Privacy
Plain English version of what data spotted.gg collects, why, and what you can do about it.
Last updated: 2026-05-26.
Who we are
spotted.gg is a one-person side project that sends you an email or Discord ping 10 minutes before your favorite Counter-Strike team plays. We act as the data controller for everything below. For any privacy question, write to hello@spotted.gg.
What we collect
- Account. Your email address. If you sign in with Google, we also receive your Google account's basic profile (name, email, profile picture URL) via OAuth. We do not see or store your Google password.
- Subscription state. Which teams you follow, your notification channels (email and/or Discord webhook URL), and the timestamp of every alert we sent you.
- Analytics (anonymous). When you visit the site, our self-hosted analytics provider (PostHog EU) records the URL you viewed, the referrer, your browser, OS, device class, and an approximate country / region / city derived from your IP address. Your IP is discarded at ingest. Nothing is stored in your browser (no analytics cookies, no localStorage). Each page load is treated as a new anonymous visitor.
- Analytics (signed in). Once you sign in, page activity is tied to your account id so we can answer questions like "is anyone actually using the gallery filters." We do not record what you type, do not capture form contents, and do not run session replay.
- Operational logs. Standard request logs (timestamp, path, status code) kept for up to 14 days for debugging and abuse prevention.
Why we collect it (legal bases)
- Contract (GDPR art. 6(1)(b)). Account data, subscription state, and notification delivery. We can't send you a match alert without your email or webhook URL.
- Legitimate interest (GDPR art. 6(1)(f)). Anonymous analytics (to understand which pages people use), signed-in product analytics (to improve the product for you specifically), and operational logs (security and debugging). We've balanced this against your privacy by using memory-only storage, anonymized IPs, no autocapture, no session replay, no third-party advertising, and no cross-site tracking.
Who else processes your data
- Oracle Cloud (EU region): hosting the database and the app.
- Resend: delivers transactional email (magic-link sign-in, match alerts, unsubscribe confirmations). Receives only the recipient email and message content.
- PostHog (EU cloud): analytics. Receives anonymized pageview events as described above.
- Google (OAuth): only if you choose "Sign in with Google." Sees that you signed in to spotted.gg. We see your basic profile in return.
- Discord: only if you provide a Discord webhook URL. We POST match notifications to it. Discord sees the webhook content.
Cookies
We use only strictly-necessary first-party cookies. No third-party cookies, no advertising cookies, no analytics cookies.
- Better Auth session cookies: keep you signed in. Lifetime 30 days, refreshed on use.
am_view_mode: remembers your preferred gallery layout (grid or list). Lifetime 1 year.spotted_unsub: short-lived helper cookie used by the unsubscribe confirmation page. Cleared on next visit.
Do Not Track / Global Privacy Control
If your browser sends the DNT or Sec-GPC signal, we do not initialize analytics at all. Nothing about your visit is recorded beyond the standard server-side request log.
How long we keep things
- Account, subscriptions, and notification history: until you delete your account.
- Analytics events: retained per PostHog's standard retention for our plan (currently up to 1 year). After that, raw events are deleted by PostHog automatically.
- Operational request logs: up to 14 days, then rotated and deleted.
- Backups: encrypted, retained for up to 30 days.
Your rights
Under GDPR you can:
- Access a copy of the data we hold about you.
- Correct anything that's wrong.
- Delete your account and all associated data.
- Export your data in a portable format.
- Object to processing based on legitimate interest (the analytics piece above).
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email hello@spotted.gg. We respond within 30 days.
Questions? Email us and we'll answer in plain English.