Notify me

Privacy Policy

Clairo asks for one thing only: your email address. This page says exactly what we do with it, for how long, who else touches it, and how you can pull everything down whenever you want.

Version 1.1 · in force since 2026-07-31

1. Who is responsible for this page

Clairo (clairo.gg) is an independent, free project run by one person from Brazil. For the purposes of data protection law, Clairo is the controller of the data described here.

Privacy channel, for anything on this page: privacy@clairo.gg. It is the same channel for exercising your rights, asking questions or complaining.

Clairo is free: there is no paid plan, no advertising, no affiliate link and no donations. Nobody pays for your data here, because it is not sold.

2. What we keep

If you signed up for the alerts:

If you only visit the site: the server keeps a technical access log — IP address, date and time, requested address, browser and referring page. That log lives in a self-rotating file (three 10 MB files; the oldest is discarded when it fills up) and serves two purposes: keeping the site running and producing an aggregate count of visits per day and per country. No IP address goes into those aggregate numbers, and they identify nobody.

What we never ask for or keep: password, name, phone number, address, payment data, store login, browsing history, favourite genres, any rating of yours. There is no account, there is no profile. No sensitive data either — origin, health, religion, political opinion, biometrics: Clairo processes none of it.

The alerts are not measured. Clairo puts no tracking pixel in the emails and does not record whether a message was delivered, opened or clicked. Clicking a game goes straight to the store, never through Clairo.

3. Why we process, and on what legal basis

Each purpose has a declared legal basis. None of them is generic: when the purpose ends, the processing ends with it.

PurposeDataLegal basisHow long
Sending the free-game alertEmail, language, games already sentConsent — LGPD art. 7(I); GDPR art. 6(1)(a); FADP art. 6(6); PIPEDA cl. 4.3For as long as you are on the list
Confirming the address is yours (double opt-in)Email, click timestampConsent and proof of consent — LGPD art. 8(§2); GDPR art. 7(1)Alongside the sign-up
Not sending to people who left or refusedEmail, list state, suppression reasonLegal obligation and legitimate interest — LGPD art. 7(II) and (IX); GDPR art. 6(1)(c) and (f)While the record exists (that is what guarantees the silence)
Proving that you accepted (and what)Accepted version, language, regime, timestampProof of consent — LGPD art. 8(§2); GDPR art. 7(1)Alongside the sign-up; gone when you request erasure
Keeping the site up and counting visits in aggregateServer technical access logLegitimate interest — LGPD art. 7(IX); GDPR art. 6(1)(f)Until the log file rotates (three 10 MB files)
Remembering your language and your privacy choicesFirst-party cookies (see section 4)Strictly necessary for the service you asked for — ePrivacy art. 5(3); LGPD art. 7(IX)1 year, or until you clear your browser

You can withdraw consent at any time, free of charge and without explanation, through the cancellation link in the footer of any of our emails. Withdrawing does not undo what was already sent, but it stops everything from then on — exactly what GDPR art. 7(3) and LGPD art. 8(§5) guarantee.

4. Cookies and what stays in your browser

Clairo has no advertising, no third-party analytics and no tracking cookie. There are only two cookies, both first-party:

CookieWhat forLifetime
clairo_langStores the language you picked so the site opens in it next time.1 year
clairo_privacyStores your privacy choices (what you allowed and which version of the text).1 year

Both are strictly necessary for the behaviour you asked for — remembering your preference and remembering your decision. That is the exemption in art. 5(3) of the ePrivacy Directive, which carves out storage “as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service”.

Site fonts. The typefaces come from Google Fonts. When your browser fetches a font, Google receives your IP address, your browser and the referring page — Google states this itself, and also states that it “does not use any information collected by Google Fonts to create profiles of end users or for targeted advertising” and that the API “does not set or log cookies”. Even so, under the regimes that require prior consent (European Union, United Kingdom and Switzerland) Clairo only loads those fonts after you allow it. If you do not, the site uses your system font and works just the same.

