Privacy Policy

Last updated: August 27, 2026

1. Scope and contact

This Privacy Policy explains how 3Social collects, uses, stores, and shares information when you use 3social.io, www.3social.io, and related 3Social services. At the time of this update, 3Social is operated as an independent project. Privacy questions and requests can be sent to legal@3social.io.

2. Wallet-based accounts and sessions

3Social primarily uses wallet-based authentication rather than passwords. When you connect a compatible externally owned or smart-contract wallet and sign a Sign-In With Ethereum (SIWE) message, we receive the public wallet address, signature result, nonce, chain and authentication metadata needed to verify the request. We do not receive or store your private key or seed phrase.

After successful authentication, 3Social uses a secure, HTTP-only session cookie to maintain your session. The current session duration is up to seven days unless it expires earlier or is revoked. We store a hash of the session token rather than the usable token in the application database.

3. Information we collect

  • Account and wallet data. Public wallet address, internal user ID, username, role, account status, connected-wallet records, last-login information, and related account metadata.
  • Authentication and security data. Session-token hashes and expiration, IP address, browser or user-agent information, SIWE nonces and signed-message records, chain information, and security or abuse signals.
  • Profile and preference data. Username, display name, bio, avatar, cover image, payout preferences, profile visibility, and broad country or region content preferences you choose. These content-location preferences are coarse and are not precise GPS location.
  • Content and media. Posts, editable captions and caption revision history, comments, forum content, profile-wall posts, direct uploads, file names, media types and sizes, storage keys, cryptographic file or content hashes, visibility, archive, renewal, and deletion or revocation state.
  • MintVid and live data. Short-form video posts; LivMint room, host, audience, participant, timing, metering, provider, and state information; and live recordings or replay media when recording is requested. Browser camera and microphone access is controlled through your device or browser permission prompt.
  • Social and relationship data. Likes, follows and requests, blocks, mentions, notifications, repost or remix relationships, bookmarks, collaboration invitations, and group memberships, roles, requests, invitations, bans, and moderation logs.
  • Messages and support communications. Direct messages, conversation metadata, collaboration communications, and support threads stored so those features can function and authorized personnel can respond.
  • Creator-program and referral data. Referral codes and attribution; creator or founding-program applications; public external profile URLs; platform and reported audience information; account age and recent publishing claims; ownership proof; acceptance timestamps; review reasons; approval, activation, and reward status.
  • Provenance and content-integrity data. Content hashes, ledger or registry identifiers, timestamps, derivative links, attribution relationships, and audit data used to establish provenance and prevent duplicate or inconsistent processing.
  • Pricing and metering data. Creator pricing and revenue-split policies, policy versions, preview and cap settings, metering sessions, event type, sequence and timing information, accrued amounts, reserves, and charge intents.
  • Payment, escrow, and payout data. USDC escrow balances and deposit-sync records, settlement amounts and status, creator/platform/upstream allocations, public wallet and payout addresses, payout verification status, blockchain transaction hashes, chain IDs, and reconciliation records.
  • Moderation and abuse-prevention data. Reports, reasons and descriptions, outcomes, bans or restrictions, risk flags, and audit records used to investigate manipulation, fraud, security events, or Terms violations.
  • Usage and first-party analytics. Page and feature interactions, search and discovery activity, anonymous or account-linked session identifiers, and sanitized event metadata used for ranking, analytics, security, product operation, and metering.

4. Cookies and local storage

3Social currently uses limited first-party browser storage, including:

  • Essential session storage. The secure session cookie used to keep a signed-in account authenticated.
  • Referral storage. A first-party referral cookie used to preserve creator or campaign attribution when applicable.
  • Public-feed preferences. A first-party cookie and browser local-storage value used to remember a signed-out visitor’s public-feed viewing preference.

You can clear cookies and local storage through your browser. Clearing essential storage may sign you out or reset preferences. We do not currently use personal information for cross-context behavioral advertising.

5. How we use information

  • authenticate wallets, maintain sessions, secure accounts, and prevent replay or unauthorized access;
  • display profiles, content, feeds, search, forums, groups, messages, collaborations, live rooms, and notifications;
  • store and deliver media, process MintVid uploads, operate LivMint streams and requested recordings, and generate replays;
  • operate MintScale pricing, previews, caps, metering, reserves, escrow, settlement, payouts, referrals, and attribution;
  • register provenance, preserve revision and derivative relationships, and maintain financial and content integrity;
  • review creator-program applications and verify submitted eligibility evidence;
  • provide support, moderate content, investigate reports, and detect fraud, farming, abuse, or settlement manipulation;
  • maintain, debug, secure, measure, rank, and improve 3Social; and
  • comply with legal obligations and enforce our Terms.

We do not sell personal information.

6. Legal bases where applicable

Where applicable law requires a legal basis, processing may rely on performance of a contract with you, legitimate interests such as security, moderation, fraud prevention and service improvement, compliance with legal obligations, and consent where a feature requires it. The basis depends on the data and purpose.

7. Public, crawler-accessible, and blockchain-visible information

Public profiles, posts, forum material, public live-room information, creator-program status that is displayed publicly, and other public surfaces can be viewed, copied, indexed, cached, analyzed, or redistributed by other users, search engines, crawlers, AI systems, archival services, and third parties. 3Social publishes crawler instructions and a static sitemap, but those instructions are guidance rather than an access-control or confidentiality mechanism.

