This policy explains what personal data the clutx team ("we", "us") collects when you use clutx.site, why we collect it, and what rights you have. We are the data controller. To contact us about privacy, email [email protected].
1. What we collect
Information you give us
- Account data: email address, username and, if you set one, a password, which is stored as a secure hash.
- If you sign in with Google or Discord, or connect them to your account: we receive your email address, name, profile picture and account ID from that service. We never see your Google or Discord password. When you sign up this way, we use your name and picture to fill in your profile, and you can change or remove them at any time. If you sign up with Discord, we also use your Discord user ID to add a live Discord status widget to your page. If you connect Discord later, we only add it when you click "Add your live Discord status". You can remove the widget from the dashboard, and connect or disconnect Google and Discord in Dashboard → Account.
- Our Discord server: when you log in with or connect Discord, Discord asks whether we may add you to servers for you (the "guilds.join" permission). We use it only to add you to our official Discord server, so that our bot can see your live status. You can leave the server at any time. Your Discord status then stops showing on your page.
- Profile content: display name, bio, location, avatar, background, music, links, clips (the links and titles of up to 6 YouTube, Twitch, Medal or Streamable videos), colours and settings, and with Premium a cursor image and link style. This is public. Anyone with your link can see it.
- Widget details: the game and account names you add to widgets, such as your Riot ID, BattleTag, Epic username, Apex Legends player name and platform, FACEIT nickname, Discord user ID, SteamID64, and osu!, Chess.com, Roblox or GitHub username. These, and the stats we look up with them, are public on your profile. For Valorant, those stats include your last 5 competitive matches: the agent, map, kills, deaths, assists and round score of each.
- Loadout and setup (only if you use Dashboard → Loadout): the Valorant agents you main, your Valorant crosshair code, and the gear you list, with its category, name and the link you add, if any. These are public on your profile.
- Stream settings (only if you use Dashboard → Stream): your Twitch and Kick channel names, and your stream schedule: the days, start times and lengths you set, your time zone and the note you add. These are public on your profile, and so is whether you are live on those channels, with your stream title, game or category and viewer count.
- Link previews: when anyone shares a link to your profile, the app it is shared in (for example Discord, X, WhatsApp or iMessage) loads a preview image from us. It shows your display name, avatar, username, badges (and your milestone badges when there is room) and one stat from your page: your Valorant rank, Fortnite wins and K/D, best Chess.com rating, or your view count if you show it. Those apps may keep their copy of the preview after you change or delete your profile.
- /profile in our Discord server: anyone in our official Discord server can use the /profile command to post a page's public details in a channel: display name, @username, avatar, the first 200 characters of the bio, badges (and milestone badges), the same one stat as link previews and the accent colour, with a link to the page. Anyone can ask for a page by its username. Someone can also pick a member of the server, but a page only comes up that way when its owner linked that Discord account and the page shows that account's Discord widget, so /profile never tells anyone which page is yours unless your page already shows your Discord. /profile on its own shows the page linked to the Discord account of the person using it. Banned pages never come up. To answer, our bot gets from Discord the user ID of the person using the command and of the member they pick. It keeps the first in its memory for 10 seconds (one lookup per person every 10 seconds) and a page's public details for a minute, and stores neither. A posted card stays in the channel as it was, even after you change or delete your page: Discord keeps it under its own policy until someone deletes it (ask a moderator of the server, or us).
- Leaderboard (only if you turn it on): the "Show me on the leaderboard" setting in Dashboard → Widgets is off unless you switch it on. While it is on, our public leaderboard at clutx.site/leaderboard lists your display name, avatar, @username and badges, with a link to your page, next to the game account name and stats from each of your Valorant, Chess.com, Fortnite and FACEIT CS2 widgets (Valorant rank and RR, best Chess.com rating and whether it is rapid, blitz or bullet, Fortnite wins and K/D, FACEIT Elo and level), your position and when those stats were last looked up. For this we store a copy of the account name and stats as the stats service returned them to our servers whenever your page or your dashboard looks your stats up. The numbers never come from anything you type. Turn the setting off and save, and your leaderboard entries are deleted straight away.
