PRIVATE LEDGER

Public status. Deliberate data boundaries.

The leaderboard is public by design. Authentication, payment operations, billing details, and moderation context are not. This notice explains that boundary.

PROFESSIONAL REVIEW REQUIRED

This implementation draft explains the intended product honestly. Qualified counsel must review it for the operator, launch jurisdictions, and Dodo's Merchant of Record requirements before meaningful production volume.

  1. 01

    Data we handle

    We handle only the information needed to authenticate accounts, operate public profiles, reconcile payments, prevent abuse, understand product use, and meet legal or provider obligations.

    • Clerk account identifiers and authentication/session state; we do not publicly display your email.
    • Profile fields you submit, including username, display name, avatar, title, bio, links, and anonymous preference.
    • Payment-operation records such as internal intent IDs, provider object IDs, amount, currency, status, refund, and dispute state. We do not store card numbers or card security codes.
    • Security, moderation, repair, and audit records.
    • Privacy-limited product analytics and session replay when PostHog is configured.
  2. 02

    Public information

    After eligible participation, public pages may show your chosen public identity, eligible cumulative Flex, rank, achievements, and verified activity. Anonymous mode replaces public identity details with an anonymous presentation but does not anonymize internal account and payment records.

    Hidden or suspended profiles are removed from public presentation without deleting the underlying financial ledger.

  3. 03

    Service providers

    Clerk provides authentication, Convex stores application data and runs backend logic, Dodo Payments acts as Merchant of Record and handles payment collection, and PostHog provides product analytics and privacy-configured session replay. Hosting and infrastructure providers process technical data needed to deliver the site.

    Dodo Payments receives billing and payment information directly through its checkout. Its privacy terms govern that provider-controlled processing.

  4. 04

    Analytics and replay privacy

    Analytics events use a defined event taxonomy and bucketed amounts/ranks. We do not intentionally send card data, billing addresses, email addresses, provider payment IDs, Clerk IDs as event properties, or free-form profile text to PostHog.

    Session replay masks all inputs, suppresses designated private regions, strips query strings and fragments from captured URLs, and removes captured network bodies and headers. Provider checkout occurs on the provider's domain and is not recorded by this site's replay configuration.

  5. 05

    Retention, security, and choices

    We retain data for as long as needed to provide the service, maintain an accurate financial and moderation record, resolve disputes, prevent fraud, and meet legal obligations. Financial records may need to remain after a public profile is hidden or account access ends.

    Contact support@iamfuckingmillionaire.lol to request access, correction, or deletion where applicable. Some records cannot be deleted immediately when retention is required for payments, disputes, fraud prevention, tax, audit, or legal compliance.