Privacy policy
The short version: we keep your email, what you tell us about your product, one revenue snapshot and one visitor count. We never store the keys or tokens you use to get them.
Last updated 2026-09-10
1Who we are
1sted.lol ("we") is a trading-card game of real software products, run by Akari Corporation. The service is the website at 1sted.lol. The terms say what the game is; this page says what we keep. Questions about this policy go to massimianivalerio1@gmail.com.
2What we collect
Account. Your email address, and if you sign in with Google, the email and account id Google gives us. No password exists.
Your card. The product name, website, type, logo, one-line description and optional X handle you enter, plus the proof that you control the domain (a token you place in DNS or on the site).
Revenue snapshot. When you attach a payment provider, we read processed volume for the last 60 days and your active subscriptions, and keep: 30-day revenue, 30-day growth, MRR, customer count, the settlement currency, and the raw totals we computed them from. We never read customer names, emails or card details.
Traffic snapshot. When you attach an analytics provider, we keep one number: unique visitors over the last 30 days, and the raw response it came from.
Payments. Stripe's Checkout Session id, the amount, and what it bought (a chair, a take, a reclaim, a raise). We never see your card number.
Referrals. If you arrived through a founder's link, a cookie remembers that for 30 days so they get credit when you mint.
3Keys and tokens we never keep
Every credential you hand us is used for one read, in the same request you send it in, and then discarded:
- Your Stripe restricted key (Charges: Read, Balance: Read, Subscriptions: Read). We ask you to revoke it after.
- Your DataFast website key or Plausible API key.
- The Google access token from "Connect Google". If your Google account can see several Analytics properties, the token waits in a browser cookie for at most ten minutes while you pick one, then is deleted. We never request offline access, so no refresh token exists.
None of these are written to our database, logs or backups, in any form.
4Google user data
1sted.lol uses Google APIs in two places: Sign in with Google (your email and basic profile, to create or find your account) and Connect Google Analytics (the analytics.readonly scope, to list the GA4 properties you can see and run one report — total users, last 30 days — on the one you pick).
The only Google data we store is your email and the visitor count. We do not store, transfer, or sell any other Google user data, do not use it for advertising, and no human reads it except to fix a bug you report or as required by law.
1sted.lol's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time at myaccount.google.com/permissions.
5Payments
Payments are processed by Stripe, which acts as merchant of record. Stripe collects your card and billing details under its own privacy policy; we receive a session id and the amount. Bids are final; see the rules.
6What is public
A card is a public thing. Once minted, the product name, website, logo, description, type, score, tier, finish, the snapshot figures (revenue, growth, customers, visitors), the provider they came from and the snapshot date are shown on the site, in the card image, and in link previews. So is the chair's number, hold, and history of takes and cuts. Your email and X handle are not shown unless you put the handle on the card.
8Who else sees data
- Supabase — authentication, database and logo storage.
- Vercel — hosting.
- Stripe — payments.
- Google, DataFast, Plausible — only when you attach them, and only the reads described above.
We do not sell data, and we do not share it with anyone else except as required by law.
9Retention and deletion
Snapshots are kept as long as the card exists, because the card is a record. Write to massimianivalerio1@gmail.com from the account's email to delete your account; a minted card's public record may be kept with the personal fields removed, as explained in the rules.
10Your rights
Depending on where you live (including the EU/EEA and UK), you may access, correct, export or delete your data, or object to how we use it. Email us and we will answer within 30 days. You may also complain to your local data-protection authority.
11Changes
When this policy changes, the date at the top changes with it and the text is versioned with the site's code.