Effective August 27, 2026.
This explains what ClusterHack collects, why, who else sees it, how long we keep it and what you can demand of us. It covers clusterhack.dev, its API and its MCP server. Written plainly on purpose — if anything here is unclear, ask us at info@clusterhack.pw.
the operator of ClusterHack decides how and why your personal information is handled on the platform itself, and is the controller (or, under US law, the “business”) for it.
Events are different. When you join a hackathon, its organizer independently decides what to do with the participant data from that event. For that data, the organizer is a controller in their own right, alongside us. Their own handling of it is their responsibility — see section 4.
| Category | What | Where it comes from |
|---|---|---|
| Account | Username, email, password (stored only as a salted hash — we never see it), first/last name. | You, at sign-up. |
| Profile | Photo, date of birth, short and long bio, phone, website, LinkedIn, GitHub, Telegram, skills, city. | You, optionally. |
| Event participation | Which events you joined, registration form answers, consent record with timestamp and IP, attendance check-in, whether you are looking for a team. | You, plus organizer check-in. |
| Teams & work | Team membership and roles, join requests, board cards and attachments, build-log posts. | You and your teammates. |
| Submissions | Project title, description, links, screenshots, pitch deck, and the scores and comments judges give it. | You; judges for scores. |
| Company pages | Employment records, positions, employment requests, admin rights. | You and company admins. |
| Billing | Plan, subscription state, payment records. Card details are handled by the payment provider — we do not store card numbers. | You and the payment provider. |
| Technical | IP address, browser and device information, pages requested, timestamps, error logs. | Automatically, as you browse. |
| MCP / API | Which app you connected, what permissions you granted, and a record of the calls it made. | Automatically, if you connect one. |
You can switch off non-essential email from your notification settings. We do not use your personal information to make decisions with legal effects about you without a human involved.
Read this before joining an event. The organizer and the administrators of an event you join can see your name, username, email, the answers you gave on their registration form, your date of birth if their form asked for it, your attendance, your team, and your submission. They can export participant lists and generate name tags and certificates from them.
We require organizers to use that information only to run their event. We cannot technically prevent an organizer from misusing what they can legitimately see, so if an organizer misuses your data, tell us at info@clusterhack.pw — we can revoke their access and remove the event.
Judges assigned to an event can see the submissions they are judging. Judges' private notes are visible to the organizer but never to your team.
Some things are published deliberately, and are visible to anyone, signed in or not:
Search engines can index these. Do not put anything in them you would not want found. Your email address, phone number and date of birth are never shown publicly.
We use a small number of outside services. Each gets only what it needs.
| Who | What for | What they receive |
|---|---|---|
| Google Analytics | Website analytics on some older pages | IP address, device and browser data, pages viewed. |
| OpenRouter | Large language models behind the AI features | Only the text you submit to an AI feature, plus related event or project context. See section 7. |
| Email delivery | Sending service and event email | Your email address and the message. |
| Hosting | Running the servers | Everything, as processor, under contract. |
No advertising trackers. We do not run advertising or retargeting pixels, and we do not track you across other websites for advertising. Nothing here is used for cross-context behavioural advertising, so there is no “sharing” of your information to opt out of.
Essential cookies keep you signed in and protect forms against CSRF; the site does not work without them.
Features such as idea generation, planning help, the organizer assistant and pitch review send the text you provide — and the relevant event, team or project context — to OpenRouter, which routes it to a model provider.
Do not paste secrets, credentials or anyone else's personal information into an AI feature. If you never use these features, nothing of yours is sent to a model provider.
If you connect an app through our MCP server, we record which app it is, the permissions you granted and when, and a log of the calls it makes: the tool name, the time, and the outcome.
Those logs are redacted. Passwords, tokens, email addresses and phone numbers are masked before being written, and long text is truncated. We keep them for 180 days, then delete them automatically. They exist so a misbehaving app can be identified and cut off — nothing else.
A connected app can only read what your account can read, further narrowed by the permissions you ticked. Revoke any of it at /settings/connections/. What the third party does with data it has already read is governed by their privacy policy, not ours.
We do not sell your personal information, and we have not sold it in the past twelve months. We do not sell or share the personal information of anyone we know to be under 16.
We also do not “share” personal information for cross-context behavioural advertising, as California uses that term. There is no advertising pixel on the service.
Delete your account and we remove your personal information, except what we must keep by law and content that has become part of a public, published result (which we can anonymise on request).
Traffic is encrypted with HTTPS. Passwords are stored only as salted hashes. Access tokens are stored hashed, are short-lived, and are bound to the account that granted them. Permission checks run on every request, including every MCP call.
No system is perfectly secure. If you find a vulnerability, please report it to info@clusterhack.pw before disclosing it publicly, and we will work with you.
You must be at least 13 to have an account. We do not knowingly collect personal information from children under 13; if we learn we have, we delete it. A parent or guardian can write to info@clusterhack.pw to review, delete or stop further collection of their child's information.
Participants under 18 should be careful about what they put on a public profile or team page.
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you have the right to:
Much of this you can do yourself: edit your profile in settings, revoke app connections, and delete your account. For anything else write to info@clusterhack.pw. We answer within 45 days and may extend once where the law allows, telling you why.
We honour the Global Privacy Control browser signal as an opt-out of sharing. An authorised agent may act for you with written proof; we may still ask you to confirm it directly.
We do not use sensitive personal information for inferring characteristics about you.
If you are in the European Economic Area, the United Kingdom or Switzerland, the GDPR (or UK GDPR) applies and you also have the rights to access, rectify, erase, restrict and object to processing, and to data portability.
Our legal bases:
Where processing rests on consent or contract and is automated, you can ask for your data in a machine-readable form. You may also complain to your local supervisory authority — in the UK, the Information Commissioner's Office.
ClusterHack is operated from the United States and your information is processed there. The analytics service in section 6 processes data in the United States, and AI requests are processed wherever the model provider operates.
If you are in the EEA, UK or Switzerland, this means your information leaves your country. Where required we rely on the European Commission's Standard Contractual Clauses, or your explicit consent for the optional cookies. Ask us for details of the safeguards.
We will update this policy as the service changes. Material changes are announced on the site or by email before they take effect, and the date at the top always tells you which version you are reading.
Privacy questions and requests: info@clusterhack.pw.
See also: Terms and Conditions · Support