Game images. The artwork comes straight from the stores (Steam, Epic, GOG, Xbox, PlayStation, Apple, Google Play, Amazon). That means that, when a card loads, your browser talks to the store and the store sees your IP address — exactly as it would if you opened the store page. Clairo does not copy those images and cannot know what you looked at.

5. Who else touches your data

Your email leaves Clairo for one place only: the service that delivers the message. The full list of providers, with each one's country and contractual safeguard, is on Providers.

Clairo never sells, rents or trades your email. There is no list swap, no marketing partner, no data broker. For the purposes of Californian law, Clairo does not sell or share personal information as those terms are defined in § 1798.140 of the California Civil Code.

6. International transfers

Clairo's database sits on a server in Brazil. To deliver the email, the address and the message content go to Resend, whose processing happens in the United States. That is an international transfer.

Safeguards: Resend's data processing agreement incorporates the EU Standard Contractual Clauses, and Resend states that it is certified under the EU-U.S. Data Privacy Framework with the U.S. Department of Commerce. These are the instruments provided for in GDPR art. 46 and LGPD art. 33(II)(b) (standard contractual clauses).

7. Your rights, and the real path to exercise them

The rights below apply to everyone, wherever you live. What changes from country to country is the response deadline and the name each right has in local law — the table at the end of this page shows what applies to you.

Path 1 — two clicks, no need to talk to anyone. Every Clairo email carries a “Your data” link in the footer. It opens a page that shows, right there, everything we hold about you, offers a JSON download (portability) and carries the button to erase it all. No password needed: the link is your key. And the unsubscribe link, in the same footer, withdraws consent in one click.

Path 2 — write to us. If you have none of our emails at hand, or want anything else, write to privacy@clairo.gg from the address you signed up with. We answer within your regime's deadline (see the table below) and, if we need to confirm the address is yours, the confirmation request goes to that very address — we never ask for ID documents.

Leaving the list is not the same as being erased. When you unsubscribe, the record is flagged as “out” — and that is exactly what guarantees nothing else is ever sent to your address. If you want to disappear for good, use the erase button on “Your data”: the record is then destroyed, together with the history of games sent and the consent record.

Deadline and authority by region

Where you areLawResponse deadlineAuthority
Brasil — LGPDLei nº 13.709/201815 daysANPD
União Europeia / EEE — GDPRRegulamento (UE) 2016/67930 daysAutoridade de controlo do seu país (lista em edpb.europa.eu)
Reino Unido — UK GDPR + PECRUK GDPR (retained) + Data Protection Act 2018 + PECR 200330 daysInformation Commissioner's Office (ICO)
Suíça — nLPD / revFADPFederal Act on Data Protection (SR 235.1)30 daysFederal Data Protection and Information Commissioner (FDPIC)
Califórnia (EUA) — CCPA/CPRACalifornia Civil Code §§ 1798.100 e seguintes45 daysCalifornia Privacy Protection Agency (CPPA)
Canadá — PIPEDAPersonal Information Protection and Electronic Documents Act, S.C. 2000, c. 530 daysOffice of the Privacy Commissioner of Canada (OPC)
Demais países — base do Clairo30 daysprivacy@clairo.gg

8. For how long

9. Security

If an incident happens that could affect you, we notify you and the competent authority within your region's legal deadline — in Brazil, the deadline in ANPD Resolution 15/2024; in the European Union, the 72 hours of GDPR art. 33.

10. Minors

Clairo is not directed at children or teenagers and asks nobody their age — because it asks for nothing beyond the email address. If you are responsible for a minor and find their address on the list, write to privacy@clairo.gg and we erase the record straight away.

11. How this page changes

This policy is versioned. Every version has a number, an effective date and a summary of what changed — the history is at the end of the page. The record of your consent stores which version you accepted, so the exact text in force on that day can be proven.

Version history

Version 1.1 — in force since 2026-07-31.