Privacy Policy

Last updated: February 2026

1. Overview

This Privacy Policy describes how Merkle ("we", "us") collects, uses, and stores information when you interact with the @MerkleMoltBot on X or use merkle.bot. We are committed to minimizing data collection to only what is necessary to operate the service.

2. Information We Collect

When you interact with Merkle, we collect and store:

  • X (Twitter) account data: Your Twitter user ID, username (handle), and follower count at the time of interaction. We do not store your email, phone number, or other personal details from X.
  • Wallet address: Your Base network wallet address, created via Privy's infrastructure and linked to your X account.
  • Transaction history: Records of bids you have placed, including amounts, URLs bid on, transaction hashes, fees, and timestamps.
  • Tweet interactions: The tweet IDs and text of mentions directed at @MerkleMoltBot, along with our replies. These are used for deduplication and rate limiting purposes.

3. How We Use Your Information

We use the collected information to:

  • Create and manage your non-custodial wallet on Base
  • Execute bid transactions on your behalf on qrcoin.fun
  • Display your bid history and wallet balance on the dashboard
  • Enforce rate limits and prevent spam/abuse
  • Debug issues and improve the service

We do not sell your data, use it for advertising, or share it with third parties except as described in Section 5.

4. Blockchain Data

All bid transactions are executed on the Base blockchain and are permanently public by nature. Your wallet address, bid amounts, and transaction hashes are visible to anyone on the blockchain. This is inherent to how public blockchains work and is outside our control.

5. Third-Party Services

We use the following third-party services which may process data on our behalf:

  • Privy: Wallet creation and management infrastructure. Privy processes your X OAuth credentials to generate and secure your wallet. See Privy's Privacy Policy.
  • Supabase: Database storage for user records, bid history, and processed tweet logs. Data is stored in encrypted databases.
  • AWS (Amazon Web Services): Cloud infrastructure hosting the bot backend, including Lambda functions and SQS message queues.
  • X (Twitter) API: We read public tweet mentions directed at @MerkleMoltBot via the X API v2.

6. Data Retention

We retain your account data (X ID, wallet address) for as long as you have an active wallet with us. Transaction history is retained indefinitely for audit and dispute resolution purposes. Tweet interaction records are retained for 90 days for rate-limiting purposes.

7. Your Rights

You may request deletion of your account data by contacting us via @MerkleMoltBot on X. Note that onchain transaction data cannot be deleted as it is permanently recorded on the blockchain.

8. Security

We use industry-standard security measures including encrypted database storage, HTTPS-only connections, and Privy's secure enclave technology for wallet key management. However, no system is 100% secure. You are responsible for protecting your X account credentials.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy at merkle.bot/privacy with a new "last updated" date.

10. Contact

For privacy-related questions or data deletion requests, contact us via @MerkleMoltBot on X.