← Back to Home

Privacy Policy

Last Updated: August 30, 2026

SubHeader ("we", "us") respects your privacy. This Privacy Policy explains how we collect, store, and use your information when you use subheader.lol.

1. Information We Collect

  • Creator Profile Data: When creators sign in via X OAuth 1.0a, we request read and profile-write permissions (account/update_profile_banner). We store your X User ID, handle, display name, avatar URL, and encrypted API access tokens.
  • Sponsor Details: We collect the sponsor's email address (provided during Dodo Payments checkout) and uploaded banner graphics.
  • Media Storage: Uploaded banner images are stored securely on Cloudflare R2 object storage.

2. How We Use Your Data

  • Automated Banner Execution: Stored API tokens are used strictly to programmatically upload approved sponsor headers and restore original backup headers at slot expiration.
  • Transaction Communications: Emails are used exclusively for sending receipt confirmations, bid approval notifications, and payout status updates.
  • Security & Encryption: All sensitive OAuth tokens are encrypted at rest using AES-256 GCM encryption. We never store plain-text passwords or financial credit card numbers.

3. Data Sharing & Third Parties

We do not sell your personal data. We integrate with trusted third-party services:

  • Dodo Payments: For escrow processing and merchant of record compliance.
  • Cloudflare R2: For hosting banner image assets.
  • Supabase / PostgreSQL: For encrypted database record storage.

4. Your Data Rights

You can revoke SubHeader's X profile permissions at any time through your X account settings (Settings & Privacy -> Security & App Access -> Connected Apps). You may also request complete deletion of your creator account by contacting us.

5. Contact

For privacy-related questions, contact us via X at @Pratyusshmd.