What we collect, what we don't, and what happens to it. Covers this website and the Chrome extension.
We don't want your data. It's a liability, not an asset.
There are no accounts, no email addresses, no analytics suites and no advertising trackers on this site. We sell nothing to anyone, and we never will.
🧬 The Chrome extension
What it sends us
Solana addresses found on the page you're viewing. Once per page as a single batched lookup, and again when you click a badge. An address is public blockchain data.
Shortened address fragments — pages often truncate an address to something like CoHwqS…pump. The extension sends the visible start and end (never surrounding text) to ask whether it matches an address we already know. A fragment is at most a few dozen characters that look like an address; our matcher is strict, but on rare occasions a word pair that resembles one (all valid base58 letters) may be sent and simply won't match anything.
Your API key, if you've entered one, so we know the request is from a paid user.
Your IP address, because every HTTP request has one. We use it only to rate-limit abuse and we do not build profiles from it.
What it never sends us
The content of the page — text, posts, messages, images. Only the address-shaped strings described above ever leave the browser.
The URL you're on, the page title, or your browsing history.
Anything you type. Input fields, text areas and editable regions are deliberately skipped.
Any wallet data: keys, seed phrases, balances, connected accounts. The extension has no wallet access of any kind and cannot sign or send a transaction.
Your name, email, or any identifier that points at you.
Cookies. The extension sets none and reads none.
What's stored, and where
On your machine (Chrome's local extension storage): your API key, and a cache of reports already fetched so scrolling doesn't re-request them. Nobody but you can read it. Uninstalling the extension deletes it.
On our servers: one report per address, cached so the next person asking about the same token costs us nothing. These are keyed by the address — never by user, session, key or IP. There is no record of who looked at what.
If you buy a key
We store what's needed to know the key is valid: a one-way hash of the key itself (never the key), the plan, the expiry, and a contact address if you gave us one. We store a coarse "last used" timestamp so we can spot a shared or leaked key. Nothing else is attached to it.
🌐 This website
No accounts. Voting and posting are anonymous. To stop one person voting a thousand times we derive a rotating, salted, one-way identifier — it can't be reversed into an IP or a person.
Cookies are used only to keep you signed in if you verify a wallet, and for CSRF protection. No advertising or cross-site cookies.
Third parties. Chain and market data comes from our sibling service memecoins.expert; that is a request we make about an address, not a request that carries anything about you. Bot protection is Cloudflare Turnstile. Nothing you submit is sent to an advertiser or data broker.
Anything you post is public and community-moderated. Don't put private information in a comment.
📬 Contact & removals
Questions, data requests, or something to correct: post on The Wall or message @solanashitlist on X. Listings are community votes on public on-chain behaviour, and the wall is unmoderated by design — but factual errors get fixed when they're pointed out.
Last updated 25 July 2026. If this policy changes materially we'll say so on the extension page rather than quietly editing it.