Tusklynk

Privacy Policy

Last updated: 5 October 2026

1. Who is responsible

The Havana Elephant Brand Limited, 128 City Road, London, EC1V 2NX, United Kingdom (company number 14531952), is the controller for the data described in this policy. Contact: hello@contentlynk.com.

Your ContentLynk account is held by ContentLynk and is covered by ContentLynk's own privacy policy.

2. The short version

You can use Tusklynk without an account and without telling us who you are. We do not run an analytics script, and we do not profile you. The only place we store a link between you and a wallet address is the watchlist you choose to save. Our methodology page (tusklynk.com/methodology) carries the complete list of what is stored, and this policy describes the same list.

3. Cookies and your browser

Tusklynk sets four cookies. All four are first-party, locked to tusklynk.com, sent only over HTTPS, and unreadable by scripts on the page. Each one exists only for a feature you use. There are no advertising, analytics or third-party cookies.

CookieWhat it holdsHow long
__Host-tusklynk_sessionYour ContentLynk user id and username, signed. No display name, no email, no balance7 days
__Host-tusklynk_sso_stateA one-time number and where to send you back to, while a sign-in is in progress10 minutes
__Host-tusklynk_hold_proofA wallet address you proved you control, and nothing else7 days
__Host-tusklynk_hold_challengeA one-time number, while you are proving a wallet5 minutes

Signing out deletes all four.

In addition, if you start a sign-in from a Save button, your browser holds the address you were saving while the sign-in is in progress, so that the save can complete when you return. It stays in your browser and is not sent to us for storage.

4. What we store on our servers

  • Your watchlist, if you are signed in. Your ContentLynk user id, each saved address, an optional label, and when it was saved. This is the only place a person and a wallet sit together on our servers. Removing an entry deletes it. We keep the rest until you remove it.
  • Daily usage counts, so the fair-use allowance works. For each visitor and each UTC day we store a count against a keyed hash, of your ContentLynk user id if you are signed in and otherwise of your IP address, and a second keyed hash of each address you looked up, so that a reload is not counted twice. No IP address, user id or wallet address is stored in these rows. The hashing key changes every day, so one day's rows cannot be matched to another's. These rows are deleted after three days.
  • Daily totals, kept when those rows are deleted. The date, how many visitors were signed in and how many were not, and how many lookups and walks there were. This row holds no key, no hash and no address, so it cannot be matched to anyone. We keep it indefinitely.
  • Caches, keyed by chain and address and never by user. Token information, daily prices, the result of our fake-token check, each wallet's computed profit-and-loss result, and the working state of a computation in progress. None of these records who asked. A profit-and-loss result is served for six hours and then recomputed. The stored result is replaced when it is recomputed, but it is not deleted on a schedule, so a wallet address that has been looked up can remain in our cache after its result has gone stale.
  • Address labels from the published lists, with their sources, and a daily count of the requests we made to each data provider.

5. What we never store

Any token balance, including the balance used to decide access to a larger watchlist. Any email address. Your password, which we never see. Any link between a person and a wallet on our servers, beyond the watchlist you chose to save. A wallet you prove you control is held in a cookie in your own browser and is not stored by us. When we check eligibility for a larger watchlist, we read that wallet's recorded allocation, show you the result, and do not keep the figure.

6. Server logs

Our host, Vercel, records a line for each request, which includes the page address. For a wallet lookup, the page address contains the wallet address you looked up. We also write short diagnostic lines of our own: whether a sign-in began at a Save button, as a single word with no address or user id beside it, and messages when something fails. A message about a failed profit-and-loss computation can include the wallet address being computed. The log we can read does not include your IP address or your browser's user agent. Vercel processes your IP address to deliver the site, under its own terms. We keep runtime logs for the period our hosting plan provides, which is currently short, measured in days.

7. Who else receives data

  • Vercel, our host, handles every request and therefore receives your IP address and your browser's user agent. Our database is hosted through Vercel in the United States.
  • ContentLynk runs sign-in. When you sign in, your browser goes to contentlynk.com, so ContentLynk receives your IP address and user agent directly. We then exchange a one-time code with ContentLynk, server to server, for your user id and username.
  • Alchemy supplies Base and Ethereum data, and Helius supplies Solana data. They receive the wallet address you looked up, and Alchemy receives a wallet address you prove you control. We call them from our own servers, so they do not receive your IP address.
  • CoinGecko supplies prices. It receives asset identifiers and dates, never an address, and not your IP address.
  • No one else. Our pages load no external script, image or font, the typeface being served from tusklynk.com. No analytics or advertising service receives anything.

8. Why we process data (legal basis)

  • Your watchlist and sign-in: to provide the service you asked for (performance of a contract).
  • The fair-use allowance, security and logs: our legitimate interest in keeping the service available, fair and safe.
  • Caches and provider request counts: our legitimate interest in running the service efficiently. They record no one.

9. International transfers

Our host and data providers operate internationally, and our database is in the United States. Where personal data leaves the UK or the European Economic Area, it is protected by the safeguards in our providers' terms, such as the EU Standard Contractual Clauses with the UK Addendum, or the EU–US Data Privacy Framework where a provider is certified under it.

10. Your rights

Where data protection law applies to you, you may ask for access to the personal data we hold about you, for its correction or deletion, for a copy of it, or that we restrict or stop processing it. You may also complain to your data protection authority: in the UK, the Information Commissioner's Office, or in the EU, the authority in your country. Write to us at hello@contentlynk.com.

In practice, the only personal data we can connect to you is your watchlist, which you can delete yourself, and your ContentLynk account, which ContentLynk holds. The usage rows are hashed with a daily key and hold no identifier, so we cannot find yours in order to act on a request about them, and they are deleted within three days.

11. Children

Tusklynk is not intended for anyone under 18. Creating an account requires declaring a date of birth showing you are 18 or over, which ContentLynk checks on its servers.

12. Changes

When this policy changes, we will change the date above, and we will announce material changes on the site.

13. Contact

The Havana Elephant Brand Limited, 128 City Road, London, EC1V 2NX, United Kingdom. Email: hello@contentlynk.com.

---