Privacy Policy
Last Updated: August 30, 2026
SubHeader ("we", "us") respects your privacy. This Privacy Policy explains how we collect, store, and use your information when you use subheader.lol.
1. Information We Collect
- Creator Profile Data: When creators sign in via X OAuth 1.0a, we request read and profile-write permissions (account/update_profile_banner). We store your X User ID, handle, display name, avatar URL, and encrypted API access tokens.
- Sponsor Details: We collect the sponsor's email address (provided during Dodo Payments checkout) and uploaded banner graphics.
- Media Storage: Uploaded banner images are stored securely on Cloudflare R2 object storage.
2. How We Use Your Data
- Automated Banner Execution: Stored API tokens are used strictly to programmatically upload approved sponsor headers and restore original backup headers at slot expiration.
- Transaction Communications: Emails are used exclusively for sending receipt confirmations, bid approval notifications, and payout status updates.
- Security & Encryption: All sensitive OAuth tokens are encrypted at rest using AES-256 GCM encryption. We never store plain-text passwords or financial credit card numbers.
3. Data Sharing & Third Parties
We do not sell your personal data. We integrate with trusted third-party services:
- Dodo Payments: For escrow processing and merchant of record compliance.
- Cloudflare R2: For hosting banner image assets.
- Supabase / PostgreSQL: For encrypted database record storage.
4. Your Data Rights
You can revoke SubHeader's X profile permissions at any time through your X account settings (Settings & Privacy -> Security & App Access -> Connected Apps). You may also request complete deletion of your creator account by contacting us.
5. Contact
For privacy-related questions, contact us via X at @Pratyusshmd.