Legal
Privacy Policy
What Burnie Arena collects, why we are allowed to hold it, where it goes, and which parts of it are public. This policy applies only to people who choose to connect an X account. If you have not connected one, we hold nothing about you.
Last updated
1. Who operates this service
Burnie Arena is operated by TODO_OPERATOR: legal entity name (we, us). The service tracks public engagement on X posts about the $BURNIE token and distributes a weekly USDC reward pool. It is not affiliated with, endorsed by, or sponsored by X Corp.
Questions about this policy, requests for a copy of your data, and deletion requests go to TODO_OPERATOR: contact email.
2. What we collect
From your X account, once you connect it
You connect through X’s own OAuth 2.0 consent screen. We request the scopes tweet.read, users.read and offline.access, and we store:
- your X user ID, which is the identity key for your record — changing your handle does not create a second one
- your handle
- your follower count
- the date your X account was created
- the OAuth access and refresh tokens X issues to us, encrypted at rest
We hold no write access of any kind. The service never posts, likes, reposts, replies, follows, or sends messages as you.
About your own posts that reference the project
Discovery is a search restricted to posts authored by connected participants that contain the $BURNIE cashtag, a mention of the official project handle, or the contract address. For each matching post we store:
- the X post ID and the time the post was created
- the post text, used to decide whether the post qualifies and to detect near-identical content posted in coordination across accounts
- derived flags — whether the post contains the cashtag, the project mention, the contract address, an image, or a video
- public engagement counts: impressions, likes, replies, reposts, quotes and bookmarks. These are written as append-only snapshots, each stamped with the time of capture and with whether the numbers came from the organic metrics your own authorization unlocks or from the post’s public metrics.
We do not read your timeline, your followers, your likes, your bookmarks, or your direct messages. Posts that do not match the filter above are never fetched, and the accounts of people who have not connected are never read at all.
From your Solana wallet
- the wallet address you prove ownership of by signing a one-time message. There is no transaction and no fee, and we never ask for, receive, or store a private key or seed phrase.
- one balance snapshot per UTC day: your $BURNIE token balance, the USD price used to value it, the resulting USD value, and whether that met the holding minimum for that day
Records we generate about your participation
- per-post scores, weekly epoch points, all-time points, rank, share of the pool, and the USDC payout amount
- streak counts, quest progress, your referral code, and referral links
- anti-abuse flags raised against your account or a post, with the reason and the review outcome
- an audit log entry for every operator action taken on your record
From your browser
Two strictly functional cookies: burnie_session, which keeps you signed in, and burnie_oauth, a short-lived one-time cookie that secures the X sign-in handshake. Both are HttpOnly and SameSite=Lax. There are no advertising cookies, no analytics cookies, and no third-party trackers on this site. Our hosting provider records ordinary server request data — IP address, user agent, timestamps — as part of serving the pages.
3. Why we are allowed to hold it
Everything above exists because you chose to connect. You grant the X read access yourself on X’s consent screen, and you prove the wallet is yours by signing a message with it. Both actions are deliberate, both are described before you take them, and both are reversible — see section 7.
Nothing is collected about people who have not connected. We build no shadow profiles, and non-participants’ posts fall outside the search filter entirely.
4. What we do with it
- compute a contribution score from the engagement your own posts earn
- publish a public leaderboard ranking connected participants by that score, and show each participant their own detailed statistics on their dashboard
- check eligibility — account age, follower count, and the daily token holding snapshot
- run anti-abuse checks and route anomalies to a human review queue rather than an automatic penalty
- produce a payout list, which an operator executes manually as USDC transfers
That is the complete list. Your data is not sold, licensed, rented, or shared with any third party. It is not used for advertising or ad targeting, and it is not used to train machine-learning models.
5. What is public
The leaderboard is public. Anyone can open it without signing in and see, for every ranked participant: X handle, tier badge, rank, points, share of the weekly pool as a percentage, and the USDC payout amount. If you do not want your handle and your payout shown publicly, do not connect an account.
- Your wallet address is not shown on the leaderboard. It is visible to operators and appears in the payout export, which is restricted to admin wallets.
- Per-post metrics and score breakdowns appear only on your own dashboard. The public board shows totals.
