sniffy
← Sniffy extension

Privacy policy

For the browser extension Sniffy — Solana rug & clone scanner.

Effective 2026-09-28

The short version

  • Pages are read on your device, only to find Solana token addresses. Page content never leaves your browser.
  • When a scan runs, the only thing sent is that one token address.
  • No wallet connection, no keys, no seed phrases, no signing. Ever.
  • No analytics, no ads, no tracking, no selling or sharing of data.

01

What the extension reads on pages

On the supported sites (x.com, pump.fun, dexscreener.com, gmgn.ai, axiom.trade, photon-sol.tinyastro.io, birdeye.so, solscan.io, jup.ag) the extension reads the text and links of the page locally in your browser, only to find Solana token addresses and place a badge next to them.

Page content never leaves your browser. It is not stored, logged or sent anywhere. The extension does not run on any other site.

02

What is sent, and when

A scan request is made only when:

  • you hover or click a badge,
  • you paste an address in the popup, or
  • you open a token's page on a supported site (one automatic scan per page; you can turn auto-scan off in the extension's settings).

Each request sends only that one token or pool address to the Sniffy API at https://sniffyscanner.xyz (fallback: https://sniffy-six.vercel.app). No cookies, no identifiers, no browsing history and no page URLs are sent.

03

What our server sees

Like any web server, the Sniffy API sees your IP address. It is used only for the anti-abuse rate limit (a count of fresh scans per IP, which expires after 10 minutes) and appears in short-lived hosting logs (Vercel). We do not link it to anything else.

Scan results are cached on the server by token address, not by user. The result data itself comes from public sources (Solana RPC, DexScreener, GeckoTerminal, pump.fun) that our server queries.

04

What is stored on your device

The extension uses chrome.storage, which stays on your device. It holds:

  • your settings: enabled sites, badge density, auto-scan on or off;
  • a short cache of recent scan results (minutes), so the same coin is not scanned twice;
  • your recent scans history: the last 30 addresses, which you can clear in the popup;
  • where you dragged the verdict pill.

Removing the extension deletes all of it.

05

What the extension never does

  • No wallet connection, no private keys, no seed phrases, no transaction signing. Ever. Sniffy will never ask for them.
  • No analytics, no ads, no tracking, no fingerprinting.
  • No selling or sharing of data with anyone.
  • No remote code: all of the extension's code ships inside the package. The API returns data only.

06

Permissions, explained

storage

Saves your settings, a short cache of results and your recent scans on your device.

Supported sites

Host access to x.com, pump.fun, dexscreener.com, gmgn.ai, axiom.trade, photon-sol.tinyastro.io, birdeye.so, solscan.io, jup.ag, so the extension can find token addresses there and show badges.

sniffyscanner.xyz, sniffy-six.vercel.app

Host access to the Sniffy API, so the extension can request a scan.

07

About the scores

Verdicts are heuristic risk scores built from public data. They can be wrong, late or incomplete. They are not guarantees and not financial advice.

08

Changes and contact

If this policy changes, the new version is posted on this page with a new effective date.

Questions: reach us on X at @sniffyscanner.