DIE ON THIS HILL

Privacy

This site takes money and publishes opinions. That means it holds a small amount of personal data. Here is all of it, who else touches it, and how to get it removed.

What is public on purpose

Claiming a hill publishes three things: the name you put on the flag, the one line you wrote under it, and the amount you paid. All three sit on the hill page and stay in that hill’s history. The name and the amount also go into the share image and into the page description search engines index.

The amount is public because it is the price of the next claim. Hiding it would break the game.

The name does not have to be your legal name. The form asks for a name, a handle, or an alias, and it does not check. Use something you are content to see in public.

When someone takes the hill from you, your entry stays in its history: who held it, at what price, for how long. That part is built to be permanent.

What is never public

Your email address. It reaches the database two ways, and it stays off the site in both.

As a buyer. When your payment settles, Polar passes on the address you paid with, and it is stored on your claim. It is used for two messages: when someone takes your hill, and when your payment landed too late to crown you and the money is going back.

As a watcher. You type an address into the box that offers to tell you when a hill changes hands. It is stored against that hill with a random token, which is what the confirmation and unsubscribe links both use. Nothing is sent to you until you click the confirmation link, so an address typed in by somebody else never turns into email.

Addresses are shown nowhere on the site, appear in no public API response, and are not sold or handed to anyone outside the list below.

Who else touches it

Polar (payments)
Card details are typed into Polar's checkout and never reach this site or its database. What comes back is an order id and the address you paid with.
Neon (database)
Hosts the Postgres database holding the hills, the claims, and the watcher list.
Vercel (hosting)
Serves every page and runs the API routes, so it handles the usual request data, your IP address included.
Resend (email)
Sends the dethronement, refund, and watcher emails. It runs on an API key. Without that key the site sends no email at all.
PostHog (product analytics)
Runs only when a project key is configured. Events record which hill, which amount, and which button. Never a name, never an email, never your one line. Events sent from the payment webhook identify a claim by its number. The default host is PostHog's EU cloud.
Google Analytics (web analytics)
Loads only when a measurement ID is configured. There is no fallback ID in the code, so leaving it unset keeps GA4 off entirely.
Upstash (rate limiting)
When configured, your IP address becomes a counter key so the checkout endpoint cannot be flooded. Those keys expire within the hour.

Several of these are US companies, so some of this data is processed outside the EU.

Cookies

The site sets no cookies of its own. There are no accounts and no sessions to keep. PostHog and Google Analytics set their own cookies when they are switched on. When they are not, your browser leaves with nothing.

How long it is kept

Watcher rows live until you unsubscribe. The link performs a real delete: the address, the hill, and the token all go. A row that is never confirmed is swept periodically without ever having been mailed.

Claims are kept indefinitely. The public half is the hill’s history and is meant to stay. The email address attached to a claim has no automatic expiry today. That is the plain answer rather than the comfortable one, and it is the line on this page most likely to change.

Polar keeps its own record of the payment. A payment record is an accounting record, so it outlives a deletion request.

Analytics events sit with PostHog or Google under their own retention settings.

One asymmetry, stated plainly

A watcher can leave without asking anyone. Every watcher email carries an unsubscribe link, and using it deletes the row.

A crowned holder cannot. There is no admin surface and no self-service deletion for a claim. Removing the address on a claim is a manual job. Asking is the only mechanism that exists.

Getting your data removed

Write to privacy@thishill.lol. Name the hill and the name that is on the flag.

Removed on request: the email address stored on your claims, and any watcher rows for your address.

Kept by default: the public history of a hill you held. If you want the published name or the one line taken down as well, say so in the same email. It is a hand edit, and it can be done.

A person reads that mailbox and makes the change. Expect a reply from a human, not an instant confirmation screen.

Your rights

You can ask what is stored about you, ask for it corrected, ask for it deleted, and object to how it is used. Same address.

If the answer does not satisfy you, you can complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), which supervises the operator.

Who runs this

Die On This Hill is operated by Huilata Oy, a Finnish company, and is the controller for everything described here. Contact: privacy@thishill.lol.

Last reviewed 29 August 2026. This page describes the site as it is built. When the handling changes, this page changes with it.

How the hills work