// privacy.txt
Privacy
Last updated 24 September 2026
What we collect
When you apply to the E404 whitelist we store:
- From X, via read-only sign-in: your account ID, username, display name, profile image URL, follower count and account creation date.
- Your Taproot address — a public Bitcoin receive address you choose to give us.
- Your signal tweet link and whether it was verified.
- Referral data — your referral code and, if you arrived through someone's link, theirs.
- A one-way hash of your IP address, used only to spot bot and duplicate sign-ups. We do not store the IP itself.
What we never ask for
Seed phrases, private keys, passwords, payments, or signatures that move funds. The X sign-in cannot post, follow, or read your DMs. Anyone asking for these in our name is not us.
Why
To run the whitelist: check each applicant is a real, unique person, rank the queue, credit referrals, and give whitelisted addresses priority for what comes next.
Cookies
Two functional cookies: e404_session keeps you signed in for up to 7 days, and e404_ref remembers a referral link for 30 days. No advertising or third-party tracking cookies.
Sharing
We don't sell your data. Your Taproot address may be used on-chain (for example in an allowlist or distribution), and anything on Bitcoin is public by design. Data is hosted with our infrastructure provider (Railway) and is only accessed by the E404 team.
Removal
Want your application deleted? Message us on X at @error404ord from the account you applied with, and we'll remove it.