onlyUponlyUp
liveno trades yet. the tape starts with the first buy.

privacy policy

what onlyup collects, why, who else sees it, and how to get it deleted.

1. what this covers

  • this policy covers the onlyup website, app and api (the "service"). "onlyup", "we" and "us" mean the team that runs it.

2. the short version

  • you sign in with x, and we get your x user id and handle, plus your public x profile. we never get your x password, we never post for you, and we don't keep your x access tokens.
  • you connect a wallet, and we store its public address. we never get your private keys or seed phrase, and we don't store wallet signatures.
  • launching a card puts some of your public profile details and your wallet address on the blockchain, permanently.
  • trades happen on a public blockchain. anyone can see them, and nobody, including us, can delete them.
  • we don't ask for your email, phone number or real-world identity. before launch, the early page asks for your x handle and takes your word for three actions on x, and nothing more (section 3a).
  • we don't keep ip addresses with your account, sessions or visits, we don't use analytics or advertising trackers, and we don't sell your data.

3. what we collect

your profile

  • from sign in with x: your x user id and handle. the access tokens x gives us are deleted right after sign-in. they're never stored or logged.
  • your public x profile details, fetched when you sign in: display name, links to your avatar and banner (links only, not copies), bio, follower and following counts, whether you're verified or protected, and when your x account was created. they update each time you sign in, appear on your card and profile, and aren't used to limit who can join.
  • we run your bio and display name through a filter and store the filtered version. when the filter objects to something, we also keep what x actually said, for that field only, so a person can check whether the filter got it wrong. we delete that copy as soon as your profile comes back clean at a later sign-in, and when you delete your account. if the filter never objects - which is almost everyone - we keep nothing of the sort.
  • how you verified. signing in with x is the only way in.
  • account details: your primary wallet address, your referral code and who referred you, your points, level, streak and spin counters, and the times things happened.

wallets

  • for each wallet you link: its public address, which account it belongs to, whether it's your primary wallet and when you linked it. you can link up to 3 wallets, and each wallet can belong to only one account.
  • to link a wallet, you sign a one-time message. the message expires after 10 minutes and can only be used once. we don't store the signature.
  • unlinking a wallet deletes its record, except for the wallet that launched your card.

your card on the blockchain

  • when you launch a card, the transaction you sign includes your x user id, your wallet address, your display name, your avatar link, a short description that says the card is a card of a public x account, how the 3% trading fee is split, and links to your card page, and your x profile link. your bio and your tagline stay off-chain.
  • that transaction is written to robinhood chain publicly and permanently. no one, including us, can change or delete it.
  • anyone can launch a card for a public x account. when they do, that account's x user id, public display name, avatar link and handle go on-chain in the launch record, together with the launcher's wallet address and handle, in a description that says the account didn't launch the card and hasn't endorsed it. this uses only public x profile data, happens without the account owner doing anything, and is permanent.

sessions and security

  • a session cookie keeps you signed in. for each session we store only a hash of the session id, your account id, and when the session was created and when it expires. we don't store your ip address or user agent with it.
  • logging out deletes your session. expired sessions are deleted 7 days after they expire.
  • to stop abuse, we count requests per ip address per minute. those counters are deleted after about 70 seconds. sticker saves are counted per account per hour.
  • our server logs can include internal account ids when someone signs in, handles when a card launches, and error messages. we don't log ip addresses, user agents, wallet addresses or x tokens.

what you do in onlyup

  • your cards and positions, trades, golden card steals, packs, stakes and claims. most of this comes from the public blockchain.
  • game and reward records: tickets, points, levels, check-ins and streaks, spins and their fairness seeds, quests, stickers and where you place them, hype reactions, wishlist, pot and pump hour results, and weekly rewards.
  • things you add to your card, like your tagline and holo style.
  • notifications we create for you inside the app.
  • when someone opens a card link, we record the page, the referral code, the referring link, whether the visit came from x, the time and, if the visitor is signed in, their account id.
  • we don't record ip addresses or user agents for visits.
  • we use this to measure clout, to complete the "people from x" quest and to spot fake traffic.

notifications you turn on

  • web push: your browser's push subscription endpoint and keys, linked to your account.
  • telegram (turned off for now): if we bring it back, connecting the onlyup bot with its 15-minute code stores your telegram chat id, your telegram username and when you linked them.

