Privacy Policy

Version 1.0 · Effective 5 August 2026

This Policy explains what personal data Tessium collects when you use the Service, why we collect it, who receives it, how long we keep it, and what you can require of us.

It covers the website at tessium.dev, the account dashboard, the documentation and the API. Tessium is referred to below as "Tessium", "we" or "us".

Contact for anything in this Policy, including requests about your data: contact@tessium.dev

1. What we collect, why, and on what basis

Account data

WhatYour email address, stored encrypted. Where you sign in with Google or GitHub, the account identifier that provider returns to us, and the email address associated with it.
WhyTo create and operate your account, to authenticate you, to send the sign-in links and codes that replace a password, and to contact you about the Service.
BasisPerformance of the contract between us. You cannot use the Service without an account, so providing this is a requirement of entering into the contract.

API keys

WhatThe keys issued to your account, the name and expiry you set, when each was created, used and revoked, and the record of a key after you delete it.
WhyTo authenticate connections, to enforce the limits of your Plan, and to investigate key theft, key sharing and reuse of revoked keys.
BasisPerformance of the contract, and our legitimate interest in protecting the Service against credential abuse.

Technical and security data

WhatThe IP address and user-agent of requests to the website and the dashboard, the IP address of your registration, the IP addresses of your API connections, and timestamps.
WhyTo keep the Service secure and available: to detect and block automated sign-up, credential stuffing and brute-force attempts, to limit how many accounts may be created from the same origin, to detect accounts operated together to circumvent Plan limits, and to diagnose faults.
BasisOur legitimate interests, specifically: preventing abuse of the free tier through multiple accounts; detecting credential theft and unauthorised use of API keys; protecting the availability of the Service against excessive and automated traffic; and preventing payment fraud. We have assessed these interests against your rights and keep a record of that assessment, which you may request.

Usage data

WhatConnection times and counts, number and type of subscriptions, data volume transmitted, events delivered, errors returned, and the breakdown of usage by Stream. We do not record the content of the events delivered to you.
WhyTo show you your usage, to apply and enforce the limits of your Plan, to calculate fair-use consumption, and to plan capacity.
BasisPerformance of the contract.

Subscription parameters

WhatThe parameters of the subscriptions you open, including the token and wallet addresses you filter on.
WhyPrimarily to deliver the events you asked for, which requires processing the parameter while the subscription is open. Beyond that, these parameters are recorded in service records for a limited period and used for one purpose only: detecting abuse of the limits of the free Plan.
How we limit itThese parameters are not used to build a profile of your activity or interests, are not combined with the on-chain data the Service publishes, are not used for marketing, are not sold, and are not disclosed to anyone outside the administrators of the Service.
BasisPerformance of the contract, for delivery. Our legitimate interest in preventing multi-account abuse, for the retained records.

Payment data

WhatThe Plan and period purchased, the amount, the crypto-asset used, the payment status and the payment identifier reported to us by the payment processor, and the resulting billing history.
WhyTo take payment, to activate and renew your Plan, to handle underpayments, overpayments and account credit, and to keep the accounting records we are required to keep.
BasisPerformance of the contract, and compliance with a legal obligation for the accounting records.
NotePayment is processed by a third-party processor and passes through the blockchain you use. We never receive or hold payment card details, because the Service does not accept cards.

Messages you send us

WhatYour email address, the topic you select, where in the site you started from, the content of your message, and our correspondence with you.
WhyTo answer you and to keep a record of what was agreed.
BasisPerformance of the contract where you are a customer; otherwise our legitimate interest in responding to enquiries about the Service.

2. What we do not do

We do not store passwords, because the Service does not use them.

We do not accept or hold payment card details.

We do not run analytics, advertising or tracking on the website, and we set no third-party marketing or advertising cookies.

We do not sell personal data, do not share it for advertising, and do not use it to build commercial profiles.

We do not send marketing email. If that changes, we will ask for your consent separately and every message will carry a working unsubscribe.

3. On-chain data delivered by the Service

The events the Service delivers are drawn from public blockchain activity. They contain blockchain addresses, which we take as we find them: we do not attach names, identities or labels to any address, and we do not attempt to determine who controls one.

We cannot alter, delete or make private anything recorded on a blockchain, because we do not control it. If you believe our published index of on-chain activity concerns you personally, write to contact@tessium.dev and we will consider what we can do within our own systems.

4. Cookies and local storage

The website and dashboard use only what is necessary to work:

PurposeWhat it isLifetime
Sign-in sessionA session cookie identifying your authenticated sessionUntil you sign out or the session expires
Request integrityA token preventing cross-site request forgeryThe session
Bot protection on the sign-in and contact formsAn artefact of the Cloudflare Turnstile challengeShort-lived

Each of these is strictly necessary to provide a service you have requested, so we do not ask for consent and show no cookie banner. We set no analytics, advertising or profiling cookies. If we ever add any, we will ask for your consent first and update this Policy.

You can block or delete cookies in your browser. Blocking the session cookie will prevent you from signing in.

5. Who receives your data

We use the following categories of provider. Each receives only what its function requires, and none is permitted to use it for its own purposes.

