Privacy Policy
This Privacy Policy explains what information the HugLink Interface at huglink.tech collects, why, and what you can do about it. We collect as little as possible: there are no user accounts with passwords, no email lists, no advertising trackers and no analytics cookies.
Much of the data the Interface works with — wallet addresses, transactions, token metadata — is public on the Solana blockchain or on IPFS by its nature. We cannot change or delete data that lives on a public blockchain.
Contents
01Information we collect
When you sign in to claim — through Hugging Face, GitHub, X, Google (YouTube), Twitch, Kick or Reddit — we receive your account ID, username, display name and profile image, and for Hugging Face the list of organizations you belong to with your role in each, so administrators can claim for their organization. We request read-only permissions, use the sign-in only to confirm which accounts you own, do not store your access tokens, cannot post on your behalf and never see your password.
Linktree verification — Linktree has no sign-in, so we give you a one-time code to place in your public Linktree bio and then read your public Linktree page (username, name, avatar and bio) to check that the code is there.
About linked creators who have not signed in — when a token is linked to a profile, we look up that profile's public information (ID, username, name, avatar and similar public details) through the platform's public API or page so balances can be tied to the right account. The Discover page shows public data fetched from the Hugging Face and GitHub public APIs.
Wallet and on-chain data — wallet addresses you connect, launch from or withdraw to, signed messages used to authorise launches, withdrawals or automatic payouts, and the transactions and balances recorded in our ledger.
Token content — the name, ticker, image, description, links and linked source you submit when launching. Images and metadata are pinned to IPFS and are public and permanent.
Technical data — IP address, browser user agent and request details, used for security, abuse prevention and rate limiting. Rate-limit counters are kept for minutes; server logs are kept for a short period and then deleted.
02How we use it
- to operate the Interface: launch tokens, split creator fees, show balances and pay withdrawals;
- to make sure creator shares go only to the verified owner of the linked profile and to prevent fraud, double spending and account takeovers;
- to show public pages such as Discover, token pages, creator profiles, feeds, leaderboards and share cards;
- to process endorsements, opt-outs, automatic payouts and featured posts on our X account;
- to secure, debug and improve the Interface, and to comply with legal obligations.
03Legal bases
Where data protection laws such as the GDPR apply, we process data because it is necessary to provide the service you request (performance of a contract), for our legitimate interests in operating a secure and transparent fee-splitting service and in crediting fees to the correct creators, and to comply with legal obligations. Where consent is required, we ask for it and you may withdraw it at any time.
04What is public
Token pages, creator profiles (name, handle, avatar, linked tokens, amounts earned and withdrawn, verified-owner status), withdrawal feeds, endorsements, the fee line in each token description and on-chain transaction signatures are public by design — transparency about where fees go is the point of HugLink. Creators who do not want to appear can opt out at any time.
05Sharing with third parties
We do not sell personal data or share it for advertising. We use service providers that process data on our behalf or independently:
- hosting and infrastructure providers (servers, databases);
- Solana RPC providers, which receive wallet addresses and transactions to read and submit them;
- Hugging Face, GitHub, X, Google (YouTube), Twitch, Kick and Reddit, for sign-in and public profile lookups;
- Linktree, whose public pages we read for profile lookups and ownership verification;
- IPFS pinning services, for token images and metadata;
- market-data and swap services such as pump.fun, GeckoTerminal and DexScreener, which receive token addresses (not your personal data);
- your wallet provider, which you choose and which has its own privacy policy.
We may disclose information if required by law or to protect the Interface and its users from fraud or abuse.
06International transfers
Our service providers may process data in countries other than yours. Where required, transfers are protected by appropriate safeguards such as standard contractual clauses. Public blockchain data is replicated worldwide by the network itself.
07Retention
- ledger entries, withdrawals and related records — kept as long as needed to pay balances, keep accurate accounts and meet legal obligations;
- cached public profiles — refreshed regularly and removed when no longer linked to any token;
- records of which accounts have been verified as owners — as long as they are linked to a token or balance;
- sign-in sessions — up to 14 days; sign-in state cookies — 10 minutes; Linktree verification codes — 30 minutes;
- server logs — a short period for security, then deleted; rate-limit counters — minutes;
- on-chain and IPFS data — permanent and outside our control.
08Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to withdraw consent. As a linked creator you can also stop payments to your account and be hidden from the Interface through the Claim page.
Some data cannot be deleted: anything on a public blockchain or IPFS, and ledger records we must keep to account for funds. To exercise your rights, message @huglinkfun on X from the account concerned. You also have the right to lodge a complaint with your local data protection authority.
09Security
We use encrypted connections, signed and HTTP-only session cookies, read-only sign-in permissions, separated hot and treasury wallets, rate limiting and access controls. No system is perfectly secure; keep your wallet and accounts safe and never share your seed phrase — we will never ask for it.
10Children
The Interface is not intended for anyone under 18, and we do not knowingly collect data from minors.
11Cookies
We only use a few first-party cookies needed to run the Interface. See the Cookie Policy for the full list.
12Changes and contact
We may update this policy; the “Last updated” date shows the current version. Questions or requests: message @huglinkfun on X.
