[ PRIVACY ]

Privacy Policy

Mr.Clu tools are built local-first: no accounts, no cloud sync, no Mr.Clu telemetry. This policy discloses in full everything that leaves your machine.

LAST UPDATED: SEPTEMBER 28, 2026

Accounts
None required, ever
Telemetry
No usage tracking, no crash reporting, no install counter, no identifier of any kind
Your Data
All config stored locally on your PC
Control
Delete app files to remove all data

Overview

Our Approach to Privacy

The principles behind how Mr.Clu software handles your data

Mr.Clu operates as a solo developer making free tools for PC enthusiasts. Current public releases of all Mr.Clu applications are designed to operate without requiring personal information. There are no user accounts, no cloud synchronisation, and no analytics that report what you do inside the software back to Mr.Clu.

The complete list of outbound network activity across all Mr.Clu software is: (1) an update-check in CLU VIEW that contacts mr-clu.com with no personal payload; (2) the same update-check in VU1 Dial Controller (vu1-update.json), in Spec Card Generator (speccard-update.json) and in CLU’D IN (cludin-update.json), each run automatically shortly after the app starts; (3) the CLU VIEW Template Store, which contacts mr-clu.com only while you have the store open, to list templates, show their preview images, download one you choose to install, and send a star rating if you choose to give one; and (4) optional weather API calls in VU1 Dial Controller when you explicitly enable the weather feature. Each is described in full below.

This policy covers the mr-clu.com website and all current Mr.Clu applications. It is the complete and accurate record of what data is involved in using Mr.Clu’s services. If you identify an omission, please email by.mr.clu@gmail.com.

Data Practices

What Mr.Clu Does Not Collect

An explicit list of data types that Mr.Clu does not receive or store

Mr.Clu applications never send your content, settings or hardware data to any server. The only database Mr.Clu operates is the one behind the website’s anonymous visit counter, described in the Website section below; the CLU VIEW update check and Template Store write to that same database as aggregate counts, and nothing in it identifies a person. Specifically, across all current releases, Mr.Clu does not collect:

  • ›Your name, email address, username, or any account credentials
  • ›Your hardware specifications, sensor readings, temperatures, fan speeds, or power values
  • ›Your CLU VIEW dashboard profiles, layout configurations, or applied themes
  • ›Your VU1 dial assignments, audio source preferences, or weather location settings
  • ›Your generated Spec Card images or the local hardware data used to create them
  • ›Your CLU’D IN gaming session data, frame-rate logs, or thermal history
  • ›Usage analytics, feature-interaction events, crash reports, or error logs from any Mr.Clu application
  • ›Your IP address in any Mr.Clu-operated log. The visit counter, the CLU VIEW update check and the Template Store all store only a salted, daily-rotating, truncated hash that cannot be reversed (see below); Cloudflare processes IPs to serve the site under its own policy

There is no exception to this and no persistent identifier anywhere in Mr.Clu software. Earlier CLU VIEW 2.0 builds carried an anonymous install counter that used a persistent random ID; it was removed in full, and updating deletes the ID those builds had stored on your PC. There is no setting for it, because there is nothing left to switch off.

Website

mr-clu.com — What the Website Collects

Cloudflare hosting plus a small, anonymous, first-party visit counter, and nothing else

mr-clu.com is served by Cloudflare and runs no third-party analytics, no advertising pixels, no retargeting tools, and no cookies. The only measurement on the site is a small first-party visit counter that Mr.Clu built and hosts on Mr.Clu’s own Cloudflare infrastructure. Your data is never shared with, or collected by, any analytics company.

Cloudflare — Hosting & CDN

What it does: Cloudflare hosts and serves the website globally. When you visit any page, Cloudflare processes standard HTTP request data including your IP address, browser type and version, operating system, referring URL, requested URL, and response codes. This processing is necessary to deliver the website and protect it from abuse.

Data retained by Cloudflare: Cloudflare may retain request logs and security signals per its data retention policy. Mr.Clu does not have access to individual request logs. Cloudflare’s full privacy policy: cloudflare.com/privacypolicy.