ProviderWhat it receivesFunction
CloudflareRequest metadata including IP address; Turnstile challenge dataNetwork protection, TLS termination, bot protection on forms
NOWPayments (FD Transfers LLC)Payment amount, asset, and the identifiers needed to match a payment to your accountCrypto-asset payment processing
PostaleYour email address and the content of the emails we send youOutbound email delivery
Google, GitHubOnly what is needed to complete the sign-in you initiatedOptional sign-in providers, used only if you choose them
TelegramAlerts to our administrators, which for suspected abuse may include the email addresses and IP information of the accounts concernedThe private channel through which administrators receive operational alerts and review suspected abuse
Infrastructure providersData stored and processed on the servers running the ServiceHosting, storage and backups

We also disclose data where the law requires it, where it is necessary to establish, exercise or defend a legal claim, or where it is necessary to protect the Service or another person against fraud, abuse or a security threat.

If the Service is transferred to an entity established to operate it, or to a successor or acquirer, account and billing data transfers with it, and this Policy continues to apply until it is replaced.

6. International transfers

The Service and the providers listed above operate in several countries, so your data may be processed outside the country you are in. Where a provider processes data in a country for which the European Commission has not issued an adequacy decision, we rely on the transfer safeguards that provider publishes, such as standard contractual clauses or certification under a recognised framework. You may ask us at contact@tessium.dev which safeguard applies to a particular provider.

7. How long we keep it

DataRetention
Account email and sign-in identifiersWhile the account exists, then deleted within 30 days of closure, except where a record below requires longer
API key records, including revoked and deleted keysWhile the account exists, and 12 months after it closes
IP address and user-agent in security logs90 days from the request. Where a record is attached to an open abuse or security investigation, until that investigation closes and no longer than 12 months afterwards
Session IP addresses and subscription parameters used for abuse analysis30 days
Usage data12 months
Payment and billing recordsAs long as the accounting and tax law applicable to us requires, which is longer than the periods above and which we cannot shorten
Messages you send us12 months after the matter is resolved
Database backupsDaily, with 14 copies retained on a rolling basis. Data deleted from the live system persists in backups until those copies expire

8. Your rights

You may ask us to:

  • confirm what we hold about you and give you a copy of it;
  • correct anything inaccurate or incomplete;
  • delete your data, subject to the records we are required to keep;
  • restrict how we use it while a dispute about it is resolved;
  • provide it in a portable form, where we hold it on the basis of the contract or your consent;
  • stop using it, where we rely on legitimate interests — see the next section.

Write to contact@tessium.dev. We answer within one month, free of charge. We may ask you to confirm control of the account email before acting, because we will not disclose an account's data to someone who cannot demonstrate it is theirs.

You may also lodge a complaint with a data protection supervisory authority in the country where you live or work, or where you believe the problem occurred. You can do that whether or not you have raised it with us first, though we would prefer the chance to fix it.

9. Your right to object

This right is set out separately because it deserves to be read separately.

Where we use your data on the basis of our legitimate interests — the security, technical, abuse-prevention and subscription-parameter records described in section 1 — you have the right to object to that use at any time. Write to contact@tessium.dev and tell us what you object to.

When you object, we stop unless we can demonstrate compelling legitimate grounds that override your interests. For records that exist to keep the Service secure and to stop the free tier being abused, we will often be able to demonstrate such grounds, and we will tell you plainly if that is our position and why. Where we cannot, we stop and delete.

10. Automated detection, and how account decisions are made

We run automated checks that identify accounts showing signs of being operated together to circumvent Plan limits. These checks produce alerts for review, and they can be wrong. We do not publish the signals they rely on, because doing so would tell the people they exist to catch how to avoid them.

No account is suspended, banned or refused by an automated decision. Every such decision is taken by a person who reviews the alert and the underlying facts and who can decide against it. Automated enforcement of the technical limits of your Plan — rejecting a request, closing a connection, refusing a subscription — is not a decision about your account and is reversed as soon as usage returns within your limits.

If your account is suspended or banned, write to contact@tessium.dev. A person will review it, you may tell us your side, and we will tell you the outcome.

11. Deleting your account

You can delete your account in the dashboard. When you do, your API keys are revoked and your connections close immediately, and your account is removed from the Service.

What we keep afterwards, and why: the key and abuse records described in section 7, so that a deleted account cannot be used to reset an abuse history; and the payment and billing records we are required by law to keep. Everything else is deleted on the schedule in section 7. Backups expire on their own cycle.

12. Security

Email addresses are stored encrypted. All traffic to the Service is encrypted in transit. Credentials and secrets are held only on the servers that need them and are not present in source repositories or logs. Access to production systems and to the database is restricted to the operator of the Service. Backups are taken daily and their restoration is tested.

If a security breach occurs that is likely to result in a high risk to you, we will tell you without undue delay and describe what happened, what data was affected, and what we are doing about it, and we will notify the competent authority where the law requires it.

No system is perfectly secure. Protecting your own API keys and sign-in access is your responsibility, as set out in the Terms of Service.

13. Age

The Service is available only to persons aged 18 or over and is not directed at children. We do not knowingly collect data from anyone under 18. If we learn that we have, we delete the account and its data.

14. Changes to this Policy

We may change this Policy. The current version and its effective date appear at the top of this page.

Where a change materially affects how we use data we already hold, we will tell you by email to the address on your account or by notice in the dashboard before it takes effect. Other changes take effect when published.

15. Contact

contact@tessium.dev, or the contact form at tessium.dev/contact.

No data protection officer is appointed, because the Service is not required to appoint one. Requests under this Policy are handled at the address above.