This policy explains how clutx.site uses cookies and similar technologies such as local storage. In short: we only use what the site needs to work, one cookie that remembers the language you pick (only once you pick one), and, if you open someone's invite link, one cookie that remembers who invited you while you sign up. We don't use advertising cookies, cross-site tracking or third-party analytics. Clips on profiles work differently: pressing play on one loads that platform's own player, which may set the platform's own cookies (see section 3). Nothing loads from the platform before then.
1. What are cookies?
Cookies are small text files a website stores in your browser. Local storage is a similar browser feature. Both let a site remember things, such as the fact that you are logged in.
2. Cookies we use
| Name | Type | Purpose | Duration |
|---|---|---|---|
sb-*-auth-token | Strictly necessary (first-party cookie) | Keeps you logged in to your dashboard and secures your session. Set by Supabase Auth only when you log in. | Up to 400 days, renewed while you use the site. Removed when you log out |
sb-*-code-verifier | Strictly necessary (first-party cookie) | Set by Supabase Auth while a sign-in is in progress: when you log in with or connect Google or Discord, sign up with email, or ask for a password reset link. It holds a one-time secret that lets us finish that sign-in securely when you come back to the site (which is why a reset link only works in the browser that asked for it). | The secret stops working once used. The cookies are cleared when you log out, or after 400 days at most |
lang | Strictly necessary (first-party preference cookie), only after you pick a language | Set when you choose a language in the menu at the bottom of the page, on the log-in and sign-up pages or in Dashboard → Account. It holds only the language you chose (en for English, es for Español, pt-BR for Português (Brasil)) so every page shows in it. Until you pick one, each page follows the language your browser asks for, which isn't stored. It isn't used for anything else and is never sent to anyone else. To go back to your browser's language, delete it in your browser settings. | 1 year, renewed each time you pick a language |
invited_by | Functional (first-party cookie), only after you open an invite link | Set when you open someone's invite link (a link to clutx.site ending in ?ref= and their username). It holds only that username, so that if you sign up, also with Google or Discord, we know who invited you (see "Invites" in our Privacy Policy). It is only read when you sign up and is never sent anywhere else. To remove it, press Remove next to "Invited by" on the sign-up page. | 24 hours, or until you finish signing up or press Remove |
cookie-notice-v1 | Strictly necessary (local storage) | Remembers that you closed the cookie notice so it doesn't appear again. | Until you clear your browser storage |
setup-checklist-v1:<account ID> | Strictly necessary (local storage) | Only in your dashboard, and only once you copy or share your page link there (the top bar's copy button or the Share panel) or collapse, hide or reopen the "Set up your page" checklist: remembers whether you shared your link and whether the checklist is collapsed or hidden, so it doesn't ask again. It stays in your browser and is never sent to us. | Until you clear your browser storage |
__stripe_mid, __stripe_sid | Strictly necessary (third-party, Stripe) | Set by Stripe only on its checkout page if you buy Premium, for fraud prevention. | Up to 1 year / 30 minutes |
Under EU/UK ePrivacy rules, strictly necessary cookies do not need consent. The language cookie is only set when you pick a language, and only remembers that choice. The invite cookie is only set when you open an invite link, and only does what that link is for: telling us who invited you if you sign up. It isn't used to track you, and you can remove it. That's why we show a notice rather than an accept/reject choice. Clip players (section 3) only load when a visitor chooses to play a clip.
3. Profile pages and third-party content
User profiles and the leaderboard may load content from third parties: game images from Valorant-API (rank emblems and agent portraits, which Dashboard → Loadout also shows), Blizzard (Overwatch), Apex Legends Status, osu!, Chess.com, Steam, Roblox and GitHub; for the live Discord status, Discord avatars from cdn.discordapp.com and Spotify album covers from i.scdn.co; profile pictures hosted by Google or Discord (for people who signed in with them); and media from our storage provider. The Discord status itself comes from our own database: the page keeps a connection open to our database provider (Supabase) to receive changes, without cookies. These requests may expose your IP address to those services, but we don't allow them to set tracking cookies through our site. The LIVE banner and stream schedule are drawn by our site: the live status comes from our own server (which asks Twitch and Kick), so nothing loads from Twitch or Kick and they can't set cookies, unless you follow the banner's link to the stream. The Copy button next to a crosshair code only writes to your clipboard when you press it, and stores nothing. View counts and the GG button use a hashed identifier that is not stored in a cookie, and the GG button stores nothing in your browser (if you are logged in, your login cookie is sent with a GG only so you can't GG your own page). See our Privacy Policy.
Clips
Profiles can show clips from YouTube, Twitch, Medal and Streamable. Until a visitor presses play, a clip is just a play button and a title drawn by our site: nothing is requested from the platform and it can't set cookies. Pressing play loads that platform's player in a frame on the page. The player comes from the platform, not from us, and it may set its own cookies or use local storage, for example to remember your volume, count views, prevent abuse or, depending on the platform, for analytics or advertising. Those cookies are covered by the platform's own policy. We can't read or control them.
| Platform | Player loads from | Their policy |
|---|---|---|
| YouTube | www.youtube-nocookie.com (YouTube's privacy-enhanced mode) | Google Privacy Policy |
| Twitch | clips.twitch.tv | Twitch Privacy Notice |
| Medal | medal.tv | Medal Privacy Policy |
| Streamable | streamable.com | Streamable Privacy Policy |
If you don't want these cookies, don't press play on clips, or block third-party cookies in your browser.
4. Managing cookies
You can block or delete cookies in your browser settings. If you block the authentication cookie you will not be able to log in, but public profiles will still work.
5. Changes
If we ever add non-essential cookies (for example, analytics), we will update this policy and ask for your consent before setting them.
6. Contact
Questions? Email [email protected].