Privacy Policy
Effective April 27, 2026
1. What we collect
From your Privy login we receive and store:
- X account: X user ID, username, display name, profile picture URL.
- Email: if you signed up with email.
- Solana wallet address: the public address linked to your Privy account. Used as your payout destination.
From your campaign activity we store:
- Tweet IDs, URLs, text snapshots, and engagement metrics (views, likes, retweets, replies, quotes, bookmarks) for posts you submit.
- On-chain transaction signatures for payouts you receive.
- Campaigns and projects you create.
2. Why we collect it
- To run the platform: verify ownership of submitted tweets, calculate earnings, send payouts.
- To prevent abuse: enforce campaign gates (followers, account age, holder requirements, verified-only).
- To communicate: if you provided email, send transactional notifications about campaigns and payouts.
3. Who we share with
- Privy — auth provider; processes login and custodies campaign treasury wallets. See privy.io/privacy.
- Supabase — Postgres + storage host.
- Solana RPC providers — for reading on-chain balances and broadcasting transactions. RPC requests include wallet addresses and transaction data, which are public on-chain.
- X (Twitter) API — for fetching tweet metadata and engagement metrics on submitted posts.
- Jupiter — for SPL token price lookups (mint address only, no user identity).
We do not sell your personal data. We do not share with advertisers.
4. Public vs. private data
Some data is public by design (tweet content, on-chain transactions). Some is private:
- Email: never shown to other users; visible only to you and platform operators.
- Wallet address: never shown to other users through the public API; visible only to you, the campaign owner you submitted to, and platform operators.
- X handle, display name, picture: shown publicly alongside your submissions and on leaderboards.
5. Cookies
We set a single first-party cookie (shillers-jwt) after login. It’s an HttpOnly Lax-SameSite cookie used to authenticate your requests to Shillers. We do not use third-party tracking or advertising cookies.
6. Retention
We retain account data while your account is active. Submission and payout records are retained indefinitely as part of the on-chain audit trail. You may request deletion of off-chain data (email, X handle, etc.); on-chain transaction history cannot be deleted.
7. Your rights
You can:
- Unlink your X account, wallet, or email at any time via Privy.
- Request a copy of personal data we hold about you.
- Request deletion of off-chain personal data (subject to retention obligations).
- Opt out of email communications.
Contact @shillers_net on X for any of the above.
8. Children
The Service is not intended for anyone under 18.
9. International transfers
Data is processed in the United States and the European Union. By using the Service you consent to that processing.
10. Changes
We’ll post material changes on our X account or by email (where applicable) before they take effect.
11. Contact
Questions: @shillers_net on X.