3a. before launch: the early list

onlyup isn't open yet. until it is, the only page is the early one. it asks for your x handle and walks you through three things on one of our posts: like it, repost it, reply to it.

  • your x handle, typed by you. it's a public name, not a way to contact you: we can't message you with it, and we don't ask for anything that would let us.
  • what you tell us you did. each step records that you said you liked, reposted or replied, and when. we don't check any of it - we have no way to ask x whether you did, so this is your word, not a verified fact. the buttons open x, and what happens there is between you and x, under x's own privacy policy.
  • browser notifications, if you turn them on at the end. we store what your browser gives us: the endpoint it issues and the two keys that encrypt the message. it's offered only after you've finished, never before, and it's for one notification: when onlyup opens. you can switch it off in your browser at any time without asking us, and then it stops working immediately.
  • no email address and no phone number. the early page asks for nothing that could reach you by mail or by phone.
  • all of it is optional. you can read the page and leave, and you can stop after any step.
  • why we keep it: to know who joined the early list before we opened, and to recognise your handle if you sign in with x later. because a handle is how x identifies you, that record can be matched to your account when you sign in - unlike an address, a handle isn't anonymous, and we'd rather say so than pretend otherwise.
  • how long: until onlyup opens, and no more than 90 days after that, for the handle and the notification subscription alike. if we never open, they're deleted within a year. a subscription that has stopped working is deleted when we find out. you can ask us to remove your handle before then, through onlyup's official channels.

4. what we don't collect

  • your x password, your x direct messages, or permission to post for you. we don't keep x access tokens.
  • your private keys or seed phrase. we don't store wallet signatures.
  • your email address, phone number, government id or payment card details.
  • your precise location or your contacts.
  • ip addresses stored with your account, sessions or visits. an ip address is only used for about a minute to limit requests.
  • we don't use analytics or advertising trackers, we serve our fonts ourselves instead of loading them from google, and we don't sell personal data.

5. why we use it

  • to run the service: signing you in, linking wallets, showing your cards and balances, building transactions for your wallet to sign, and running pots, packs, spins, quests, stickers and rewards.
  • fairness and anti-abuse: detecting multiple accounts, bots, wash trading and fake traffic, and reviewing large payouts.
  • security: protecting sessions, limiting requests and investigating attacks.
  • notifications: sending the in-app and push alerts you turn on (and telegram alerts, if we bring telegram back).
  • improving onlyup: looking at aggregate numbers from our own database.
  • if data protection laws like the gdpr apply to you, our legal bases are: performing our agreement with you (running the service), our legitimate interests (security, fraud prevention and improving the service), your consent (push and telegram notifications) and legal obligations.

6. who else sees data

  • the blockchain. your wallet address, trades, steals, stakes, burns and claims are public on robinhood chain, permanently, along with the profile details written when you launch a card. this is how blockchains work, and it's outside our control.
  • x. you sign in on x. we look up public profile details through api.fxtwitter.com by handle. profile pictures load directly from x's image servers, which see your ip address.
  • robinhood chain rpc. our servers send wallet addresses and transaction hashes to public robinhood chain rpc endpoints to check balances, transactions and wallet signatures. your browser also talks directly to the public robinhood chain rpc to read balances and send your transactions, so that endpoint sees your ip address and wallet address.
  • price data. we read the eth price from coinbase and on-chain price feeds. no personal data is sent.
  • telegram. turned off for now. if we bring the bot back and you connect it, telegram receives your chat id and the messages we send you.
  • web push. push notifications, including the one before launch, are delivered through your browser vendor's push service (apple, google, mozilla). it sees the endpoint it issued, not who we are sending to.
  • hosting. our servers, our reverse proxy and any content delivery network in front of them handle your requests, and see your ip address while serving them.
  • wallets and sites you choose. your wallet extension, walletconnect if you use it, and sites you open from onlyup (like the block explorer, relay or across) have their own privacy policies. they only get your data when you use them.
  • legal and safety. we may share information when the law requires it, or to protect our users, the service or others.
  • if onlyup is ever merged or sold, data may move to the new owner under this policy.

