Skip to content
Ethereum
|Chain 1|

Privacy

Plain answers about what this site records, and what the blockchain records whether we like it or not.

Who operates this site

Crypto Tattoo is operated from the European Union. For any question, request, or complaint about your data, write to contact [at] enshrine.tattoo.

What we don't do — and what we measure

This site sets no cookies, runs no advertising, and loads no third-party tracking scripts or analytics services. If that ever changes, this page changes first.

We do count our own traffic, first-party and anonymously: page views with the page path, the referring site, and a coarse device class (mobile/desktop) — recorded without any IP address, cookie, or identifier of any kind, kept for 30 days. There is no way for us to connect these counts to you, and that is by design.

When you upload a tattoo

Your image is checked for prohibited content by Google Cloud Vision (the image bytes are sent to Google for that single analysis; Google acts as our processor). Before storage, we strip EXIF metadata — including any GPS location your camera embedded — so it is never stored or published.

If you mint, your image and its metadata are published to IPFS, a public peer-to-peer network. IPFS content is public and effectively permanent — that is the point of this site, and it means we cannot later make a minted image private.

Uploads are recorded in a security log with your IP address, the image fingerprint, and a timestamp — kept for 90 days (with an off-site backup), then deleted. Image views are recorded without any IP address — only which image was served, and when.

What the blockchain records

Minting writes your wallet address, the token, and the payment to the public Ethereum blockchain. That record is replicated worldwide and cannot be altered by anyone, including us — we cannot ever delete it. Treat your wallet address as public information before you mint.

Infrastructure that sees traffic

Our API sits behind Cloudflare and the site is served by Vercel; both see standard connection data as part of delivering the site. Your browser's blockchain reads go through our own server to the RPC provider (Alchemy) — those requests are not written to any log. Other API requests appear in a technical access log (your IP and the path requested — with wallet addresses redacted) kept for 30 days for debugging, then deleted; it is never backed up off-site. Rate limiting holds your IP briefly in memory and forgets it. Your wallet app and any IPFS gateway you open have their own privacy policies.

Your rights

Under the GDPR you can ask what we hold about you, ask for correction or deletion, and complain to a supervisory authority. Server-side data (logs, stored images that were never minted) can be deleted on request. On-chain and IPFS data cannot — no one can delete it, which is why this page tells you before you mint, not after.

This notice is updated whenever the site's data handling changes. Last updated: August 2026.