Privacy Policy
Effective October 3, 2026
Information stored
OsuCards stores your osu! user ID, account status, legal acknowledgment versions and timestamps, manual refresh timestamp, saved card designs, and any layout snapshots you choose to share. Public osu! profile information and statistics are cached to render cards. We do not collect your osu! password or retain OAuth access tokens in the account database.
Cookies and browser storage
A signed HttpOnly cookie keeps you signed in for up to 30 days. A short-lived signed cookie protects the OAuth login flow. Browser localStorage holds your site theme hue, editor view preferences, and dismissed help hints. These preferences are not stored with your account or card designs. A short-lived sessionStorage cache holds public profile statistics for this browser tab to speed up reloads. It contains no authentication tokens and is cleared when you log out or delete your account.
Public cards
An activated card is publicly accessible and contains the profile fields and text included in its design. External sites may cache shared images independently.
Shared layouts
Layout links expose the saved layout, including its static text. New links capture only the public osu! fields needed to render the creator preview; older links retain their previous behavior. Shared snapshots remain stored until you stop sharing them or delete their source card or your account. Recipients' saved copies are independent and are removed when those recipients delete them.
Community template data
Publications store the saved design and only its relevant public stats and image references. Previews are rendered from that JSON; no rendered image snapshot or entire profile is stored for a publication. Updating a publication replaces its captured data. Its clone counter records successful copies by other users. Publications and their captured data are deleted when unpublished or when their source card or owner account is deleted.
Feedback
We store your feedback message, type, submission and edit timestamps, status labels, and osu! username and user ID. Feedback is linked to your account. New suggestions and bug reports, including your username and profile link, are publicly readable without signing in. Reports submitted under the previous private-report policy remain private to their author and me (Tanese). A keyed network fingerprint and account-based limits help prevent spam; raw IP addresses and internal account IDs are not included in public responses. Feedback stays stored until you or I delete it, or you delete your account.
Contacting me through the Discord link opens Discord, where Discord's own privacy policy and messaging settings apply.
Service providers
Vercel hosts the application and its image cache. Neon PostgreSQL stores account, design, and cached profile data. osu! supplies authentication and public profile information. Providers may process operational request logs needed to run and protect the service.
Deletion
Deleting your account removes your account record, all owned designs, and feedback submitted while signed in to that account. Public osu! cache rows may remain for cache reuse; they contain public profile data. Existing browser and third-party cached images are outside OsuCards’ control.
Policy changes
Meaningful changes are shown before you continue to use OsuCards. Minor corrections do not require another acknowledgment.