Public blockchain activity is inherently transparent. Deposits, withdrawals, settlements, wallet addresses, transaction hashes, contract events, and registered hashes or ledger identifiers may be permanently visible on Base or another enabled public blockchain. Removing or restricting application content does not erase a blockchain record already published.

8. Profile, block, and group privacy controls

Where enabled, 3Social provides application-level public/private profiles, approved-follower access, blocks, and public or private groups. When a private profile is viewed by someone without access, 3Social conditionally omits the wallet address and address-derived fields from supported profile, metadata, preview, and list surfaces. Identicon seeds are generated independently of the wallet address.

These controls are not blockchain anonymity. Setting a profile private, blocking someone, making a group private, or deleting content changes what supported 3Social surfaces show going forward; it cannot retract public blockchain information or copies already made by third parties. 3Social may retain off-chain provenance, audit, moderation, settlement, membership, and security records needed for platform integrity.

9. How information is shared

  • Other users and the public. Public profile, content, social, program, and blockchain information is visible as described above. Private content is shared with the audience selected or permitted by the applicable feature.
  • Infrastructure providers. Providers process information for hosting, managed databases, object storage, cache or queues, media delivery, blockchain RPC/node access, security, and related operations. LivMint uses Amazon Interactive Video Service and related AWS storage or delivery services.
  • Wallets, blockchains, and link destinations. Wallet software and blockchain systems process transactions and signatures under their own practices. If 3Social retrieves a preview for a link you submit, the destination or its provider may receive an infrastructure request for that URL.
  • Administrators and support personnel. Authorized personnel can access information reasonably necessary for support, moderation, creator-program review, settlement, security, and platform administration.
  • Legal and safety disclosures. We may disclose information when reasonably necessary to comply with law or legal process, protect rights or safety, investigate fraud or abuse, or defend legal claims.
  • Business changes. Information may be transferred as part of a financing, reorganization, acquisition, asset transfer, or change of operator, subject to applicable law.

10. Media processing and device permissions

Media uploads may be sent directly to object storage through time-limited upload authorization. 3Social receives or creates associated metadata such as file name, type, size, hash, and storage key. For MintVid or LivMint capture, your browser or device asks whether to allow camera and microphone access; 3Social cannot activate those devices through the feature unless you grant permission. Revoking a device permission prevents future capture but does not delete media you already submitted.

11. Storage and international processing

Off-chain information is stored in managed hosting and database infrastructure. Uploaded media and requested live recordings are stored in S3-compatible or AWS object storage, while temporary background processing uses queue and cache infrastructure. Providers may process data in the United States and other places where they operate. Public blockchain records are distributed globally and are not controlled by a single provider.

12. Data retention

We retain information for as long as reasonably necessary to provide the service, maintain account and financial integrity, preserve provenance and attribution, resolve disputes, enforce the Terms, meet security needs, and comply with legal obligations. Sessions and temporary records expire according to operational schedules. LivMint recordings use the retention period configured or shown for the room or feature; the current platform default is 14 days, but the configured period can vary. A replay selected for longer-term publication, an operational backup, or a record required for provenance, moderation, security, settlement, or law may remain longer.

Caption revisions, transaction, audit, moderation, provenance, application-review, and settlement records may remain after content or an account is no longer public where needed for those purposes. Public blockchain information may be effectively permanent and cannot be deleted or modified by 3Social.

13. Your choices and privacy rights

You can edit supported profile and preference fields, manage content and audience visibility where available, deny or revoke camera and microphone permission, clear browser storage, disconnect your wallet, and withdraw unused escrow through supported controls.

Depending on where you live and applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, or an appeal; to withdraw consent where processing relies on consent; and to receive information about how personal information is used and retained. 3Social does not sell personal information and does not currently use it for cross-context behavioral advertising.

Send requests to legal@3social.io. We may verify control of the relevant account or wallet. A request may be limited where retention is required for security, fraud prevention, legal obligations, financial records, provenance, others’ rights, or other lawful purposes. We cannot delete data from a public blockchain or copies controlled by third parties.

14. Children

3Social is not directed to children under 13, and we do not knowingly collect personal information from them. If we learn that a child under 13 provided personal information in circumstances covered by applicable child-privacy law, we will take appropriate steps to restrict or delete off-chain information as required. A parent or guardian can contact legal@3social.io.

15. Security

We use measures intended to protect off-chain information, including access controls, authenticated administrative routes, encrypted network connections, token hashing, wallet signature verification for sensitive changes, and audit or replay protections for settlement. No system is perfectly secure. You remain responsible for your wallet, private keys, device, browser permissions, and signing decisions.

16. Automated ranking, metering, and abuse detection

3Social uses automated logic for feed ranking, metering, rate and cap enforcement, duplicate detection, program review support, and abuse or farming detection. These systems can affect what content is surfaced, whether an interaction generates a charge, whether an application or activity is flagged for human review, or whether a feature is restricted. Where applicable law provides rights relating to automated processing, contact us using the address above.

17. Changes to this policy

We may update this Policy as 3Social changes. Material revisions will be reflected by the “Last updated” date and, where appropriate, additional notice in the product.

18. Contact

Privacy and legal requests: legal@3social.io. General support: support@3social.io.