PRE-LAUNCH · SITE ONLINEMASCOT: ASLEEPWEBSITE: SOMEHOW ONLINEPRIVATE SALE: NOT FOUNDSECRET HEAD START: DENIEDSERVER RACKS: SUSPICIOUS

LEGAL FILE 01

Privacy notice

How the website is designed to minimize data collection, logging and chat retention.

DRAFT · LEGAL REVIEW REQUIRED

Scope

This draft explains how the live PROMPOSSUM website is designed to handle information. It requires qualified legal review before it can be treated as final. Privacy questions can be sent to [email protected].

Information you choose to submit

Browsing the website does not require an account, wallet connection or newsletter signup. Community uploads, when an intake is open, require X sign-in to verify creator credit. Do not submit a seed phrase, private key, password, personal financial information or other sensitive data.

Technical request data

Cloudflare necessarily processes technical request data to deliver and protect the website. This can include IP address, device and browser information, requested URL, time, selected request headers, network and security signals. Cloudflare and Sites infrastructure may retain some of this metadata, including raw IP addresses, in operational and security logs according to provider controls and retention settings. PROMPOSSUM does not intentionally add application logs containing submission contents, cookies, authentication tokens or secrets.

Community and bounty submissions

Challenge 001 is still a draft and no public bounty is open. Creative intake is separate from reward rounds and opens only when the website operator enables it with working X sign-in and current permission text. Campaign entries additionally require an explicitly opened campaign and published assignment. Installing the submission system or submitting a creation does not open or enter a reward round.

An active creation intake uses X sign-in to confirm the creator account. Following @PROMPOSSUM, @Rookmakes or any other account is optional and is not checked. X sign-in requests read-only profile and post permissions; this flow retrieves only the profile needed for identity, not posts. The verified handle is retained for creator credit and identity records use a keyed pseudonymous account identifier. The access token is used during sign-in and is not stored for later use. New sign-ins do not request follow access, email, direct messages, posting, automatic following or refresh tokens. No wallet connection is used for submissions.

The form stores the title, category, optional description, optional Telegram and TikTok handles, uploaded media and the exact permission and intake-policy versions accepted. A campaign entry also records its assignment. Optional social handles are not treated as verified ownership and are not shown in the public gallery. Do not include private information in titles, descriptions or artwork. Original filenames are not retained by the application. Files themselves can contain embedded metadata, so do not upload location data or other private metadata.

Original uploads are held in private storage and never served as public asset URLs. Only authorized reward administrators can retrieve them. Container signature checks are an initial format check, not a guarantee that a file is safe. Technical and content review are separate steps. A proposed share version requires a human check of readable creator credit, removed private metadata and all frames where applicable. Review and preparation do not automatically publish work. Approved work may be shared with creator credit on the website and the configured official X, Telegram or TikTok / BURROW TV channels after separate publication approval.

An active Burrow Bounty intake may process an X handle, selected bounty, description, evidence, an optional supporting link and an optional screenshot. Security issues should be sent privately to [email protected] with the subject “Security report”, not uploaded through a public bounty form. This contact is available even when no bounty is open.

Cookies and analytics

Community Creations require a verified X account, not a follow relationship. Optional links to @PROMPOSSUM and @Rookmakes help visitors find updates. X does not sponsor or organize PROMPOSSUM Community & Rewards. Signing in or following does not grant publication permission or a reward.

The former follow-check system stored session-bound encrypted credentials and minimal verification evidence. That check is retired: the server no longer reads those credentials or creates new follow evidence. Expired encrypted records are removed in bounded cleanup batches; sign-out and withdrawal also remove the corresponding credentials. Historical verification evidence has a 90-day retention period from its check time and becomes eligible for deletion after that period. Loading the creator desk triggers automatic database cleanup at most once per hour, with up to 500 records per category in a batch. This depends on site traffic and successful database access, so deletion is not promised at an exact time. The operator can also run cleanup and inspect maintenance logs. Historical permission records, valid submissions and creator credit are preserved separately.

Reward sign-in uses a signed OAuth state cookie for up to ten minutes and an opaque session cookie for up to twelve hours. Both are host-only, Secure and HttpOnly. A separate host-only CSRF cookie protects form actions and is readable by the page. Session token hashes are stored server-side; raw session tokens are not. Signing out revokes that session. Pseudonymous fixed-window counters limit sign-in and upload requests without storing an application-level IP address or handle in those counters.

The website does not enable advertising trackers or invasive profiling. Cloudflare's security layer may set strictly necessary short lived security cookies, including __cf_bm, and run bot detection code during normal browsing. PROMPOSSUM uses these controls to detect automated abuse and protect availability, not for advertising.

The live website currently uses Cloudflare Web Analytics. It reports aggregate page view, referrer, country, browser/device and performance measurements so the operator can understand reach and reliability. It is not used for advertising or tracking across sites. Cloudflare's retention, processing and consent settings remain subject to Cloudflare's controls. The operator must keep this notice and the applicable consent analysis aligned with the live settings and relevant jurisdiction.

Third parties

The website depends on Cloudflare and Sites for hosting, storage, delivery and security. Official links lead to X, Telegram, TikTok and the Robinhood Chain explorer; after a verified launch, the site may also publish the official Pons V2 launchpad link. Those services have their own privacy practices. Opening an external link sends the usual network request to that service. X processes its own sign-in and permission screen when you choose to sign in.

Retention and rights

Uploaded originals are assigned a 90-day private retention period. Media access stops after that period or when sharing permission is withdrawn. The owner runs bounded cleanup batches to remove expired or withdrawn originals and their stored share versions, plus expired sessions and rate-limit counters. Physical deletion is not claimed to happen automatically at an exact time. Private storage and provider backups may follow their own retention processes.

While signed in, the Community page offers sign-out and withdrawal of participation. Withdrawal blocks new use and private media access, revokes all of that participant's sessions and removes optional Telegram and TikTok handles. It does not erase the immutable review history or automatically remove posts already published on an external platform. The operator must review those publications and any further access or erasure request separately. Creator-credit history, record identifiers and review or transaction evidence may remain for accountability pending that review. A withdrawal is not represented as full account or audit-record erasure.

Operational logs should use the shortest practical retention period and access should be limited. Requests about access, deletion or other privacy rights can be sent to [email protected]; the operator must keep the process suited to the relevant jurisdiction and legal requirements.

Changes

This notice may change when the website, submission controls, analytics choices or legal requirements change. Material changes should be dated and reviewed before publication.