ExplorerScan
- networks tracked- block explorersRequestStatus
Companion site:RPCScan ↗RPC endpoint directory with latency and uptime leaderboards and per-provider posture

ExplorerScan privacy policy

Effective 10 October 2026. Short, because there is not much to say.

The short version

  • We never log your IP address. Not in application logs, not in our database, not anywhere we can query.
  • Google Analytics runs on this domain. It is the one third party with a script on the page, it sets its own cookies, and Google receives your IP address. The section below says exactly what that means and how to stop it.
  • We set no tracking cookies ourselves. Our only cookie is a login session, and only if you sign in.
  • Nothing else is loaded from anyone else. No pixels, no hosted fonts, no embeds, no tag manager, no session recorder.
  • No account required to use any public part of the site.
  • Nothing is sold or shared. There is no advertising network and no data broker in this stack.

Why there is no IP address here

Most sites keep IP addresses by default, because the logging tools they install do it automatically and nobody turns it off. An IP is a durable identifier. Combined with the pages you looked at, it says a great deal about who you are and what you were researching.

On a site like this one it would say even more than usual. The RPC endpoints and block explorers you compare, and the chains you look up, map closely onto what you are building or what you hold. We decided that was a record worth not creating, so the field does not exist in our data model. You can see the decision in the source: the ticket record carries a comment reading “Intentionally no IP field”, and stores a two-letter country code instead.

The practical consequence is that if someone subpoenas us, or compromises us, there is no address list to hand over or steal. That is the point.

What we do store

Four things, all of them optional and all of them initiated by you.

WhatWhyRetention
Login session
A public key and a timestamp
Keeps you signed in. Your key is generated in your browser from a 12-word phrase. The private key and the phrase never leave your device, so we hold no password and nothing to reset.Until you sign out, or the session expires
Tickets
Subject, body, country, edge location, browser string, referring hostname
Lets us act on a correction and spot abuse. Country and edge location give the same operational signal as an IP without identifying anyone. The referring URL is cut down to its hostname so your search terms never reach us.Until resolved, then removed on request
Settings
Endpoint priority, posture floor, region
Only exists if you are signed in and changed a default. Keyed to your public key.Until you change or delete it
Donations
Transaction hash, amount, optional name and note
Shown on the public donations list. Everything here is already public on-chain. Tick anonymous and we store no name.Indefinite, as a public record

The explorer telemetry, specifically

We record one row per proxied call so we can tell which upstreams are healthy. That row holds the chain, the method name, the upstream hostname, the status and the latency. Where a signed-in user made the call it carries their public key; otherwise it literally carries the string anon.

It does not hold your IP, your request body, your wallet address, or any parameter you passed. We measure the endpoint, not the caller.

Who else sees your traffic

Being straight about the parts we do not control matters more than a clean-sounding claim.

  • Cloudflare serves every request and therefore sees your IP, the same as any site behind a CDN. They act as our processor and keep their own short-lived edge logs. We do not pull those logs into anything, and we have no IP-level reporting built on them.
  • Upstream operators. When you use the proxy at <chain>.rpcscan.xyz, we make the outbound call for you, so the upstream sees our address rather than yours. That is a privacy gain over calling them directly. They still see the call itself.
  • Sites you click through to. Outbound links to explorers, chain websites and GitHub are ordinary links, and once you follow one you are on their terms, not ours.
  • Google. Google Analytics loads on this domain, so Google receives your IP address, the pages you viewed and a cookie that recognises you on your next visit. We turned off Google Signals and ad personalisation, which keeps this out of advertising and cross-device profiles, but the pageview data itself is Google’s to hold under their terms. RPCScan does not load it.

That list is the whole of it. Beyond Google Analytics there is no error-reporting service, no session recorder, no tag manager, no hosted font and no social embed anywhere on this site.

Cookies

Ours is one cookie, named rpcscan_session, set only after you sign in. It is HttpOnly, Secure and SameSite=Lax, it holds a signed reference to your public key, and it is used for nothing but keeping you logged in.

Google Analytics sets its own on top of that, the _ga pair, which is how it tells a returning visitor from a new one. Blocking it changes nothing about how the site works: any content blocker, Firefox strict mode, Safari with cross-site tracking prevention, or a browser sending Global Privacy Control will stop it loading, and every page here still renders and functions exactly the same.

Your choices

You can use everything public here without identifying yourself, so for most visitors there is no record to exercise rights over. If you have signed in or filed a ticket, write to contact@explorerscan.com and we will tell you what is held against your key and delete it. No form, no identity check beyond proving you hold the key.

ExplorerScan and RPCScan are one service run by one person. A policy change will be reflected by the effective date above, and anything that materially widens what we collect will be called out on the announcements page rather than quietly edited in.

Contact

Stephen Molnar, Las Vegas, NV. contact@explorerscan.com. Privacy questions and complaints go to the same address as everything else and are answered by the person who wrote the code.