Privacy policy
This is an English translation provided for convenience. The Spanish version (política de privacidad) is the legally binding one, as the site operates under Spanish law.
The short version, no fine print: this site uses no cookies, has no user accounts, sells no data to anyone and shows no ads. The only personal data it processes is what you give it yourself — your Telegram chat identifier if you sign up for alerts, your email address if you subscribe to the newsletter — plus the technical logs any web server generates. The full detail follows.
Data controller
Article 13 of Regulation (EU) 2016/679 (GDPR) requires that you be told the identity and contact details of whoever processes your data. That is what you will find here:
- Controller: Rafael Devos Cerezo
- Contact: contacto@nodewitness.com
The site owner's tax details and postal address are not part of this information and are not requested here: they appear separately in the legal notice.
What data is processed and why
1. Telegram alerts (only if you sign up)
If you start a conversation with the alerts bot (@NodeWitnessBot), we store only your numeric Telegram chat identifier (chat_id) — not your name, username, phone number or anything else. It is the bare minimum needed to send you the alert message.
- Purpose: notifying you when the Score phase changes.
- Legal basis: your consent (signing up is your own voluntary action: messaging the bot).
- Retention: until you unsubscribe. Sending the
/stopcommand to the bot deletes your record entirely from the database — no unsubscribe history is kept. - Note about Telegram: communication happens through the Telegram platform, which processes your data under its own privacy policy, independent of this site.
2. Server technical logs
Like any web server, ours automatically logs technical data for each request: IP address, date and time, requested URL and browser user agent.
- Purpose: security (abuse detection, per-IP rate limits) and technical diagnostics.
- Legal basis: legitimate interest in keeping the service secure and operational.
- Retention: the technically necessary time for those purposes; logs are rotated and deleted.
- The origin server is hosted in the European Union (Germany, provider Contabo GmbH).
- Content delivery network (CDN): since August 2026 the site's pages are served through Cloudflare, Inc., acting as a technical intermediary between your browser and our server. To do so it also processes connection data (IP address, requested URL, user agent), for the purpose of speeding up delivery and protecting it against abuse. Cloudflare is a US company with a global network, so this data may be processed outside the European Union, under the safeguards the GDPR provides for international transfers.
- A deliberate exception, and you can check it: requests from the
analysis tools go to
api.nodewitness.com, which does not go through Cloudflare — they travel straight to the server in Germany. It is set up that way on purpose so that the contents of those queries, including an extended public key (xpub) if you choose to use one, pass through no additional intermediary. A DNS lookup of that subdomain returns our server's address, not a Cloudflare one.
3. Web analytics (cookieless)
We use Cloudflare Web Analytics in its cookieless variant: it sets no cookies, uses no persistent identifiers or fingerprinting techniques, and produces only aggregate statistics (page views, country of origin, browser type). It cannot identify you or track you across sites.
This is the same provider that supplies the CDN described in the previous point; that section explains what connection data it processes in that other role, and where.
4. Bitcoin addresses you analyse in the tools
Addresses you enter in the address analyser are public Bitcoin blockchain data. The site queries them against public sources to generate the analysis and may temporarily cache the public data retrieved, to speed up future responses. They are not linked to your identity or your IP beyond the technical logs described in section 2.
The privacy audit and the wallet movement report for advisors also accept an extended public key (xpub), from which they derive the wallet's addresses for the analysis. These two tools share an in-memory cache: to avoid repeating queries to the node, the result is kept for a few minutes in the server's memory and disappears on its own, with nothing for anyone to delete — it is never written to disk or to any log.
5. Newsletter (only if you subscribe)
If you subscribe to the newsletter we store your email address plus the date, time and IP address from which you confirmed the subscription. Nothing else: not your name, nor any data you did not give us yourself in the form.
- Purpose: sending you the content we publish and, where applicable, information about our own services. It is used for nothing else and is not cross-referenced with the other data in this policy.
- Legal basis: your consent, confirmed in two steps — you fill in the form and then click a link in a verification email. Without that second step you are not added to the list.
- Retention: until you unsubscribe. From then on we keep only the record that you gave and withdrew consent, for 3 years, because the regulation requires us to be able to demonstrate it if anyone challenges it; everything else is deleted. It is not a profile: it is the record that this address consented, and when it stopped.
- Unsubscribing: every email we send carries an unsubscribe link that works in one click, free of charge: you are out the moment you click it, with no further steps. Afterwards our provider shows an optional question about why — you do not have to answer it, the unsubscribe is already done. You can also write to contacto@nodewitness.com.
- Withdrawing consent at any time does not affect the lawfulness of emails sent before that.
- Tracking: this is not the answer we would like to give you. Our sending provider rewrites the links in the newsletter to count clicks, and it cannot be turned off: they tell us it is part of their platform. You can check it yourself in two seconds — hover over any link in the email and you will see a domain of theirs, not ours. The same applies to the confirmation email. What is within our control is not using that data: we do not look at who opens or who clicks, and none of it is cross-referenced with anything else. We also have tracking anonymisation switched on in the account settings, which records the event without tying it to your address; we have verified that on the confirmation email, but we have not been able to verify it on the newsletter, so we are not claiming it. If this bothers you, that is fair enough: you can read us on the web without leaving any trace of this kind.
- Provider: emails are sent by Brevo (Sendinblue SAS, France), acting as data processor under a contract that forbids using your data for any purpose of its own. Your address is stored in European Union data centres (France and Belgium). Some of its own suppliers — the content delivery network and the support tool — also have servers in the United States, and some of its group companies provide support from outside the EU, so there may be access from third countries, under the safeguards the GDPR provides: the EU-US Data Privacy Framework, standard contractual clauses and binding corporate rules. The full, current list is in the subprocessor annex of its terms.
Cookies and local storage
This site sets no cookies, first-party or third-party. It does use the browser's local storage (localStorage), for these purposes:
- Score cache: the latest indicator response, so the page loads without flickering.
- Your address list: any addresses you save to the watchlist in the tools section stay here. They are never sent to a server and never linked to you: clear your browser storage and they are gone, with no copy anywhere else.
- Notices you have dismissed: if you close the Telegram channel notice or the language notice, we remember so as not to show it again, along with a page-view counter whose only job is to avoid showing you a notice on your first visit.
None of this data leaves your browser, none of it contains personal information, and you can delete all of it at any time from your browser settings. Being strictly technical storage plus preferences you set yourself, it requires no prior consent — which is why you will not see a cookie banner.
What we do NOT do
- No user accounts or registration forms.
- We send no email to anyone who has not expressly subscribed.
- No selling or sharing of data with third parties.
- No advertising or ad trackers.
- No user profiling.
Your rights
You can exercise your rights of access, rectification, erasure,
objection, restriction of processing and portability at any time by
writing to contacto@nodewitness.com. For Telegram alerts, the
most direct route is the bot itself: /stop deletes your data instantly,
no need to write to us. For the newsletter, the unsubscribe link in every
email is the fastest route.
If you believe the processing does not comply with the regulations, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es).
Changes to this policy
If the site adds features in the future that change this data processing, this policy will be updated before they go live, and the last-updated date (at the bottom) will reflect it.
See also the legal notice.
Last updated: August 6, 2026