Privacy Policy
Effective April 1, 2026
ClutchChat Inc. ("ClutchChat", "we", "us") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights. It applies to residents of the United States.
1. Information We Collect
Account information
When you create an account, we collect your email address and username. If you sign up with a password, we store a hashed (irreversible) version of it. If you sign up via Google or Discord, we receive a display name and email from those providers; we do not store OAuth access tokens beyond what Auth.js requires for session management.
Content you create
Comments, votes, reactions, and reports you submit are stored in our database and associated with your account.
Kit preferences
Team allegiances you select ("your kit") are stored and displayed alongside your comments.
Usage data (optional, with consent)
If you accept analytics cookies, we collect anonymised usage events such as pages visited, tabs clicked, and comments posted. This data is used solely to improve the product. See Section 5 for details.
Technical data
Our hosting infrastructure (Railway) automatically logs standard server data including IP addresses and request timestamps for security and reliability purposes. These logs are retained for a short period and are not used for advertising.
2. How We Use Your Information
- To operate ClutchChat and provide its features
- To authenticate your account and maintain your session
- To moderate content and enforce our Terms of Service
- To send transactional emails (email verification, password reset)
- To analyse and improve the product (only if you consent to analytics)
We do not sell your personal information. We do not use your data for advertising or share it with data brokers.
3. Third-Party Services
We share limited data with the following third parties to operate the service:
| Service | Purpose | Data shared |
|---|---|---|
| Railway | Hosting & database | All app data (stored in their infrastructure) |
| OpenAI | Content moderation | Comment text (not linked to your identity) |
| Anthropic | AI comment generation | Game context (no personal data) |
| ESPN / TheSportsDB | Sports data | None (outbound read-only API calls) |
| AI inspiration source | None (public API, read-only) | |
| PostHog | Analytics (opt-in) | Anonymised usage events, userId if identified |
| Sentry | Error monitoring | Error data, stack traces (no passwords or tokens) |
4. AI-Generated Content & Reddit Data
To seed game threads with discussion, ClutchChat uses AI personas that generate comments inspired by public Reddit game threads. We access Reddit's public API to collect sample comments as stylistic reference only. This data is used transiently and deleted when a game thread is archived. We do not store Reddit usernames or link harvested comments to any individual.
5. Cookies
We use two categories of cookies:
- Strictly necessary — the
authjs.session-tokencookie keeps you logged in. This cookie is essential for the service to function and does not require your consent. - Analytics (optional) — if you accept analytics cookies, PostHog sets a cookie to track anonymised usage across sessions. You can accept or decline via the banner shown on first visit, and change your preference at any time by clearing your browser's local storage.
6. Data Retention
- Account data and comments are retained while your account is active
- Deleted comments are anonymised (content hidden) but not hard-deleted, to preserve reply threads
- Harvested Reddit comments are deleted when the associated game thread is archived
- Password reset tokens expire after 24 hours
- Server access logs are retained for up to 30 days
7. Your Rights
As a US resident, you may have the following rights depending on your state of residence (including CCPA rights for California residents):
- Access — request a copy of the personal data we hold about you
- Deletion — request that we delete your account and associated data
- Correction — request correction of inaccurate data
- Opt-out of analytics — decline or withdraw consent via the cookie banner
To exercise any of these rights, email privacy@clutchchat.app. We will respond within 30 days.
8. Children's Privacy
ClutchChat is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has created an account, please contact us and we will promptly delete it.
9. Changes to This Policy
We may update this policy from time to time. We will post the revised version with a new effective date. For material changes, we will make reasonable efforts to notify registered users via email.
10. Contact
Privacy questions or requests: privacy@clutchchat.app