Privacy Policy
Last updated October 10, 2026
We collect as little as we can. Here is exactly what we store and why.
When you sign in
- If you sign up with a password: your username, email and a salted scrypt hash of your password (never the password itself).
- If you use Google or Discord: your account ID there, display name, avatar and verified email address.
- If you add a passkey: its public key and a device label. Your fingerprint or face data never leaves your device.
- If you connect Spotify: your Spotify user ID, display name and access tokens (encrypted), used only to show what you're listening to. Disconnect any time to delete them.
- A signed session cookie that keeps you logged in for 30 days.
What you add
Your profile details, links, social handles, appearance settings and any files you upload. These are public on your page, except your email.
Visitor analytics
- When someone views your page or clicks a link we record the time, referring website, device type (desktop, mobile or tablet) and country if our host provides it.
- To count unique visitors we store a one-way hash of the visitor's IP address and browser, salted and rotated daily. We never store IP addresses themselves.
Third parties
- Google and Discord, if you choose to sign in with them.
- Lanyard (api.lanyard.rest), if you enable Discord presence — visitors' browsers fetch your public status from it.
- Spotify, if you connect it — we read what you're currently or recently playing.
- LRCLIB (lrclib.net), to look up lyrics for the song on your page. Only the song title, artist, album and length are sent.
- Discord's and Spotify's image CDNs, for avatars and album art shown in your presence card.
Your choices
Export all your data as JSON or delete your account at any time from Settings.