LEGAL
Privacy
What RobinType collects, what becomes public, and what you can ask us to do with it.
Working draft · 23 September 2026
What we collect
When you take the typing challenge
Your profile — display name, optional website, X handle, and optionally an avatar image derived from that X handle — is stored in your own browser (local storage). When you submit a finished run to the public leaderboard, the same details plus the run result are sent to our database: name, website, X handle, avatar URL, words per minute, accuracy, duration and a timestamp.
Your profile and local run history remain in your browser unless you submit a result. If you choose an X avatar, the browser may request the image from the avatar provider before submission; no leaderboard record is created until you submit.
When you buy a keycap placement
To operate a purchase we process the buyer's brand name, uploaded logo path, destination website, placement and term, checkout and payment status, the payment token used, the transaction hash, the payer wallet address, timestamps and at least one contact method (an email address or an X handle).
We never ask for private keys or seed phrases, and we never hold your funds. Payments move directly from your wallet to the receiving address shown at checkout. RobinType does not collect card details.
Automatically
Our hosting and database providers keep standard server and request logs (IP address, user agent, timestamps) for security and abuse prevention.
What becomes public
- Leaderboard: your display name, X handle, website and avatar, together with WPM, accuracy and the date of the run, appear on the public board and on any keycap your run has won. Your email address is never published.
- Keycap placements: the brand name, logo, destination website and submitted X handle of an active placement are shown publicly on the selected key and in the placement listing. Contact email addresses and wallet addresses are not published by RobinType.
- Blockchain: a crypto payment is a public transaction. The sending address, the receiving address and the amount are permanently visible on the public chain explorer. We cannot delete or alter on-chain data.
Service providers
- Supabase stores leaderboard results, inventory, placement and moderation records, and serves the checkout API.
- Cloudflare hosts the site and runs the worker that watches for incoming payments.
- unavatar.io may resolve an X profile picture from your X handle. The browser requests that image when the avatar option is used; the handle is also stored with a submitted result.
- Public blockchain explorers and RPC providers are queried to confirm payments and read token prices.
We do not sell personal data, and we do not run advertising or cross-site tracking pixels.
Cookies and local storage
We do not set advertising cookies. The site stores a small amount of data in your browser: your profile, your local list of past runs, your light/dark theme choice, and — during checkout — a temporary draft used to carry your order into the checkout page. The draft is deleted as soon as the checkout page has created your payment.
How long we keep it
Leaderboard entries are kept while the board is published, unless you ask us to remove them or we need to retain limited records for security or legal reasons. Placement and payment records are retained only as long as needed to deliver the placement, resolve disputes and meet accounting obligations. Server logs are kept for a short period for security purposes.
Your rights
You can ask us to access, correct or delete the personal data we hold about you, and to remove a leaderboard result or a published placement detail. Send a direct message to @robin_type on X and we will handle the request, subject to any record we are legally required to keep and to data that is permanently written on a public blockchain.
Security
Private data is access-controlled, server credentials never ship to the browser, database tables are protected with row-level security, and the payment watcher authenticates with a server-only key. No system is perfectly secure; if you believe you have found a vulnerability, please tell us before disclosing it publicly.
Changes and contact
This policy is a working draft and will be updated as the project develops; the date at the top always reflects the current version. Questions: send a direct message to @robin_type on X.