terror.wtf
Privacy Policy
1. Who is responsible for your data (Controller)
For the purposes of the EU General Data Protection Regulation (GDPR) and related EU/EEA data-protection law, the controller of your personal data is:
- Controller: The operator of terror.wtf, established in the European Economic Area
- Contact / privacy enquiries: support@terror.wtf
You may request our registered name and postal address at support@terror.wtf where required for exercising your rights or for legal notices. If GDPR Article 27 requires us to appoint an EU representative, we will publish those details here or provide them on request.
2. Scope
This Policy explains what personal data we collect when you use terror.wtf, why we collect it, the legal bases we rely on under the GDPR, who we share it with, how long we keep it, international transfers, and the rights you have. It applies to visitors, registered users, and people whose profile pages are viewed publicly.
It does not apply to third-party services you connect to or link from your pages (such as Discord or sites behind your links), which have their own privacy policies.
3. Personal data we collect
3.1 Account data
- Unique user ID and username.
- Password (stored only as a hash; we never store your plaintext password).
- Account roles and status (for example premium, verified, gifter, admin, banned).
- Account creation and update timestamps.
3.2 Profile / User Content
- Display name, bio text, layout and customisation settings (colours, effects, card options, enter overlay text, and similar configuration).
- Links you add (labels, URLs, optional icons) and badges assigned to your account.
- Media you upload (avatars, backgrounds, audio, link icons) and related metadata.
- Optional Discord user ID and related presence fields used to show Discord status on your profile.
- Public view counts and related view analytics.
Much of this content is, by design, public (see Section 8).
3.3 Discord presence data
If you save a Discord user ID on your profile, we may fetch and display presence information (such as status, activity, and display tag) from Discord-related APIs so your biolink can show it. We store the Discord ID you provide and may cache recent presence fields for display. We do not receive your Discord password.
3.4 Premium / store records
Premium is granted through our Discord / store process. We store whether your account has premium (and related badges/roles). Payment instrument details are handled outside the Service during purchase and are not stored by us as card data. We may retain limited purchase confirmation records needed for support, fraud prevention, and legal / accounting obligations.
3.5 Technical, session, and visitor data
- Sessions: a signed session cookie that identifies your logged-in account (user ID and username).
- Visitor ID: a random anonymous browser ID used to count and de-duplicate profile views. It is not your IP address.
- Profile views: records linking a visitor ID to a profile owner (and daily aggregates) so we can count unique views.
- Server logs: standard application and error logs generated while operating the Service, which may incidentally include request metadata (such as IP address, user-agent, and timestamps) for security and debugging, typically retained only for a short period.
We do not intentionally collect special-category data (GDPR Article 9), and you should not place such data on public pages. We do not perform automated decision-making that produces legal or similarly significant effects on you (GDPR Article 22); automated checks (such as rate limiting and abuse detection) are used only to operate and protect the Service.
4. Where the data comes from
Most data comes directly from you (registration, profile editing, uploads). Some is generated by your use of the Service (sessions, views, logs). Some is received from third parties when you choose to enable integrations (for example Discord presence based on an ID you provide).
5. Why we process your data and the legal bases (GDPR Art. 6)
| Purpose | Categories used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and manage your account; provide biolink pages, hosting, and core features | Account, profile, session | Performance of a contract — Art. 6(1)(b) |
| Authenticate logins and keep you signed in | Account, session cookie | Performance of a contract — Art. 6(1)(b) |
| Display Discord presence and other integrations you configure | Discord ID / presence fields | Contract Art. 6(1)(b) and/or consent Art. 6(1)(a) (you enable and can remove it) |
| Process premium unlocks and store-related account status; keep necessary purchase records | Account roles, purchase confirmations | Contract Art. 6(1)(b); legal obligation Art. 6(1)(c) where accounting/tax rules apply |
| Keep the Service secure; prevent fraud and abuse; moderate content; enforce Terms and bans | Account, content, logs | Legitimate interests Art. 6(1)(f); legal obligation Art. 6(1)(c) where applicable |
| Count and de-duplicate public page views | Visitor ID, owner ID, view records | Legitimate interests — Art. 6(1)(f) |
| Respond to support requests and exercise/defend legal claims | As relevant | Contract / legitimate interests / legal obligation — Art. 6(1)(b)/(f)/(c) |
| Comply with lawful requests and legal obligations | As relevant | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, our interest is operating, securing, improving, and providing a reliable Service (including unique view counts for public profiles). We have considered your rights and you may object (see Section 11). Where we rely on consent, you can withdraw it at any time without affecting prior processing.
6. Cookies and similar technologies (ePrivacy)
terror.wtf uses a minimal set of cookies that are strictly necessary to provide the Service you request, and does not currently use advertising or third-party tracking cookies. Under the ePrivacy rules, strictly necessary cookies do not require consent.
- a session cookie to keep you logged in; and
- a visitor cookie needed to provide unique profile view counting (a core feature of public biolink pages).
