mutate.lol

Exactly what is kept, where, for how long, who else handles it, and how to have it deleted. Nothing here is vaguer than the code.

Last changed 23 September 2026

Who
01

Who is responsible

mutate.lol, status.mutate.lol and preinfection.lol are run by one person. Questions, requests to delete your data, and reports all go to the owner, through the form on the report page or on Discord. Passwords are never visible to anyone, the owner included.

The short version: no ads, no trackers, nothing sold, and no record of who visits whose page. What follows is the long version, all of it.

Accounts
02

What is kept if you have an account

  • Your email address, to send your sign-up code and so one person cannot sign up a hundred times.
  • Your password, never. Only a one-way hash of it (PBKDF2, 100,000 rounds, a random salt, and a secret pepper kept in Cloudflare's encrypted secret store rather than the database). It cannot be turned back into your password by anyone, including the owner.
  • Your username, display name and everything on your page: bio, links, badges, colours, settings, and the pictures, music and files you upload. Files over 4 MB are kept in Cloudflare R2 rather than Cloudflare KV; both are Cloudflare.
  • For each hosted file or bundle: whether it is one-time, when it deletes itself if you set that, and, if you set a password, only a one-way hash of it (the same kind as account passwords). A one-time link keeps when it was opened and a hash of the opening browser's key, nothing about who opened it.
  • A report you send from the report page: what you reported, why, what you wrote, and a way to reach you only if you typed one. Your address is not kept with it. When it names a profile, a one-way code made from your address and that profile is kept, only so one person cannot count as several; it cannot be turned back into your address, and it is different for every profile. A profile several different people report is hidden until it has been looked at. A report about a child is also sent straight to the owner on Discord.
  • Where you are signed in: for each sign-in, when it started and was last used, the country (only the country), a label like “Chrome on Windows” (never your full browser details), whether it used a password or a passkey, and a one-way hash of a random id kept in your browser, so the same browser is recognised. Your address is never kept. A sign-in from a device or country your account has not used before sends an email to your account's address.
  • If you add a passkey: only its public key. The private half never leaves your device.
  • Codes sent by email (forgot password, changing your email): only a one-way hash, for ten minutes, deleted once used.
  • Friends: who you asked and who said yes. Accepted friends appear on each other's pages, which you can turn off.
  • If you turn on “Show me on Explore”: your name, picture, bio and view counts are listed on mutate.lol/explore. It is off unless you turn it on.
  • Templates you like: which ones, so the count is right.
  • Your aliases, if you claim any.
  • If you turn on two-factor sign-in: its secret, and your recovery codes as hashes. A recovery code is deleted the moment it is used.
  • If you link Discord: your Discord id, handle and picture. If you take a live-status slot, the bot keeps your current status and activity so your page can show it.
  • The date and time you agreed to the terms, when you last signed in, and the country (only the country) your last sign-in came from.
Visitors
03

What is kept about people who visit a page

  • Counts, not people. Each page keeps a running total of views, a total for each day and a total for each country. There is no record of an individual visit: no address, no city, no browser, no time.
  • “Here now” uses a hash of your address mixed with a secret that changes every day. It cannot be turned back into the address and is deleted within two minutes of you leaving.
  • Rate limits (how many sign-in or sign-up attempts one visitor makes) use the same kind of salted hash and expire within minutes.
  • Security blocks. An address caught probing the sites for weaknesses is blocked from all three for a year, and only a salted hash of that address is kept.

Your address itself is never written down anywhere by this site.

Browser
04

What is stored in your own browser

  • mutate_session, a cookie, only if you sign in: keeps you signed in for 30 days. Signing out, signing that device out from Security, or “sign out everywhere”, ends it.
  • mutate_device, a cookie set when you sign in: a random id, so a sign-in from this browser is not treated as a new device. It holds nothing about you.
  • A one-day cookie per profile you view, so refreshing does not count as a second view.
  • A ten-minute cookie while you are linking Discord, to make sure the reply is really yours.
  • A cookie for a protected file link you open: fifteen minutes for a one-time link, a day for a password link, and only ever sent back to that one link.
  • Which announcement you dismissed in the dashboard, so it stays dismissed.
  • Your sound choice for each profile (muted or not, and the volume), so a page remembers what you picked.
  • Dashboard conveniences: whether the sidebar is open and where it was scrolled.

