Salvage
← Back to Salvage

Privacy Policy

Last updated: July 9, 2026

Salvage (“Salvage”, “we”, “us”) is a non-custodial recovery protocol for stranded ERC-20 tokens. This page explains what data the app at usesalvage.xyzand the Base App Mini App collect, why, and who it's shared with. We built Salvage to need as little data as possible to work — most of what it touches is already public on-chain.

What we collect

  • Wallet address. When you connect a wallet, we see the public address you connect with. We never have access to private keys, seed phrases, or custody of your funds — every transaction is signed by you in your own wallet.
  • Addresses and transaction data you submit for scanning. Contract addresses, wallet addresses, and transaction hashes you paste into the scanner are sent to our server so it can query Alchemy and Etherscan on your behalf. This data is already public on the relevant blockchain.
  • Signed messages and claims.If you register a “find” or start a recovery claim, we store the wallet address involved, the message signature, the relevant token address and transaction hash, and the USD value at time of scan in our database (Supabase). This is what powers first-finder-wins priority and claim/settlement tracking, and it mirrors information that is (or becomes, once a claim is registered on-chain) publicly visible on Ethereum or Base anyway.
  • Mini App notification opt-in. If you open Salvage inside the Base App and it has notification permissions, we may store your wallet address to notify you about recovery-relevant activity in the future. We do not currently send notifications — this is opt-in data collection ahead of that feature shipping.

We do not collect names, email addresses, or physical addresses unless you email us directly. We do not use advertising cookies or ad-tracking pixels.

Chrome extension

The Salvage Chrome extension (“Stranded Token Warning”) watches text and textarea fields on every page you visit for a pattern that looks like an EVM address (0x followed by 40 hex characters) as you type or paste. It does not read, store, or transmit anything else you type — only a matched address pattern, and only once one appears.

When a match is found, the extension sends that address to Salvage's own usesalvage.xyzAPI to check whether it has contract code on Ethereum or Base — the same check the scanner on this site performs. The extension's host_permissions are scoped to usesalvage.xyz only, so it cannot send data to, or fetch code from, any other destination. Nothing is sent to third-party analytics, and no browsing history or page content beyond the matched address is ever collected. Address checks may be cached locally in your browser (chrome.storage.session) for up to 10 minutes to avoid redundant checks; this cache is cleared automatically and never leaves your device.

What we don't control

Our hosting and infrastructure providers (Vercel, Alchemy, Etherscan, Supabase) may log standard technical/operational data as part of running their services — things like IP address, request timestamps, and user-agent strings. This is normal infrastructure logging, not something Salvage requests or has special access to beyond what's needed to keep the app running.

Third parties we rely on

  • Alchemy — RPC access and token/pricing data for scans.
  • Etherscan (API v2) — contract verification status and ABI data.
  • Supabase — database for the finds/claims registry and leaderboard.
  • Vercel — application hosting.
  • Coinbase Wallet SDK / your browser wallet extension — used only to request signatures and transactions; Salvage never receives your private keys.
  • Google Search Console — used to verify site ownership so this site can appear correctly in Google Search. This is a one-time verification tag, not analytics — it does not track visitors or collect personal data.

On-chain data is permanent

Once a recovery claim is registered or settled on-chain, that transaction is part of the public, permanent record of Ethereum or Base — it cannot be edited or deleted by us or by you. Anything we store off-chain (Supabase records backing the finds/claims registry) exists to support that on-chain process and the leaderboard; it is not sold, and it is not used for anything beyond operating Salvage.

Your choices

You can use most of Salvage's scanning features without connecting a wallet at all. If you'd like an off-chain record we hold (e.g. a find registration) removed from our database, email us and we'll act on it — with the caveat that we can't remove anything already committed on-chain, since no one can.

Children's privacy

Salvage is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

If this policy changes materially, we'll update the date at the top of this page. Continued use of Salvage after a change means you accept the updated policy.

Contact

Questions about this policy or your data: gethelp.salvage@gmail.com.

Salvage v0.1 · Ethereum + Base · Alchemy + Etherscan API V2
TermsPrivacyBuilt by Abu Olumi ↗