If we later add analytics, advertising, or other non-essential cookies/trackers, we will request consent through a cookie banner before they are set, and will update this Policy.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
terror_session | Maintain your authenticated session | Strictly necessary | Up to 30 days |
terror_vid | Anonymous visitor ID for unique view counting | Strictly necessary | Up to 1 year |
Note: third-party content embedded on pages or destinations you link to may set their own cookies controlled by those third parties.
7. Who we share data with (recipients and processors)
We do not sell your personal data. We share it only with service providers who act on our instructions (processors), with third-party services you choose to connect, and where required by law. We require processors to process personal data only on our instructions and with appropriate safeguards under GDPR Articles 28 and 32.
| Category of recipient | Purpose |
|---|---|
| Hosting and infrastructure providers | Running the application, database, and servers |
| Storage / content delivery (as used) | Storing and serving uploaded media |
| Integration providers (e.g. Discord) | Presence and other features you enable |
| Payment providers (where used for purchases) | Processing payments; card data handled by the provider |
| Authorities and professional advisers | Legal compliance and establishing, exercising, or defending legal claims |
8. Public information
By design, the following are publicly accessible to anyone with the link (and may be indexed by search engines): your username / handle, your public biolink page and its content (bio, links, badges, uploaded media, customisation, Discord presence if enabled), and public view counts. Do not publish personal or sensitive information you do not want to be public.
9. International data transfers
Some processors or integrations (for example hosting providers or Discord) may process data outside the European Economic Area (EEA), including in the United States. Where this happens, we rely on appropriate safeguards under GDPR Chapter V, such as:
- an adequacy decision by the European Commission;
- the European Commission’s Standard Contractual Clauses (SCCs); and/or
- where applicable, the EU–US Data Privacy Framework, together with supplementary measures where needed.
You can request more information about relevant safeguards at support@terror.wtf.
10. How long we keep your data (retention)
We keep personal data only as long as needed for the purposes described in this Policy, or as required by law:
- Account and profile data: for the life of your account, then deleted or anonymised after a verified deletion request, subject to the exceptions below.
- Session cookie: up to 30 days (or until you log out / clear cookies).
- Visitor ID and view records: while needed for unique view counting and related analytics; may be pruned over time.
- Server / security logs: typically a short period (for example up to 90 days), unless needed longer for an active investigation.
- Purchase / accounting records: for as long as applicable accounting, tax, or consumer law requires (often several years), even after account deletion.
When you request account deletion and the request is verified, we permanently delete your personal account data and user-generated content from active systems. This process is irreversible for deleted content. Limited backups, security logs, and records we must retain by law may temporarily persist, after which they are purged. We do not keep deleted user data for marketing or unrelated analytics once deletion is complete.
11. Your rights under the GDPR
Subject to the conditions in the GDPR, if you are in the EU/EEA (or otherwise protected by the GDPR) you have the right to:
- access your personal data and obtain a copy (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- erasure (“right to be forgotten”) (Art. 17);
- restrict processing in certain cases (Art. 18);
- data portability — receive your data in a structured, commonly used, machine-readable format and, where feasible, have it transmitted to another controller (Art. 20);
- object to processing based on legitimate interests (Art. 21), including unique view analytics;
- withdraw consent at any time where processing is based on consent (Art. 7), without affecting prior processing; and
- not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22) — we do not carry out such decision-making.
How to exercise your rights:
- Update or remove much of your profile data yourself in the dashboard.
- For access, portability (export), erasure, restriction, objection, or other requests, email support@terror.wtf from the address associated with your account (or include your username and enough detail for us to verify you).
- We will respond within one month of receiving a valid request, extendable by up to two further months for complex or numerous requests (GDPR Art. 12). We will tell you if we need an extension. We may need to verify your identity before acting, and may refuse or limit requests where the GDPR allows (for example manifestly unfounded or excessive requests).
12. Right to lodge a complaint
If you believe we have processed your personal data unlawfully, contact us first at support@terror.wtf. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement. A list of EU data-protection authorities is available from the EDPB: edpb.europa.eu — members.
13. Security and personal-data breaches
We take appropriate technical and organisational measures under GDPR Article 32 to protect personal data, including hashing passwords, using httpOnly cookies for sessions and visitor IDs, transport encryption (HTTPS), access controls for staff/admin tools, and limiting access to personal data on a need-to-know basis. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and we will inform affected individuals where required by GDPR Articles 33 and 34.
14. Children
You must meet the age requirements in our Terms of Service (including GDPR Article 8 age-of-consent rules in the EU/EEA). We do not knowingly collect personal data from children below the applicable threshold. If you believe a child has provided us personal data in violation of those rules, contact support@terror.wtf and we will take appropriate steps to delete it.
15. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice on the Service where appropriate. Your continued use of the Service after changes take effect means you acknowledge the updated Policy.
16. Contact
Questions or requests regarding this Policy or your personal data: The operator of terror.wtf at support@terror.wtf.