- Payouts are Solana transactions. Once sent they are permanently public on the blockchain, and neither we nor anyone else can remove them.
- We link to your posts on X rather than reproducing their content elsewhere.
6. Storage, security, and the processors we use
Data is held in a Postgres database. OAuth access and refresh tokens are encrypted with AES-256-GCM before they are written; the encryption key is held in deployment configuration rather than in the database, and can be rotated without forcing anyone to re-link. The site is served over HTTPS. Operator surfaces are restricted to an allowlist of admin wallet addresses, and every operator action is written to an audit log.
These are the third parties that actually process data for us:
- X— the source of all profile and engagement data. Your relationship with X is governed by X’s own terms and privacy policy.
- Helius — the Solana RPC provider we query to read token balances. It receives your public wallet address.
- Jupiter — the token price API. It is queried by token mint address only and receives nothing about you.
- Neon — the managed Postgres service that hosts the database.
- Vercel — hosting and scheduled jobs, which handles ordinary web request data.
No other party receives your data.
7. Your choices
Disconnect
Disconnectat the bottom of your dashboard ends the connection immediately and completely. It deletes the access and refresh tokens X issued us, asks X to revoke them so the grant is invalidated on X’s side too, marks your record disconnected, and signs you out. From that moment we collect nothing further about you: no new posts are discovered, and no further metrics are read on the posts we already hold. It takes one confirmation and no email to us.
Disconnecting is not deletion, and we would rather say so than let you assume otherwise. Your existing record stays: past posts, scores, settled epoch results, all-time points and tier. That is deliberate — those rows are the audit trail behind payouts that have already been sent, and rewriting them retroactively would corrupt results other participants were ranked against. If you want the record removed as well, see Delete your data below.
Nothing is lost by leaving. Re-linking the same X account later restores the record you already had, with your all-time points and tier intact, rather than starting you over.
Revoke our access from X’s side
You can also withdraw the grant from X directly: Settings and privacy → Security and account access → Apps and sessions → Connected apps. This invalidates our tokens immediately, and from that moment we can no longer read the organic metrics on your posts.
Be clear about what revoking from X alone does not do. Our post discovery is a search run with our own application credentials rather than with your tokens, so as long as your record here is still active it can keep surfacing your public posts that match the project filter. Revoking at X stops the organic-metrics reads; it is Disconnect above that stops collection entirely. If you want both, use Disconnect — it does the revocation for you.
Sign out
Signing out clears the session cookie in that browser. It is not disconnecting: it does not revoke the X connection, does not stop collection, and does not delete anything. Closing a browser is not a withdrawal of consent, so we do not treat it as one.
Delete your data
Write to TODO_OPERATOR: contact email and we will remove your participant record and everything keyed to it: stored tokens, posts, metric snapshots, balance snapshots, scores, streaks, quest progress and referral links. Two things are outside our reach: payments already sent are permanent entries on the Solana blockchain, and your posts belong to you on X, where only you can delete them.
See or correct what we hold
Your dashboard shows your own record — identity, checklist, statistics, post history, quests and referrals. Your handle and follower count are refreshed from X rather than edited here. For a copy of your records in another form, or to correct something, contact us.
8. How long we keep it
For as long as the program runs and your record is active. Scoring history is retained deliberately: past epochs stay auditable, and a change to the scoring formula replays history rather than silently rewriting old results. The internal ledger used to avoid paying twice for the same X API resource is purged after two days. A deletion request ends retention as described in section 7.
Disconnecting is the exception to “active” above. Your stored X tokens are deleted at the moment you disconnect and are never retained afterwards; the historical record described in section 7 is kept, and a deletion request is what ends that too.
9. Children
This service is not directed at children. Taking part requires an X account, which is subject to X’s own minimum age requirements, and that account must be at least 30 days old.
10. Changes to this policy
If this policy changes, the revised version appears here and the date at the top is updated. Continuing to participate after a change means you accept the updated policy. If a change materially widens what we collect, we will say so on the site rather than relying on you to re-read this page.
11. Contact
Operator: TODO_OPERATOR: legal entity name. Email: TODO_OPERATOR: contact email.
See also the Terms of Service, which cover eligibility, scoring, rewards and prohibited conduct.