Privacy Policy
Last updated August 17, 2026
Karto is a small, independent archive of Anno beauty builds. This page explains what we collect when you use it, why, and what say you have over it — in plain language, not legal filler.
Information we collect
We collect the minimum needed to run the archive and moderation queue:
Account information
If you register — with an email and password, or by continuing with Google or Discord — we store your email address, a display name, and, for OAuth sign-ins, whatever your provider hands us for that (typically a name and avatar image). We never see or store your Google or Discord password; authentication happens entirely on their side.
Build submissions
When you submit a build, we store the title, author name, description, mods list, hours played, and the screenshots you upload. If you submit without an account, we also ask for a contact email — kept separate from the build itself, never shown publicly, and used only to tell you when your submission is published or rejected.
Newsletter signup
You can subscribe to the weekly newsletter without creating an account — just an email address, confirmed by clicking a link we send you before anything is sent to it. If you never click that link, the address is never subscribed and we don't follow up. Unsubscribing removes the address entirely rather than just marking it inactive.
Cookies and session data
A single cookie keeps you signed in between visits. See Cookies below for the full breakdown.
Analytics
We use Vercel Web Analytics to see how many people visit and which pages get read — page views, referring site, general region (country-level, from your IP, which isn't stored), and device/browser type. It's cookieless and doesn't track you individually or across other sites; we only ever see aggregate numbers, not a profile tied to you. We don't run advertising trackers.
Log data
Like any hosted website, our infrastructure providers (see below) automatically log standard technical data — IP address, browser type, pages requested, timestamps — for security and debugging. We don't use this for tracking or profiling.
How we use it
- To run your account and remember you're signed in
- To review, publish, and display submitted builds
- To email you about your own submission's status
- To send an occasional newsletter of picked builds from the archive to registered accounts — see below for how to stop receiving it
- To keep the archive secure and stop abuse of the submission form
- To see, in aggregate, how the site is used and where it's worth improving
Every account starts subscribed to the newsletter; every newsletter email includes a one-click unsubscribe link that turns it off immediately, no login required.
We do not sell your information, and we do not use it to build advertising profiles.
Legal basis (GDPR)
If you're in the European Economic Area or UK, we rely on:
- Contract — creating an account, and reviewing a build you submit, both require processing your information to do the thing you asked for.
- Legitimate interest — keeping the site secure, preventing spam, diagnosing bugs, and sending the occasional newsletter to registered accounts about the archive they already have a relationship with — always with a one-click unsubscribe in every email.
- Consent — anywhere else we ask first, for anything more than that.
How long we keep it
- Account data — kept while your account is active, deleted within 30 days of a deletion request.
- Newsletter subscription status — tied to your account, and deleted along with it. A no-account newsletter signup is kept until you unsubscribe, at which point the address is deleted outright, or until it goes unconfirmed indefinitely, in which case it's never subscribed in the first place.
- Published builds — kept indefinitely as part of the public archive, unless you ask us to take yours down.
- Rejected or withdrawn submissions — deleted within 90 days.
- Anonymous submitter contact emails — deleted once the submission is resolved (published or rejected) and you've been notified.
Your rights
Wherever you are, you can ask us to access, correct, or delete your information. Depending on where you live, you may have specific legal rights on top of that:
If you're in the EEA or UK (GDPR)
Right to access, rectify, erase, restrict, or port your data, and to object to certain processing. You also have the right to lodge a complaint with your local data protection authority.
If you're a California resident (CCPA/CPRA)
Right to know what we collect, right to delete it, and right to non-discrimination for exercising these rights. We don't sell or share personal information for cross-context advertising, so there's no opt-out needed for that.
To exercise any of these, email us at the address below — we'll respond within 30 days.
International transfers
Our database runs on Supabase infrastructure in the EU. Some of our other providers (Vercel, SendGrid, Google, Discord) are based in or operate servers in the United States, meaning some data may be processed there. Where required, we rely on those providers' standard contractual clauses or equivalent safeguards for such transfers.
Children's privacy
Karto isn't directed at children, and we don't knowingly collect information from anyone under 13 (or the minimum age required in your country). If you believe a child has given us information, contact us and we'll delete it.
Security
We use industry-standard measures — encrypted connections, access controls on our database, short-lived signed upload URLs — to protect your information. No system is perfectly secure, but we take reasonable steps to prevent unauthorized access.
Changes to this policy
If we make a material change, we'll update the date at the top of this page and, for significant changes, post a notice on the site. Continuing to use Karto after a change means you accept the updated policy.
Contact us
Questions, requests, or concerns about your data: developer@karto.gg