Security model

Read-only by design.

What Shingan never does

What it does

You give Shingan public addresses only. It reads on-chain activity, scores risk, and alerts you on Telegram. Revoking is a call you sign — Shingan only builds approve(spender, 0) (or Permit2.approve(…, 0, 0) for Permit2 allowances) and hands you the link.

Data

Shingan stores your Telegram ID, the public addresses you connect, and the events and approvals it observes. No KYC. No email required. The web analytics are first-party and cookie-less — IPs are hashed, never stored raw.

Account security

Alerts and your account live in Telegram. If you lose access to Telegram, contact support — we can help you re-register, but we cannot recover a Telegram account for you.

Honest limits

Monitoring is best-effort and can be delayed or incomplete, and it depends on external providers. Shingan is a security aid, not a guarantee. Read the Risk Disclosure and Security pages.