- Invites: if you sign up with someone's invite link, we store who invited you (their account), when you signed up, and whether and when your invite counted. It counts once your email address is confirmed (or you signed up with Google or Discord) and your page has an avatar or a bio, plus a link or a widget other than the Discord status. The person who invited you then gets 7 days of Premium, for up to 4 invites a month, and we store how many days each invite gave them. To stop people inviting themselves, we compare the email addresses of the two accounts (ignoring capital letters, anything after a "+", and dots in Gmail addresses); we show them to nobody. So that each email address only counts once, an invite that counted keeps a one-way hash (a SHA-256 fingerprint) of your confirmed address, compared the same way, never the address itself; another account with the same address then doesn't count. The person who invited you only sees numbers (how many people signed up with their link, how many set up their page, the days they earned), never who. Whether a page has Premium, and until when for Premium from invites, can be read by anyone, like the Premium badge.
- Payment data: if you buy Premium, Stripe handles your card details. We only receive confirmation that you paid and a Stripe customer ID.
- Messages: anything you send us, such as support requests or abuse reports.
Information collected automatically
- Profile view counts: to count unique daily views, we create a one-way, salted hash of the visitor's IP address and the date. We do not store raw IP addresses. These hashes are only used to prevent double-counting and are deleted after 30 days.
- Link clicks: we count how many times each link is clicked. We do not record who clicked.
- GGs: visitors can tap GG on a profile once a day. To count each visitor only once, we create a one-way, salted hash of their IP address (for an IPv6 address, only its first half, the part one home or phone network shares), that profile and the date. We do not store raw IP addresses, and no cookie is set for it. These hashes are only used to refuse a second GG on the same day and are deleted after 2 days. When a GG is sent, our server also keeps that address (or its first half) in its memory for a short time, usually a minute or two, to limit how many GGs one connection can send. How many GGs a profile has is shown on it, unless its owner turns the GG button off. If you are logged in, your login cookie is sent with a GG and we only use it to stop you giving GGs to your own page. We do not record who gave a GG.
- Milestone badges: your page shows a badge when it passes 1,000, 10,000, 100,000 or 1,000,000 views, or 100, 1,000 or 10,000 GGs. We work them out from those counts each time your page or its link preview is drawn, so nothing more is stored. View milestones only show while you show your view count, and GG milestones while your GG button is on.
- Live Discord status: if you connect your Discord account to your profile, add the Discord widget, and are in our official Discord server, our bot in that server stores your current Discord status: your Discord user ID, username, display name, avatar, whether you are online, idle, on do not disturb or offline, the game or app you are using, your custom status, and the Spotify song, artist and album cover you are listening to. It is updated as your status changes and is public on that profile, like the widget itself. We only store this for people who connected their own Discord account and show the widget, never for other people in the server, and nobody can show someone else's Discord status.
- Language: to show the site in English, Spanish or Portuguese, our server reads the language your browser asks for (its Accept-Language setting) with each page request. It isn't stored. If you pick a language in the menu at the bottom of the page, on the log-in and sign-up pages or in Dashboard → Account, a cookie remembers your choice on your device (see our Cookie Policy).
- Technical logs: our hosting and database providers may keep short-lived server logs (IP address, request time, URL) for security and debugging.
- Cookies: only the ones the site needs, one that remembers the language you pick (once you pick one), and, after you open someone's invite link, one that holds their username for up to 24 hours so we know who invited you if you sign up. See our Cookie Policy.
