RPCScan
- networks tracked- RPC URLsRequestStatus
Companion site:ExplorerScan ↗Block explorer directory with per-provider drill-downs and TLS posture per host

RPCScan privacy policy

Effective 10 October 2026. Short, because there is not much to say.

The short version

  • We never log your IP address. Not in application logs, not in our database, not anywhere we can query.
  • No analytics. No Google Analytics, no Plausible, no Fathom, nothing.
  • No tracking cookies. The only cookie we ever set is a login session, and only if you choose to sign in.
  • No third-party tags, pixels, fonts or embeds. Pages load from our origin only.
  • No account required to use any public part of the site.
  • Nothing is sold or shared. There is no advertising network and no data broker in this stack.

Why there is no IP address here

Most sites keep IP addresses by default, because the logging tools they install do it automatically and nobody turns it off. An IP is a durable identifier. Combined with the pages you looked at, it says a great deal about who you are and what you were researching.

On a site like this one it would say even more than usual. The RPC endpoints and block explorers you compare, and the chains you look up, map closely onto what you are building or what you hold. We decided that was a record worth not creating, so the field does not exist in our data model. You can see the decision in the source: the ticket record carries a comment reading “Intentionally no IP field”, and stores a two-letter country code instead.

The practical consequence is that if someone subpoenas us, or compromises us, there is no address list to hand over or steal. That is the point.

What we do store

Four things, all of them optional and all of them initiated by you.

WhatWhyRetention
Login session
A public key and a timestamp
Keeps you signed in. Your key is generated in your browser from a 12-word phrase. The private key and the phrase never leave your device, so we hold no password and nothing to reset.Until you sign out, or the session expires
Tickets
Subject, body, country, edge location, browser string, referring hostname
Lets us act on a correction and spot abuse. Country and edge location give the same operational signal as an IP without identifying anyone. The referring URL is cut down to its hostname so your search terms never reach us.Until resolved, then removed on request
Settings
Endpoint priority, posture floor, region
Only exists if you are signed in and changed a default. Keyed to your public key.Until you change or delete it
Donations
Transaction hash, amount, optional name and note
Shown on the public donations list. Everything here is already public on-chain. Tick anonymous and we store no name.Indefinite, as a public record

The RPC telemetry, specifically

We record one row per proxied call so we can tell which upstreams are healthy. That row holds the chain, the method name, the upstream hostname, the status and the latency. Where a signed-in user made the call it carries their public key; otherwise it literally carries the string anon.

It does not hold your IP, your request body, your wallet address, or any parameter you passed. We measure the endpoint, not the caller.

Who else sees your traffic

Being straight about the parts we do not control matters more than a clean-sounding claim.

  • Cloudflare serves every request and therefore sees your IP, the same as any site behind a CDN. They act as our processor and keep their own short-lived edge logs. We do not pull those logs into anything, and we have no IP-level reporting built on them.
  • Upstream operators. When you use the proxy at <chain>.rpcscan.xyz, we make the outbound call for you, so the upstream sees our address rather than yours. That is a privacy gain over calling them directly. They still see the call itself.
  • Sites you click through to. Outbound links to explorers, chain websites and GitHub are ordinary links, and once you follow one you are on their terms, not ours.

That list is the whole of it. There is no analytics vendor, no error-reporting service, no session recorder, no tag manager, no hosted font, and no social embed anywhere on this site.

Cookies

Ours is one cookie, named rpcscan_session, set only after you sign in. It is HttpOnly, Secure and SameSite=Lax, it holds a signed reference to your public key, and it is used for nothing but keeping you logged in.

There is no consent banner on this site because there is nothing to consent to.

Your choices

You can use everything public here without identifying yourself, so for most visitors there is no record to exercise rights over. If you have signed in or filed a ticket, write to contact@rpcscan.com and we will tell you what is held against your key and delete it. No form, no identity check beyond proving you hold the key.

RPCScan and ExplorerScan are one service run by one person. A policy change will be reflected by the effective date above, and anything that materially widens what we collect will be called out on the announcements page rather than quietly edited in.

Contact

Stephen Molnar, Las Vegas, NV. contact@rpcscan.com. Privacy questions and complaints go to the same address as everything else and are answered by the person who wrote the code.