Import
New Build

Legal

Privacy notice

What codbuilds.com collects, why it is collected, who else sees it, how long it is kept, and how to get it corrected or removed.

Last updated 19 September 2026.

Who is responsible

codbuilds.com is a fan site run by one person, not by a company. That person is responsible for the personal information described here and also acts as the site’s Privacy Officer.

Privacy contact: codbuilds.com Privacy Officer. Write to legal@codbuilds.com about anything on this page, including a request to see, correct or delete your data.

What is collected

Your account. The email address you sign in with, the handle you choose, which versions of the terms of use you have accepted and when, and your role on the site. For each passkey: its public key, the name you gave it and the kind of device it is on. A passkey’s private key is never sent to this site. Your device or a passkey manager (Apple, Google, Microsoft or a password manager) may sync it between your own devices, under that provider’s terms. If you set a password, only a one-way hash of it is stored.

Your sessions. For each device you are signed in on: when the session started and the IP address and browser description it started from. You can see these, and sign them out, on account security.

What you do here. The builds you publish with their titles and descriptions, the ratings and bookmarks you leave, the reports you send, and the screenshots you contribute along with what is read from them.

Technical records. Every request passes through Cloudflare, which logs and traces it: the address asked for, the time, the result, and details of the connection such as your IP address. Sign-in and rate-limit checks keep a count per IP address for a short time (see below).

Error reports and performance traces. When something breaks, in your browser or on the server, a report goes to Sentry: what went wrong and where in the code, the page address without anything after the ?, technical details that may include your browser and operating system, and a short list of the pages and requests just before it, also cut at the ?. About one page load and request in ten also sends a timing trace, which records how long each part took. The site does not attach your account, your email or your IP address to either, though Sentry sees the address a report is sent from, as any server does. There is no session recording.

There is no analytics product on this site, no advertising and no tracking across other sites.

Why it is collected

To create your account and sign you in; to show what you publish under the handle you chose; to keep ratings and bookmarks one per person; to review contributed screenshots and build the catalog from them; to keep the site working and find what broke; and to keep abuse and spam down. Nothing is used for anything else.

Under Canadian law you consent to these uses by creating an account and using the site, and you can withdraw that consent by deleting your account. Some records have to stay for a time even then (see below), and without an account you can still read the site.

Where the EU or UK GDPR applies to you, the legal basis for running your account and showing what you publish is the contract with you. For security, abuse prevention and error reports it is legitimate interests, and you can object to those by writing to legal@codbuilds.com. Keeping records the law requires is a legal obligation.

Who can see what

Anyone can see your handle, your public profile, the builds you have published and their titles and descriptions. Ratings are shown only as an average and a count, never as who gave what. Bookmarks are seen only by you.

Your email address is never on your public profile or a build page, and is never sent to another user. You see it on your own account pages. Moderators and admins can see account email addresses in the site’s admin console, so they can handle reports and the requests described below.

Moderators and admins also see the screenshots you contribute, with the personal corners of the game’s screen blanked out, and what was read from them. They see the reports you send and who sent them, and the record of moderation actions. The file exactly as you uploaded it is read only by the extractor and is never shown to anyone.

Cookies and browser storage

Only cookies the site needs to sign you in are used. All of them are this site’s own and none can be read by the page’s scripts:

Session: keeps you signed in, and ends 30 days after you last used the site. Session cache: a signed copy of your session, including your email address and role, so the site does not look up your session on every request. It lasts five minutes. Passkey check: set for five minutes while you register or use a passkey. Admin only: two more, lasting at most an hour, while an admin is viewing the site as another account to investigate a problem.

Browser storage is used only in the moderators’ review screen, to remember display settings. The builder also checks for catalog data an older version of the site left in your browser, and deletes it.

Error reports and traces store nothing in your browser. There are no analytics, advertising or third-party cookies, so there is nothing to opt in to. If you do not want your browser to send error reports at all, a content blocker that blocks sentry.io stops them, and the site works without them.

Who else processes it

Cloudflare runs the site. It serves every page, stores the database and the contributed images, keeps the request logs, and sends the sign-in, password-reset and terms-change emails, which means it handles each message’s address, subject, contents and delivery status. Sentry receives the error reports and traces described above. Both work for this site under contract and may not use your data for their own purposes.

Nothing is sold, and nothing is handed to advertisers or data brokers. Data is disclosed otherwise only where the law requires it.