None of these follow you to other sites, and the sound and dashboard choices never leave your device. Clearing this site's data in your browser forgets all of them.

Others
05

Who else handles anything

  • Cloudflare hosts the sites, the database and the file storage, runs the sign-up check (Turnstile), and, as with any host, processes each request to deliver it. Cloudflare's own Web Analytics is also switched on for the site's pages; it uses no cookies and reports only totals.
  • Resend sends your sign-up code, so it sees the address the code goes to.
  • Cloudflare Workers AI looks at each picture you upload for your profile (avatar, background, badge, link icon or cursor), to check it is not sexual or nude.
  • Cloudflare's security DNS is asked whether the website a profile links to is a known malware or phishing site, when the link is added and when a visitor clicks it. Only the website's name is sent, never who is asking.
  • Have I Been Pwned is asked whether a new password has appeared in a known data breach. Only the first five characters of a one-way hash of it are sent; the password itself never leaves the site.
  • Discord, only if you link your account or add your Discord id; Lanyard supplies live status for Discord ids added to a page.
  • Google Fonts, GitHub, Roblox, Spotify, YouTube and the avatar-decoration hosts provide fonts, widgets and decorations. Every one of them is fetched by this site and served from it, so your browser never contacts them and they never see who you are.

Nothing is sold, rented or shared for advertising. There are no ads.

Time
06

How long things are kept

  • Your account and page: until you delete them or ask for the account to be deleted.
  • An account that never verifies its email: deleted automatically once its ten-minute code has expired, and the name goes back into circulation.
  • A deleted file: its record and bytes go at once and it cannot be restored. Its key is kept as deleted, so the site refuses it even where Cloudflare still has a cached copy. A browser that already loaded it may keep its own copy.
  • A file set to delete itself: deleted, the same way, within minutes of its time. A bundle set to expire: its link is removed; the files in it stay until you delete them.
  • Reports: kept until the owner deletes them.
  • View totals: for as long as the page exists.
  • “Here now”: two minutes. Rate limits: minutes. Security blocks: one year.
  • Sign-in records: an ended session is marked ended; the list of where you are signed in is deleted with your account.
  • Backups: a copy of the database is saved every night to private Cloudflare storage and kept for 30 days, so the site can be brought back if something goes wrong. Deleting something removes it from the site at once; it drops out of the backups as they age out.
  • Status checks on status.mutate.lol: 90 days of results; its incident history clears every night at midnight, eastern time.
  • A refused image: only a fingerprint of it (a SHA-256 hash) is kept, for good, so the same image is refused on sight. The image itself is not kept.
  • Banned handles: kept for good, so nobody can take them again.
Security
07

How it is protected

  • Passwords are hashed as described above; the site cannot read them and never stores them in a file.
  • Every secret the site uses (the pepper, the session signing key, the bot token) lives in Cloudflare's encrypted secret store, not in the code or the database.
  • Sessions are signed, expire, and can all be ended at once with “sign out everywhere”. Two-factor sign-in is available.
  • Profiles and the file host tell browsers to run only the site's own code, and cannot be framed by other sites.
  • Every file link tells search engines not to index, archive or preview it. A one-time or password file's own address is never handed out; visitors only ever get its protected link.
  • Passkeys and two-factor sign-in are available, and new passwords are checked against known data breaches.
  • Before a visitor follows a link off a profile to a site that is not well known, the page shows where it goes, and links to known malware or phishing sites are blocked.
  • No system is perfectly secure. If something ever went wrong in a way that affected your data, it would be said plainly in the changelog.
Choices
08

What you can do

  • See and change everything on your page, any time, in the dashboard.
  • Delete anything you uploaded, any time, yourself.
  • Download a copy of what is kept about your account, and every file you uploaded, yourself, from Settings in the dashboard. Or ask for the whole account to be deleted, with everything on it.
  • Turn off the live status, the Discord link and “here now” on your own page.

Requests go to the owner through the report page or on Discord. Say which account it is about; you may be asked to prove it is yours from inside it.

Age
09

Children

Accounts are for people aged 13 and over, and signing up requires confirming it. If an account turns out to belong to someone younger, it is deleted with everything on it.

Changes
10

When this changes

If what the site keeps changes, this page changes with it and the changelog says so.