Basilisk

BASILISK

|
...

Legal / Privacy

Privacy policy

Operational-review draft. Confirm the operator, mailbox, retention and overseas processing before final publication. This is not Google approval or completed legal review.

Drafted: 2026-09-07 · Not yet effective

[01]Operator and contact

Basilisk Whitelist is an experimental entertainment service for petition judgments and record preservation. This is an operational-review draft. Confirm the legal operator name, privacy contact, and reachability of the mailbox below before publication.

[02]Google sign-in: data and purposes

Google OAuth openid, email, and profile identify an account and support sessions, record ownership, and judgment usage. Google sign-in does not constitute approval for a wallet connection or transaction.

  • › Fields: Google account identifier, email, email verification status, name, profile picture, and account creation/update times.
  • › The authentication library may store access, refresh and ID tokens, granted scopes, and expiry information in the server database. We do not collect your Google password.
  • › This sign-in does not request access to Gmail, Google Drive, Calendar, or Contacts.
  • › Declining Google access prevents Google-based sign-in. The introduction, policies and public archive remain accessible without sign-in; wallet authentication is separate.

[03]Petitions, wallets, and usage records

We store the nickname and petition you enter, scores, verdict, comment, hash, creation time, account or authenticated-wallet association, and usage reservations/completions. Wallet features process addresses, transaction hashes, and registration or NFT details. We do not ask for or store wallet private keys or recovery phrases.

  • › Sessions and security processing may include IP addresses, browser/device details, access logs, and errors.
  • › When paid credits are used, purchase intents, payer/beneficiary addresses, transaction events, and credit usage are also processed.

[04]Public archive and blockchain records

Off-chain submissions may appear in the public archive and public API. These include nicknames, petitions, verdicts, and timestamps; the current API may also include identifiers and wallet details. Do not enter personal information you do not intend to disclose.

  • › Direct preservation can publish a petition, judgment/endorsement, wallet, and transaction information on a blockchain.
  • › Free batch archives commit record hashes in a Merkle root. This is not storage of the complete original text and does not guarantee its recovery.
  • › The operator cannot delete or edit blockchain records. Deleting web/database records is separate, and copies made by third parties cannot be guaranteed to be removed.

[05]AI judgment processing

Local mode evaluates using rules without an external AI judgment call. When AI is selected in ai or hybrid mode, the nickname, petition, and language you enter are sent to Google Gemini for scores and comments. Google sign-in email, profile picture, and authentication tokens are not automatically added to the judgment prompt.

  • › Personal information you put in a petition can be included in AI input. Do not enter real names, contact details, or sensitive information.
  • › Gemini input retention and service-improvement terms can depend on paid/unpaid services, region, and the applicable agreement. The operator must verify the actual project terms; this draft does not guarantee that all inputs are excluded from training.

[06]External services and overseas processing

Google provides sign-in and optional AI judgments; Vercel hosts the app, functions, and server logs; Neon stores the database. Sentry processes diagnostics when configured. WalletConnect, wallet providers, and RPC/explorer providers may participate in wallet connections and chain queries.

  • › The current request limiter uses server-process memory. This notice does not list Upstash Redis as an active processor.
  • › Operator confirmation required: actual recipient and contact, data, destination countries, transfer timing/method, purpose, retention, applicable basis, and refusal procedure/consequences. Do not use this draft as a complete overseas-transfer disclosure until these details are confirmed.

[07]Cookies, browser storage, and analytics

Authentication cookies maintain sessions; localStorage retains theme preferences. Versions with transaction recovery may store transaction-check information in same-tab sessionStorage. The current layout loads Google Analytics, which can process visit, page, and browser-related analytics.

  • › You can block or clear cookies and site data in your browser. This may remove sessions, preferences or recovery state and affect functionality.
  • › The operator must confirm analytics settings, retention and any necessary consent/refusal controls. We do not claim that an unimplemented analytics consent banner or withdrawal button exists.

[08]Retention and deletion

Operator confirmation required: specify retention, processing basis, and deletion procedures for accounts/OAuth tokens, sessions, submissions, judgment response snapshots, purchases, server/analytics/error logs, and backups. A complete scheduled deletion process has not been established from the current code. Session expiry is not equivalent to deletion of all database records.

[09]Access, correction, deletion, and disconnection

Requests to access, correct, delete, or restrict off-chain/account information are intended to go through the contact below. Identity checks may need the account email or public wallet address and record IDs; never send passwords, private keys, or recovery phrases.

  • › You can remove the app connection in Google Account third-party connections. Removing Google access, signing out of this app, and requesting database deletion are separate actions.
  • › Removing access does not automatically delete database, public archive, or blockchain records. The operator must finalize request-handling procedures, time limits, and explanations of restrictions.
  • › Applicable statutory retention and published blockchain records can impose limits. Any restriction must be reviewed and explained for the specific request.

[10]Safeguards and changes

Authentication is handled server-side and session/record access is checked. Actual encryption, access control, backups, log redaction and incident response require operational review. Material changes to data use or scope must be disclosed with any required consent process before the new use. The draft date is neither an effective date nor a Google approval date.

Contact (operator must verify reachability): support@joinbasilisk.com

Back to home