Legal

Privacy Policy

What Burnie Arena collects, why we are allowed to hold it, where it goes, and which parts of it are public. This policy applies only to people who choose to connect an X account. If you have not connected one, we hold nothing about you.

Last updated

1. Who operates this service

Burnie Arena is operated by TODO_OPERATOR: legal entity name (we, us). The service tracks public engagement on X posts about the $BURNIE token and distributes a weekly USDC reward pool. It is not affiliated with, endorsed by, or sponsored by X Corp.

Questions about this policy, requests for a copy of your data, and deletion requests go to TODO_OPERATOR: contact email.

2. What we collect

From your X account, once you connect it

You connect through X’s own OAuth 2.0 consent screen. We request the scopes tweet.read, users.read and offline.access, and we store:

We hold no write access of any kind. The service never posts, likes, reposts, replies, follows, or sends messages as you.

About your own posts that reference the project

Discovery is a search restricted to posts authored by connected participants that contain the $BURNIE cashtag, a mention of the official project handle, or the contract address. For each matching post we store:

We do not read your timeline, your followers, your likes, your bookmarks, or your direct messages. Posts that do not match the filter above are never fetched, and the accounts of people who have not connected are never read at all.

From your Solana wallet

Records we generate about your participation

From your browser

Two strictly functional cookies: burnie_session, which keeps you signed in, and burnie_oauth, a short-lived one-time cookie that secures the X sign-in handshake. Both are HttpOnly and SameSite=Lax. There are no advertising cookies, no analytics cookies, and no third-party trackers on this site. Our hosting provider records ordinary server request data — IP address, user agent, timestamps — as part of serving the pages.

3. Why we are allowed to hold it

Everything above exists because you chose to connect. You grant the X read access yourself on X’s consent screen, and you prove the wallet is yours by signing a message with it. Both actions are deliberate, both are described before you take them, and both are reversible — see section 7.

Nothing is collected about people who have not connected. We build no shadow profiles, and non-participants’ posts fall outside the search filter entirely.

4. What we do with it

That is the complete list. Your data is not sold, licensed, rented, or shared with any third party. It is not used for advertising or ad targeting, and it is not used to train machine-learning models.

5. What is public

The leaderboard is public. Anyone can open it without signing in and see, for every ranked participant: X handle, tier badge, rank, points, share of the weekly pool as a percentage, and the USDC payout amount. If you do not want your handle and your payout shown publicly, do not connect an account.

6. Storage, security, and the processors we use

Data is held in a Postgres database. OAuth access and refresh tokens are encrypted with AES-256-GCM before they are written; the encryption key is held in deployment configuration rather than in the database, and can be rotated without forcing anyone to re-link. The site is served over HTTPS. Operator surfaces are restricted to an allowlist of admin wallet addresses, and every operator action is written to an audit log.

These are the third parties that actually process data for us:

No other party receives your data.

7. Your choices

Disconnect

Disconnectat the bottom of your dashboard ends the connection immediately and completely. It deletes the access and refresh tokens X issued us, asks X to revoke them so the grant is invalidated on X’s side too, marks your record disconnected, and signs you out. From that moment we collect nothing further about you: no new posts are discovered, and no further metrics are read on the posts we already hold. It takes one confirmation and no email to us.

Disconnecting is not deletion, and we would rather say so than let you assume otherwise. Your existing record stays: past posts, scores, settled epoch results, all-time points and tier. That is deliberate — those rows are the audit trail behind payouts that have already been sent, and rewriting them retroactively would corrupt results other participants were ranked against. If you want the record removed as well, see Delete your data below.

Nothing is lost by leaving. Re-linking the same X account later restores the record you already had, with your all-time points and tier intact, rather than starting you over.

Revoke our access from X’s side

You can also withdraw the grant from X directly: Settings and privacy → Security and account access → Apps and sessions → Connected apps. This invalidates our tokens immediately, and from that moment we can no longer read the organic metrics on your posts.

Be clear about what revoking from X alone does not do. Our post discovery is a search run with our own application credentials rather than with your tokens, so as long as your record here is still active it can keep surfacing your public posts that match the project filter. Revoking at X stops the organic-metrics reads; it is Disconnect above that stops collection entirely. If you want both, use Disconnect — it does the revocation for you.

Sign out

Signing out clears the session cookie in that browser. It is not disconnecting: it does not revoke the X connection, does not stop collection, and does not delete anything. Closing a browser is not a withdrawal of consent, so we do not treat it as one.

Delete your data

Write to TODO_OPERATOR: contact email and we will remove your participant record and everything keyed to it: stored tokens, posts, metric snapshots, balance snapshots, scores, streaks, quest progress and referral links. Two things are outside our reach: payments already sent are permanent entries on the Solana blockchain, and your posts belong to you on X, where only you can delete them.

See or correct what we hold

Your dashboard shows your own record — identity, checklist, statistics, post history, quests and referrals. Your handle and follower count are refreshed from X rather than edited here. For a copy of your records in another form, or to correct something, contact us.

8. How long we keep it

For as long as the program runs and your record is active. Scoring history is retained deliberately: past epochs stay auditable, and a change to the scoring formula replays history rather than silently rewriting old results. The internal ledger used to avoid paying twice for the same X API resource is purged after two days. A deletion request ends retention as described in section 7.

Disconnecting is the exception to “active” above. Your stored X tokens are deleted at the moment you disconnect and are never retained afterwards; the historical record described in section 7 is kept, and a deletion request is what ends that too.

9. Children

This service is not directed at children. Taking part requires an X account, which is subject to X’s own minimum age requirements, and that account must be at least 30 days old.

10. Changes to this policy

If this policy changes, the revised version appears here and the date at the top is updated. Continuing to participate after a change means you accept the updated policy. If a change materially widens what we collect, we will say so on the site rather than relying on you to re-read this page.

11. Contact

Operator: TODO_OPERATOR: legal entity name. Email: TODO_OPERATOR: contact email.

See also the Terms of Service, which cover eligibility, scoring, rewards and prohibited conduct.