Privacy Policy
This is a template policy. Adapt it to the data you actually process and the law that applies to you (GDPR, CCPA, your local equivalent).
What we collect
- Account data — name, username, phone number, and optionally an email address and profile picture.
- Content — the statuses, comments and reactions you publish.
- Financial data — points ledger entries, payment records, and payout account details. Payout details are encrypted at rest.
- Security data — sign-in events, IP addresses, and browser user agent, retained in an append-only audit log.
What we do not store in the clear
Passwords are hashed with bcrypt. One-time verification codes are hashed and expire. Gateway credentials and payout destinations are encrypted with the application key. On high-volume tables (status views, ad impressions) IP addresses are stored only as a keyed hash, not as raw addresses.
Why we collect it
To operate your account, run the points economy, pay you out, prevent fraud, and meet our legal obligations.
Sharing
We share data with the payment, SMS and captcha providers configured by the operator, strictly to deliver those services. Advertising networks configured by the operator may set their own cookies — review their policies.
Your rights
You can view your security log at any time from your account settings, correct your profile data, and request export or deletion by contacting support. Some records (financial ledgers, audit logs) are retained where the law requires it.
Retention
Statuses expire automatically. Security logs are kept for at least 90 days. Financial records are kept as long as tax and accounting rules require.
Last updated Sep 23, 2026