Your data and privacy
Scrya collects what it needs to confirm your holdings for the business that asked. This page explains what that is, who can see it, and how to have it exported or deleted.
What Scrya holds about you
Your details: your name, your email address and, if the business entered it, your date of birth.
For a private wallet verification:
- the public address you enter, and its network
- the message you signed and your signature
- what the public blockchain shows for that address: its balance, number of transactions and last activity
For an exchange verification:
- which exchange you connected
- your API key and secret (and passphrase, for OKX), stored encrypted
- the balance of the asset being verified
What Scrya can’t do
- Move your crypto. Signing a message gives no one access to your wallet, and a read-only API key can’t trade or withdraw.
- Ask for your seed phrase, recovery words or private key. Scrya never needs them.
Create your API key with read-only permissions only. Scrya uses it just to read balances, and a key with trading or withdrawal rights allows far more than Scrya needs.
How your API key is protected
- Your key and secret are encrypted before they’re stored. They’re only decrypted on Scrya’s servers, while your balance is being checked.
- They’re never sent back to your browser, and the business never sees them in readable form.
- Scrya keeps the encrypted key so you can reuse it on a later request, under Use a saved API key or add a new one. Each reuse runs a fresh balance check.
- You can stop a key working at any time by deleting it at your exchange. See Revoking your API key.
What’s cleared after 30 days
About 30 days after a verification completes, Scrya automatically:
- deletes your signature, the signed message and any stored exchange keys
- shortens the stored wallet address to its first 6 and last 4 characters
Scrya also deletes operational records on a schedule: logs such as email delivery and error records after between 90 days and 12 months, and audit history after 24 months.
Who can see your results
- The business that asked. Its team can see your requests, the addresses or exchange you used, the balances and the outcome. If you start a request yourself with Verify an asset, the business you choose can see it as soon as you create it.
- Only that business. If you’re a customer of more than one business, each one sees only its own requests.
- Scrya administrators, who can access verification records to run and support the service.
- You, in your portal.
Getting a copy of your data, or having it deleted
There’s no export or delete button in the customer portal. To ask for either:
- Contact the business that invited you. An administrator there can download your data or erase it.
- Or email support@scrya.io.
An export is a file containing your customer record, your verification requests, your addresses and their results, exchange balances, and a log of emails sent to you. It never includes signatures or API keys.
Erasure is permanent. It deletes your customer record with that business and its requests, addresses, balances and stored keys, plus related notifications, email and error logs and audit history. It also deletes your Scrya login, unless another business still has you as a customer.
For how Scrya handles personal information more broadly, see the Scrya Privacy Policy.
