Privacy Policy
Last updated: April 7, 2026
Polar Manifests ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle your information when you use our desktop application and related services (the "Software").
1. Information We Collect
To provide and maintain the Software, we collect a minimal amount of information:
- Account information: Email address and Discord ID (if linked). Used for account management, authentication, and customer support.
- Hardware ID (HWID): A hashed, non-reversible identifier of your machine used solely to enforce one-device-per-account restrictions. This is considered personal data under applicable privacy laws.
- Usage data: Games added, removed, or synced. Used for analytics, leaderboard features, and service improvement. This data is tied to your account.
- Session token: Stored locally on your device and transmitted to our authentication server over HTTPS. This is not a license key - it authenticates your active session.
2. Information We Do Not Collect
- We do not collect or store passwords (authentication is handled by our auth provider, Clerk)
- We do not collect payment card details (handled by third-party payment processors)
- We do not collect personal files, Steam credentials, or game content
- We do not track your browsing activity outside the Software
- We do not sell, rent, or share your personal data with third parties for marketing purposes
3. How We Use Your Information
The limited information we collect is used exclusively to:
- Create and manage your account
- Validate your account and device authorization
- Provide cloud sync functionality (if enabled by you)
- Generate aggregated, anonymized analytics to improve the Software
- Communicate with you regarding your account or support inquiries
- Enforce our Terms of Service
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), our legal basis for collecting and using your information is:
- Contract performance: Processing your account data to provide the Software you purchased
- Legitimate interest: Aggregated analytics, fraud prevention, and service improvement
- Consent: Optional features like cloud sync and Discord Rich Presence, which you can enable or disable
5. Data Storage and Processors
Your data is processed and stored by the following services:
- Supabase (US) - Account data, plan records, activity logs
- BunnyCDN (Global) - Cloud sync files, game manifests, support transcripts
- BunnyNet (Global) - Account validation via edge workers, CDN delivery
- Clerk (US) - Authentication provider
All data is transmitted over HTTPS/TLS. These providers act as data processors on our behalf and are bound by their own privacy and security commitments.
6. International Data Transfers
Our servers and data processors are primarily located in the United States. If you are accessing the Software from outside the US, your data may be transferred to and processed in the US. By using the Software, you consent to this transfer. We rely on standard contractual clauses and processor agreements where applicable.
7. Data Retention
- Account data is retained while your account is active
- Cloud sync data is deleted 30 days after your plan expires
- Support transcripts are retained for 90 days
- Activity logs are retained for 12 months, then automatically purged
- Upon account deletion, all associated personal data is removed within 30 days
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Portability: Request your data in a machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Where we process data based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal
- Lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority in your country of residence if you believe your data is being processed unlawfully
To exercise any of these rights, contact us via Discord or email at support@polarmanifests.com. We will respond within 30 days.
9. Data Security
We implement appropriate security measures to protect your data, including HTTPS encryption for all communications, hashed hardware identifiers, and restricted access to user data. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Data Breach Notification
In the event of a data breach that affects your personal data, we will notify affected users within 72 hours via email or through the Software, and will report to relevant supervisory authorities as required by law.
11. Third-Party Services
The Software interacts with the following third-party services, which have their own privacy policies:
- Steam Store API & SteamSpy: Game metadata (descriptions, images, tags, pricing)
- Discord: Account linking, community features, Rich Presence
We encourage you to review their respective privacy policies.
12. Cookies and Local Storage
The desktop application uses local storage to persist preferences (theme, view mode, cached data). The website does not use cookies or third-party tracking scripts.
13. Children's Privacy
The Software is not intended for users under 13 years of age. We do not knowingly collect information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on our website and updating the "Last Updated" date. If a change is material, we will provide at least 14 days' notice. Your continued use of the Software after changes constitutes acceptance.
15. Data Controller and Contact
Polar Manifests acts as the data controller for information collected through the Software. We do not currently have a designated Data Protection Officer. If you are located in the European Economic Area and have concerns about our data practices, you may contact your local data protection authority.
For privacy concerns, data requests, or questions about this policy, contact us via our Discord server or by email at support@polarmanifests.com.