2. Why we use it (legal bases)
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account and showing your public profile | Contract |
| Processing Premium payments | Contract, and legal obligation (tax records) |
| Showing your live Discord status, and adding you to our Discord server when you log in with or connect Discord | Contract |
| Showing public pages with /profile in our Discord server | Legitimate interest (showing pages their owners made public) |
| Listing you on the leaderboard, if you turn it on | Consent: turn the setting off at any time |
| Invites: remembering who invited you, giving them Premium days, refusing invites to yourself, and counting each email address once | Contract (invites are part of the Service), and legitimate interest (preventing abuse) |
| View and click analytics shown in your dashboard | Legitimate interest |
| Counting GGs once per visitor per day, and showing GG counts and milestone badges | Legitimate interest |
| Showing the site in your language, and remembering the language you pick | Legitimate interest |
| Security, fraud and abuse prevention, and moderation | Legitimate interest |
| Service emails such as account confirmation and policy changes | Contract |
| Complying with legal requests | Legal obligation |
We do not sell your personal data, sell or place ads, or use your data for advertising profiling. A clip's player comes from its platform, not from us, and once a visitor presses play it may show that platform's own ads (see section 3).
3. Who we share it with
We share data only with service providers (processors) that help us run the Service:
- Supabase: database, authentication and file storage
- Google and Discord: to sign you in, or to connect them to your account, if you choose to use them. Discord also runs our Discord server, where our bot reads the live status for Discord widgets and answers /profile (Discord receives and shows the public page details it posts, and loads the page's avatar to show it)
- Oracle Cloud (or our hosting provider): the server that runs the website and our Discord bot
- ngrok or Cloudflare: carry visitors' connections to that server (they see your IP address and the page you request, and don't store page contents for us)
- Stripe: payment processing, only if you buy Premium (we also tell it the language to show its checkout page in)
To show widget stats, our servers send the game or account name you entered to the matching stats service: HenrikDev API (Valorant), Riot Games (League of Legends), OverFast API (Overwatch 2, which reads Blizzard's public career pages), Apex Legends Status (Apex Legends), FACEIT (Counter-Strike 2), osu!, Fortnite-API.com, Steam, Chess.com, Roblox and GitHub. We only send the name you entered (and the region, platform or game mode you picked), never your email or other account details. For the LIVE banner, our servers send the Twitch or Kick channel name you entered to Twitch (the Twitch API) or Kick (the Kick Public API), about once a minute while your page is open somewhere and while you edit it in your dashboard, and show what they return: whether you are live, the stream title, game or category and viewer count. Visitors' browsers get this from us and load nothing from Twitch or Kick, unless they follow the banner's link. Your schedule is turned into each visitor's time zone in their own browser, and their time zone isn't sent to us. The Discord widget's live status comes from our own database: while someone views a page with a Discord widget, their browser keeps a connection open to Supabase to receive status changes, and it doesn't contact any third-party status service. When someone visits your profile or the leaderboard, their browser also loads images from Valorant-API (Valorant rank emblems and agent portraits), Blizzard (Overwatch rank icons and avatars), Apex Legends Status (Apex rank badges), osu!, Chess.com, Steam, Roblox and GitHub, Discord avatars from Discord (cdn.discordapp.com), Spotify album covers from Spotify (i.scdn.co), and profile pictures hosted by Google or Discord for people who signed in with them. Those services may see the visitor's IP address. Links in a Setup list go straight to the site you chose, so when a visitor follows one, that site sees their IP address and that they came from clutx.site. To list the agents you can pick in Dashboard → Loadout, our servers download Valorant-API's public list of agents, which sends nothing about you; their portraits then load from Valorant-API in your browser, like on profiles. On pages without Premium, our servers make a still copy (the first frame) of an uploaded avatar from our storage, so an animated one doesn't move, and visitors load that copy from us. Premium pages show it too, to visitors whose device asks for less motion and while a visitor has paused the page's animations. To draw link-preview images, our servers download your avatar from where it is hosted, fonts from Google Fonts and emoji images from jsDelivr. If your display name uses letters our own fonts don't have (for example Cyrillic, Chinese or Japanese), Google Fonts receives those letters so it can send a matching font, and jsDelivr sees which emoji are used. These requests come from our servers and include no visitor data. We may also disclose data if the law requires it, or to protect the rights and safety of our users.
