Why signing in is offered

For one reason: so the usage numbers reflect real people rather than a pile of anonymous hits. Knowing that a handful of people use the compare page a lot is useful. Knowing that the compare page was opened four hundred times by nobody in particular is not.

That is the whole reason it is offered. It is optional, and every tool that reads a profile works without it. Two things do need it, because they belong to somebody: adding the bot to a server, and keeping a watch list. You can sign out whenever you like.

What happens when you sign in

The site sends you to haunt.gg, and haunt.gg asks you whether you agree. It is their screen, on their domain, and this site never sees your haunt.gg password at any point.

If you agree, haunt.gg confirms to this site who you are. That confirmation is what keeps you signed in from one page to the next, and what lets your activity on the site be counted as yours rather than as an anonymous visit.

Only the person who runs the site can see any of it. It is not sent back to haunt.gg. The temporary access keys that exist for helping someone with a problem cannot reach it either, whatever rights they carry.

One exception, and it is worth stating plainly. While you are signed in, the visit counter named below is told who is reading, so that a path through the site reads as one person rather than as a string of unconnected visits. What it receives is your haunt.gg id, your username and the link to your avatar, and nothing else. Not what you looked up, not what you did there. Sign out and it is told that nobody is there.

Connecting Discord

Connecting a Discord account is optional, and useful for two things: putting the bot in up to three of your servers, and receiving a watch notification. For servers, it is what tells the bot that those servers are yours, so that nobody else can add it in your name.

It works the same way as signing in with haunt.gg: Discord asks you whether you agree, on their screen and on their domain, and this site never sees your Discord password at any point. Adding the bot to a server is a second, separate agreement on the same kind of screen.

The bot page lists the servers you added the bot to, and lets you remove any of them, or undo the whole connection, whenever you like. Undoing the connection undoes the servers with it, and the bot stops answering there.

The bot shows the same public haunt.gg profiles the site shows, through the same official API. It reads nothing from your Discord server: not the messages, not the member list, not the channels. That is why it asks for no permission when it is added.

The inactivity watch

A watch is a short list of public haunt.gg profiles that you build yourself. The list sits under the Discord account it belongs to, because that is where the notification has to arrive, and it holds nothing about you beyond that.

You see the whole list on the watch page and through /watch in Discord, and removing a profile takes it out of both at once. Disconnecting Discord takes the list with it.

When a watched profile goes inactive, the bot sends you a direct message. If it cannot reach you that way, it tries the server you added it to, and if that fails too the notification is simply dropped. Nobody else is told what you watch.

A watched profile is read through the same official API the rest of the site uses, and only the fact that haunt.gg marks it inactive is looked at. A profile that asked to be left out of these tools cannot be watched at all.

The dashboard theme

The theme is a userscript that runs in your own browser. It never contacts this site and sends nothing anywhere. It works whether or not you have an account here.

Its C4C and L4L check does read, and it is worth being precise about what. When you press Scan, it reads the comment and feedback lists that are already displayed on your own dashboard, through the session you are already signed into. It is never triggered on its own, and nothing about it reaches this site or anyone else.

One button does make requests, and only that one. "Verify aliases" opens each flagged profile on haunt.gg in the background to read the real username behind it, because a name that looks like a debtor is often the same person under another handle. Those requests go to haunt.gg and nowhere else, they are the same pages you could open by hand, they are spaced out, and they only happen when you press that button. The rest of the check makes no request at all.

The script keeps three things on your device, through your script manager: your colours, whether you have seen its first-run notice, and the result of your last scan so the next one can tell you what changed. None of it is ever sent anywhere, and the script's own reset button deletes all three.

The colours you pick are kept by your script manager, on your device, and nothing about them is ever sent to this site. Removing the script removes them.

One contact does exist, and it is worth knowing about: script managers check for updates on their own, so yours will ask this site every so often whether a newer version of the file exists. That is your extension asking, on its own schedule, and it can be turned off in the extension.

Paying for Pro

There is no payment on this site. No form asks you for bank details, no checkout runs here, and no payment provider is loaded on any page. Pro is arranged directly with the person who runs the site, on Discord, and you receive a key that you post yourself in your server.

Whatever you and that person exchange to make the payment happens on Discord and through whichever means you both agree on. It does not pass through this site, and this site has no part in it.

What never leaves your browser

Some things are kept on your device and are never sent anywhere:

Clearing your browser data for this site removes all of it, and nothing breaks.

Cookies

The site sets a cookie when you sign in, and one when the owner signs in to the dashboard. Both exist purely to keep that session going, both are restricted so that scripts cannot read them, and both are sent only over a secure connection.

There is a third, and only if you say yes. The visit counter can set one so that it recognises you when you come back another day, rather than treating every visit as a stranger. You are asked before anything is set, in a bar at the top of the page, and saying no means the counter is not even loaded. It comes from portus.sh, the counter, rather than from anything this site decides; it now reaches your browser through this site's own domain, which is a change of route and not a change of who it belongs to. No script on the page can read it, and it is tied to this site alone: the same browser on another site gets a different one, so it cannot be used to follow you around the web.

This site sets no advertising cookies, and nothing at all until you sign in. If your browser sends a Global Privacy Control signal, the counter's cookie is refused whatever you or anyone else has chosen.

Your address, and what is done with it

Your IP address is not written down anywhere. No record of an account, of a Discord link, or of anything else here holds it, and it is never handed to the visit counter or to anyone else.

It is not simply ignored either, and the honest version is worth a paragraph. Every request that reaches the site is turned into a short one-way fingerprint that mixes it with the browser, the date and a secret. That fingerprint is what counts a day's visitors as people rather than as page loads, and what holds the few-searches-a -minute limit in place. It cannot be turned back into an address, no fingerprint is kept beyond the day it belongs to, and the one behind the rate limit expires after a minute.

Your email address is not kept either, and has not been since the site stopped asking haunt.gg for it. Nothing here has one to lose.

Other places your browser talks to

A page here is not entirely self contained, and it is fair to know who else your browser reaches while a page loads:

Each of those is a separate company with its own policy, and this site has no control over what they do at their end. None of them are told who you are.

Profiles that are shown here

Profile content comes from the official haunt.gg API and belongs to haunt.gg and to the people who wrote it. This site stores a copy of a profile briefly, so that searching the same name twice in a row does not hit their API twice. That copy expires on its own.

The profile lookup also shows a profile's Discord presence when that profile has a Discord account linked and is in the haunt.gg Discord: the status, what they are playing or listening to, their Discord badges and guild tag. It is the same thing the presence widget shows on their own profile, read through the official API. A profile that asked to be left out of these tools is not read at all, presence included.

If you would rather your profile did not appear here at all, ask and it will be hidden, on every tool at once. See the terms for how that works.

Having it removed

Sign out and the session ends immediately. If you want everything connected to your account cleared from the site as well, ask and it will be erased. There is no form, no waiting period, and no attempt to talk you out of it.

Changes

This page can change. The date at the top is the version marker.

Getting in touch

Anything at all, including removal requests and questions about this page: the profile of the person who runs the site. Not the haunt.gg team, they have nothing to do with this.