Outside your country. Cloudflare runs a global network and may process your data in any country it operates in, including the United States. Sentry stores reports in the United States or the European Union. So your data may be processed where privacy law is different from yours, and authorities there may be able to demand access to it. Both providers’ published data processing terms apply, including the EU standard contractual clauses where EU or UK rules require a safeguard. The operator remains responsible for your information while they process it.

How long it is kept

Your account is kept until you delete it or it is removed. Your terms acceptance record goes with it.

Sessions are deleted within ten minutes of expiring, 30 days after last use, or at once when you sign out. Unused sign-in links are deleted within ten minutes of expiring, which happens after ten minutes (thirty for a password reset). The per-IP counters used to limit sign-in attempts are deleted a day after the last attempt.

Contributed screenshots. The file as you sent it is deleted seven days after a moderator decides on it, 90 days after upload if the extractor could not read it, and in every case within 180 days. The blanked-out copy moderators review is kept with the contribution. The attachment statistics a moderator approved become part of the catalog, which is about the game and not about you. The operator may also copy blanked-out copies and approved readings into a private test set used to check and improve the extractor. That set is not linked to your account.

Reports and moderation records are kept for as long as the site runs, so a decision can be explained later. They name accounts only by an internal number, never by email address.

Cloudflare’s request logs and traces are kept for 7 days and its record of sent emails for 30 days. The database has point-in-time backups for 30 days, so something deleted can stay in a backup for up to 30 days before it is gone for good. Sentry keeps error reports for up to 90 days and traces for up to 30, though some plans keep a sample of trace data for up to 13 months.

Deleting your account

You can delete your account yourself on account security. That deletes, straight away: your email address, credentials and sessions; your ratings (which come out of every average) and bookmarks; your contributed screenshots and everything read from them; the handles you used before; and the link from any report you sent to you. The report stays, without your name.

Your published builds are your choice. When you delete your account you can take them all down with it: their titles and descriptions are deleted and your handle comes off them. If you leave them up, they stay attributed to your handle, and nobody else can take that handle, so a build someone forked from yours does not lose its author or gain a new one. If you have nothing left published, your handle is removed too.

Changed your mind after deleting? Write to legal@codbuilds.com with the handle, and everything still published under it will be taken down. The account no longer exists, so you will not be asked to prove it was yours. The request can only take a deleted account’s name off its own builds.

What stays either way: a loadout itself is a share code anyone can decode, so a build page can still be opened by its code, and it stays up where somebody else also published it. Approved catalog statistics stay. Records of moderation decisions stay, naming the account only by number.

Your rights, and how to use them

You can ask for a copy of the personal information held about you, ask for it to be corrected, ask for it to be deleted, or withdraw your consent. Write to legal@codbuilds.com from the email address on your account. The reply goes to that address, which is how the request is confirmed as yours. If you can no longer use that address, say so, and you will be asked for something only the account’s owner would know. Much of this you can do yourself: change your handle, remove passkeys, sign out sessions, unpublish builds and delete your account.

Requests are free and are answered within 30 days. If a request needs longer, you will be told why and when to expect an answer, and it will not take more than 30 days longer. If something cannot be provided or deleted, for example because the law requires keeping it, the reply says what and why.

Complaints. Write to legal@codbuilds.com first if you can, and you will get an answer. If you are in Canada and are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada.

If the EU or UK GDPR applies to you, you also have the right to receive your data in a portable form, to object to processing based on legitimate interests, and to ask for processing to be restricted. Use the same address. You can complain to the data protection authority where you live or work at any time, whether or not you have written here first.

Children

You must be 16 or older to hold an account, and registering means confirming that you are. The site is not meant for children and does not knowingly collect personal information from anyone under 16.

If you believe an account belongs to someone under 16, write to legal@codbuilds.com with its handle. The account is suspended as soon as the message is read. Unless it turns out to belong to someone old enough, it is then deleted, along with everything it published and contributed.

If advertising arrives

There is no advertising on this site today, and no advertising network is loaded on any page. The site may carry advertising later to cover what it costs to run.

If that happens, this notice will be updated before the first advert is served, and it will name the advertising provider and say what it receives. Where the law requires consent for advertising or measurement cookies, you will be asked before any are set, and refusing will leave the site working.

Changes to this notice

This notice can change. The date at the top says when it last did. A change to what is collected, why, or who receives it takes effect only after that date has moved and the new text is here. It does not apply to information already collected without the notice that is needed.