Privacy Policy

Last updated: 2026-07-19

Who we are

The $MOTION protocol (“the protocol”, “we”) operates this dashboard, an ingestion service that reads public X (Twitter) activity, and an on-chain burn pipeline. Questions and requests: email contact@motion.tips, contact the protocol’s official X account, or open an issue on the protocol’s GitHub repository.

What we collect

Public X activity

The protocol ingests public X content related to the tracked token and account: posts, replies, quotes, retweets, engagement counts, and public profile fields (handle, display name, follower counts, account-creation date, avatar URL). This data is obtained through a third-party X data provider (twitterapi.io) and is already public at its source. It is used to score engagement and compute protocol burns.

Wallet-to-X linking

If you choose to link a wallet, we store: your wallet address, your X account identifier and handle, the OAuth subject returned by X, and timestamps. Your Sign-In-With-Ethereum (SIWE) signature is verified once to prove wallet control but is not retained. We do not store your X password or long-lived X access tokens, and we never gain the ability to post from your account.

Cookies

Two cookies only, both HttpOnly and signed: __Host-motion_session (your secure linking session; local development uses motion_session) and motion_oauth (a transaction cookie that expires within minutes during the X OAuth flow). No advertising or cross-site tracking cookies.

Abuse prevention

Our application abuse-prevention records do not store raw network addresses. In live deployments, the trusted gateway transforms a client address into a keyed pseudonym that rotates daily. Authentication challenges use that pseudonym only during their ten-minute validity window and delete it immediately after successful verification; expired challenges and per-minute rate limit records are removed through bounded cleanup.

How it is used

Engagement data drives the protocol’s public scoring, leaderboard, graph, and burn calculations. Link data attributes engagement to a wallet so rewards can reach you. We do not sell personal data, and we do not use it for advertising.

Retention and deletion

You may request unlinking and deletion of your link record at any time via the contact channels above. On a verified request we remove the identity link (wallet address, OAuth subject, SIWE proof) from the live database.

Two categories cannot be erased and are excluded from deletion: on-chain transactions (public, immutable blockchain records) and already-published burn-evidence artifacts, which are part of the protocol’s public financial audit trail. Public X content remains public at its source under X’s own terms; deleting your content on X removes it from future ingestion.

Third parties

Data is processed with: twitterapi.io (public X data source), X Corp. (OAuth identity verification), and blockchain RPC providers (transaction broadcast and reads). Each operates under its own terms and privacy policy.

Changes

Material changes to this policy are published on this page with an updated date above.