Privacy
What we store, and what we don’t.
Last updated 8 September 2026
This page is written to be read, not to be survived. It lists everything the site and the bot actually record, because that list is short.
Who runs this
GhostMacro is a small, independently run project. It is not a company, and it is not affiliated with, endorsed by, or connected to Supercell. There is no support email: everything — questions, purchases, key problems, deletion requests — goes through the Discord server, which is also where you can reach a human.
We never ask for an email address
There is no account to create, no newsletter, no password. The free trial asks for nothing at all, and the optional Discord username field is exactly that — optional.
What the website records
- Server logs. The web server writes the usual access log line for every request: IP address, timestamp, the page requested, the referring page and your browser’s user-agent string. This is how the server is operated and how abuse is spotted. Logs rotate and are not kept indefinitely.
- Product analytics (PostHog, EU servers). Page views and a short, fixed list of events — pricing section seen, trial key requested, trial key issued, checkout started, Discord link clicked. Before you accept cookies, PostHog runs in anonymous mode: nothing is written to your device, no profile is created, and you are not followed from one visit to the next. Your IP address and user-agent still reach PostHog’s EU servers as part of the request itself, because every HTTP request carries them. URLs are stripped of everything except campaign tags before they are recorded, so nothing in a link’s query string is kept.
- Session replay (Microsoft Clarity) — only if you accept. If you press “Allow” on the cookie banner, Clarity is loaded and records how the page is used (scrolling, clicks, mouse movement) so layout problems can be found. It writes to your device. Press “No thanks” and it is never loaded.
Declining costs you nothing on this site: no feature is gated behind the banner. Your choice is
stored in your browser’s local storage under gm_analytics_consent and you can clear
it at any time by clearing site data.
What the free trial records
Requesting a trial key stores one row: your IP address, the key that was issued, the time it was issued, and the Discord username you typed, if you typed one. The IP is what enforces “one trial per PC” — without it the limit would not exist. When the key is activated in the app, the machine identifier described below is added to that row.
What a licence records
- The key itself and its expiry date.
- A machine identifier (HWID). A value derived from your hardware, used for one thing: locking a key to one PC so it cannot be shared. It is not a browser cookie and it is not used to track you anywhere else.
- Your Discord username and user ID, because keys are delivered and supported on
Discord and
/statushas to know whose bot it is reporting on. - Farming totals — gold, elixir, dark elixir, walls, attacks, wins and
losses — plus a heartbeat with the time your bot was last seen and whether it is running.
These feed the
/statusand/topDiscord commands and the cumulative counters on the home page. They are game numbers, not personal data, and nothing about what is on your screen is transmitted.
The bot does not send screenshots, keystrokes, files, or anything about your PC beyond the machine identifier and those game totals.
Payments
Payment is arranged on Discord and processed by Stripe. Card details are entered on Stripe’s own pages and are never seen by, sent to, or stored on our servers — we receive a payment confirmation and a session reference, nothing more. Stripe acts as its own controller for what it collects; see stripe.com/privacy.
Who else sees any of this
Nothing is sold, rented, or handed to advertisers. The only third parties involved are the ones named above — PostHog (EU), Microsoft Clarity (only with consent), Stripe (payments) and the hosting provider — each doing the single job described.
How long it is kept
Licence and trial rows are kept while the licence exists, plus the daily database backups, which are kept for 30 days. Server logs rotate on a short cycle. Analytics data is kept under the retention policy of the tool that holds it.
Deleting your data
Open a ticket on the Discord server and ask. A trial row, a licence row and the totals attached to it can all be deleted on request. Deleting an active licence also ends it — the key is the record. You can also ask for a copy of what is held about you, or for a correction.
Changes
If this page changes in a way that matters, the date at the top changes with it and the change is announced on Discord.