Last updated 8 October 2026
The short version: a Discord id, an email address, your orders and your customisation settings. No analytics scripts, no advertising trackers, and no Discord access tokens.
If you sign in, the account record holds your Discord user id, your Discord username, your avatar hash and the email address Discord supplied. That is the whole of the profile.
Discord OAuth access and refresh tokens are discarded before the account record is written, because nothing on this site needs to act on your Discord account. Only the identify and email scopes are requested in the first place.
Card details never reach this site. Stripe Checkout is hosted by Stripe and the payment form is on Stripe's own origin, so there is no card data here to store or to lose.
There are no analytics scripts, no advertising pixels, no session recording and no third-party tag manager on any page.
Stripe processes payments and holds the payment record. Discord authenticates you if you choose to sign in. Both receive only what is needed to do that, and neither receives your customisation settings.
An uploaded backdrop is decoded on the server, resized, stripped of every metadata block including any location data a camera wrote, and re-encoded as a new file. The original bytes are not kept. The re-encoded file is stored outside the web root and is served only through an authenticated route.
Orders are kept while the account exists, because they are the record of what was sold and what lets you re-download it. Download logs are kept for abuse monitoring. Sessions expire after thirty days of inactivity.
To have an account, its orders and its uploads deleted, contact support from the email address on the account. Stripe keeps its own payment records independently, for the period its own obligations require.
One cookie: the session token, set only if you sign in. It is httpOnly, SameSite=Lax and, in production, Secure. There are no analytics or advertising cookies, which is why there is no consent banner.