Privacy Policy
Last updated: September 28, 2026
What this site stores, why, and what you can do about it. It covers commited.wtf.
1. What you give us
To have an account
- An email address. Used to sign in, to confirm it is yours, and to reach you about the account.
- A username, and whatever display name you pick.
- A password, kept only as a scrypt hash. Nobody here can read it back.
- If you turn on two-factor: a shared secret and a set of recovery codes, both kept server-side.
To have a page
Everything you put on it — bio text, links, socials, avatar, background, music, cursor,
favicon, badges you made, projects, skills, and every appearance setting. All of it is
public, because a public page is what it is for.
As you use it
- A session cookie. Signed, HTTP-only, and required for the dashboard to work.
- A view count per page, deduplicated with a short-lived fingerprint made from the request's
address and browser string. It exists to stop one person counting as fifty, and is not
used to build a profile of anybody.
- The statistics a page's owner sees in their dashboard: views, unique visitors and link
clicks per day for the last 120 days, and running totals of which links were pressed,
which country visitors came from, which site sent them and whether they were on a phone,
tablet or computer. These are counts, not records — nothing in them identifies a visitor,
no cookie is set for them, and the country is the one our host reads from the connection,
not a location you are asked for. Only the page's owner and the site's admins see them.
- Rate-limiting counters on sign-in and other sensitive routes.
2. What other services tell us
Discord
If you link Discord, we receive your Discord id, username, avatar, whether you have Nitro,
and the connections you have already set to visible on your Discord profile. Ones you have
hidden there are in the response and are discarded rather than stored — publishing those
would be publishing something you declined to publish.
The coloured status dot comes from this project's own Discord server, through the widget
Discord publishes for it. That widget lists who is online under an anonymous id, and an
account is matched to it only when exactly one member carries that name. Not being in that
server means no dot, and nothing else.
Other accounts you connect
For a sign-in connector we keep the service's id for your account and the display name it
gives us. For the code-in-your-bio route we read that public profile once, check the code
is there, and keep the same two things. No password and no access token is stored beyond
the moment it is used.
3. What we send elsewhere
- Brevo delivers email — confirmation codes, and notices about your account.
- Cloudflare Turnstile checks that sign-ups are people. It sees the challenge, not the form.
- Discord is where the shop takes payment, in a ticket on our server. Nothing about a
payment passes through this site, and no card details ever reach us.
- Vercel hosts the site; Postgres stores the accounts, and **S3-compatible object
storage (with Vercel Blob or Supabase** on some deployments) holds the uploads.
Nothing is sold, and nothing is handed to anybody else except where the law requires it or
where somebody is being harmed.
4. What visitors see
The page, and everything on it. Discover and the leaderboard list pages their owners have not
hidden. Email addresses appear on no public page, in no API response, and in no export.
If you embed something — a Spotify player, a YouTube video, a widget that fetches from
another service — that service sees your visitors when it loads. Its rules apply to that,
not ours.
5. Cookies
Two: the session cookie, and one that remembers you closed the cookie notice. Both are listed
by name at /cookies. There is no advertising, no analytics script and no third-party
tracker on any page of this site. Some settings are kept in your own browser's
storage, which never leaves it.
6. How long it is kept
Account and page data stay while the account does. Ask for deletion and the account and its
page go within 30 days, apart from anything we have to keep — an audit line about a
suspension, for instance, or a record needed to deal with fraud. View fingerprints expire
on their own within a day.
7. What you can do
- See and change everything about your page from the dashboard
- Download nothing you did not put there — there is nothing else
- Ask for the account to be deleted, and it will be
- Ask what is held about you, and get a straight answer
Write to the address at the bottom. Depending on where you live you may have these rights by
law; you have them here either way.
8. Security
Passwords are hashed, sessions are signed, two-factor is available, and the routes that
matter are rate-limited. The site is small and run by people, not by a security department —
use a password you use nowhere else.
If you find something wrong, report it through the bug form or by email rather than by
demonstrating it on somebody else's account.
9. Under-13s
The site is not for children under 13 and we do not knowingly keep anything about one. Tell
us and the account goes.
10. Where it runs
On servers outside your country, most likely. Using the site means that is acceptable to you.
11. Changes
This page changes when the site does, and the date at the top says when.
12. Getting in touch
larpbioo@gmail.com