legal
privacy policy
last updated September 16, 2026
what this covers
This describes what seized.wtf (“we”, “the service”) collects when you create an account or visit a profile, why, and how you can get it removed. This is a plain-language description of how the service actually works, not a substitute for legal advice — if you need a formal legal opinion about your own use of the service, talk to a lawyer.
what we collect
Account information
Your email address, and a password hash (never the password itself — it’s hashed with bcrypt before it ever touches the database, and we have no way to recover it). If you sign in with Discord instead, we receive your Discord ID, username, and avatar from Discord’s OAuth flow rather than collecting a password.
Profile content
Anything you put on your page yourself — username, display name, bio, links, social links, uploaded images (avatar, background, cursor, badge images), theme/color choices, and any widget configuration (a Roblox or GitHub username you type in, for example). This is all visible to anyone who visits your published page — that’s the point of the service.
Discord data (if you connect it)
Connecting Discord to show live presence requires being a member of the seized.wtf Discord server — while connected, we store your Discord ID and whether you’re currently in that server, and (if you enable the presence widget) your current status/activity as reported by Discord, so it can be shown on your page.
Analytics
Profile views and link clicks, along with referrer, approximate country, and device type. Visitor identity for deduplication (so refreshing your own page doesn’t count as ten views) is a one-way hash of IP address — we don’t store raw IP addresses for this. Your own IP address is logged at signup and login for abuse prevention (see below).
Payments
We don’t process payments or store payment/card information on seized.wtf at all. Premium and paid extras are currently purchased through the seized.wtf Discord server and applied to your account manually by staff — your card details never reach our servers.
why we collect it
- To run the service — render your page, log you in, let you customize it.
- To show you analytics about your own page.
- To prevent abuse — rate limiting signups/logins, and reclaiming usernames from accounts that never verify their email.
- To email you when necessary (email verification, account-related notices) — never marketing you didn’t ask for.
who else sees it
We use a small number of infrastructure providers to run the service:
- Vercel — hosting the website.
- Railway — hosting the database.
- Cloudflare R2 — storing uploaded images/audio.
- Resend — sending verification emails.
- Discord — if you connect or sign in with it.
If a widget on your page pulls from a public API (Roblox, GitHub, Minecraft, stats.fm), only the username you provided is sent to that service to fetch public data — we don’t share your account email or any private data with them. We don’t sell data to anyone, and we don’t run third-party ad trackers.
how long we keep it
For as long as your account exists. Your account isn’t created until you verify your email — if you sign up and never click the verification link, nothing is kept beyond a couple hours. This exists to stop bulk-signup scripts from squatting usernames, not to delete real accounts in progress.
deleting your data
You can delete your account yourself at any time from Settings → danger zone. This removes your profile, links, uploaded media, and account record. If you’d rather ask us to do it, reach out in the Discord server.
cookies
Just what’s needed to keep you signed in (a session cookie) and to protect signup/login forms from forgery (a CSRF token). No third-party advertising or tracking cookies.
children
seized.wtf isn’t directed at children under 13, and we don’t knowingly collect data from anyone under that age.
changes
If this changes in a meaningful way, we’ll update the date at the top of this page.
contact
Questions about any of this — reach out in the seized.wtf Discord server.
