlist records are separate from accounts, so if you also joined the waitlist, email us to have that address removed too.

Keeping it safe

These are the protections that are actually in place:

And the limits, which matter just as much. We can read the account database, so an account is a matter of trusting us. Rate limiting is a speed bump rather than a wall. The app page loads a styling library from a third-party network, and a compromise there would run with access to what your browser has stored for this site. Nothing on the internet is beyond attack, and we would rather say so than offer a reassurance we can't stand behind.

If a privacy breach occurs that is likely to cause serious harm, we will notify the people affected and the relevant regulator, as the notifiable privacy breach scheme in New Zealand and the notifiable data breaches scheme in Australia both require.

Your rights

You can ask us what personal information we hold about you, ask us to correct it, and ask us to delete it. Email hello@tokemetrics.com and we'll respond within 20 working days, which is the timeframe the New Zealand Privacy Act sets.

If you're unhappy with how we've handled your information, you can complain to the Office of the Privacy Commissioner in New Zealand, or the Office of the Australian Information Commissioner in Australia.

How to contact us

Davinchi Limited, trading as Tokemetrics
NZBN 9429049300529
99B Main Road, Redcliffs, Christchurch 8081, New Zealand
hello@tokemetrics.com

Requests about your personal information can be made by email or in writing to the address above.

Children

Tokemetrics is not intended for people under 16, and we don't knowingly collect their information. If you believe we have, contact us and we'll delete it.

Changes

If this policy changes in a way that materially affects you, we'll say so on this page and update the version above. If the change affects how we use an email address you've already given us, we'll ask you again rather than assume.