At sympathy.club, operated by Nocturne LLC ("we", "us", "our", or "the Company"), we take your privacy seriously. This Privacy Policy describes how we collect, store, use, and share your personal data when you visit or use our platform, located at sympathy.club and all related subdomains and settings dashboards (collectively, "the Service").
Please read this Privacy Policy carefully to understand our practices regarding your personal data. By accessing or using our Service, you consent to the data collection and processing activities described herein.
1. The Information We Collect
We collect only the minimum data required to establish and run your public profile page. This data falls into the following categories:
1.1 Authentication & Discord Profile Data
To register or log in, you must use your Discord account via OAuth. During this authentication flow, we retrieve and store the following details from Discord:
- Discord ID: The unique numeric identifier assigned to your Discord profile.
- Discord Username: Your current Discord username.
- Avatar URL: The link to your Discord profile image.
Note: We never have access to, nor do we request or store, your Discord passwords or login credentials.
1.2 Profile Content and Visual Themes
When customizing your public profile page, we store any content you input or select:
- Profile metadata: bio, custom links, platform handles, layout template selections, and profile tags.
- Visual styling attributes: theme presets, custom color codes, cursor trail styles, background options (e.g., custom color, audio, or video background URLs).
- Custom CSS: custom CSS overrides you write (if you are a Pro subscriber).
- Real-time Presence Sync: If you use our Discord presence feature, we stream live data (such as current game, active status, and Spotify song details) through the Lanyard API. This status updates dynamically in the browser and is not persistently logged in our database.
1.3 Payment and Financial Transaction Data
Transaction processing for Premium and Pro upgrades is handled securely by our payment processor, Stripe. We do not store or process raw financial details (such as credit card numbers or security codes). Stripe provides us with tokenized transaction confirmations, subscription statuses, billing country, and reference transaction IDs.
1.4 Analytical & Performance Data
We track platform usage and stability metrics using privacy-focused analytics tools (PostHog and Sentry):
- PostHog: Tracks page views, layout interactions, and button clicks. These analytics are aggregated to help us optimize the platform design. We do not track individual keystrokes or sensitive input fields.
- Sentry: Captures error stacks, system crashes, browser types, and device configurations when a bug occurs. This is used solely to maintain platform stability.
2. How and Why We Use Your Information
We process your personal data based on the following legal grounds and business purposes:
- Performance of Contract: To create your user account, verify your identity, render your public profile page, and process your billing subscriptions.
- Legitimate Interests: To monitor the security, speed, and health of our systems; debug platform crashes; and prevent fraudulent signups or billing actions.
- Consent: To stream your real-time Discord presence or Spotify activity onto your public page, which you can toggle on or off in settings at any time.
3. Third-Party Data Sharing & Storage
We do not sell, trade, or lease your personal information to marketing firms or advertisers. We share data only with the service providers essential for operating sympathy.club:
- Supabase: Used for cloud database hosting, user management, and API infrastructure (data is hosted on secure servers located in the United States).
- Stripe: Used for payment gateway security and customer billing portals.
- PostHog: Used to gather aggregated site performance metrics.
- Sentry: Used to capture technical crash logs.
- Lanyard: Used to fetch real-time Discord presence details for profile pages.
4. Cookies, Session Keys, and Web Storage
We use cookies and local storage (localStorage/sessionStorage) in your browser to maintain vital features:
- Session Tokens: Secure identifiers stored in cookies to verify that you are logged into your account dashboard.
- Preferences: We store visual configuration values (such as dark mode preferences and active dashboard tabs) in local storage for a faster user experience.
- Entrance State: A transient flag (`gate-seen`) is stored in sessionStorage to prevent the entrance gate animation from triggering repeatedly on every page load during a single browser session.
5. Data Retention and Account Deletion
We retain your personal data for as long as your sympathy.club account remains active.
Account Deletion: You have the right to delete your account and all associated profile data at any time. You can perform this action instantly via the Settings page inside your dashboard. Once clicked, all profile details, customization settings, and links will be permanently deleted from our databases. Remaining billing logs stored in Stripe are retained for compliance, tax, and accounting purposes as required by law.
6. GDPR and California Privacy Rights (CCPA)
If you reside in the European Economic Area (EEA), United Kingdom, or California, you possess specific data protection rights under regulations like the GDPR and CCPA. These rights include:
- The right to access, update, or delete the information we hold on you.
- The right of rectification (to correct inaccurate or incomplete data).
- The right to object to or restrict the processing of your data.
- The right to data portability (requesting a copy of your personal data in a structured, machine-readable format).
To exercise any of these rights, you may modify your profile via the settings dashboard or email us directly at the address listed below.
7. Changes to This Privacy Policy
We may modify this Privacy Policy to reflect changes in our data practices or operational requirements. We will notify you of any changes by updating the "Last Updated" date at the top of this page. Your continued use of the platform following the publication of changes signifies your acceptance of the updated policy.
8. Contact Information
For any privacy concerns, data deletion requests, or questions regarding how we process your information, please contact our privacy compliance officer at: [email protected].