BASEPAINT LIVE ROOMS / PRIVACY

Privacy policy

Effective August 4, 2026Version 1.0
01

Who operates the extension

BasePaint Live Rooms is an independent, open-source hackathon project maintained by XipleETH. It is not operated by or affiliated with BasePaint. Questions or privacy requests can be submitted through the project's public support page.

02

Single purpose

The extension adds verified live artist rooms and per-artist saved-pixel layers to the BasePaint Paint page. It does not alter transactions, take custody of assets, access seed phrases, or provide financial services.

03

Information processed

Public wallet and artist information

The extension reads the wallet already connected to BasePaint, public blockchain contribution data, and public ENS or Basename profile information. A broadcaster's public wallet address and display name are shown to viewers so the room can be attributed to the correct artist.

Wallet signature

When an artist chooses to go live, the wallet is asked to sign a short-lived BasePaint Live sign-in message. The signature, wallet address, room name, and timestamp are sent over HTTPS to the BasePaint Live API only to verify control of the wallet and BasePaint Brush ownership. BasePaint Live does not request or receive private keys or seed phrases, and does not store the signature in an application database.

Camera, microphone, and screen

These sources are accessed only after the user explicitly selects a sharing control and approves the browser prompt. Camera and microphone capture runs in a temporary offscreen extension document because the BasePaint page disables those devices in its Permissions Policy; that document closes when both devices stop or the BasePaint tab closes. Selected media is transmitted to room viewers through LiveKit using encrypted WebRTC transport. BasePaint Live does not record or store the media. The broadcaster can stop any source or end the room at any time.

Operational information

The service processes short-lived room tokens, room names, track state, and participant counts to operate live rooms. Hosting and realtime providers may process standard connection information such as IP address, user agent, timestamps, and diagnostic logs under their own policies.

04

Services involved

BasePaint Live communicates only with services necessary for its disclosed purpose:

  • BasePaint and its public GraphQL indexer for canvas, contribution, and artist data.
  • Base network public RPC to verify BasePaint Brush ownership.
  • web3.bio to resolve public ENS and Basename labels.
  • LiveKit Cloud to route realtime audio and video.
  • Vercel to host the website and issue short-lived room tokens.
05

Use, sharing, and retention

Information is used only to provide and secure live artist rooms, saved-pixel views, and related reliability features. It is not sold, used for personalized advertising, used to determine creditworthiness, or shared for unrelated purposes.

BasePaint Live has no application database for wallet signatures or media. Room tokens expire, live media ends when tracks or rooms close, and in-memory interface state is discarded when the page closes. Infrastructure providers may retain limited operational logs according to their security and retention practices.

06

User controls and security

Users control every sensitive action through the browser and wallet interfaces. They can reject a signature, deny media access, stop sharing, end a room, revoke browser permissions, or uninstall the extension. Personal or sensitive information is transmitted only through HTTPS, WSS, or encrypted WebRTC transport.

07

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. BasePaint Live does not currently request access to Google account APIs.

08

Changes to this policy

If the extension's data practices change, this policy and the Chrome Web Store disclosures will be updated before the changed version is released. Material changes will also be disclosed in the extension interface or release notes when appropriate.