Legal-ish
Privacy
Last updated August 23, 2026.
What we collect
- X account id, username, display name, and avatar if you sign in with X.
- Listings you submit: name, tagline, URLs, stack, claimed MRR, screenshots.
- TrustMRR slug/URL if you paste one, plus the MRR we pulled at verify time.
- Swipes, watchlist, bids, Call BS challenges, and in-app pings.
- Payment records: amount, kind, Stripe session id. Card data stays at Stripe.
- Basic request logs and a coarse visitor count. No ad-tech pixel farm.
What we don't
We don't sell your email list, because we barely have one. Demo login (@demo_hacker) is a shared toy account for local/staging, not a production identity.
Processors
Hosting and database on whatever we deploy to (typically Vercel + Postgres). Auth via Auth.js. Payments via Stripe. Optional TrustMRR lookup when you ask us to verify. X if you use Continue with X.
Retention
Listings and swipe history stay until you ask us to delete the account or we shut the joke down. Payment records stick around as long as tax/Stripe rules say they must.
Delete / contact
DM @alexboots19 to export or wipe a profile. Public roast cards already screenshotted by the internet are gone from our DB, not from the timeline.
Payments and stakes are in the terms.