Privacy
Last updated 2026-09-06
This describes what 1spot.lol collects and what happens to it. Where something is awkward, it says so — a policy that only lists the flattering parts is not much use to you.
What we collect
- From X, when you sign in: your user id, handle and avatar image.
- From Stripe, once, at your first payment: an email address for your receipt. That is the only place an email reaches our own database, and we use it for nothing else.
- From you: whatever you type or upload as an entry.
- Automatically: your bids and payment records, and server request logs that include your IP address.
Scopes, and where your data actually lands
Three different things, which are easy to run together:
- What we ask X for. Sign-in runs through Supabase Auth, which requests
users.email tweet.read users.read offline.accessfrom X. That list is fixed by Supabase and cannot be removed by configuration — scopes we pass are added to it, not substituted for it. So an email address is requested from X on every sign-in.tweet.readis read-only and is what X requires to identify you at all. - What Supabase Auth holds. Your X identity and its metadata, which may include the email address returned under that scope.
- What our own database stores. Your X id, handle and avatar — and an email address only if you gave one to Stripe for a receipt.
We never request a write or posting scope. The share button opens X’s own compose window with some text filled in; we cannot post for you and have not asked to be able to.
Why we process it
- To perform the contract — running the auction, taking payment, showing who holds a crown.
- Because the law requires it — keeping financial records.
- Legitimate interests — safety scanning and fraud prevention, so the board is not a harassment vector and payments are not fraudulent.
Who else sees it
| Processor | Role | What it sees |
|---|---|---|
| Supabase | Database, sign-in, file storage | Everything we store, including the sign-in record |
| Stripe | Payments | Card details (which never reach our servers), email, amounts |
| Vercel | Hosting | Request logs, including IP addresses |
| X | Sign-in provider | That you signed in, and your id, handle and avatar |
| OpenAI | Automated content-safety scan | Your entry text and re-encoded images |
That last row is easy to miss and matters: entries are sent to a third-party classifier before a person sees them.
Automated checks on your entry
Entries are scanned before a moderator sees them. Text and re-encoded images go to the classifier above, and a separate deterministic check refuses entries containing email addresses, phone numbers, national ID numbers, payment card numbers or street addresses — yours or anyone else’s.
A refused entry is rejected before any payment is taken. Nothing is charged, so there is nothing to refund; fix it and post again. A clear result is not approval — it only means your entry joins the queue for a person to review.
We will not tell you which check refused you, because a precise message is a map for anyone trying to get around it. If you think it was wrong, write to support@1spot.lol and a person will look within 5 working days.
How long we keep it
Entries that reach the board and the bids behind them are part of the board’s public history and are kept. Payment records are kept because we are required to keep them. Server logs expire on our host’s schedule.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to stop, or object. Write to support@1spot.lol and we will answer within one month. You can also complain to your local data protection authority.
Deleting your account
Write to support@1spot.lol. We remove your identity — handle, avatar, sign-in record and the link to your X account — and take your entries off the board.
Three things we keep, and we would rather say so than imply otherwise:
- Payment records. Amounts, dates and references, because we are required to. Stripe keeps its own copy of the payment under its own obligations, as a separate controller — that copy is not ours to delete.
- Backups. Our backups cannot be edited in place. They age out on a fixed schedule, and if we ever restore one we re-apply your deletion to the restored data.
- Server logs.IP-bearing and expiring on our host’s schedule.
What remains is kept under an opaque id and no longer identifies you by name or handle.
Cookies
Browsing the board sets no cookies at all. Signing in does: it stores a cookie that keeps you signed in for up to 400 days, and we tell you so on the sign-in button before you go to X. Stripe sets its own cookies on the payment step for fraud prevention.
There is no analytics, advertising or tracking on this site. If that ever changes, this page changes with it and you will be asked first.
Under 18s
The service is for adults — see the terms. We do not knowingly collect data from under-18s; if you believe we have, write to legal@1spot.lol and we will remove it.
International transfers
Our processors operate internationally, so your data may be processed outside your country under the safeguards those providers offer.
Contact
legal@1spot.lol for privacy questions, support@1spot.lol for requests about your own data.