Privacy
What Halo stores about you, and how you control it — without contacting anyone.
What we store
Your profile: a handle you chose, a display name you can leave empty, a bio you can leave empty, and anything you add to the profile card (social links, a banner, a background image or video you host yourself, a music file you host yourself, cosmetic unlocks, GitHub or Steam widget settings). Either the account profile or the terms name how each of those is stored.
Your visit data: for your own profile only — how many distinct visitors your profile has had, aggregated per day in the visitor counter you can embed anywhere. We do not store who visited whose profile in a way any surface shows, and we never build an activity log of a visitor across profiles (each view records one row against one profile and one pseudonymous cookie id, used to dedupe counts).
Your Discord data, if you link it: your Discord user id (self-reported, so anyone can claim one), a stored avatar, and whatever Lanyard — a free third-party service you can leave — publishes to your profile. Steam and GitHub data, when you configure a widget, is read live from those platforms' public APIs and not stored on our servers beyond the few strings you typed.
Cookies: one signed, pseudonymous id for view-count dedupe, your sign-in session, and the referral cookie only if you arrived on a referral link. No advertising cookies, no analytics cookies, no trackers of any kind.
What is not here: your email never leaves Supabase Auth — accounts are username-only and the internal address is derived from your handle, so there is no inbox to leak. We do not run ad tech, sell data, or train anything on your profile.
Your data, your hands
Export (GDPR Art. 20): from Dashboard → Account, one click downloads a JSON document with every field you have stored here — profile, links, badges, visit history, reports you filed or received, and unlocks. Machine-readable by design; it is your copy, generated fresh at download time.
Delete (GDPR Art. 17): from Dashboard → Account. Deletion starts a 7-day window during which your profile is hidden everywhere and nothing is destroyed yet — you can cancel from the same page and everything returns untouched. At the end of the window the account is erased automatically: your profile row is deleted, everything owned by your account cascades with it, your sign-in credential is retired at Supabase, and your handle cannot be re-registered by anyone including you.
Correct or remove individual things: every field in your profile is editable in place from the dashboard — that is the point of the editor drawer. Badges, unlocks and past reports cannot be individually deleted because they are records of things that happened, not content you authored; deleting the account removes them all.
Retention
Everything you store is kept until you delete it, the account is deleted, or every visitor view and profile edit has faded from the live product — which ever comes first. Nothing has an archive "just in case". Anonymous moderation tickets about a deleted account may persist without your handle attached, because a ticket is a record of a complaint, not a copy of your profile.
Backups are not copies of your data for us to hand over: they exist so a database outage costs hours, not your account. A deletion from the dashboard is permanent because the row is gone from the live database — restored backups are a disaster-recovery tool, not a resurrection service, and are not treated as a store where personal data lives.
Contact
There is deliberately no contact form, support inbox, or appeal email on Halo. Every right the GDPR gives a person here is a button on a page — your account tools handle export and erasure, and the terms set out how moderation decisions are made and what you can do about them in the product itself. Legal notices about the service itself can be placed via the site's hosting provider under that provider's own abuse process.
You are also always free to object to processing by deleting your account.