Account and profile information
Accounts may include an email address held by the authentication provider, a unique public username, display name, avatar and profile biography. Email addresses are not published on creator profiles.
Optional Clash profile verification
A creator may choose to verify a Clash of Clans player profile. Verification uses the player tag and the temporary API token shown inside the game. The in-game API token is sent directly to the server for one verification request and is never written to the platform database, logs or public profile.
After successful verification, the platform may store and display selected public game data such as player tag, player name, Town Hall level, trophies, war stars, current clan, clan badge, clan level, member count and clan role. Creators control whether verified player and clan information appears publicly and can unlink it later.
Clan recruitment
Clan promotion is optional. A creator may advertise only the current clan returned for their verified player. The platform does not accept a manually typed clan identity as verified. Clan information may be hidden when it has not been refreshed recently, and it updates when the creator refreshes their linked profile.
Base submissions and community activity
Submitted bases include layout information, a processed screenshot and moderation history. Community activity may include comments, favorites, ratings, follows and reports. Public creator statistics may summarize approved uploads, downloads, ratings and follower counts. Private account notifications may record moderation decisions, comments, follows, reports and platform announcements so users can review important updates.
Transactional email
The platform may email administrators about new submissions and email creators when a submission is approved or rejected. The email provider receives the destination address and message content required for delivery. Limited delivery records—such as recipient, template, provider message identifier, status and error details—are retained for troubleshooting and are visible only to administrators.
Security and abuse prevention
Limited technical information is processed for bot protection, rate limiting, account protection and fraud prevention. Network and browser signals are transformed into keyed hashes before being used in short-lived rate-limit buckets. Private account-security activity may also record a sign-in or password-change time, IP address, approximate IP-based city or country, browser, operating system, device category and sign-in method. These records are visible only to the account owner and authorized service administrators and are retained while reasonably needed for security and incident review.
New or unusual device activity may trigger an in-site alert and transactional email. Approximate location is inferred from network information and is not an exact street address. A random necessary-device cookie helps distinguish a previously seen browser without storing the cookie value itself in the database.
Images
Uploaded screenshots are decoded, resized and re-encoded to remove embedded metadata. Pending screenshots are stored privately and become public only after approval. Rejected screenshots are removed from the moderation bucket.
Cookies and advertising
Necessary cookies maintain sign-in sessions and security preferences. Clearly labeled Monetag sponsored-link cards may appear on public non-account pages for signed-in and signed-out visitors; the third-party destination is contacted only after a visitor chooses to open the sponsored link. Monetag In-Page Push advertising loads only after optional advertising consent and remains disabled on authentication, account, upload and administration pages. The format does not require a browser-notification subscription. Monetag may receive limited technical and interaction information needed to deliver, measure and protect advertising under its own privacy terms.
Retention and user choices
Account and submission records are retained while needed to operate the service, resolve disputes and prevent abuse. Users may edit profile visibility, unlink a verified game profile, and request access, correction or deletion subject to security, legal and moderation requirements.
Third-party processors
Hosting, authentication, database, storage, bot protection, transactional email, the official Clash of Clans API, analytics and advertising providers may process limited information under their own terms. The planned production stack includes Vercel, Supabase, Cloudflare Turnstile, Resend and Monetag, with Google used when Google sign-in is enabled. The operator must add the final legal identity and contact details before public launch.
Use the contact address configured by the site operator. For removal requests, include the affected page URL and enough information to verify your request.
Open removal procedure