Privacy Policy

Last updated 25 August 2026

What we collect, why we collect it, and who else sees it. We have written this against what the product actually does rather than in general terms, so you can check it against your own account. Every section has its own link.

1.Who we are

PaidHype is a product of Momentum Labs LLC, doing business as PaidHype, 30 N Gould St Ste N, Sheridan, WY 82801, United States. Momentum Labs LLC is the data controller for everything described here: we decide what is collected and why.

Privacy questions and requests: privacy@paidhype.com, or write to us at that address marked for the attention of the privacy team.

2.What we collect

Your account. Your email address, and your name and profile image if you sign in with Google or 𝕏. Your email is how we sign you in and how we tell you what happened to your claims and your money.

Your connection to 𝕏 or Google. When you sign in with either, the sign-in library stores the access token that connection issues, a refresh token where the provider gives one, and the scope you granted. We request read-only access: we do not read your direct messages and we cannot post on your behalf. We do not in fact use these tokens to read anything, because the public 𝕏 data we need comes from our metrics provider instead, but they are held on your account record and we would rather say so than leave them out. You can revoke the connection at any time in that provider’s own connected-apps settings.

Your 𝕏 account, from public data. Its handle, its 𝕏user ID, follower count, account creation date, verified (Premium) status and bio, captured when you connect the account. We use these to check bounty eligibility and to score brand fit.

Posts you submit. The tweet URL and ID, its text, and its public metrics over time (views, likes, replies, reposts, bookmarks), captured repeatedly through the measurement window, which runs from submission to the end of that bounty’s hold and is 14 days by default. Where a bounty puts the link in your first reply, we also store that reply’s ID and text. We keep the full time series because it is the evidence behind what you were paid.

What our automated checks conclude about you. A brand-fit score, a bot-likelihood score, a content-risk score, and a short written rationale for each, plus the verdict and reasoning on each post you submit. Section 5 explains how these are produced and what they decide. Section 6 explains who sees them.

Clicks on tracked links. When someone follows a tracked link we store the time of the click, a bot flag, and a salted SHA-256 hash of their IP address and browser user-agent. The salt is a secret held on our servers and never published. We store neither the IP address nor the user-agent string itself. The hash exists only to tell one visitor from another so click counts are not inflated, and we treat it as personal data rather than claiming it is anonymous. Click records written before 25 August 2026 also hold the raw user-agent string; those are deleted on the 24-month schedule in section 9 and none are being created now.

Conversions. Where a brand reports back that a click led to a signup, trial or sale, we store that event, its value if given, the click it belongs to, and the creator handle carried in the link, so the right creator gets credit.

Payout data. Your Stripe account identifier, whether onboarding is complete, the country Stripe reports, and your earnings and payout ledger.

API keys and verification codes. If you create an API key we store only a SHA-256 hash of it plus its first few characters, so we can show you which key is which. If you request a one-time 𝕏 ownership code we store the code, the handle it is for, and when it expires.

The notices we sent you. Every notice about a claim or a payout, with its text, when you read it, and whether the email behind it failed to send. We keep them so “were you told about this” has an answer.

A few working figures. A rolling median of your own view counts, which the fraud screen compares a post against; the last time each API key was used; and a row for every pre-post draft check you run, so we can hold you to the daily limit.

An audit log. Actions that affect money or status (approvals, rejections, freezes, payouts) with who did them and when.

3.What we deliberately do not hold

Your bank details, government ID and tax forms. Those go directly to Stripe during payout onboarding. We pass Stripe your email address so they can reach you; everything else you give them yourself. We never see the underlying documents.

Card or payment credentials. Brands do not pay through the site, so we do not collect card details from anyone.

Passwords. Sign-in is by emailed link, Google, or 𝕏. There is no password to leak.

4.Why we process it, and on what basis

To run the service you asked for, which means verifying you own an 𝕏 account, checking eligibility, measuring posts, calculating earnings, and paying you. Legal basis: performing our contract with you.

To keep the marketplace honest, which means fraud screening, brand-safety scoring, and click deduplication. Legal basis: our legitimate interest in not paying for fake performance and in giving brands a platform they can trust. You can object to this; section 10 says how.

To meet legal obligations, including tax reporting and keeping payment records. Legal basis: compliance with a legal obligation.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use it to build advertising profiles.

