LegalPrivacy policy
Draft for legal review. Fields in brackets are filled in before launch.
Last updated October 2, 2026
Privacy policy
This policy explains what personal data Clmify collects, why we need it and what you can do with it. We collect only what the Service needs to work.
1. Who is responsible
The controller of your personal data is [seller's full legal name], [country]. Contact for any privacy question: [privacy email].
2. What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Email, password hash, language | Your account and sign-in. We never store your password itself, only a hash of it. | Contract |
| Discord or Google account ID, email, name and avatar | Sign-in with Discord or Google, if you choose it. Access tokens are stored encrypted. | Contract |
| Scans, uploaded lists, hits, watchlist, drop preferences | The core features of the Service. | Contract |
| Notification settings: Discord user ID, webhook URL, Telegram chat ID, browser push subscription | Sending alerts where you asked for them. Webhook URLs are stored encrypted. | Contract |
| Plan, payments and check balance history | Billing, refunds and accounting. We never see your full card number. | Contract, legal obligation |
| IP address and browser details of a session | Keeping your account secure, limiting sign-up and sign-in attempts. | Legitimate interest |
| IP address of a guest check, stored only as a salted hash | The limit of 5 free checks a day. | Legitimate interest |
| Pages viewed and actions in the Service | Product analytics, see section 5. | Consent or legitimate interest |
| Messages you send us | Answering you. | Contract, legitimate interest |
To check a name, we send only the name itself to Discord. Nothing about you is sent with it.
We use your country, detected from your IP address, to show which payment methods are available to you.
3. Where your data is stored
Our servers are in the European Union (Amsterdam, the Netherlands). Some providers listed below process data outside the EU. In that case transfers rely on an adequacy decision of the European Commission or the EU Standard Contractual Clauses.
4. Who processes data for us
| Provider | What for | Location |
|---|---|---|
| Timeweb Cloud | Server hosting | Netherlands |
| Cloudflare | Network protection, bot checks (Turnstile), backup storage | Global network, USA |
| Paddle | Card payments as Merchant of Record | United Kingdom |
| CryptoCloud | Crypto payments | [CryptoCloud location] |
| PostHog | Product analytics | EU (Germany) |
| [email provider] | Sending emails | [location] |
| Discord | Sign-in with Discord, alerts through our bot or your webhook | USA |
| Sign-in with Google | USA | |
| Telegram | Alerts through our bot, if you connect it | [location] |
Paddle acts as an independent controller for the payment data it collects at checkout. Its own privacy notice applies to that data.
Error reports from our servers contain only technical details. Before a report is sent, we remove email addresses, IP addresses, usernames and request contents.
We do not sell your data and do not share it for advertising.
5. Analytics
We use PostHog Cloud EU to understand how the Service is used. Requests to PostHog go through our own domain. We do not use Google Analytics or advertising trackers.
If you are in the EU, the EEA or the UK, PostHog sets no cookies until you accept analytics in the cookie banner. Without consent, visits are counted without cookies, using a hash that changes every day and cannot recognize you on later days. Details are in the Cookie policy.
Some events are recorded on our server and linked to your account: sign-up, payment, plan change, refund, scan started and finished, hit found, drop offered and claimed.
6. How long we keep data
| Data | How long |
|---|---|
| Account, scans (without uploaded lists), hits, watchlist | Until you delete your account |
| Uploaded lists and the retry queue of a scan | 30 days after the scan ends |
| Sessions | 30 days |
| Guest checks (salted IP hash) | 7 days |
| Shared cache of name statuses, not linked to you | 7 days after the last check of the name |
| Notification log | 90 days |
| Payment provider events | 1 year |
| Payments and check balance history | Kept for accounting; anonymized when you delete your account |
| Hash of your email after account deletion | 180 days |
| Database backups | 30 days |
Old data is removed automatically once a day.
7. Deleting your account
You can delete your account in settings at any time. When you do:
- your card subscription is canceled at once;
- your account, scans, hits, watchlist and notification settings are deleted;
- payment records are anonymized and kept only for accounting;
- a hash of your email address is kept for 180 days. If you sign up again with the same email in that time, the new account gets no Free monthly checks and no right to a refund. This prevents abuse of the Free plan and of refunds.
Deleted data disappears from backups within 30 days.
8. Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format and withdraw your consent at any time. Write to [privacy email] from the email of your account. We answer within one month.
You can also lodge a complaint with the data protection authority of your country.
9. Security
The site works only over HTTPS. Passwords are stored as hashes. Access tokens, webhook URLs and other secrets are encrypted. You can turn on two-factor sign-in, and our staff always use two-factor authentication for admin access.
10. Children
The Service is not meant for children under 16. If you believe a child has given us personal data, write to us and we will delete it.
11. Changes to this policy
We may update this policy. We tell you about important changes by email or with a notice on the site before they take effect.
The English version of this policy is the binding one. Versions in other languages are translations for your convenience.