First-Party Visit Counter

What it records: Each page on the site reports basic, anonymous visit statistics to a private database on Mr.Clu’s Cloudflare account: the page viewed, the referring site (if your browser sends one), country and device type (desktop or mobile), time spent on the page, how far you scrolled, which links you clicked, which installers are downloaded via the site’s /dl/ links, and the address of any page on this site that returns “not found” (a daily count per address, so broken links can be found and fixed; no visitor detail is attached to it). This exists so a solo developer can see which pages and downloads people find useful, and which links are broken. Nothing more.

Privacy design: No cookies are used and your browser is not fingerprinted. Repeat visits are counted with a salted, truncated SHA-256 hash of your IP address and browser signature whose salt rotates every day. It cannot be reversed to reveal your IP, cannot recognise you from one day to the next, and cannot follow you to any other website. Your raw IP address is never written to the database. A random session id lives in your tab’s sessionStorage and is deleted the moment the tab closes.

Retention: All visit statistics are automatically and permanently purged after 90 days.

Opt-out: Two ways, and you can use either. Global Privacy Control: if your browser or extension sends the Sec-GPC signal (Brave and DuckDuckGo send it by default; Firefox has it under “Tell websites not to sell or share my data”), every counter described above is switched off for every request you make, including downloads you open directly and pages that return “not found”. Nothing to install and nothing to remember. Or run localStorage.setItem('mc_ignore','1') in your browser’s console on mr-clu.com, which stops all page, scroll, timing and click measurement in that browser and marks any download you start from a link on this site so it is not counted either. Because this site sets no cookies, that setting lives only in your browser and cannot be read by the server, so a /dl/ address opened directly rather than clicked, and a page that returns “not found”, are the two cases it cannot reach. Global Privacy Control covers those.

Application

CLU VIEW — Sensor Panel

What CLU VIEW stores locally and what (if anything) leaves your machine

CLU VIEW stores all user data locally on your PC in the application’s AppData directory. This includes dashboard profiles, widget configurations, theme preferences, layout settings, and application logs. None of this data is transmitted to Mr.Clu or any third party.

Data Type Where It Stays Detail
Dashboard profilesLOCALStored in AppData. Never transmitted.
Sensor readingsLOCALRead from hardware and displayed on-screen. Never transmitted.
Application logsLOCALWritten to AppData. Never transmitted to Mr.Clu.
Version checkEXTERNALHTTPS request to mr-clu.com. No personal data in payload. IP address processed by Cloudflare per their policy, then reduced to the daily anonymous hash described in the Website section.
Template StoreEXTERNALOnly while the store is open. Fetches the catalogue, preview images and any template you install; sends a star rating only if you give one. See the Template Store section below.

Update check detail: CLU VIEW requests https://mr-clu.com/cluview-update.json at startup, and again whenever you press Check for Updates, to see whether a newer version exists. CLU VIEW NOVA (2.x) additionally fetches a signed release manifest and, if you accept an update, downloads the installer. CLU’D IN behaves the same way as CLU VIEW NOVA, using cludin-update.json and its signed manifest cludin-latest.json. These requests are strictly domain-whitelisted to mr-clu.com, use HTTPS only, are limited in response size to prevent abuse, and contain no hardware data, no configuration and no personal identifier beyond the IP address inherent to any HTTPS request.

What is recorded: the update check writes one row per day per installation, holding the date, which application checked, and the daily anonymous hash described in the Website section. Nothing else, and no version number. Because that hash is re-salted every day it cannot be followed from one day to the next, so these rows indicate traffic rather than a count of people. Those rows are purged after 90 days along with the rest of the visit statistics.

Application

CLU VIEW — No Install Tracking

There is no install counter and no persistent identifier: what changed, and what it cost

CLU VIEW does not count installations. It does not generate, store or transmit an install ID, a device ID, or any other value that could link one run of the app to another, or one day’s use to the next day’s. There is no setting for this because there is no mechanism to switch off.

What changed

Earlier CLU VIEW 2.0 builds did include an anonymous install counter: a random identifier generated on your PC at first run and sent, at most once a day, with the app version and whether you were on Windows or Linux. It was removed in full: the code, the setting, and the disclosure that described it.

If you are updating

The identifier those builds stored in your configuration file is deleted the first time the new version starts, and the file is rewritten without it. Nothing further is sent, and nothing on the server can be associated with your PC again.