5.Automated decisions, including AI

Two automated systems decide things that affect your money, and we would rather you knew exactly how they work.

The compliance and scoring check. We pass your public 𝕏 content to Anthropic as an API request. For account scoring the inputs are your handle, bio, follower count, account age and verified status. For a submitted post the input is the post text, alongside the bounty brief and the brand’s approved-claims and hard-rules lists, and the text of other submissions on the same bounty so originality can be judged. The model returns a brand-fit score, a bot-likelihood score, a content-risk score, and a verdict on the post with its reasoning. We store all of it.

Some of these decisions are made with no person involved. If the check finds your post breaks a brand’s hard rules, makes a claim the brand has not approved, is off-brief, or duplicates another submission, the post is rejected automatically and earns nothing. That includes your first post.

Where the check passes but something needs a second look, a person decides instead: your first-ever submission, a post the AI layer could not check, and a post that looks like an attempt to manipulate the checker all go to a human queue.

You can always get a person. Because these decisions affect what you are paid, you have the right to human intervention, to give your side, and to contest the outcome. Write to support@paidhype.com or privacy@paidhype.com and a member of our team, not a model, will look again. We store the model’s reasoning next to every verdict, and you can ask us for it.

Brand-safety scoring can touch sensitive subjects. The content-risk score asks whether your account would sit uncomfortably next to a brand, and in doing that the model can form a view on topics that count as sensitive personal data in the UK and EU, including political subjects and adult content. It works from your public profile: your handle, bio and account numbers. You can object to this scoring under section 10, and we can delete the score we hold about you.

The fraud screen. Separately, every measured post runs through a rules engine looking for views climbing without matching likes, replies or reposts, and for a post performing far outside your own typical numbers. A flag rejects nothing on its own: it freezes the payout and sends the post to a person.

Under our agreement with Anthropic, what we send is not used to train their models. We rely on their commercial terms for that rather than on our own inspection, and we will update this policy if those terms change.

6.Who else sees it

The brands whose bounties you claim. When you claim, that brand’s team sees your handle, follower count, the post you submitted and its public metrics, and the automated assessment we generate about your account, including the brand-fit, bot-likelihood and content-risk scores and the reasoning behind them. They use it to decide whether to approve you and your post. A brand decides that for itself, so for that purpose it is an independent controller and its own privacy policy applies to what it does next.

Anyone visiting paidhype.com. A connected handle is listed publicly by default: the handle itself, its 𝕏 profile picture and its follower count. Nothing about your earnings, your claims or your scores is ever shown there. You can turn the listing off for each handle separately, from Account or from creator onboarding, and turning it off removes you from the public site. Handles connected before 25 August 2026 are not listed unless their owner switched it on: the default changed forwards only.

Stripe: payout onboarding, identity verification, tax forms, and moving the money. For identity and tax, Stripe acts as its own controller under its own terms, not on our instructions.

Anthropic: the automated checks described above.

Monid: our metrics provider. We send them the handle or tweet ID we are asking about, repeatedly through the measurement window, and they return the public data 𝕏 publishes about it.

𝕏 and Google: when you sign in with either, that provider knows you signed in to PaidHype, and returns us the profile data described in section 2.

Resend: sign-in links and the notices we send you about your claims and payouts.

Vercel and Neon: hosting and the database.

Other than the brands and Stripe as described above, each of these is bound by written data processing terms limiting them to processing your data on our documented instructions, requiring confidentiality and appropriate security, and restricting further sub-processors. None of them is a party we sell data to.

Where your data goes. PaidHype is operated from the United States and your personal data is stored there. Where we move personal data out of the UK, the EEA or Switzerland we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, or on a recipient’s certification under the EU-US Data Privacy Framework where it has one. Ask us at privacy@paidhype.com for a copy of the safeguards that apply to a particular provider.

We will also disclose data where the law requires it, and to a buyer if this business is sold, in which case this policy travels with it.

7.Cookies

A small number of strictly necessary cookies, and nothing else. One keeps you signed in; the others protect the sign-in form against cross-site request forgery and carry you safely through a Google or𝕏 sign-in. They are all required for the site to work, so we do not ask for consent to set them and there is no cookie banner.