7. how long we keep it

  • profile and account data: while your account exists.
  • game and reward records (points, tickets, prizes and payouts) and records that mirror the blockchain: while your account exists. if you delete your account, they stay attached to an anonymised account record, for accounting and fraud prevention.
  • notifications: while your account exists. they're deleted with your account.
  • sessions: until you log out or they expire after 30 days. expired session records are deleted within 7 days.
  • temporary sign-in data (x sign-in secrets and wallet sign-in messages): 10 to 15 minutes.
  • the early list (your x handle, the steps you said you did, and a browser notification subscription if you turned it on): until onlyup opens, and no more than 90 days after. within a year if we never open. a dead subscription goes as soon as we find out.
  • request-limit counters: about 70 seconds.
  • server logs: rotated automatically and kept only up to a limited size, so older lines are removed on their own.
  • text our filter objected to: until your profile comes back clean at a later sign-in, or until you delete your account, whichever comes first.
  • card link visits: 90 days. after that, only aggregate clout numbers remain.
  • push and telegram links: until you remove them.
  • do-not-launch list (handles and x user ids taken down on request): for as long as onlyup runs, so a card can't be launched for them.
  • on-chain data: forever. it's public, and we can't delete it.

8. your choices and rights

  • log out, unlink wallets (except the wallet that launched your card) or turn off push notifications in settings. the same goes for telegram if we bring it back.
  • revoke onlyup's access in your x settings under connected apps.
  • if you joined the early list before launch, you can ask us to remove your handle through onlyup's official channels, with no account needed.
  • if someone launched a card for your x account, sign in with that account to claim it or opt out. opting out hides the card on onlyup, and you can reverse it later. if you ask us to take down a handle that has no card yet, we add it to our do-not-launch list.
  • you can ask us, through onlyup's official channels, for a copy of your data or to correct or delete it.
  • when we delete an account, we remove your sessions, wallet links, push and telegram links, visit records and notifications. your handle, avatar and wallet address are also removed from other people's notifications.
  • we also wipe your profile (handle, display name, avatar, banner and bio) and unlink your x account, so signing in with it again creates a new account.
  • an anonymised account record stays, so that points, prize and payout records, and records that mirror the blockchain, remain consistent for accounting and fraud prevention.
  • we can't delete anything on the blockchain, including the details written when you launched a card.
  • depending on where you live, you may have more rights, like objecting to some processing or complaining to your data protection authority.

9. cookies and browser storage

  • onlyup_session: keeps you signed in for 30 days. it's essential, http-only and secure.
  • onlyup_xoauth: used for up to 10 minutes while you sign in with x.
  • those two are the only cookies. the website itself sets none, and there are no advertising or analytics cookies. the early page sets no cookies at all.
  • local storage on your device: your light or dark theme, a draft of your sticker layout, which cards you hyped today, which card links you've already opened from x (so a visit counts only once) and your notification toggles. these stay in your browser and aren't sent to us.
  • session storage: the page to return to while you sign in with x. it's deleted once you're back.
  • wallet connections: your wallet library remembers your last connected wallet in local storage. walletconnect, if you use it, keeps its own connection data in your browser.

10. security

  • session ids are stored hashed, and our cookies can't be read by scripts. x access tokens are thrown away right after sign-in, wallet signatures aren't stored, and ip addresses aren't kept with sessions or visits.
  • no system is perfectly secure. keep your wallet and devices safe, and remember we'll never ask for your seed phrase.

11. age

  • onlyup is only for adults, 18 or older. we don't knowingly collect data from children. if you believe a minor is using onlyup, let us know through onlyup's official channels.

12. changes

  • we may update this policy. we'll post the updated version here and, for material changes, tell you in the app.