Privacy Policy
Clairo asks for one thing only: your email address. This page says exactly what we do with it, for how long, who else touches it, and how you can pull everything down whenever you want.
Version 1.1 · in force since 2026-07-31
1. Who is responsible for this page
Clairo (clairo.gg) is an independent, free project run by one person from Brazil. For the purposes of data protection law, Clairo is the controller of the data described here.
Privacy channel, for anything on this page: privacy@clairo.gg. It is the same channel for exercising your rights, asking questions or complaining.
Clairo is free: there is no paid plan, no advertising, no affiliate link and no donations. Nobody pays for your data here, because it is not sold.
2. What we keep
If you signed up for the alerts:
- Your email address.
- The language you signed up in.
- Dates: sign-up, confirmation, last alert sent, departure from the list.
- Which games have already been sent to you — that is what stops the same game from arriving twice.
- Whether you are on the list or have left, and whether your provider refused delivery permanently or marked the message as spam (in which case we stop sending).
- The record of your consent: which version of this policy and of the terms you accepted, in which language, under which regime and when.
If you only visit the site: the server keeps a technical access log — IP address, date and time, requested address, browser and referring page. That log lives in a self-rotating file (three 10 MB files; the oldest is discarded when it fills up) and serves two purposes: keeping the site running and producing an aggregate count of visits per day and per country. No IP address goes into those aggregate numbers, and they identify nobody.
What we never ask for or keep: password, name, phone number, address, payment data, store login, browsing history, favourite genres, any rating of yours. There is no account, there is no profile. No sensitive data either — origin, health, religion, political opinion, biometrics: Clairo processes none of it.
The alerts are not measured. Clairo puts no tracking pixel in the emails and does not record whether a message was delivered, opened or clicked. Clicking a game goes straight to the store, never through Clairo.
3. Why we process, and on what legal basis
Each purpose has a declared legal basis. None of them is generic: when the purpose ends, the processing ends with it.
| Purpose | Data | Legal basis | How long |
|---|---|---|---|
| Sending the free-game alert | Email, language, games already sent | Consent — LGPD art. 7(I); GDPR art. 6(1)(a); FADP art. 6(6); PIPEDA cl. 4.3 | For as long as you are on the list |
| Confirming the address is yours (double opt-in) | Email, click timestamp | Consent and proof of consent — LGPD art. 8(§2); GDPR art. 7(1) | Alongside the sign-up |
| Not sending to people who left or refused | Email, list state, suppression reason | Legal obligation and legitimate interest — LGPD art. 7(II) and (IX); GDPR art. 6(1)(c) and (f) | While the record exists (that is what guarantees the silence) |
| Proving that you accepted (and what) | Accepted version, language, regime, timestamp | Proof of consent — LGPD art. 8(§2); GDPR art. 7(1) | Alongside the sign-up; gone when you request erasure |
| Keeping the site up and counting visits in aggregate | Server technical access log | Legitimate interest — LGPD art. 7(IX); GDPR art. 6(1)(f) | Until the log file rotates (three 10 MB files) |
| Remembering your language and your privacy choices | First-party cookies (see section 4) | Strictly necessary for the service you asked for — ePrivacy art. 5(3); LGPD art. 7(IX) | 1 year, or until you clear your browser |
You can withdraw consent at any time, free of charge and without explanation, through the cancellation link in the footer of any of our emails. Withdrawing does not undo what was already sent, but it stops everything from then on — exactly what GDPR art. 7(3) and LGPD art. 8(§5) guarantee.
5. Who else touches your data
Your email leaves Clairo for one place only: the service that delivers the message. The full list of providers, with each one's country and contractual safeguard, is on Providers.
Clairo never sells, rents or trades your email. There is no list swap, no marketing partner, no data broker. For the purposes of Californian law, Clairo does not sell or share personal information as those terms are defined in § 1798.140 of the California Civil Code.
6. International transfers
Clairo's database sits on a server in Brazil. To deliver the email, the address and the message content go to Resend, whose processing happens in the United States. That is an international transfer.
Safeguards: Resend's data processing agreement incorporates the EU Standard Contractual Clauses, and Resend states that it is certified under the EU-U.S. Data Privacy Framework with the U.S. Department of Commerce. These are the instruments provided for in GDPR art. 46 and LGPD art. 33(II)(b) (standard contractual clauses).
7. Your rights, and the real path to exercise them
The rights below apply to everyone, wherever you live. What changes from country to country is the response deadline and the name each right has in local law — the table at the end of this page shows what applies to you.
- Know and access — see everything Clairo holds about you.
