Privacy Policy
Last updated
Placeholder draft: this page has not yet been reviewed by legal counsel.
Who we are
This Privacy Policy explains what information BountyPad collects, how it is used and shared, and the choices you have. BountyPad is operated by [Company legal name] ([Jurisdiction]), which is responsible for the personal information described here. You can reach us about privacy at [contact email].
You don't need to give BountyPad your name, email address or phone number to use it. But much of what you do on BountyPad happens on a public blockchain, which nobody, including us, can make private. Please read the next section carefully.
Your wallet is your account
You sign in by signing a one-time message with your Solana wallet (Sign-In With Solana), which our authentication provider verifies. Your wallet address becomes your account identifier.
Wallet addresses are public on-chain. When you launch a token, fund a treasury or bounty, or send or receive a payout, the transaction, including wallet addresses and amounts, is permanently recorded on the Solana blockchain, where anyone can see it and connect it to your BountyPad profile. We cannot change or delete on-chain data.
When you launch a token, its name, ticker, description, image and links are published as public token metadata that Pump.fun, block explorers and other sites may display. Your wallet app and Pump.fun are independent services with their own privacy policies.
BountyPad never asks for, collects or stores your seed phrase or private keys.
Information we collect
We collect what you give us, what your use of BountyPad generates, and public blockchain data:
- Profile: username, display name, bio, avatar, website, X and GitHub handles, and skills.
- Projects and bounties: names, tickers, descriptions, images, links, team members, bounty terms and project updates.
- Submissions: titles, descriptions, links, notes and uploaded files, plus the reviews, ratings and notes a project team leaves on them.
- Disputes and reports: the reasons, statements and evidence links you provide.
- Activity: notifications, follows, saved bounties, reputation events, and records of the transactions you prepare through BountyPad (signatures, amounts and status).
- Technical data: IP address, browser and device information, and request logs, used for security, rate limiting and troubleshooting.
- Blockchain data: public information about wallets, tokens, escrows and payouts, which we read to show balances and to verify funding and payments.
Who can see what
Visibility depends on the type of information:
- Public: your profile, reputation and stats, projects, published bounties, project updates, payouts, activity and accepted submissions. Anyone can see these, with or without an account.
- Private to the project team until accepted: submissions. While your submission is pending, only you, the project's review team and BountyPad moderators can see it. Files you attach are kept in private storage and opened through short-lived links. Once a project accepts a submission, it and its attachments may be shown on the bounty page.
- Limited: disputes are visible only to the people involved and to moderators, reports only to the reporter and moderators, and notifications only to you.
How we use information
We don't sell your personal information, share it with advertisers or use advertising trackers. We use information only to:
- sign you in and run BountyPad: show profiles, projects, bounties and submissions, and prepare the transactions you ask for;
- read the blockchain to confirm that bounties are funded and payouts were made, and to show balances and market data;
- send you in-app notifications about your submissions, your bounties, disputes and the projects you follow;
- calculate reputation from verified activity, such as confirmed payouts and review ratings;
- keep BountyPad safe: rate limits, bot checks, blocking malicious links, moderation, and handling disputes and reports;
- comply with the law and enforce our Terms.
Service providers
We share personal information with service providers only as needed to run BountyPad, and they may use it only to provide their services to us. We may also disclose information when the law requires it, to protect the rights and safety of users or BountyPad, or as part of a merger or acquisition. Our service providers are:
- Supabase: database, authentication (wallet sign-in) and file storage.
- Vercel: website hosting and request logs.
- Our Solana RPC provider, [RPC provider name]: our servers relay blockchain reads and your signed transactions through it, which includes public wallet addresses and transaction data.
- Cloudflare Turnstile (optional): when enabled, a bot check at sign-in that processes technical data such as your IP address and browser characteristics.
- An IPFS pinning service (optional): when enabled, it hosts the public metadata of tokens launched through BountyPad.
Retention and your rights
We keep account information while your account is active and for a reasonable period afterwards. Records of moderation actions, disputes, reports and transactions may be kept longer where needed for security, fraud prevention, resolving disputes or legal obligations. Rate-limit records are deleted after a short period.
Depending on where you live, you may have the right to access, correct, export or delete your personal information, or to object to or restrict how we use it. Email [contact email] to make a request; we may ask you to sign a message with your wallet to confirm the account is yours. We can delete or anonymize information we hold, but not information recorded on the blockchain or already published as token metadata.
BountyPad is not intended for anyone under 18. Our providers may process information outside your country, including in the United States; where required, we use appropriate safeguards for those transfers. We'll post changes to this policy on this page and update the date above.