Privacy Policy
ClashCookie is an independent, fan-made companion for Clash of Clans - a website (clashcookie.com) and a Discord bot. This policy explains exactly what each one stores, why, who else processes it, and how to have it deleted.
Last updated: 25 July 2026
The website
Browsing ClashCookie without signing in collects no personal account data. If you sign in with Discord or Google, we store the account ID, display name, email address, and avatar image that provider gives us, plus any additional provider you link from the same account. This keeps you signed in, saves your favorite clans and players, and keeps your upgrade planner and planner alerts attached to your account across devices.
This data lives in our own PostgreSQL database on our own server. We do not sell it, and we do not run any third-party advertising or analytics trackers on the site.
Cookies. Every cookie we set is our own, and none of them are used for advertising or cross-site tracking. Signing in sets the session cookie that keeps you signed in, alongside the standard sign-in helper cookies (a CSRF token and the page to return you to). Signed in or not, browsing also sets a signed same-site token so our own pages can call our own API without a key. Three more are set only when you do the thing that needs them: an anonymous browser id the first time you upvote a base layout while signed out, so one browser counts once, and two preference cookies remembering your home clan and your chosen region on the rankings page.
IP addresses. The application itself holds your IP only in memory, inside a short rate-limiting window, and never writes it to our database or ties it to your account. Our web server does keep ordinary access logs that include the requesting IP, and Cloudflare, which sits in front of the site, keeps its own request logs under its policy. Those logs exist to operate the service and to block abuse - not to profile you - and we do not sell or share them.
The Discord bot
When the bot is added to a Discord server, it stores only what it needs to run the features that server turns on:
- Server & channel configuration - the server ID, the clan tag you set with
/setup, and the channel IDs you choose for alerts, logs, and boards. - Account links & verified claims - when you use
/linkor/claim, we store your Discord user ID next to the in-game player tag you link. A claim is verified with the one-time API token you generate in-game; we use that token only to confirm ownership and do not keep it. - Server membership & nicknames - with the Server Members intent, the bot reads the member list and can set roles and nicknames for the features you enable (Town Hall roles, verified role, nickname sync). It reads this to act on it, not to build a profile of you.
- Moderation records - if server staff issue a strike or ban with the bot, we store the player tag, the reason, and the staff action so the tools work.
- Roster snapshots & donation counts- to power join/leave logs and donation leaderboards that survive Supercell’s season resets, the bot keeps a lightweight snapshot of the clan roster and per-member donation totals.
We do not read your messages.Our hosted bot runs without Discord’s Message Content intent, so it cannot see the text of messages in your server. It responds only to its own slash commands and the buttons it posts. An optional legacy donation-message parser, disabled by default and not enabled on our hosted bot, is the only feature that would ever require that intent.
Bot data lives in a private database on our own server, separate from the website database. We do not sell it and we do not share it with advertisers.
Cross-platform claim sync
A verified claim you make in the bot and one you make on the website are recognised in both places, because your Discord account is the shared identity. When you verify an account, that link (your Discord ID and the player tag) is mirrored between the bot and clashcookie.com so you don’t have to prove ownership twice.
Removal is not fully symmetrical today, so here is exactly what happens. /unclaim in the bot removes the claim in both places: the bot deletes its own record and tells the website to revoke the verified claim. Removing a claimed account on the website deletes it from your website account and from the shared verified-claim store, so the bot stops treating it as verified - but the plain per-server link you created with /linkstays in that server’s bot data until you run /unlink or /unclaim there, or email us. We would rather say this plainly than promise a sync we have not built.
Game data is not your personal data
Clan, player, and war information shown by the site and the bot comes from Supercell’s official Clash of Clans API and, where needed, complementary public game-data feeds. This is public game data keyed by public in-game tags - it is not private information about you, and it is available to anyone who queries the game’s API.
Who else is involved
Discord and Google process your sign-in and (for the bot) your Discord account under their own privacy policies. Supercell operates the Clash of Clans API the game data comes from. Cloudflare sits in front of the website as our network/CDN provider. We do not use any other third-party processors, and we never sell personal data to anyone.
Your control & deletion
On the website you can disconnect a linked provider anytime from Account settings. In the bot you can remove a link yourself with /unclaim or /unlink.
A server owner can remove the bot at any time, which immediately stops it reading anything or acting in that server. Removing it does notby itself erase what the bot already stored for that server - the server and channel IDs, the clan tag, roster and donation snapshots, and any moderation records stay in our bot database until they are deleted. We have not built automatic deletion on removal yet. To have a server’s data erased, email us with the server ID and we will delete it.
To request deletion of your account and all data we hold about you - on the website, in the bot, or both - or a copy of that data, email [email protected]. We will action it promptly.
ClashCookie is a general-audience fan service and is not directed to children. It is not intended for use by anyone under the minimum age required by Clash of Clans or by Discord in their region.
Unofficial fan content
This material is unofficial and is not endorsed by Supercell. For more information see Supercell’s Fan Content Policy: supercell.com/fan-content-policy. Clash of Clans and Supercell are trademarks of Supercell Oy; ClashCookie is not affiliated with, endorsed by, sponsored by, or specifically approved by Supercell.
Changes & contact
If this policy changes materially, we will update the date above. Questions, data requests, or anything else: [email protected].