- Rectify — fix anything wrong (here, in practice, the language).
- Erase — disappear from the database, with no trace left.
- Take it with you (portability) — receive your data in a file another service can read.
- Withdraw consent — stop the alerts at any time.
- Object to processing carried out on the legitimate interest basis.
- Complain to the data protection authority in your country.
Path 1 — two clicks, no need to talk to anyone. Every Clairo email carries a “Your data” link in the footer. It opens a page that shows, right there, everything we hold about you, offers a JSON download (portability) and carries the button to erase it all. No password needed: the link is your key. And the unsubscribe link, in the same footer, withdraws consent in one click.
Path 2 — write to us. If you have none of our emails at hand, or want anything else, write to privacy@clairo.gg from the address you signed up with. We answer within your regime's deadline (see the table below) and, if we need to confirm the address is yours, the confirmation request goes to that very address — we never ask for ID documents.
Leaving the list is not the same as being erased. When you unsubscribe, the record is flagged as “out” — and that is exactly what guarantees nothing else is ever sent to your address. If you want to disappear for good, use the erase button on “Your data”: the record is then destroyed, together with the history of games sent and the consent record.
Deadline and authority by region
| Where you are | Law | Response deadline | Authority |
|---|---|---|---|
| Brasil — LGPD | Lei nº 13.709/2018 | 15 days | ANPD |
| União Europeia / EEE — GDPR | Regulamento (UE) 2016/679 | 30 days | Autoridade de controlo do seu país (lista em edpb.europa.eu) |
| Reino Unido — UK GDPR + PECR | UK GDPR (retained) + Data Protection Act 2018 + PECR 2003 | 30 days | Information Commissioner's Office (ICO) |
| Suíça — nLPD / revFADP | Federal Act on Data Protection (SR 235.1) | 30 days | Federal Data Protection and Information Commissioner (FDPIC) |
| Califórnia (EUA) — CCPA/CPRA | California Civil Code §§ 1798.100 e seguintes | 45 days | California Privacy Protection Agency (CPPA) |
| Canadá — PIPEDA | Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 | 30 days | Office of the Privacy Commissioner of Canada (OPC) |
| Demais países — base do Clairo | — | 30 days | privacy@clairo.gg |
8. For how long
- While you are on the list: the data in section 2 is kept.
- After you leave: the record stays, flagged as off the list, because it is what prevents an accidental send. Nothing else is sent.
- When you request erasure: the record, the history of games sent and the consent record are destroyed within 30 days.
- Server technical access log: disappears on its own when the file rotates (three 10 MB files).
- Aggregate visit counts: kept indefinitely, because they identify nobody.
9. Security
- The whole site and the whole API answer over HTTPS only, with mandatory redirect and HSTS.
- There is no password to leak, because Clairo has no login. Access to your data is through a personal link sent to your own inbox.
- The database is not exposed to the internet — only the application talks to it, over the server's internal network.
- The processes run in containers that are unprivileged, capability-stripped and read-only on the filesystem.
- Pages carry security headers (CSP, HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-Frame-Options).
- Addresses and access tokens are redacted from the application logs.
If an incident happens that could affect you, we notify you and the competent authority within your region's legal deadline — in Brazil, the deadline in ANPD Resolution 15/2024; in the European Union, the 72 hours of GDPR art. 33.
10. Minors
Clairo is not directed at children or teenagers and asks nobody their age — because it asks for nothing beyond the email address. If you are responsible for a minor and find their address on the list, write to privacy@clairo.gg and we erase the record straight away.
11. How this page changes
This policy is versioned. Every version has a number, an effective date and a summary of what changed — the history is at the end of the page. The record of your consent stores which version you accepted, so the exact text in force on that day can be proven.
- Material change (new purpose, new provider receiving data, new legal basis): we ask for your consent again before applying it.
- Editorial change (clearer wording, link fix, translation): it lands as a new version, with no fresh consent.
- No legal text is ever published automatically. A checker watches the official sources cited here and raises a flag when one changes; the decision to rewrite is always human.
Version history
Version 1.1 — in force since 2026-07-31.
- Version 1.1 — 2026-07-31 · The consent notice now declares both things your browser fetches from outside Clairo — the typeface from Google Fonts and the game covers, served straight by the stores — and states that the choice offered covers the typeface. The previous version mentioned only the typeface. Nothing changed in the data processing: the covers always came from the stores, as section 4 already described.
- Version 1.0 — 2026-07-26 · First version. Describes Clairo's actual data processing and adopts the Brazilian, European Union, United Kingdom, Swiss, Californian and Canadian regimes.