Luminos (luminos.capital) is operated under the trading name Luminos Capital. Luminos Capital is a trading name, not a registered company, corporation, GmbH, Sàrl, Ltd, or other incorporated legal entity. The operator is based in Switzerland, and Swiss law governs the service — see "Governing law" in our Terms of Service.
For the operator's and contributors' safety, we do not publish the personal name or physical address of the individual(s) behind Luminos: this site publishes adverse, automated findings about specific token teams' distribution patterns, and doing so carries a real personal safety and doxxing risk for the people who build and run it. [email protected] is the accountable contact point for every privacy, legal, and appeals matter — it is how the operator stands behind this service and can be reached, not a way to avoid being reached.
We do not run accounts or logins for the public scanner — there is no signup, no profile, and no username tied to your activity. The data below is everything the app itself collects.
Every scan is recorded in an audit log (scan_audit.log)
that stores ip_hash — a truncated (64-bit) SHA-256 hash of
the visitor's IP address — for rate-limiting and abuse prevention. We
treat this as personal data, not anonymous data: a hash of an IP
is pseudonymous, and because the IPv4 address space is finite, a
truncated hash like this can in principle be matched back to a real IP
by brute force. The app itself never stores your raw IP address.
The site runs behind Cloudflare, which fronts our servers as a content delivery network and tunnel. Cloudflare processes — and likely logs at its network edge — your real IP address and standard connection metadata as part of routing, securing, and delivering the site. Cloudflare acts as a data processor on our behalf for this infrastructure layer; see Cloudflare's own privacy policy for how it handles that data.
We set two cookies of our own, and Google Analytics sets its own once you have accepted the notice on your first visit. None of them is an advertising cookie.
luminos_session — HttpOnly, Secure, SameSite=Strict,
expires after 48 hours. Holds a signed JWT used purely to authenticate
your session (functional/auth cookie).luminos_terms_ok — set by client-side JavaScript,
SameSite=Lax, expires after 1 year. Its value is the version of this
Privacy Policy and our Terms of Service you accepted, so a future
material change (a new version) automatically shows you the notice
again instead of silently reusing an old acceptance._ga and _ga_<property> — set by
Google Analytics, SameSite=Lax, Secure, and only after you accept.
They hold a random number that lets Google tell a returning browser
from a new one, so a person who visits twice is counted once. They
carry no name, no email, and nothing you searched for. Clearing your
cookies clears them, and they are never set at all if you do not
accept or if your browser sends a Do Not Track signal (see below).When you accept the disclaimer shown on your first visit (or after we
materially update these documents), your browser both sets the
luminos_terms_ok cookie above and sends us a small,
permanent, append-only server-side record of that acceptance: a UTC
timestamp, the document version you accepted, the same truncated,
one-way hashed IP address described above (never a raw IP), and your
browser's user-agent string. We treat this the same way we treat the
hashed-IP audit log — as personal data, not anonymous data. Its purpose
is narrow and specific: a site that publishes automated risk findings
about named projects needs to be able to demonstrate that a given
visitor was actually shown, and accepted, a specific version of these
documents before using it. This record is never used for advertising,
analytics, or any purpose beyond that.
We run lightweight, first-party analytics to understand site usage — page views per day, scan counts, cache-hit rate, and which tokens are popular. This is computed entirely on our own server, from data already described on this page (the hashed IP used for the security log above, and the scan/token history below): it sets no additional cookies, makes no third-party requests, and never stores your raw IP address. Only bounded, aggregate counters are kept — not a row per visit or per request — and they're pruned after 90 days. This data is visible only to the operator, through an admin-only dashboard, and is never shared, sold, or used for advertising.
