Privacy Policy
Last updated: October 4, 2026
This page explains what richs.lol stores, why, and what you can do about it.
Account data
- Your email address and, if you use one, a password hash (Argon2id). We never store your password itself.
- If you sign in with Google or Discord, we store the provider's account ID so we can recognise you. We do not keep their access tokens.
- Active sessions: a hashed session token, when it was created and last used, and your browser's user-agent string so you can recognise devices in Settings.
Profile data
Everything you add to your profile — username, display name, bio, links, avatar, appearance settings — is public once you publish. Drafts are only visible to you.
Discord
- If you link Discord, we store your Discord account ID, name, avatar and public profile badges. The Discord card only appears on your profile if you switch it on.
- With “Live status” on, your profile shows your current Discord status, the game you are playing, what you are listening to and your custom status. Discord only shares these with a server you are a member of, so linking adds you to our Discord server when that is how this site reads them (Discord's consent screen says so), or you join the Lanyard server yourself. We keep only the latest status, and delete it when you unlink Discord or delete your account.
- With “Last seen and recent activity” on, your profile also shows when you were last online on Discord and what you did last, while you are offline or nothing is running. This is off unless you switch it on. Where this site reads your status with its own bot, the bot notes that time and activity for linked accounts so it can be shown if you choose to; it is deleted with the rest when you unlink Discord or delete your account.
- Visitors' browsers never contact Discord for this; your status is read through this site.
Roblox, YouTube and profile widgets
- If you add a Roblox or YouTube widget, we store the public ID of the account or channel you chose and show its public details (name, picture, follower or subscriber counts, your latest video). We read them from Roblox and YouTube on our server; we never ask for access to your account there.
- A visitor's browser loads the pictures of those cards from Roblox's and YouTube's image servers, which see the visitor's IP address as with any image on the web.
- A profile widget shows another profile of this site, and only what that profile already shows publicly.
Templates
A template you publish contains the look of your profile (colors, layout, effects, background media) and the name, description, tags and preview image you give it. It does not contain your bio, links, music or other personal content. Public templates show your username and avatar if your profile is public.
Analytics and visitor counting
- When someone views a published profile, we count the view. Raw IP addresses are not stored as analytics data.
- Instead the server computes a keyed one-way hash (HMAC-SHA-256) from the visitor's network address, browser user-agent and the profile being viewed, and optionally from a random first-party cookie (
richs_vid). The hash is specific to one profile. - These identifiers are used only to avoid counting the same visitor repeatedly, and are deleted after the retention period (90 days by default). Daily totals are kept.
- Profile owners only see totals (views, unique visitors, link clicks). They never see identifiers, IP addresses or individual visits.
- “Unique visitors” is an estimate: shared networks, VPNs and cleared cookies mean it cannot equal the number of people exactly.
Uploaded media
Images you upload are re-encoded, which removes embedded metadata such as camera details and GPS location, and stored with our storage provider.
Cookies
See the Cookie Policy.
Your choices
- Edit or unpublish your profile at any time.
- Delete your account from Settings. This removes your profile, links, uploads, sessions and the visitor data associated with your profile. Your username is held for a cooldown period to prevent impersonation.