What we collect, and what we don’t.
Plain terms, no filler. If something here is unclear, email us and we’ll clarify it — and fix the page.
Who operates this site
MSR Decode is operated by Main Street Research LLC. This policy covers msrdecode.com and every page on it, including the wallet checker and the commissioned-investigation inquiry form on Capabilities.
What we collect
When you submit a form on this site, we collect only what that specific form asks for:
- The historical wallet checker. The wallet address or handle you submit. If it matches the published July 2026 cohort, the tool replays that published result and no email is collected. If it does not match, the tool says the wallet is outside the cohort and collects nothing — new-wallet submissions are not accepted through it, and it does not queue a reconstruction.
- The commissioned-investigation inquiry form. Your work email; optionally your name or organization, an inquiry type (journalist, forensic investigation, market-integrity review, ongoing research, or other), a free-text description of what you’re trying to establish (which may include a wallet, market, transaction or source you name), and an optional deadline. These fields are combined into one note attached to your email.
- Your browser’s user-agent string and the page you submitted from (referer), on every form submission — standard request metadata, kept for abuse prevention and debugging.
We do not ask for or collect passwords, payment details, or government identifiers anywhere on this site.
Where it’s stored
Form submissions are stored in MSR’s hosted database environment with access controls designed to prevent unauthenticated retrieval or modification. The wallet checker replays the published July 2026 cohort directly from a static file for wallets on file; a wallet outside that cohort is not classified, and no address or email from that attempt is stored.
What it’s used for, and who else sees it
Only to respond to the request you made: replying to a commissioned-investigation inquiry. We do not use your email for anything you did not ask for. MSR Decode does not sell personal information or share it for advertising. Limited information may be processed by service providers used to operate the website, database, forms, hosting and analytics, subject to their role in providing those services — currently Supabase (form and job storage) and, where a submission also triggers a best-effort email copy, Resend (email delivery).
Retention
Information is retained only as long as reasonably necessary to respond to the request, maintain relevant research or business records, prevent abuse, satisfy legal obligations, or resolve disputes. We do not currently operate a fixed automatic-deletion schedule; the deletion-request process below is the fastest way to have your own submission removed sooner.
Analytics
We use Vercel Web Analytics, a first-party analytics service, for aggregate site-usage information such as page visits and referrers. We do not run advertising pixels or third-party behavioural-advertising analytics on this site. Vercel may process technical request information as part of operating its hosting and analytics services; how it does so is governed by Vercel’s own terms and privacy documentation rather than by this page.
Deletion requests
To have your email and any associated submission deleted, contact ceo@msrdecode.com. We will confirm deletion by email.
Changes to this policy
Corrections and changes. If this policy changes in a way that affects how existing data is used, we will update this page and note the change. See Terms of Use for how we handle corrections to published claims generally.
This policy describes current practice for this website; it is not a certified security or compliance framework. The channels on this site — the wallet checker and the institutional inquiry form — are intended for initial contact and public-record research only. Do not submit privileged, legally restricted or materially confidential information through them. Where an engagement is accepted, how any client-provided information may be handled is defined in that engagement’s written terms, not by this page.