What we read, and what we leave alone
ROUTEPAY needs to know that a page is yours before paying you. This is everything it reads to find out, and what happens to it after.
The short version
ROUTEPAY routes the fees of a coin on Robinhood Chain to destinations chosen by its creator, including pages on other platforms. To pay the owner of a page we need to know one thing: that the person claiming it controls it. We read the minimum that answers that question, and nothing else.
- We never post, follow, message or change anything on your accounts. Every access we ask for is read only.
- We do not keep the access a platform gives us. It is used once, for a few seconds, then discarded.
- We do not run advertising or analytics trackers, and we do not sell or rent data.
- Payments happen on a public blockchain. What is written there is public and cannot be erased by anyone, including us.
When you connect a page
Connecting a page sends you to the platform, which asks you to approve a read-only access. When you come back, we read the identity of the account, then discard the access token. It is never written to our database or to a log.
- YouTube
- The channels of the Google account: channel id, handle, title and picture. Scope: youtube.readonly.
- GitHub
- The account and the organisations it owns: id, login, name and picture.
- X
- The account: id, username, name and picture.
- The professional account: id, username, name and picture. Scope: instagram_business_basic.
- Twitch
- The channel: id, login, name and picture.
- The Pages the account manages: id, username, name and picture.
- TikTok
- The account: id, username, name and picture.
- A domain
- No sign-in. We look up a public DNS record that you add to the domain.
We do not read your videos, posts, messages, followers, e-mail address, contacts, or anything private. The list above is all of it.
What we read is kept in a signed cookie in your browser for 30 minutes, so the page can show what waits for you. The public picture of the page is copied to our server, so its profile here shows its own face. The rest is stored on our side only if you claim, as described below.
When you claim
Claiming binds a page to the wallet that will be paid. At that moment we store:
- The platform, the id of the account on that platform, its handle, its display name and the address of its picture.
- The address of the wallet you chose, and the time of the claim.
- How the page was proved: a platform sign-in, or a DNS record.
A claimed page and the wallet it pays are shown on the public profile of the page. Payments to it are transactions on Robinhood Chain and are public.
Google and YouTube
ROUTEPAY uses YouTube API Services to confirm that you own a channel. By connecting a channel you also agree to the YouTube Terms of Service, and the Google Privacy Policy applies to the data Google holds.
ROUTEPAY's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. The information is used only to identify the channel being claimed. It is not used for advertising, not transferred to others, not used to train models, and not read by a person unless you ask us for help or the law requires it.
Wallets and the dashboard
Signing in with a wallet means signing a message. It costs no gas and gives us no ability to move your funds. We store the address of the wallet and keep you signed in with a signed cookie for 30 days.
A creator who sets up routing stores their configuration with us: the coin, the destinations and their shares. If you use the Telegram bot we also store your Telegram user id and username, to know whose configuration it is.
Some wallets are operated by ROUTEPAY: the wallet that collects the fees of a coin, and the vault of each page. Their keys are stored encrypted.
Delete your data
Write to hello@routepay.dev from a contact we can match to the page, or after connecting the page again so we know it is yours. Tell us the platform and the handle. We answer within 30 days.
- We erase the account id, the display name and the picture we hold for the page, and unbind the wallet.
- The cookies can be erased at any time from your browser, or with "Disconnect" on the claim page.
- The access you approved can be removed on the platform itself, in the settings of your account, under connected apps.
- Payments already made stay on the blockchain. The record that a public page received a given amount stays too: it is the accounting of the coin that paid it.
Security, age and changes
The site is served over HTTPS. Keys are stored encrypted, platform tokens are not stored at all, and cookies are signed so they cannot be forged.
ROUTEPAY is not meant for anyone under 18, and we do not knowingly collect data from them.
When this page changes, the date at the top changes with it. A change that widens what we read or keep is announced on routepay.dev before it applies.