We also use Google Analytics 4 to see how many people use the site, which pages they open, roughly where in the world they are, and whether they arrived from a search engine, a link, or typed the address in. It runs only when we have it switched on; when it is off, no Google code is loaded at all. Here is exactly how we run it:
/analysis/:token, every chart
page as /ta/:token, and everything after the "?" in a
web address is thrown away except the name of the tab you are on. So
we learn how many analyses were viewed; Google does not learn which
coins you personally looked at. The same replacement is applied to
the page you came from, so moving between scans does not leak them
either.What Google itself receives, as with any site that uses it, is your IP address (used for coarse location and then discarded — GA4 does not store IP addresses), your browser and device type, the page names described above, and the random cookie identifier. Google acts as our processor for this and is a US company; that means an international transfer of data, made under the European Commission's standard contractual clauses and the EU–US / Swiss–US Data Privacy Framework. You can opt out at any time — see "Your rights" below.
Beyond analytics, every page load makes a small number of direct requests to these providers, each of which can see your IP address and standard request metadata (like user-agent) as an inherent side effect of your browser fetching content from their servers:
fonts.googleapis.com,
fonts.gstatic.com) — loads the site's webfont files.challenges.cloudflare.com) —
a bot-check / abuse-prevention widget.We keep a record of scanned tokens — the token address, the
classification, and the score — in scan_history.db /
scan_log.db. This data describes tokens, not people: it
carries no user-identifying information and is not linked to any
visitor identity, because there is no account system to link it to.
If you submit the appeal form, we store what you submit — the token address, your written argument, your contact email, and any evidence links you include — plus a hashed IP address (same one-way hash described above) and a timestamp. This is personal data (most directly, your email address), collected because you gave it to us for a specific purpose: contesting a classification and letting us follow up with you about it. We keep this record permanently as our good-faith log of every contest received; we do not sell it, use it for marketing, or share it beyond the operator and, if engaged, legal counsel reviewing the appeal. An appeal record's status (reviewed / actioned) can be updated by the operator; the submission you wrote is never edited.
scan_audit.log) rotates
automatically once it reaches 10 MB, keeping up to 3 rotated backups
(roughly 40 MB total) before the oldest entries are permanently
deleted — a data-volume-bounded rolling window, not a fixed number of
days.The operator is based in Switzerland, not the EU or UK. The primary law governing our processing of personal data is Switzerland's revised Federal Act on Data Protection (revFADP), in force since 1 September 2023. The EU General Data Protection Regulation (GDPR) can also apply to us, extraterritorially, to the extent we offer the service to — and process personal data about — people located in the EU/EEA (GDPR Art. 3(2)); that does not make the operator an EU-established controller. Where the two frameworks differ, we apply whichever gives you the more protective outcome. Under GDPR Article 6 (to the extent it applies to you) and the equivalent purpose-limitation and proportionality principles under the revFADP, we rely on:
None of this processing is used for advertising, profiling, or automated decision-making about individuals.
Because we don't operate accounts, most of these rights concern the hashed-IP audit log and the consent record described above. Subject to applicable law — the revFADP as a matter of Swiss law, and GDPR to the extent it applies to you as an EU/EEA-located visitor — you have the right to:
To exercise any of these rights, contact us at [email protected].
Cloudflare operates a global network, so connection and request metadata may be processed outside Switzerland (and, for EU/EEA visitors, outside the EU/EEA) as part of its routing and security infrastructure. The European Commission recognizes Switzerland as providing an adequate level of data protection, which facilitates transfers between Switzerland and the EU/EEA in both directions. Where data is transferred to a country not recognized as adequate (by the European Commission or on the Swiss FDPIC's own list), we rely on our processors' standard safeguards for that transfer — for example, Cloudflare's Data Processing Addendum, which incorporates the EU Standard Contractual Clauses. The same applies to Google Analytics: Google is a US company, and its Data Processing Terms incorporate the EU Standard Contractual Clauses alongside its certification under the EU–US and Swiss–US Data Privacy Frameworks.
Connections are served over HTTPS via Cloudflare. Our cookies are HttpOnly and Secure where applicable, and we store a hash rather than a raw IP address in our own audit log and consent record. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Luminos is not directed at children, and we do not knowingly collect data from children.
We may update this policy as the app or its data handling changes. Material changes are reflected by updating this page and its version identifier above; a version change also means the disclaimer gate will show and record acceptance again on your next visit.