Local graphics processing
When you start a GPU search, Vanito checks WebGPU and adapter availability locally. Only public curve points are sent to GPU buffers; private scalars remain in browser memory on the CPU side. Hardware information, mode selection and measured speed are not sent to the server.
Who operates the service
The service is operated under the public name Vanito, an independent development activity based in Brussels, Belgium. For privacy requests, contact contact@vanito.org. Hosting information supplied by the operator: United Internet, Elgendorfer Str. 57, 56410 Montabaur, Germany.
Keys and searches stay on your device
Private keys, generated addresses, public keys, redeem scripts, search patterns and selected thread counts are processed in your browser. Vanito does not send these values to the server, put them in URLs, or write them to cookies, local storage or IndexedDB.
A result remains in page memory until it is cleared or the page is left. Keys are hidden until you choose to reveal them, and hidden again when the page loses focus. JavaScript memory management prevents a guarantee that every memory copy has been erased.
Copying a key uses your device clipboard after your explicit action. Your operating system, clipboard manager, extensions or other applications may retain it. Those functions are outside this website’s control.
The aggregate generation counter
After a result has passed local verification, the browser sends a same-origin report containing only a server-issued temporary token. It does not send the result, selected network, pattern or performance measurements. The counter records one total and a temporary registry used to prevent replay of the same report.
Tokens are random, expire after 24 hours and are not stored in a browser cookie. They are not linked by the application to an IP address, account or generated key. Expired replay records are removed on the next access to the counter. The anonymous aggregate is retained while the service uses the counter. Reporting failures do not prevent local generation.
This counter is used to provide an approximate service total, not to profile visitors, track them across websites or measure their finances. The server necessarily receives ordinary connection information when a report is delivered.
Technical connection data
The web server and hosting provider necessarily process an IP address and technical request information to deliver and protect the site. Depending on the hosting configuration, access and security logs may include request time, URL, response status and browser user-agent. A selected interface language can appear in the URL. No search pattern or key is added to a request URL.
Vanito includes no advertising, third-party analytics, remote fonts, embedded social widgets or externally hosted cryptographic scripts. It reads the browser-reported logical thread count locally to configure the search. It does not attempt to bypass browser privacy protections or build a device fingerprint.
Messages you choose to send
If you email us, we receive your address, the contents of the message and any information you include. We use these to handle the enquiry and, where relevant, a security report or rights request. Do not send private keys, seed phrases or unnecessary sensitive information.
The website has no registration form, customer profile, payment form or newsletter subscription.
Purposes and legal bases
Processing needed to deliver a requested service can rely on performance of that service under Article 6(1)(b) GDPR where applicable. Limited security, abuse prevention and handling of general enquiries rely on legitimate interests under Article 6(1)(f), balanced against your rights. Processing needed to meet a legal duty relies on Article 6(1)(c).
The final anonymous counter total is not intended to identify a person. Any personal data processed through its transport or temporary safeguards is limited to operating and protecting this feature. We do not use these activities as permission for advertising or unrelated tracking.
Retention
Keys and search inputs exist only in the active page memory. Counter tokens last at most 24 hours, and expired server records are pruned when the counter is next accessed. The aggregate has no visitor-by-visitor history.
Technical logs are retained only for the time reasonably needed to operate the hosting service, detect and investigate incidents and meet applicable legal obligations. The actual hosting log schedule is controlled by the hosting arrangement, not by this website’s source code; contact us for the current applicable schedule.
Correspondence is retained as needed to resolve the enquiry, demonstrate the response to a rights request or handle a documented dispute or legal retention duty. Data no longer needed for those purposes should be deleted.
Recipients and international processing
Access to personal data is limited to the operator and providers needed for hosting or correspondence, subject to their roles and applicable obligations. Information may be disclosed where required by law or to protect legitimate rights through lawful procedures. We do not sell visitor data.
The stated hosting provider has a German address. That address alone does not establish the location of every server, backup or subprocessor. The applicable hosting and email arrangements determine those locations. Where an arrangement requires a transfer outside the EEA, the applicable lawful transfer mechanism and safeguards must be in place; you may request information about the relevant providers and safeguards.
Your rights
Where GDPR applies, you can request access, rectification, erasure, restriction and, where applicable, portability of your personal data. You can object to processing based on legitimate interests. If a separate activity relies on consent, you may withdraw it without affecting earlier lawful processing. Send requests to contact@vanito.org.
We may request only information reasonably needed to verify and handle a request. We normally respond within one month; a lawful extension may apply to complex or numerous requests and will be explained. We cannot retrieve a private key never received, or identify your contribution in a total that no longer contains a link to you.
You may complain to the Belgian Data Protection Authority or another competent supervisory authority, including in your habitual residence. There is no automated decision-making producing legal or similarly significant effects, and no profiling by the application.
Security, children and changes
Access restrictions, HTTPS when deployed correctly, restrictive browser policies, local result verification and limited data collection reduce risk. No internet service or device can be guaranteed immune to compromise. Report concerns without disclosing wallet secrets.
Vanito is not directed at children under 16 and does not knowingly build profiles of children. If you believe personal data relating to a child has been sent to us, contact us.
This policy describes the supplied application and the operator information given above. Hosting features added later must be assessed and disclosed. Material changes to these practices will be reflected in an updated policy before any processing that requires new consent begins.
Brussels, Belgium
contact@vanito.org