Last updated 16 August 2026
We store the account details you give us and the profile you build. We never store visitors' IP addresses. Where we need to tell visitors apart — to stop one person inflating a view counter, or to rate limit abuse — we store a one-way keyed hash instead, which cannot be turned back into an address.
We do not sell your data, we do not run advertising, and there are no third-party trackers or analytics scripts on this site.
This policy explains exactly what is collected, why, how long it is kept, and who else can see it. It covers nettyuh.cc and nothing else.
| Data | Why |
|---|---|
| Email address | Sign-in, password reset, verification, and security alerts |
| Username & display name | Your public profile address and identity |
| Password | Stored only as a scrypt hash — we never see or keep the password itself |
| Profile content | Bio, avatar, banner, background, music, colours and links you choose to publish |
| Discord user ID | Optional. Only if you switch on Discord presence |
| Two-factor secret & backup codes | Optional. Codes are stored hashed |
| Sessions | Browser, operating system, device type, and a hashed IP, so you can review and revoke sign-ins |
| Recognised devices | A hashed fingerprint, so we can alert you to a sign-in from somewhere new |
| Account timestamps | Created, last sign-in, last active |
Everything on your public profile is, by definition, public. Only publish what you are happy for anyone to see.
You do not need an account to view a profile, and we do not ask visitors for anything. When a profile is viewed we record:
The hash exists for one reason: so repeat views from the same visitor within a short window count once, and so abuse can be rate limited. The same approach is used for link clicks.
Profile owners never see visitor identities. They see totals and trends only — how many views, on which days, and which of their links were clicked.
We use two cookies, both strictly necessary. There is no consent banner because we set no advertising, analytics, or tracking cookies.
| Cookie | Purpose |
|---|---|
| nyh_sess | Keeps you signed in. Expires after 12 hours, or 30 days if you choose "remember me" |
| nyh_csrf | Protects forms against cross-site request forgery |
Both are removed when you sign out. Visitors who never sign in are not given a session cookie.
We do not sell or rent personal data, and we do not share it for advertising. Data reaches third parties only in these specific cases:
| Who | What, and when |
|---|---|
| Email provider | Your email address and the message, when we send a verification, password reset, or security alert |
| Hosting provider | Runs the server the site sits on, and therefore holds the data at rest |
| Discord | Only if a profile owner enables Discord presence. We request their status from a public presence API from our server, so visitors' addresses are never sent to it. However, the Discord avatar shown on that profile is loaded by the visitor's browser directly from Discord's CDN, which means Discord can see the visitor's IP address. The same applies to album art when a profile shows what its owner is listening to. |
| Network provider | If the site sits behind a CDN or proxy, that provider handles traffic in transit |
| Authorities | Where we are legally required to disclose, or to report content involving the exploitation of minors |
| Data | Kept for |
|---|---|
| Account & profile | Until you delete the account |
| Deleted accounts | Recoverable for 14 days, then permanently erased |
| View & click records | 400 days. Lifetime totals are counters and remain |
| Sessions | 12 hours, or 30 days with "remember me". Revocable at any time |
| Password reset & verification links | 1 hour |
| Moderation records | Kept while needed to enforce a ban and defend the decision |
| Backups | Rotated regularly; deleted data disappears as backups age out |
Depending on where you live you may have rights over your personal data. We offer these to everyone, regardless of location:
To exercise anything not covered by a self-service control, contact the site operator. If you are in the UK or EU and are unhappy with our response, you may complain to your local data protection authority.
No system is perfectly secure. If a breach affects your personal data, we will tell you and any relevant regulator as required by law.
nettyuh.cc is not intended for children under 13, and we do not knowingly collect their data. If you believe a child under 13 has an account, contact us and we will remove it.
If we change this policy we will update the date at the top. Where a change materially affects how we handle your data, we will make a reasonable effort to notify account holders before it takes effect.
Questions about this document? Contact the site owner.