Privacy Policy

Last updated: September 11, 2026

Who we are

PublicAML is a free crypto AML/KYT screening service at publicaml.org, together with the PublicAML Intelligence API (intelapi.publicaml.org), the PublicAML app for ChatGPT and other MCP clients (mcp.publicaml.org), and the PublicAML Telegram bot. This policy covers all of them. Contact: [email protected].

What we collect

Addresses and transaction hashes you submit. When you screen a wallet, trace funds or check a transaction — on the website, through the API, in the Telegram bot or through the ChatGPT/MCP app — we receive the blockchain address or transaction hash, the chain, and any options you set (for example the number of hops to follow). These are public blockchain identifiers. We do not ask for, and you should not enter, names, government IDs, payment card details, passwords or private keys.

Account data, only if you sign in. Checks do not require an account. If you create one, we store your email address, your login session, and the checks and case reports tied to your account.

Reports you file. If you report a scam or theft, we store what you put in the report: the addresses involved, the category, your description, and whether you chose to make it public.

Technical data. Like any web service we process IP addresses and request metadata (time, endpoint, response code, duration) to deliver responses, enforce the anonymous rate limit and investigate errors. API keys are identified by a short hint, never stored in plain text in logs.

Website analytics and local storage. The website uses Google Tag Manager / Google Analytics to measure page visits, and stores a few values in your browser (login session, language and theme preferences). The API, the MCP app and the Telegram bot do not use analytics cookies.

The ChatGPT and MCP app

The app exposes read-only tools: screen_address, trace_funds, trace_source_of_funds, list_counterparties, list_transactions, screen_transaction and follow_swap. Each tool receives only the address or transaction hash, the chain and the tool's own options. It does not receive your chat history, your name, your email or your ChatGPT account details, and it never moves funds or changes anything on-chain.

Tool results contain public blockchain data and our analysis of it: AML score and risk level, category and labels, sanctions and incident exposure, counterparties, transfers, and where funds came from or went. The MCP server itself keeps no record of the addresses you look up; requests are passed to the PublicAML Intelligence API, which records usage as aggregate counters (calls per endpoint, errors, response time) rather than per-address logs.

How we use data

  • To return the screening, tracing and transaction results you asked for.
  • To run your account, show your check history and publish reports you mark public.
  • To keep the service up: rate limiting, abuse prevention and error diagnosis.
  • To understand aggregate usage and improve coverage. We do not build profiles of the people who run checks.

We do not sell personal data and we do not use it for advertising.

Who receives it

  • Our infrastructure providers — hosting and Cloudflare (network delivery and protection) — which process requests on our behalf.
  • Google, for website analytics, and for sign-in if you choose Google login.
  • Error monitoring, which receives technical details of failed requests.
  • OpenAI, when you use the ChatGPT app: your conversation is handled by OpenAI under its own privacy policy; we receive only the tool inputs described above.
  • The public, only for reports you explicitly publish, and for risk labels on blockchain addresses (not on people).
  • Authorities, where the law requires it.

How long we keep it

  • Addresses looked up anonymously or via the ChatGPT/MCP app: not stored against you; only aggregate usage counters are kept.
  • Request logs and error traces: up to 30 days.
  • Account data and check history: until you delete your account.
  • Published reports and address risk labels: kept while they are relevant to screening; you can ask us to withdraw a report you filed.

Your choices and rights

  • Use every screening feature without an account.
  • Ask for a copy of your account data, or for it to be corrected or deleted, by writing to [email protected].
  • Withdraw a report you filed, or dispute a label on an address you control, at the same address.
  • Block analytics with your browser settings or an ad blocker; the service keeps working.
  • Disconnect the PublicAML app in ChatGPT at any time from ChatGPT's settings.

We answer requests within 30 days.

Changes

When this policy changes we update the date at the top of this page. Material changes to what the ChatGPT/MCP app collects will be reflected here before they ship.

← Back to home