What this cost, stated plainly

Mr.Clu can no longer say how many installations exist. Downloads and update checks are still counted, but only in aggregate against the daily rotating hash described in the Website section. That hash is deliberately re-salted every day, so it cannot be followed from one day to the next. It shows traffic, not a user count. That trade was made on purpose, in favour of the app carrying no identifier at all.

Application

CLU VIEW Template Store

Browsing, downloading, rating, and sharing a template of your own

The Template Store lets you install dashboards other people have made. It is inert until you open it: nothing is fetched, and nothing is recorded, while you are simply using a dashboard.

Browsing and installing

What is sent: ordinary HTTPS requests to mr-clu.com for the catalogue, for preview images, and for the template file itself when you install one. No hardware data, no dashboard of yours, and no identifier are attached to any of them.

What is recorded: installing a template writes a download row (the date, which template, the country Cloudflare reports, and the same daily anonymous hash used everywhere else), and repeat installs of the same template from the same daily hash within an hour are counted once. That is what produces a template’s download count. Browsing the catalogue and viewing preview images record nothing. Download rows are purged after 90 days.

Rating a template

Rating is optional and only offered for templates you have installed. When you download a template the server issues a one-time token; if you rate it, CLU VIEW sends the star value with that token. What is stored is the template id, the number of stars, a hash of the token, and timestamps. The token itself is never stored, and the record contains nothing about you. The hash exists so one download cannot be counted as two votes. Ratings are kept for as long as the template is listed, because they are what produces its score.

Sharing a template of your own

Uploading is entirely optional and happens on this website, not inside the application: CLU VIEW opens mr-clu.com/upload in your own browser. If you submit a template, you provide a display name of your choosing (there is no account, and it does not have to be your real name), a title and description, the template file, and a preview image (required; a submission without one is rejected). Those are stored so the template can be listed, and the display name is published with it. Treat that field as public.

The upload is also recorded against the same daily anonymous hash, to enforce a submission limit of three per hour. That hash is additionally stored on the template’s own record for as long as the template exists, so a submission can be traced back to its other submissions if one has to be moderated; it is not covered by the routine analytics purge. The form is also checked by Cloudflare Turnstile, a privacy-preserving alternative to a CAPTCHA that confirms a human is submitting the form. Turnstile is operated by Cloudflare under its own privacy policy.

Submitted templates are reviewed by hand before they appear in the store. A template you submitted can be taken down on request. Email by.mr.clu@gmail.com.

Application

VU1 Dial Controller

What VU1 Dial Controller stores locally and the optional weather feature’s external contacts

VU1 Dial Controller stores all configuration locally, including dial assignments, theme settings, and serial port preferences. None of this data is transmitted to Mr.Clu.

Data Type Where It Stays Detail
Dial configurationLOCALStored in AppData. Never transmitted.
Hardware readingsLOCALCPU, GPU, RAM, fan data read and displayed locally. Never transmitted.
Audio dataLOCALCaptured and processed locally via WASAPI. Never transmitted.
IP geolocation (weather)OPTIONALSent to ipapi.co when weather feature is first enabled. Returns approximate location. See below.
Weather queryOPTIONALLat/lon co-ordinates sent to Open-Meteo. Returns weather data. See below.
Location co-ordinatesLOCALStored locally after ipapi.co lookup. Used for Open-Meteo requests. Not sent to Mr.Clu.
Update checkMR.CLUAutomatic on start-up: fetches mr-clu.com/vu1-update.json and compares the version number. No payload beyond the request itself.

Weather feature, step by step: When you enable the weather feature for the first time, or when you request a location refresh, the following sequence occurs:

  • ›Step 1: ipapi.co (IP geolocation). An HTTPS request is made to https://ipapi.co/json/. Your device’s IP address is transmitted to ipapi.co. It returns your approximate city name, country, latitude, and longitude. The returned co-ordinates are stored locally. Governed by ipapi.co’s Privacy Policy.
  • ›Step 2: Open-Meteo (weather data). An HTTPS request is made to https://api.open-meteo.com/v1/forecast with the latitude and longitude from Step 1. No additional personal data is included. Governed by Open-Meteo’s Terms of Service.

