Privacy Policy — View on CMC
Last updated: 23 September 2026.
Summary
The extension reads the page you are on to find blockchain addresses, and asks CoinMarketCap whether each one is a listed token. An address is the only thing that leaves your browser. The page you are on, its URL, its title and the rest of its contents are never transmitted, and no profile of you is built or stored anywhere.
Please read the note below on wallet addresses: the extension cannot tell a token contract from a wallet before it asks.
What is sent, and where
When a blockchain address becomes visible on a page, the extension sends that address, and a guess at which blockchain it belongs to, to CoinMarketCap. It asks three things:
- Is this a token CoinMarketCap lists, and on which blockchains?
- What is its price, liquidity, trading volume and market value?
- What is known about the contract — any risk warnings, and any buy or sell tax?
The description is requested in your browser's language, so that language is included in the request alongside the address.
That address is the whole of it. Nothing else about you, and nothing else about the page, is included. The extension sends data to CoinMarketCap and to no other company.
There is one other request. When the hover card shows a token's logo, your browser loads that picture from CoinMarketCap's image server. It is sent without a referrer, so it does not reveal which page you were reading.
Requests carry no cookies, so they cannot be connected to a CoinMarketCap account — even if you are signed in to CoinMarketCap in the same browser. As with visiting any website, CoinMarketCap's servers do see the IP address the request came from.
The extension only looks up addresses tied to something actually on screen, and no more than 80 on any one page.
One case deserves spelling out. Many sites print a shortened address such as 0xc6e...7a7d54. To turn that into something useful, the extension looks for the full value elsewhere in the page — a copy button, a link, or data the site embedded for its own use but never displays. So while the shortened form is always something you can see, the full address that gets sent may have been read from part of the page that is not shown on screen. The extension only does this to expand a shortened address you are looking at; it does not harvest addresses from hidden page data on its own. Results are cached, so revisiting a token does not repeat the request.
Wallet addresses
A token contract address and a personal wallet address are the same shape, and there is no way to tell them apart without asking — which is exactly what the lookup does. So if a wallet address is visible on a page you are reading, it may be sent to CoinMarketCap too, and CoinMarketCap will answer that it is not a listed token. The clearest example: if you view your own address on a block explorer, your address is on that page and may be looked up.
What this means in practice:
- The request carries the address and nothing else — no cookies, no account, no identifier. As with any web request, the server sees your IP address.
- Addresses that are not listed tokens are cached as "not a token" and are not looked up again.
- Nothing links an address to you, and no history of looked-up addresses is stored anywhere by the extension.
- If you would rather this never happened on a particular site — your portfolio tracker or a block explorer, say — exclude it with
Alt+Shift+Cor from the toolbar popup, and no addresses from that site are ever read or sent.
What is never sent
- The URL, domain or title of any page you visit
- Page content, other than a contract address itself
- Your browsing history
- Any account, name, email address or device identifier
- Anything at all from a page where detection is switched off
What is stored, and where
Your preferences fall into two groups, stored differently on purpose.
Kept on this device only — never synced: your list of excluded sites. That list says which sites you consider sensitive enough to hide from an extension, which is a statement about your own browsing, so it stays on the machine you set it on. It does not travel to your other devices, and it is not handed to your browser account.
Synced across your devices: the harmless interface preferences — which chains to detect, whether to show the pill, and so on. If you are signed in to your browser these follow you around, the same way your bookmarks do.
Neither group is ever sent to CoinMarketCap or to us, and both are deleted when you uninstall the extension.
Nothing else is persisted. There is no local database of what you have viewed.
Analytics and tracking
The extension contains no analytics, telemetry, tracking pixels, session recording or third-party SDKs of any kind. Nothing is loaded from a remote server at runtime; all code ships inside the extension package.
When you deliberately click through to CoinMarketCap, the link carries UTM parameters (utm_source=cmc-extension and similar) identifying the extension as the referrer. This is standard web referral attribution: it tells CoinMarketCap that a visit came from the extension and which control was clicked. It contains no identifier for you, and it only happens when you choose to click.
Third-party links
Links in the hover card to block explorers, project websites and X are shown for your convenience. Following one is an ordinary web navigation, and those sites' own privacy policies then apply. The extension does not contact them in the background — nothing is fetched from them unless you click.
Sites the extension does not touch
- CoinMarketCap's own site is never scanned. That is built into the extension, not a setting that could be switched on by accident
- Webmail, documents and design tools are excluded out of the box: Gmail, Google Docs, Slack and Figma
- Anywhere you are typing is skipped — form fields, comment boxes and text editors are left alone
- You can exclude any site from the toolbar popup, or with
Alt+Shift+C, and turn the extension off entirely from Settings
Permissions, and why each is needed
| What it can do | Why it needs to |
|---|---|
| Read the text of pages you visit, on any site | A contract address can turn up anywhere — a social post, a forum thread, a news article, an explorer. The extension cannot know in advance which sites those will be, so a fixed list would defeat the feature. It reads text only, looking for the two address patterns. The one thing it adds to a page is its own small marker beside an address it recognised. |
| Save settings | To remember your preferences and your excluded sites |
| Add one right-click menu item | The "View token on CoinMarketCap" option when you select text |
The extension requests no access to cookies, browsing history, downloads, bookmarks, the clipboard beyond an explicit copy you initiate, or any other browser data.
Data sharing and sale
No data is sold, rented or shared with third parties. No data is used for advertising, profiling or credit assessment. Contract addresses are sent to CoinMarketCap solely to answer "is this a token, and what is it".
Changes
Material changes to this policy will be accompanied by a version bump and noted in the repository history.
Contact
Raise an issue in the repository, or contact the maintainer listed in the Chrome Web Store listing.