There are no advertising or third-party tracking cookies on PaidHype, and no analytics scripts. The tracked links in creator posts set no cookie on the visitor: the deduplication hash described in section 2 is calculated server-side and never written to their browser.

8.How we protect it

Traffic to PaidHype is encrypted in transit, and our database provider encrypts data at rest. There is no password on a PaidHype account, so there is no password to steal. API keys are stored only as SHA-256 hashes, shown to you in full exactly once when you create them, and stop working the moment you revoke them. Click identifiers are salted hashes rather than raw IP addresses. Access to production data is limited to the people who need it, and every action that moves money is written to an audit log.

No system is perfectly secure, and we do not claim otherwise. If personal data we hold is exposed in a way likely to put you at risk, we will tell you directly and without undue delay: what happened, what data was involved, what we have done, and what you should do. Where the law requires it we will also notify the relevant authority within 72 hours of becoming aware.

9.How long we keep it

Post metrics and the time series behind a payout: we stop collecting when the measurement window closes, and keep the record for seven years, because it is the evidence behind what you were paid.

Payout records, Stripe identifiers and the audit log: seven years from the end of the tax year the payment falls in, which is what tax and accounting record-keeping requires of us.

Account and 𝕏 profile data, and the scores about you: while your account is open, and for 12 months after you ask us to close it, so a dispute or a late payout can still be resolved.

Click records: 24 months, then deleted by a daily sweep.

Verification codes: deleted by the same sweep once they expire.

Where we have to keep something longer because of a legal claim or a regulator, we keep only what that requires and delete the rest.

10.Your rights

Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it.

If you are in the UK, the EEA or Switzerland you also have the right to have our use of your data restricted while a dispute is resolved, to object to processing we base on our legitimate interests (including fraud and brand-safety scoring), to receive the data you gave us in a portable machine-readable form, to human intervention in the automated decisions described in section 5, and to withdraw any consent you have given without affecting what came before.

You can complain to a regulator. If you think we have handled your data wrongly you can lodge a complaint with your local data protection authority, and in the UK with the Information Commissioner’s Office. We would rather you came to us first, but that is your right and not conditional on it.

Deletion has limits worth stating plainly. If you ask us to delete your account we close it, stop scoring you, and take your profile out of the product straight away. We hold the account record and the scores for the 12 months section 9 gives, in case a payout or a dispute is still open, then delete them. The payout and tax records behind money that actually moved we have to keep for the seven years section 9 gives, whatever else you ask us to delete.

Write to privacy@paidhype.com from the address on your account and we will respond within 30 days, telling you if we need longer and why. There is no charge unless a request is repetitive or excessive.

Revoking PaidHype’s access in 𝕏’s connected-apps settings stops us reading anything new from that account, but it does not delete what we already hold. Ask us and we will remove it.

11.If you are in California

In the last 12 months we have collected these categories of personal information: identifiers (email, name, 𝕏 handle and user ID, Stripe account ID), internet and network activity (clicks on tracked links, user-agent strings, hashed IP), professional or employment-related information (your follower count and account standing as a creator), commercial information (earnings, payouts, conversions), approximate geolocation (the country Stripe reports), and inferences (the brand-fit, bot-likelihood and content-risk scores).

Sources: you, public 𝕏 data through our metrics provider, Stripe, and brands reporting conversions. Business purposes: running the service, fraud prevention, and legal compliance, as set out in section 4. Categories disclosed for a business purpose: all of the above, to the recipients named in section 6.

We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not in the last 12 months. We do not knowingly do either for anyone under 16.

You can ask us to know, delete, or correct, and you can use an authorised agent. We will not discriminate against you for asking: your access to bounties and your earnings do not change. Requests go to privacy@paidhype.com.

12.Children

PaidHype is only for people aged 18 or over, the same rule our Terms set. We do not knowingly collect data about anyone younger. If we learn an account belongs to someone under 18 we will close it and delete their personal data.

13.Changes, and contact

If we change this policy we will update the date at the top, and tell you directly where the change is significant, before it takes effect. Earlier versions are available on request.

Questions or complaints: privacy@paidhype.com.

Momentum Labs LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States.

PaidHype is operated by Momentum Labs LLC, doing business as PaidHype.

30 N Gould St Ste N

Sheridan, WY 82801

United States