Privacy Policy
Effective 13 September 2026. This is exactly what pairmention.com collects, why, and for how long. There is no user database.
1. What we collect
| Data | When | Why | Where it lives / how long |
|---|---|---|---|
| Your public profile from X, GitHub, TikTok, YouTube or Instagram: user id, username, display name, avatar URL | Only when you choose "Sign in" on the claim page | To know which account you are, so the claim goes to its owner | A signed cookie in your own browser, up to 7 days. Not stored on our servers. The platform's access token is used once and discarded. |
| Short-lived sign-in cookies (state, PKCE) | During a sign-in attempt | To protect the sign-in against forgery | Your browser, 10 minutes |
| Your wallet address | When you connect a wallet | To build the on-chain transactions you sign and the claim authorization | Not stored by us. Once you transact, the address is public on the blockchain, like every transaction there. |
| Coin images you upload | When you launch a coin | To show the coin on the site and in link previews | Our server, publicly served, kept as long as the coin exists (we may remove abusive images) |
| Server logs: IP address, browser type, requested URL, time | Every request, like any website | Operations, abuse prevention, debugging | Our server, rotated within a few weeks |
| Public blockchain data: launches, trades, harvests, claims | Continuously, from the chain | To show prices, volumes and fees | Our indexer. This data is public by nature and permanent on-chain. |
2. What we do not do
- We do not sell, rent or share your data with advertisers. There are no ad trackers or analytics pixels on the site.
- We cannot post, follow, message, read private data or change anything on your X, GitHub, TikTok, YouTube or Instagram account. We ask only for read-only public profile access, and the platform's permission screen shows exactly that.
- We do not store platform access tokens, passwords or private keys. Passwords are typed on the platform's own site, never on ours.
- We do not keep a database of users. Your identity lives in your browser's cookie until it expires or you sign out.
3. Third parties
- X, GitHub, TikTok, YouTube (Google), Instagram (Meta) handle the sign-in under their own privacy policies. You can revoke PairMention at any time in their settings (X: Settings → Security → Connected apps; GitHub: Settings → Applications → Authorized OAuth Apps; TikTok: Settings → Security → Manage app permissions).
- Base RPC: your browser talks to a public blockchain node to read data and send the transactions you sign. The node operator sees your IP address like any website does.
- Price sources (Coinbase, CoinGecko, Kraken) are queried by our server for the ETH price only; nothing about you is sent.
- Wallets (MetaMask, Phantom, Rabby, Robinhood Wallet, WalletConnect) run under their own policies.
- Links to DexScreener, GeckoTerminal, Uniswap and the block explorer lead to their sites.
4. Cookies
Two kinds, both first-party and strictly functional: the session cookie (xl_session, signed, up to 7 days) and the temporary sign-in cookies (10 minutes). No third-party cookies. Signing out deletes the session cookie.
5. Your choices and rights
- Sign out at any time on the claim page; revoke the app at the platform to stop any future sign-in.
- Ask us to remove an uploaded image from the site. Blockchain data cannot be deleted by anyone.
- Depending on where you live you may have rights to access, correct or delete personal data. Since we hold almost none, most requests are answered by the paragraph above. Contact us and we will help.
6. Children
The site is not for anyone under 18 and we do not knowingly collect data from children.
7. Changes and contact
We may update this policy; the effective date at the top changes when we do. Questions or requests: @PairMention on X. See also the Terms of Service.