If the weather feature is never enabled, neither request is ever made. You can disable the weather feature at any time in the application settings, after which no further requests to ipapi.co or Open-Meteo will be made.

Application

Spec Card Generator

Fully local: hardware data and images never leave your machine

SPEC CARD 2 reads hardware information through Windows APIs (WMI, DXGI, the display configuration API, NVML on NVIDIA cards, and HWiNFO or LibreHardwareMonitor if you run them): CPU, GPU, memory modules, drives and free space, motherboard and BIOS, monitors, network adapters, audio and USB device names, uptime, and live temperatures, loads and clocks. Spec Card Generator 1.x reads CPU model, GPU model, RAM capacity, storage devices and display details using the systeminformation library. For CPU temperature, fan speeds and voltages, SPEC CARD 2 can run with administrator access and use the PawnIO hardware driver; both happen only after your explicit yes, and an in-app update never installs the driver. In both versions everything is read on your machine and rendered on your machine. Nothing is transmitted. The one outbound request is the update check described in the Overview: on start-up the app fetches mr-clu.com/speccard-update.json and compares the version number, sending nothing beyond the request itself.

Generated spec card images are saved to a location you choose on your local file system. If you subsequently share a generated image via a third-party service (Discord, Reddit, social media, etc.), that service’s own privacy policy governs what happens to the image once you upload it.

Application

CLU’D IN — Gaming Diagnostics

All diagnostics stay local; the only network activity is the update check

CLU’D IN stores gaming session data, hardware readings, crash records, and diagnostic logs in a local SQLite database on your PC. None of it is transmitted to Mr.Clu or any external service.

Its only outbound network activity is the update check described above: a request to https://mr-clu.com/cludin-update.json at startup and whenever you press Check for Updates, carrying no hardware data, no configuration, no version number and no identifier beyond the IP address inherent to any HTTPS request. If an update exists and you accept it, the app fetches the signed release manifest and downloads the installer from mr-clu.com, verifying its cryptographic signature before running it.

As development progresses and new features are added, this section will be updated to reflect any changes to data handling before those features are released.

Website

Cookies & Tracking

What cookies are set and by whom when you visit mr-clu.com

Mr.Clu does not set cookies on this website. Mr.Clu does not use advertising networks, social media tracking pixels, session replay tools, heatmap tools, or any third-party analytics platform. The site’s own visit counter (described above) is cookieless by design.

The website uses a few plain flags in your browser’s local storage. None of them contains an identifier and none is sent to any third party:

  • ›Returning-visitor flags (mrclu_seen, mc_seen): simple yes/no markers so the site can adjust what it highlights for returning visitors. No identifier is created or transmitted.
  • ›Per-tab session id (mc_sid in sessionStorage): a random value used by the visit counter to group the pages viewed in one tab; deleted automatically when the tab closes.
  • ›Preference flags (e.g., mc_ignore for the analytics opt-out, or remembering a banner you dismissed): stored only in your browser.
  • ›Cloudflare may set functional and security cookies of its own (e.g., __cf_bm, cf_clearance) to protect the site from abuse. These are not advertising cookies and are not set by Mr.Clu.
  • ›YouTube can store its own cookies and local data once its video player loads. On the home page, the CLU VIEW timelapse starts playing muted when you scroll to it, so the player loads without a click. On /cluview, nothing loads from YouTube until you press play. Google’s privacy policy covers what YouTube stores.

Mr.Clu Software applications are desktop applications and do not use browser cookies in any form.

External Services

Third-Party Services & Links

Services linked from the website or integrated into Mr.Clu software

The Website and Software may link to or integrate with the following third-party services. Each service operates independently under its own terms and privacy policy. Mr.Clu has no control over, and accepts no responsibility for, any third party’s data practices.