Clips are shown as a play button and a title, drawn by our site. Nothing is loaded from YouTube, Twitch, Medal or Streamable until a visitor presses play. Then the visitor's browser loads that clip's player straight from the platform (for YouTube, its privacy-enhanced player at youtube-nocookie.com). From that moment the platform receives the visitor's IP address and browser details, knows which clip is playing and that it is shown on clutx.site, and may set cookies or use similar storage under its own privacy policy. See our Cookie Policy. We don't receive any data back from these players.
4. International transfers
Our providers may process data outside your country, including in the United States. Where required, transfers are protected by Standard Contractual Clauses or equivalent safeguards.
5. How long we keep it
- Account and profile data: until you delete your account.
- Uploaded files: deleted when you save your page after replacing or removing them, or when you delete your account. Files you uploaded but never saved are deleted the next time you save, once they are an hour old.
- View de-duplication hashes: 30 days.
- GG de-duplication hashes: 2 days. The GG count itself stays on your profile until you delete your account.
- Email sign-ups that are never confirmed: deleted after 2 days, with their profile and username.
- Live Discord status: only while a profile shows a Discord widget with your ID and you are in our Discord server. Our bot deletes it within about a minute after no profile shows that ID any more (the widget is removed, the account is deleted or the profile is banned) or you leave the server.
- Leaderboard entries: only while the setting is on and the widget is on your page. They are deleted as soon as you turn the setting off, remove or change that widget, are banned or delete your account. Entries whose stats haven't been looked up for 30 days (because nobody opened your page or your dashboard, or the lookup kept failing) are hidden from the leaderboard and deleted by a nightly clean-up. The leaderboard page itself is cached for up to a minute.
- Live status for the LIVE banner: kept in our server's memory for about a minute, then asked again. It is never stored in our database. Your channel names and schedule stay until you remove them in Dashboard → Stream or delete your account.
- Loadout and setup: until you remove them in Dashboard → Loadout or delete your account.
- Invites: while the account that invited you exists. If you delete your account before your invite earned them Premium days, the record of it is deleted with your account. Once it has earned days, the record stays with their account, so the monthly limit can't be dodged by deleting accounts, but it no longer points to you: only the one-way hash of your email address stays with it, so the same address can't count again. The invite cookie: 24 hours at most.
- /profile in Discord: the Discord user ID of whoever used it, 10 seconds in our bot's memory, and a page's public details, a minute; neither is stored. Cards already posted stay in Discord until someone deletes them.
- The language cookie: on your device, for a year after you last picked a language, or until you delete it.
- Link-preview images: our servers and hosting provider cache each one for about 10 minutes, then draw it again from your current profile. Apps where your link was shared keep their own copies under their own policies.
- Still copies of avatars: kept by our servers and visitors' browsers for up to a day, then made again from the avatar your page shows.
- Payment records: as long as tax law requires, usually 6–10 years. Stripe keeps these.
- Backups: up to 30 days after deletion.
6. Your rights
Depending on where you live (for example, under GDPR, UK GDPR or CCPA/CPRA), you have the right to:
- access the personal data we hold about you and get a copy of it;
- correct inaccurate data (you can edit most of it yourself in the dashboard);
- delete your data. Use Dashboard → Account → Delete my account, or email us;
- object to or restrict certain processing;
- receive your data in a portable format;
- complain to your local data-protection authority.
To use any of these rights, email [email protected]. We will reply within 30 days. We do not discriminate against you for using your rights.
7. Children
The Service is not for children under 13. We do not knowingly collect data from them. If you believe a child under 13 has created an account, email us and we will delete it.
8. Security
We use HTTPS, hashed passwords, row-level database security and restricted access to production systems. No system is 100% secure, so please use a unique password.
9. Changes
We will post any changes on this page and update the date at the top. If we make material changes, we will notify you by email.