Legal

Privacy Policy

Last updated: 9 March 2025

This Privacy Policy explains how The Cooldown collects, uses, and protects your personal data. We are committed to being transparent about how we handle your information and to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

The Cooldown is operated as a personal project by an individual based in the United Kingdom. We are the data controller for personal data collected through thecooldown.app.

For any privacy-related queries, message @irvkits on thecooldown.

2. Data We Collect

We collect the following categories of personal data:

Account data

  • Email address (used for authentication)
  • Username and display name
  • Profile picture (if you choose to upload one)
  • Bio

Activity data

  • Games you log, score, and review
  • Tier lists you create
  • Community posts and replies
  • Accounts you follow

Third-party integration data (optional)

  • Steam ID and library data, if you choose to connect your Steam account
  • Discord username and ID, if you choose to connect your Discord account

Technical data

  • IP address and basic usage data collected automatically by our infrastructure providers (Vercel and Supabase)

3. How We Use Your Data

We use your data to:

  • Create and manage your account
  • Display your profile and activity to other users
  • Generate personalised game recommendations using AI (via Anthropic's Claude API)
  • Enable social features such as following other users and community discussions
  • Sync your Steam game library if you choose to connect Steam
  • Send account-related emails such as password reset and email confirmation
  • Improve and maintain the platform

4. Legal Basis for Processing

Under UK GDPR, we process your personal data on the following legal bases:

  • Contract: Processing necessary to provide you with the service you've signed up for
  • Legitimate interests: Improving the platform and keeping it secure
  • Consent: Where you have actively chosen to connect third-party accounts such as Steam or Discord

5. AI Recommendations

When you use our AI recommendations feature, data about your reviewed games and scores is sent to Anthropic's API to generate personalised suggestions. No personally identifiable information such as your name or email is included in these requests.

Anthropic's privacy policy applies to data processed through their API. You can view it at anthropic.com/privacy.

6. Data Sharing

We do not sell your personal data. We share data only with the following third-party services that are necessary to operate the platform:

  • Supabase — database and authentication infrastructure (data stored in EU region)
  • Vercel — hosting and edge network
  • Anthropic — AI recommendations (anonymised game data only)
  • Steam (Valve) — if you choose to link your Steam account
  • Discord — if you choose to link your Discord account

All third-party providers are required to handle your data in accordance with applicable data protection law.

7. Data Retention

We retain your personal data for as long as your account is active. If you delete your account, your personal data and all associated content is permanently deleted from our systems.

Some anonymised or aggregated data may be retained for analytical purposes after account deletion.

8. Your Rights

Under UK GDPR, you have the following rights:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — ask us to correct inaccurate data
  • Right to erasure — request deletion of your personal data (you can also do this directly by deleting your account in Settings)
  • Right to restrict processing — ask us to limit how we use your data
  • Right to data portability — request your data in a machine-readable format
  • Right to object — object to processing based on legitimate interests

To exercise any of these rights, message @irvkits on thecooldown and we will respond within 30 days.

You also have the right to lodge a complaint with the UK's Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been handled unlawfully.

9. Cookies

The Cooldown uses cookies and local storage solely for authentication purposes — to keep you logged in between sessions. We do not use tracking, advertising, or analytics cookies.

You can disable cookies in your browser settings, but this will prevent you from being able to log in.

10. Security

We take reasonable technical measures to protect your personal data, including encrypted connections (HTTPS), database-level access controls, and row-level security policies.

No method of transmission over the internet is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

11. Children's Privacy

The Cooldown is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we become aware that we have done so, we will delete that data promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page when changes are made. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.

13. Contact

If you have any questions or concerns about this Privacy Policy or how we handle your data, message @irvkits on thecooldown.