Gemba Tools ← Back to app

Privacy Policy

Last updated: 28 June 2026

In short: Gemba Tools is privacy-first and non-custodial. We use no cookies, no tracking and no analytics, and the app collects no personal data. We never see your private keys. The only personal data we ever process is what you voluntarily type into the contact form, and we use it only to reply to you.

1. Data controller

GEMBA EOOD (EIK 208656371), Varna, Bulgaria, operates gembatools.io. Contact: [email protected].

2. No cookies, no tracking, no analytics

Gemba Tools sets no cookies and uses no advertising, analytics or cross-site tracking of any kind. We do not build profiles of you and we do not sell or share any data.

3. Non-custodial — we never see your keys

You connect your own Web3 wallet and sign every transaction yourself. We never receive, store or have access to your private keys or seed phrase, and we take no custody of your funds. Your wallet address and your on-chain activity are public on the blockchain by nature — that is inherent to public blockchains and is not something we collect or control.

4. Local storage in your browser

For your convenience the app may store small, non-personal data in your browser’s local storage — such as your interface preferences and a cache of the token/contract addresses you have deployed or viewed. This data stays on your device, is never transmitted to us, and you can clear it at any time from your browser. It is not a cookie and is not used for tracking.

5. The contact form (the only data we collect)

If you choose to use the contact form, you provide your name, email address and message. We process this only to read and reply to your inquiry. To stop spam and abuse, the form uses Cloudflare Turnstile (a privacy-friendly, no-tracking anti-bot check) and is rate-limited by IP. We do not use your contact details for marketing and we do not sell or share them.

6. Hosting & security (Cloudflare)

The site is served behind Cloudflare for security and delivery. Like any web host, Cloudflare automatically processes technical request data (such as your IP address) to protect the site against attacks and abuse. This is processed under Cloudflare’s own policies for security purposes only.

7. On-chain data is public & immutable

Any contract you deploy and any transaction you sign is recorded on a public blockchain. Such data is public, permanent and outside our control — it cannot be edited or deleted by us or anyone.

8. Legal basis (GDPR)

Where we process the contact-form data, our legal basis is your consent and our legitimate interest in answering inquiries and keeping the service secure (Art. 6(1)(a) and (f) GDPR).

9. Retention

Contact-form emails are kept only as long as needed to handle your inquiry and any follow-up, then deleted. Security logs are kept for a short period for protection purposes.

10. Your rights

Under the GDPR you may request access to, correction of, or deletion of the personal data we hold about you (which, in practice, is limited to any contact-form correspondence), and you may object to processing or lodge a complaint with a supervisory authority. To exercise your rights, email [email protected].

11. Changes

We may update this Policy; the “Last updated” date will change. Continued use after an update means you accept the revised Policy.

12. Contact

Questions about privacy? Email [email protected].