weirdonbasePrivacy Policy
Last updated: 7 October 2026
These terms apply to WeirdOnBase at weirdonbase.com and studio.weirdonbase.com.
1. What this policy covers
This policy describes how WeirdOnBase handles data for X sign-in, private character generation and video prompt kits. Future autonomous influencer and publishing features will require additional disclosure and authorization before activation.
2. Information we collect
- Account profile: numeric X ID, current handle, display name and profile image URL received during sign-in.
- Authentication: a hashed studio session token, expiration time and temporary OAuth state/PKCE information. Your X password is not collected. The X access token is used to read your profile during sign-in and is not retained.
- Character records: presentation choice, generated traits, prompt, DNA, creator snapshot, image, review status, timestamps and video prompt kit.
- Operational records: request identifiers, provider usage/billing state and redacted error diagnostics. The hosting/reverse-proxy layer may record IP addresses, request paths, response status and timestamps for operations and security.
- Support: information you choose to provide when contacting us.
Bankr wallet linking and user token payments are not active. X sign-in does not automatically reveal or authorize control of a Bankr wallet. If those features are added, wallet and payment data handling will be disclosed separately.
3. Why we use information
We use account data to identify you, maintain a private session, restrict access to your collection and attribute characters to their creator. We use generation and operational records to deliver outputs, enforce attempt limits, diagnose failures, track provider usage and respond to support requests.
We do not sell X account data, use it for advertising targeting, or use X API data to train the character generator. Your X ID and profile are not inserted into image generation prompts.
4. Cookies and browser storage
The essential wob_session cookie normally lasts seven days and is HttpOnly, SameSite=Lax and Secure on HTTPS. The temporary wob_oauth cookie lasts up to ten minutes for sign-in verification. Cookies are scoped to the studio host.
The browser can store a pending order key and presentation choice in localStorage to recover an interrupted submission without submitting it again. This is removed after a received outcome or when you start a separate attempt. It does not store your X credentials or Bankr API key. Image blob URLs exist temporarily in the browser to display authenticated images.
This release does not include advertising trackers or analytics cookies. The display of your X avatar can make a request to the image host used by X. External services apply their own privacy policies.
5. Providers and disclosures
X receives sign-in requests and provides your authorized profile. Bankr LLM and the underlying model provider receive the character generation prompt and process the image request. The provider's retention and privacy terms apply; we do not claim zero retention for all models.
Character images and studio records are stored on the operator's server. Studio access is checked against ownership; authorized operators can access records for operation and support. Hosting and backup providers may process data as part of infrastructure. Data may be processed outside your country according to where these services operate.
Your collection is not published automatically. If you download an image/JSON and share it, its content and any included attribution become visible to the recipients. We may disclose data when required by law or to protect legitimate security interests.
6. Retention
Profile and character records are retained while your account and collection are maintained, or until an applicable deletion request is fulfilled. Expired sessions and sign-in states stop authorizing access; expired rows are cleaned during later authentication operations and consumed OAuth states are removed.
Operational data may be retained as needed to investigate security issues or unresolved generation charges. Backup copies can retain deleted data until their rotation cycle expires. The deployment guide recommends a 30-day backup rotation. Actual backup retention is controlled by the operator, including any external backup copies. Contact us for retention details applicable to a deletion request.
7. Your choices and requests
You can sign out, download individual character images/JSON, and request access, correction, account closure or deletion through the contact address below. Verify control of your account when requested. Applicable legal requirements or unresolved disputes can require limited retention; we will explain relevant exceptions when handling a request.
You can revoke the application's access in X's account settings. Revocation prevents future authorized profile access but does not automatically notify or delete every existing WeirdOnBase session or stored record. Sign out of the studio and request account/session removal if you want access and records closed.
8. Future X publishing and automation
The current release has no posting or autonomous account-management integration. If introduced, additional OAuth scopes, stored tokens, action history, schedules and retention rules will be disclosed before authorization. Users will be given a way to stop automation and disconnect the authorized account. Login alone will not enable write actions.
9. Security, age and updates
We use hashed session credentials, HTTPS in production and access checks for private records. No service can guarantee perfect security. Do not send credentials or private keys in support messages. WeirdOnBase is intended for adults and is not designed for children under 18. Contact us if a child has provided personal information.
We will revise this policy when data handling changes and update the date above. New sensitive permissions will require appropriate notice and authorization.
Contact
For support, privacy questions, account closure or data access/deletion requests, email lineanity@gmail.com. Include your X handle and a description of the request. Do not send passwords, wallet private keys or API secrets. We may ask you to verify control of your account before releasing or deleting personal data.