Service Context Privacy Policy
CloudflareHosting, CDN, securitycloudflare.com/privacypolicy
Cloudflare TurnstileHuman check on the Template Store upload form onlycloudflare.com/privacypolicy
YouTubeCLU VIEW videos. Home page: loads and plays muted when you scroll to the video. /cluview: loads only after you press play. Both use youtube-nocookie.com (YouTube’s privacy-enhanced mode)policies.google.com/privacy
ipapi.coVU1 weather location lookup (optional)ipapi.co/privacy
Open-MeteoVU1 weather data (optional)open-meteo.com/en/terms
Buy Me a CoffeeOptional voluntary support (linked from Website)buymeacoffee.com/privacy-policy
PatreonOptional voluntary support (linked from Website)patreon.com/policy/privacy
DiscordCommunity server (linked from Website and Software)discord.com/privacy
Google FormsBug report form (linked from Website and Software). Whatever you type into it goes to Google, not to this sitepolicies.google.com/privacy

Security

Data Security

How data in transit and at rest is protected

Because Mr.Clu applications keep your data on your own machine, the primary security responsibility for locally stored application data (profiles, configurations, logs) rests with your own device and OS security practices. The website’s visit statistics are anonymised before storage and held in a private database accessible only to Mr.Clu.

All outbound network communication from Mr.Clu Software uses HTTPS (TLS). The CLU VIEW update checker enforces a strict domain whitelist and response-size limit to reduce exposure to malicious responses.

If you discover a security vulnerability in any Mr.Clu Software or this website, please report it responsibly by emailing by.mr.clu@gmail.com before public disclosure, allowing time for a fix to be developed.

Age

Children’s Privacy

Mr.Clu software is not directed at children

Mr.Clu Software and this Website are not directed at children under 13 years of age (or the applicable minimum digital age in your jurisdiction, which may be higher). Mr.Clu does not knowingly collect personal information from children.

If you believe that a child has provided personal information through any Mr.Clu channel, please notify by.mr.clu@gmail.com and any such information will be promptly deleted.

Rights

Your Privacy Rights

Your rights under GDPR, UK GDPR, CCPA, and similar laws

Because Mr.Clu applications keep your data on your own machine, most data rights can be exercised directly and immediately by managing or deleting the application’s local files. The website’s visit statistics are anonymised and cannot be linked back to you, and are deleted automatically after 90 days in any case.

EU / UK GDPR Rights

If you are in the European Economic Area or United Kingdom, you have the following rights regarding personal data that Mr.Clu processes (which for the website is limited to the anonymised, short-lived visit statistics described above):

  • ›Right of access: Request a copy of personal data Mr.Clu holds about you.
  • ›Right to rectification: Request correction of inaccurate personal data.
  • ›Right to erasure: Request deletion of personal data Mr.Clu holds.
  • ›Right to restriction: Request that processing be restricted in certain circumstances.
  • ›Right to data portability: Receive personal data in a structured, machine-readable format.
  • ›Right to object: Object to processing based on legitimate interests.
  • ›Right to lodge a complaint: You have the right to lodge a complaint with your local data protection supervisory authority (e.g., ICO in the UK, or your national DPA in the EU).

Given the local-first architecture and the anonymised, auto-deleting nature of the website statistics, most of these rights are effectively pre-satisfied. For any request, contact by.mr.clu@gmail.com.

California Residents (CCPA / CPRA)

California residents have specific rights under the California Consumer Privacy Act. Mr.Clu does not sell or share personal information. Mr.Clu does not use personal information for cross-context behavioural advertising. Because the only data Mr.Clu holds is anonymised website statistics that cannot identify you, your CCPA rights (access, deletion, opt-out of sale) are effectively pre-satisfied. For any California privacy request, contact by.mr.clu@gmail.com.

Updates

Changes to This Policy

How and when this privacy policy is updated

This Privacy Policy may be updated from time to time to reflect changes in Mr.Clu software features, applicable law, or third-party services. Significant changes will be posted on this page with a revised “Last updated” date. For material changes affecting your rights, Mr.Clu may additionally post a notice in the Software or on the Website.

Continued use of the Services after a revised policy is posted constitutes acceptance of the revised policy. If you disagree with any change, stop using the affected Software or Website features.

Contact

Privacy Questions & Requests

How to reach Mr.Clu about this policy

For privacy questions, data-subject rights requests, security vulnerability reports, or any concerns about this policy, email by.mr.clu@gmail.com. Please include “Privacy” or “Security” in the subject line as appropriate.

Related documents: Terms of Use • Licenses & Attributions