What we collect. Almost nothing.
Public monitoring pages require no account. Optional account features, subscriptions, webhook management, and alert preferences, use Telegram authentication. We don't run ads, sell data, or fingerprint you.
Website (pegana.xyz)
The dashboard, asset detail pages, and methodology docs are served as static or server-rendered HTML. We don't set any analytics cookies or embed third-party tracking pixels. The following providers process visitor or service data as part of normal operation: Hetzner (backend hosting), Vercel (web hosting + analytics), Sentry (error monitoring), Cloudflare R2 (backup storage), and Telegram (login widget + bot). Standard server logs (IP, user-agent, requested path, response code) are retained for 30 days for abuse investigation and discarded afterwards.
API + WebSocket (/v1/*)
Every API request is logged the same way as the website. We rate-limit by IP to keep the service responsive. That rate-limit bucket lives in memory and resets when the process restarts. No request body inspection, no per-key analytics.
Telegram alert bot (@PeganaWatchBot)
If you /start a chat with the bot we store your Telegram user_id, chat_id, language preference, and the assets you subscribe to. This is the minimum we need to actually deliver the alerts you ask for. You can /stop at any time, which marks the row as blocked but doesn't hard-delete it. We keep it so we can prove to ourselves we stopped sending you messages. If you want a full hard delete instead, email rafael@pegana.xyz with your Telegram handle.
Web account features + Telegram Login Widget
Public monitoring pages require no account. Optional account features, subscriptions, webhook management, and alert preferences, use Telegram authentication. The Telegram Login Widget (telegram.org/js/telegram-widget.js) processes browser metadata. We store your Telegram user_id, chat_id, language preference, and subscribed assets. JWT sessions are issued for web account features. Subscriptions, alert preferences, and webhook URLs are persisted in Postgres. Webhook URLs are user-provided and stored as configured.
Third parties we talk to
Pegana pulls public data from Pyth, Sanctum, Jupiter, DexScreener, DefiLlama, and Solana RPC providers. Those calls don't carry any information about you, they're server-to-server requests asking for on-chain or oracle data.
Storage and security
Account, subscription, alert preference, and webhook data lives in Postgres. Backups go to a private Cloudflare R2 bucket. Both are encrypted at rest. Sentry receives backend error telemetry only. No request bodies, chat IDs, or PII are sent. Browser-side Sentry Replay is not enabled.
Data retention
Server logs are retained for 30 days. Telegram and bot data is retained until you request deletion: /stopmarks your record as blocked, while an email request triggers hard deletion. Accounts, subscriptions, alert preferences, and webhooks are retained until you delete them. Backups are retained for 30 days in Cloudflare R2. Sentry events are retained per Sentry's default retention period of 90 days; no PII is sent to Sentry.
Children
The service is not directed at children under 13. If you believe a minor has subscribed, contact the email above and we will remove the record.
Changes
If we ever expand what we collect, the new policy ships before the new collection does. The Last updated date at the top of this page is the source of truth.