Privacy Policy
Last updated: May 12, 2026
BlockApps Inc. (“BlockApps,” “we,” “us”) operates STRATOSCAN (the “Service”), a block explorer for the STRATO blockchain network. This Privacy Policy explains what information we collect when you use the Service and how we use it.
1. Information you provide
Account credentials
If you choose to sign in to interact with smart contracts, we authenticate you through Keycloak (operated by BlockApps). We receive your username and an access token; we do not see or store your password. Access tokens are kept in your browser’s local storage and are sent to our servers only when you submit a contract write request, at which point we forward them to the STRATO node to sign the transaction.
User-supplied content
Tags you attach to addresses and items you pin for quick access are stored exclusively in your browser’s local storage. They are not transmitted to our servers and are not visible to other users.
2. Information collected automatically
Server logs
Each request to the Service generates a log entry that may include your IP address, the time of the request, the URL you accessed, your user agent, and any HTTP errors that occurred. We retain logs for a limited period for security, abuse-prevention, and debugging purposes.
Rate limiting
We apply per-IP rate limits to protect the Service and the underlying STRATO node. Limits and counters are held in memory only.
Cookies and similar technologies
STRATOSCAN itself sets a small number of cookies and local storage items required for the Service to function (e.g. theme preference, session token after login). For more detail see our Cookie Policy.
Analytics
We use third-party analytics (currently Lucky Orange) to understand how visitors interact with the Service. These tools may collect IP addresses, browser type, device information, and a session recording of mouse movements, clicks, and page scrolls. We do not link this data to STRATO blockchain addresses unless you explicitly sign in.
3. Public blockchain data
The STRATO blockchain is itself a public ledger. Block, transaction, and address data displayed by the Service is derived from on-chain state and is not personal data we collect from you — it’s information you and other users have published to the chain. BlockApps cannot delete or modify on-chain data.
4. How we use information
- To operate, secure, and improve the Service
- To authenticate users who choose to sign in for contract writes
- To diagnose errors and respond to abuse or security incidents
- To comply with legal obligations
5. How we share information
We share information only with:
- Service providers acting on our behalf (analytics, infrastructure hosting, error monitoring) under contractual confidentiality obligations.
- The operator of the STRATO node we connect to — when you submit a contract write, your bearer token and transaction payload are forwarded so the node can sign and broadcast the transaction.
- Law enforcement or regulators when required by valid legal process.
We do not sell personal information.
6. Your choices
- You can use the Service without signing in to view public chain data.
- You can clear your browser’s local storage at any time to remove tags, pins, recent items, and your access token.
- You can configure your browser to block cookies, accepting that some functionality may not work.
7. Security
We use industry-standard measures (HTTPS, JWT signature verification, in-memory rate limiting, security headers including CSP and HSTS) to protect the Service. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
8. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children.
9. Changes to this Policy
We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date at the top of this page.
10. Contact
Questions about this Policy can be sent to [email protected].