whomst.

Privacy Policy

Last updated: August 25, 2026

What we collect

Account data: your name, email, headline, role, company, and an optional photo. If you sign in or verify with LinkedIn, we receive your name, email, and profile photo from LinkedIn via OpenID Connect — we do not access your connections or anything else, and we never scrape LinkedIn. Marketplace data: the bounties, pledges, claims, nominations, and vouches you submit. Usage data: product analytics events (page and funnel activity) tied to your account.

How it's used

To run the marketplace: showing your profile where the product requires it (see below), matching bounties to claimants, sending transactional email (sign-in links, renewal and confirmation notices), and processing payments. Submissions are evaluated by an automated review system (an AI model with human oversight) to screen for prohibited categories, spam, and sales intent; its reasoning is visible only to administrators.

What's public

Bounty posters appear publicly on their bounty. On pooled bounties, every pledge's amount and question are public. Your name and photo are shown alongside them only if you choose so at pledge time — otherwise you appear as Anonymous, and your identity is shared only with the person who accepts the bounty. Claimants are private to the bounty poster unless selected, at which point name, photo, and headline appear on the bounty page.

Who processes it

Supabase (database, authentication, file storage), Stripe (payments — whomst never stores card numbers), Anthropic (automated review of submission text), Resend (email delivery), and Vercel (hosting). Each receives only what it needs to perform its function. We do not sell personal data.

Retention and deletion

Completed bounties remain public as a permanent record of the transaction. You can request deletion of your account and personal data by email; data needed for financial records is retained as required by law.

Contact

daniel.m.son21@gmail.com