clmify
DiscordRobloxsoon
Sign inStart free

LegalPrivacy policy

Draft for legal review. Fields in brackets are filled in before launch.

Last updated October 2, 2026

Privacy policy

This policy explains what personal data Clmify collects, why we need it and what you can do with it. We collect only what the Service needs to work.

1. Who is responsible

The controller of your personal data is [seller's full legal name], [country]. Contact for any privacy question: [privacy email].

2. What we collect and why

DataWhyLegal basis
Email, password hash, languageYour account and sign-in. We never store your password itself, only a hash of it.Contract
Discord or Google account ID, email, name and avatarSign-in with Discord or Google, if you choose it. Access tokens are stored encrypted.Contract
Scans, uploaded lists, hits, watchlist, drop preferencesThe core features of the Service.Contract
Notification settings: Discord user ID, webhook URL, Telegram chat ID, browser push subscriptionSending alerts where you asked for them. Webhook URLs are stored encrypted.Contract
Plan, payments and check balance historyBilling, refunds and accounting. We never see your full card number.Contract, legal obligation
IP address and browser details of a sessionKeeping your account secure, limiting sign-up and sign-in attempts.Legitimate interest
IP address of a guest check, stored only as a salted hashThe limit of 5 free checks a day.Legitimate interest
Pages viewed and actions in the ServiceProduct analytics, see section 5.Consent or legitimate interest
Messages you send usAnswering you.Contract, legitimate interest

To check a name, we send only the name itself to Discord. Nothing about you is sent with it.

We use your country, detected from your IP address, to show which payment methods are available to you.

3. Where your data is stored

Our servers are in the European Union (Amsterdam, the Netherlands). Some providers listed below process data outside the EU. In that case transfers rely on an adequacy decision of the European Commission or the EU Standard Contractual Clauses.

4. Who processes data for us

ProviderWhat forLocation
Timeweb CloudServer hostingNetherlands
CloudflareNetwork protection, bot checks (Turnstile), backup storageGlobal network, USA
PaddleCard payments as Merchant of RecordUnited Kingdom
CryptoCloudCrypto payments[CryptoCloud location]
PostHogProduct analyticsEU (Germany)
[email provider]Sending emails[location]
DiscordSign-in with Discord, alerts through our bot or your webhookUSA
GoogleSign-in with GoogleUSA
TelegramAlerts through our bot, if you connect it[location]

Paddle acts as an independent controller for the payment data it collects at checkout. Its own privacy notice applies to that data.

Error reports from our servers contain only technical details. Before a report is sent, we remove email addresses, IP addresses, usernames and request contents.

We do not sell your data and do not share it for advertising.

5. Analytics

We use PostHog Cloud EU to understand how the Service is used. Requests to PostHog go through our own domain. We do not use Google Analytics or advertising trackers.

If you are in the EU, the EEA or the UK, PostHog sets no cookies until you accept analytics in the cookie banner. Without consent, visits are counted without cookies, using a hash that changes every day and cannot recognize you on later days. Details are in the Cookie policy.

Some events are recorded on our server and linked to your account: sign-up, payment, plan change, refund, scan started and finished, hit found, drop offered and claimed.

6. How long we keep data

DataHow long
Account, scans (without uploaded lists), hits, watchlistUntil you delete your account
Uploaded lists and the retry queue of a scan30 days after the scan ends
Sessions30 days
Guest checks (salted IP hash)7 days
Shared cache of name statuses, not linked to you7 days after the last check of the name
Notification log90 days
Payment provider events1 year
Payments and check balance historyKept for accounting; anonymized when you delete your account
Hash of your email after account deletion180 days
Database backups30 days

Old data is removed automatically once a day.

7. Deleting your account

You can delete your account in settings at any time. When you do:

  • your card subscription is canceled at once;
  • your account, scans, hits, watchlist and notification settings are deleted;
  • payment records are anonymized and kept only for accounting;
  • a hash of your email address is kept for 180 days. If you sign up again with the same email in that time, the new account gets no Free monthly checks and no right to a refund. This prevents abuse of the Free plan and of refunds.

Deleted data disappears from backups within 30 days.

8. Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format and withdraw your consent at any time. Write to [privacy email] from the email of your account. We answer within one month.

You can also lodge a complaint with the data protection authority of your country.

9. Security

The site works only over HTTPS. Passwords are stored as hashes. Access tokens, webhook URLs and other secrets are encrypted. You can turn on two-factor sign-in, and our staff always use two-factor authentication for admin access.

10. Children

The Service is not meant for children under 16. If you believe a child has given us personal data, write to us and we will delete it.

11. Changes to this policy

We may update this policy. We tell you about important changes by email or with a notice on the site before they take effect.

The English version of this policy is the binding one. Versions in other languages are translations for your convenience.