Privacy Policy

Last updated: 2026-09-03

This policy covers the profile card, the booking page and the collabs page, served on three subdomains of the same site. It explains what personal information is collected and what we do with it. It is written to be read — not scrolled past.

What we collect

Sign-in with X (Twitter). To send a collab request or claim a creator profile, you sign in with your X account. We receive from X your display name, your username, your account id and the address of your profile picture. These values are placed in a signed session token kept in a cookie in your browser; they are not written to an account database. We never post to your X account.

Booking form. A request records your X username, your name, the address of your profile picture, the link to your X profile, the collab type, the city, the dates, your message and, where applicable, the event or creator it concerns, with the time of the request. A creator card (username, name, picture) is created or updated at the same time. Depending on the option you pick, the content of your request is also handed to WhatsApp or Telegram, under their own policies.

Creator profiles. A profile may hold an X username, a name, a picture, a bio, links, availability (city and dates) and the status of a consent letter. Profiles are public: they are displayed on the site and returned by its data interface.

Suggestions. A suggestion records its type, your message (up to 1,000 characters), an optional link and, if you provide them, your X username, profile picture and city.

Events. Events are created by the operator. When you join an event, your X username, name and picture appear publicly in that event's participant list.

Where this data is kept

Booking requests, profiles, suggestions and events are written to files in a code repository hosted on GitHub (GitHub, Inc.), under the operator's account. The site itself is hosted by Vercel and its images are delivered by Bunny.net; these providers may keep technical logs (IP address, browser) under their own policies. No automatic retention period applies: this information is kept until you ask for its deletion.

Cookies

This site uses first-party cookies only, all strictly functional:

  • __Secure-next-auth.session-token — your session after signing in with X (a signed token holding the values described above). It is shared across the site's subdomains so that one sign-in works on each of them, and expires after 30 days at the latest.
  • __Secure-next-auth.callback-url — the page you return to after signing in.
  • __Host-next-auth.csrf-token — protection against forged requests.
  • Short-lived cookies from the sign-in library (state and PKCE verifier) for the duration of the round trip to X.

No advertising cookies, no third-party tracking, and no third-party analytics run on this site.

External services

The site links out to third-party services (social networks, messaging apps, content platforms, shops). What you do there is governed by their policies. On a creator profile page, a QR code pointing to the consent letter is generated by a third-party image service, which then receives the address of that letter.

Payments

Payments happen on external pages (Wise, Square), under their own policies. No payment data ever passes through or is stored on this site.

What we don't do

We do not sell your information. We do not share it for advertising. We collect nothing beyond what is described above.

Your rights (Law 25, Québec)

You may request access to your information, its correction or deletion, and withdraw consent at any time. To end your session, sign out from the booking page or clear this site's cookies in your browser.

Changes

Any change to this policy will be posted here with its date. A change affecting what we collect will not apply retroactively to what you already entrusted to us without your consent.