Privacy Policy
Last updated: 2026-08-09.
The short version
By default, nothing about your lists ever leaves your browser — they live in localStorage. If you sign in or create an account (email or Steam), your lists sync to our server so you can get them back on another device. Analytics are off until you press "Accept" on the cookie banner, and payments are handled by Paddle, not by us.
What we collect
- If you sign in by email: your email address, used only for sign-in (one-time codes/links — we never see or store a password).
- If you sign in with Steam: your public SteamID and, if you choose to import, your public owned-games list and playtime. We never request purchase history or your friends list.
- Your lists: whatever you rank, name, or write (hot takes) — stored so they can sync and, if you publish, be shown on a public page.
- A random device id: a UUID stored in a cookie named mtc_bid (mirrored in localStorage). It contains nothing about you — it is what lets the daily duel count one vote per browser and keeps guest features working before you have an account. It is set whatever you answer on the cookie banner, because it is not analytics.
Analytics and the cookie banner
We use PostHog for product analytics — how many people start a ranking, finish a session, publish a list. The "Allow analytics cookies?" banner is the gate, not a notice about tracking that already started: PostHog is loaded opted-out, and nothing is captured unless you press Accept.
- If you decline (or ignore the banner): PostHog captures nothing and sets no cookie of its own. We record your answer as the single value madethecut.analyticsConsent in localStorage so we stop asking.
- If you accept: PostHog sets its own cookie and records page views, its default interaction events (clicks on links and buttons), and our own product events — which feature you used, not what you ranked. Your list contents and hot takes are never sent to it.
- If you are signed in when you accept: we also send your account id, so the same person on two devices is counted once. Signed-out visitors stay anonymous to PostHog.
Payments
Checkout is run by Paddle, our merchant of record. Paddle's script loads only when you actually open a checkout — not on ordinary page loads. Paddle receives your payment details and the email you type into its form; we never see or store card numbers. If you are signed in, we pass your account id along so the purchase lands on the right account, and your account email is pre-filled.
After a payment, Paddle sends us a signed notification containing the transaction, the product bought, and its own customer id — and, if you checked out as a guest, we ask Paddle for the checkout email so we can attach (or create) the account that gets what you paid for. Receipts, refunds, and cancelling a subscription happen in Paddle's own customer portal, which we open on request; we don't hold a copy of your payment method.
Cookies and local storage
- Always: mtc_bid (the random device id above).
- Only if you sign in: Supabase's session cookies, which keep you signed in.
- Only if you accept analytics: PostHog's own cookie.
- In localStorage: your lists (until you sign in and sync), your consent answer, and a mirror of the device id.
To change your mind about analytics, clear this site's cookies and site data in your browser. That deletes the stored answer, so the banner asks again on your next visit — and it clears PostHog's cookie at the same time. There is no in-app switch for this yet.
What we don't do
We don't sell your data. We don't share it with advertisers. We don't track you across other sites.
Third-party services
Supabase stores your account and your lists — that is what "syncing" means above, so it necessarily holds your rankings and hot takes. Sign-in emails are sent via Resend. Product analytics run on PostHog (only after you accept). Payments run on Paddle (only when you open a checkout).
Catalog metadata (titles, cover art) comes from IGDB, TMDB, SteamGridDB, Steam and OpenLibrary— see the attribution in the footer. We fetch the search results ourselves and serve cover images through our own image resizer, but if that resizer can't handle an image your browser loads it straight from the source CDN.
If you turn on chat vote during a duel, your browser opens a direct, anonymous connection to Twitch chat to read votes from the channel you name. It reads only; nothing about your list is sent, and no Twitch account is involved.
PostHog, Paddle, IGDB, TMDB, SteamGridDB, Steam, OpenLibrary and Twitch never receive your rankings or hot takes.
Your rights
You can export any list as CSV at any time (the "Export" button in the app). You can delete your account and all associated data at any time from the app — this permanently removes your lists, linked identities, and account record from our servers.
Report a problem
If you find public content that shouldn't be there, or have a DMCA notice, email contact@madethecut.app with a description and a link to the content.
Contact
Questions about this policy: contact@madethecut.app.