Privacy Policy
This policy explains how Valhist Donate handles information when you use its Chrome extension, creator pages, and related services.
1. Overview
Valhist Donate lets people support creators on X using supported tokens on Base and lets creators connect an X account to view donations, then use a wallet when they choose to claim. We process only the data needed to authenticate accounts, verify blockchain activity, provide donation history, and protect the service.
Valhist Donate does not ask for or store your wallet seed phrase or private key. Wallet approvals and signatures are handled by your wallet provider.
2. Data we handle
X account information
When you choose to connect X through OAuth, we receive the X account's numeric user ID and may receive its current handle, display name, avatar, and email address when X supplies one to the authentication provider. We use the numeric ID to distinguish connected account records and derive the escrow recipient reference even if a handle changes. Supabase Auth may retain the email as part of its authentication record; Valhist does not use it to route donations or display it in the extension. A creator must complete X OAuth before donations are enabled; a wallet is not requested during X connection. The normalized handle remains display metadata for the selected post. The extension does not receive the email address, and we do not receive your X password.
Wallet and authentication information
Connecting X in the current Chrome extension does not request a wallet address or wallet signature. When you explicitly choose Donate or Claim, we process the public active wallet address and Base network details needed to prepare the requested transactions. Your wallet submits those normal blockchain transactions, and the escrow contract uses the transaction sender to prove wallet control. Compatible older versions may use a one-time no-spend wallet-link signature; it is not a private key and is not retained after verification. After Chrome's X authorization succeeds, the extension receives a revocable Valhist session token rather than an X or Supabase OAuth token. X and Supabase access or refresh tokens are not returned to or stored by the extension. The Valhist session is stored in Chrome extension storage restricted to trusted extension contexts and expires.
Donation and Base transaction information
To create, verify, display, and claim donations, we may process a Base transaction hash and log index, token contract and symbol, token amount, creator reference, X post ID or link, optional donor comment, timestamps, and claim or verification status. This data is checked against public Base records; a submitted record is not treated as a completed donation until the relevant onchain event is verified.
Extension preferences and operational data
The extension may keep preferences and pending action state in Chrome's local extension storage. Our hosting and security systems may also process limited request data such as IP address, user agent, timestamps, and error details to deliver and protect the service.
3. How we use data
We use the information described above to:
- authenticate a connected X account and prepare wallet binding when its owner explicitly claims;
- prepare donation transactions requested by a donor;
- verify transaction receipts and eligible claim amounts on Base;
- show creators their donation history and supporter messages;
- show attribution and supporter totals when the relevant donor has connected an X account;
- detect duplicate, invalid, abusive, or fraudulent activity;
- maintain, troubleshoot, and secure the service; and
- comply with applicable legal obligations.
Depending on where you live, these activities may rely on your consent, performance of the service you request, our legitimate interests in operating and securing Valhist Donate, or legal obligations.
4. What other people can see
A creator's dashboard may show a connected donor's X handle, display name, avatar, donation token and amount, related post, and comment. Aggregated supporter rankings may also show connected X identities and donation totals. Valhist Donate is designed not to display wallet addresses in its public user interface.
Base is a public blockchain. Transaction hashes, contract and token addresses, wallet addresses, amounts, and event data written onchain can be viewed independently through Base explorers, RPC services, and other blockchain software. Valhist cannot make public blockchain records private or delete them.
5. Service providers and disclosures
We use service providers to operate Valhist Donate. They process data under their own terms and privacy practices and only for the functions they provide to us:
- Supabase for OAuth session support and protected database services;
- Vercel for application hosting, delivery, and operational logs;
- X for the OAuth identity information you choose to connect; and
- Base network and RPC providers to submit or read public blockchain transactions and verify contract events.
We may also disclose information when required by law, to protect users or the service, or as part of a business reorganization with appropriate safeguards. We do not sell personal information, use it for third-party targeted advertising, or run advertising in Valhist Donate.
6. Retention and deletion
We keep offchain account links and donation metadata for as long as reasonably needed to provide donation history and claims, prevent duplicate or fraudulent activity, resolve disputes, and meet legal or security requirements. Operational logs may be kept according to the applicable provider's retention settings.
You may ask us to disconnect your X identity, remove or de-identify eligible offchain profile data, or suppress it from Valhist's public interface. We evaluate requests against claim, fraud-prevention, legal, and record-integrity needs. Blockchain transactions and other data already written to Base are immutable and cannot be erased by Valhist.
7. Your choices and rights
You can disconnect X in the product, disconnect your wallet in your wallet provider, clear extension storage by removing or resetting the extension, and choose not to submit an optional donation comment.
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection, or to withdraw consent for future processing. These rights can be limited where we must retain information for security, claims, legal compliance, or because the information is already on a public blockchain. Contact us to make a request; we may need to verify your X account or wallet control before acting on it.
8. Security
We use technical and organizational safeguards intended to limit unauthorized access, including OAuth-based identity checks, Base transaction-sender checks, restricted server-side credentials, and onchain receipt verification. Compatible older clients may additionally use a one-time no-spend wallet-control signature. No online or blockchain system is risk-free, so you should review wallet prompts carefully and protect your wallet recovery information.
9. Changes to this policy
We may update this policy as Valhist Donate changes. The effective date at the top will change when a revised version is published. If a change materially affects how connected account data is used, we will provide notice through the service or another reasonable channel before the change applies where required.
10. Contact
For privacy questions or requests, contact Valhist on X. Please do not send seed phrases, private keys, passwords, or other wallet recovery information.