Privacy
The service is operated by The operator (registration on file). Questions and requests: legal@example.com.
placeholder identity: this deployment has not set its legal entity
This page says what is read, what is kept, for how long and why, in the same words the code uses.
What the Mac app reads
The app reads exactly these things and nothing else:
- system idle time, to know there was input in the last three minutes;
- lock and display state: whether the display is awake, the session is unlocked and the screen saver is off;
- whether its own status item is on screen: visible, not occluded, not hidden by a fullscreen app, not pushed into overflow;
- the hardware model string, so the anomaly sweep can tell a virtual machine from a Mac.
What the app never reads: screen contents, keystrokes, the clipboard, the list of running apps, browser history. Every 60 seconds it posts one record per minute saying whether each condition held, signed with a device key that is generated at install and kept in the Keychain. A click on the sponsor item opens a signed redirect; one click per host, creative and day is counted.
What is read from X
When a host signs in, and nightly after that, the platform reads the host's own account with the token their sign-in granted: followers, following, listed count, post count, account created date, verified type, bio, and the date of the newest post. Monthly, it reads the public metrics of the last 10 posts. Posts are read to compute the engagement figure and the labels and are then discarded. Counts, the score and the labels are stored; post text never is. Nothing is read from anyone else's account.
The sign-in token is stored encrypted on the server, is never shown to anyone, and is used for these reads only. A host can withdraw it on X at any time; the profile then keeps its last figures until they sign in again, and the profile page says so.
What is stored
- Hosts: the X account id and handle, the figures above, the score and its parts, labels with their confidence and read date, verified minutes by day, earnings, payout status, blocked categories, one device record, the IP address and app version of each heartbeat batch.
- Advertisers: the sign-in address, company name, creatives, bids, the ledger of every hold, charge, release and top-up, API key hashes and their last use. Card details are held by Stripe and never touch this server.
- Everyone: server logs for thirty days.
Why it is stored
To run the market (the score, the labels and expected hours are what is sold), to pay hosts and charge advertisers (the ledger), to keep the numbers honest (the heartbeat, the device key and the sweep), and to meet tax and accounting law (the ledger again, kept as long as that law requires).
Who sees it
A public profile shows the handle, display name, country, tier, score, the top labels, follower count and expected hours, each with the date it was read. A host who opts out of the public profile is still biddable by signed-in advertisers. Advertisers see verified hours and clicks by label, never by named host, on the day calendar. Stripe processes payments and payouts under its own privacy terms. No advertising trackers run on this site.
Product analytics
The site counts page views to know whether the market is working: which pages are seen, where visitors came from, which device family they use, how many go on to become hosts or advertisers, how many days are bid on and how many balances are topped up. The counting is done by PostHog, sent from this site's own address, with no cookie and no script from a third party. A page view carries the page, the referring site, the campaign tag if the link had one, the browser family and the operating system. It never carries a query string, a signed link, an email address, a handle or a company name.
A browser gets a random id kept in its own local storage, which ties its page views together and can be cleared with the site data. When that browser signs in, the id is paired once with the account, so the pages seen before signing up can be attributed to it. Events about an account (becoming a host, placing a bid, adding funds) are sent by the server under the account id with amounts and counts only. A browser that sends Do Not Track is not counted at all. Account deletion covers this too: the account id is erased and the events under it point at nothing.
Your rights
You can read everything held about you from your dashboard, correct your profile, dispute a label, pause the app and uninstall it. You can delete your account from the dashboard: profile, labels, device and minute records are erased within thirty days, and only the ledger rows the law requires are kept, without the profile they pointed to. Hosts and advertisers in the EU and the UK have the rights the GDPR gives them, including access, portability, rectification, erasure and complaint to a supervisory authority, and can exercise them at the address above.
Changes
Adding anything to what the app reads means adding it to this page, the specification and the README in the same change. That is the rule the project is run by.