Privacy Policy

Last updated 3 August 2026

This policy explains what builds.center collects, why, and what you can do about it. It is written to be read, not to be survived.

Who we are

builds.center is operated by Bagas Naufal Insani, an individual based in Tangerang, Indonesia, acting as the data controller for the personal data described here. You can reach us at support@builds.center; our postal address is on the contact page.

The short version

  • We collect what is needed to run an account and show your builds to the people you choose.
  • There are no third-party analytics, advertising or tracking scripts on this site. Not Google Analytics, not a pixel, not a tag manager. Our fonts are served from our own servers rather than a font CDN.
  • We do not sell your personal data, and we do not share it for advertising.
  • We never see your password or your card number. Sign-in is handled by Clerk and payments by Paddle.
  • You can delete your account, and doing so deletes the content attached to it.

What we collect

Account and profile

Your account is created and secured through Clerk, our authentication provider. Clerk holds your credentials — passwords, one-time codes and connected sign-in providers such as Google, GitHub or Discord. We never receive or store your password.

From Clerk we mirror, and store in our own database:

  • your user id, username and email address;
  • your display name and avatar image URL, if you set them.

You may add a short biography to your profile. Your username, display name, avatar and biography appear on your public profile page.

Content you create

Builds and their revision history, the parts and links inside them, posts, comments, reactions, follows, collections, tags, and any images you upload. Builds you mark as public are readable by anyone, including search engines. Builds you keep private are not.

Safety and moderation

Reports you submit, accounts you block, and the record of any moderation action taken on your account or content — including whether an account has been suspended. We keep these so that moderation decisions can be reviewed and appealed.

Usage

We record a view when a public build page is opened. Each view event stores:

  • which build was viewed;
  • a viewer key — your account id if you are signed in, or the random identifier in the bc_anon cookie if you are not;
  • the date, with repeat views by the same viewer on the same day counted once;
  • the country the request came from, as a two-letter code, so that a creator can see roughly where their readers are. Our CDN derives it from the network address and passes on the country alone — we neither receive nor store anything more precise, and a country on its own does not identify you.

We also count clicks on the purchase links inside a build, recording which build, which link, and the same two-letter country. Click records are not tied to a viewer key or to your account.

We do not store your IP address in our database, and we do not build advertising or behavioural profiles. Our hosting provider processes IP addresses transiently in order to deliver the site and to defend against abuse, as any web host must.

Payments

If you buy a paid plan, the transaction is handled by Paddle, which acts as the merchant of record — the seller on the receipt. Paddle collects and processes your payment details and billing information under its own privacy policy. Card numbers never reach our servers.

From that transaction we store only your Paddle customer and subscription identifiers, your plan tier and any extra capacity you have purchased.

Correspondence

If you email us, we keep the message and our reply so that we can deal with the matter and refer back to it if it recurs.

Why we use it, and on what basis

Where the UK and EU General Data Protection Regulation applies, our legal bases are as follows.

  • To provide the service — creating your account, storing and publishing your builds, showing you the feed and notifications. Necessary for performance of our contract with you.
  • To show creators how their builds are doing — view and click counts. Legitimate interests: creators reasonably expect to see whether their work is being read, and the data involved is minimal and not used to profile visitors.
  • To keep the platform usable and safe — rate limiting, the anonymous view limit, moderation, and enforcing our Terms. Legitimate interests, and compliance with law where we are required to act.
  • To take payment — necessary for performance of our contract with you.
  • To contact you about the service — for example a security notice or a material change to these terms. Legitimate interests, or a legal obligation.

Under Indonesian Law No. 27 of 2022 on Personal Data Protection, we process personal data on the equivalent grounds of contractual necessity, legal obligation, and legitimate interest, and with consent where consent is the appropriate basis.

Who else processes it

We use a small number of providers, each for a specific job:

  • Clerk — authentication and account credentials.
  • Neon — the managed PostgreSQL database holding your account and content.
  • Amazon Web Services — application hosting, image and page storage, and the content delivery network that serves the site. Our infrastructure runs in the Asia Pacific (Singapore) region.
  • Paddle — merchant of record for payments, if and when you buy a paid plan.
  • YouTube — only if a creator has embedded a video in a build. Those embeds use YouTube's privacy-enhanced mode, so YouTube does not set its usual tracking cookies unless you play the video. See our Cookie Policy.

We do not sell personal data, and we do not disclose it to anyone else except where we are legally required to, or where it is necessary to establish or defend a legal claim.

Where your data goes

Our servers and database are in Singapore. Clerk and Paddle are established outside Indonesia and process data in their own regions, including the United States and the European Union. Where the GDPR applies to a transfer, it is made under the European Commission's Standard Contractual Clauses or another lawful transfer mechanism offered by that provider. Where Indonesian law applies, transfers are made to jurisdictions with an adequate level of protection or under equivalent contractual safeguards.

How long we keep it

  • Account and content — until you delete them, or until you delete your account.
  • Deleted content — removed from the live service immediately. Encrypted backups are retained for up to 30 days, after which deletion is complete.
  • View and click records — retained for up to 24 months so that creators can see trends over time, then deleted.
  • Moderation and safety records — retained while the account exists and for up to 12 months afterwards, so that a banned account cannot be trivially recreated.
  • Payment records — retained by Paddle and by us for as long as tax and accounting law requires.

Your rights

You can access, correct, export, or delete your personal data; object to or restrict processing based on legitimate interests; and withdraw consent where processing relies on it. Most of this is available directly in your account settings, including deleting your account. For anything else, email support@builds.center and we will respond within 30 days.

Deleting your account removes your profile, builds, posts, comments and uploaded media. Records we are required to keep — such as payment records for tax purposes, and moderation records as described above — are retained for the periods set out here.

If you are in the EU or UK you may complain to your local supervisory authority. If you are in Indonesia you may raise a complaint with the relevant authority under the Personal Data Protection Law. We would prefer you told us first, so we can try to fix it.

Security

Traffic is encrypted in transit with TLS. Data is encrypted at rest by our database and storage providers. Passwords are held by Clerk and never reach us. Access to production systems is limited to the operator and protected by multi-factor authentication and short-lived credentials.

No service is perfectly secure. If you believe you have found a vulnerability, please email support@builds.center and give us a reasonable opportunity to fix it before disclosing it publicly.

Children

builds.center is not intended for children under 13, and we do not knowingly collect their personal data. Where the GDPR applies and your national law sets a higher age for consent to online services — up to 16 — that age applies instead. If you believe a child has created an account, contact us and we will remove it.

Changes

We will update this page when our practices change, and change the date at the top. If a change materially affects your rights, we will tell registered users by email or by a notice in the app before it takes effect.

Contact

Questions, requests, or complaints about privacy: support@builds.center. See also our contact page.