← Back to Pixoot

Privacy Policy

Last updated: 3 October 2026

Pixoot ("we", "us", "the game") is a browser-based pixel-art co-op RPG operated from pixoot.com. This privacy policy explains what data we collect, why we collect it (our legal basis under the GDPR), how long we keep it, and your rights. It covers the game, your account and the in-game chat.

We are the data controller for the data described here. We have not appointed a Data Protection Officer — our processing does not meet the legal threshold for one. Privacy questions: [email protected].

1. Data We Collect

1.1 Account Information

When you sign up with email and password, we store:

When you sign up with Google Sign-In, we store:

We also store a nickname (display name) of 1-16 characters. This is the name shown beside your messages in chat; you can change it in Account Settings, and if you never set one we generate a unique Nick#1234567 for you. We never collect your real name, date of birth, phone number, or any other personally identifiable information beyond what is listed above.

We also record which Terms & Privacy Policy versions you accepted, and when — so we can prove which text applied to your account, and ask you to confirm a new version if the policy changes (see §11).

1.2 Game Data

We store your game progress server-side, including:

This data is linked to your account and is deleted when you delete your account.

1.3 Chat

The game includes public chat channels (Global, LFG, Single player, Builds), staff-run read-only channels (FAQ, News) and a chat for your current co-op room. To keep chat usable and attributable:

Moderation records. Every message the filters touch — obvious spam (blocked), banned-word hits, and borderline messages (rejected and flagged for review) — is recorded in a moderation log with the message text, the rules it matched, a spam score, your nickname and account ID, the action taken, and a truncated hash of your IP address (never the raw address, and only for linking related abuse from the same source). This log powers the admin "Spam" review view; it is pruned to keep approximately the newest 2,000 entries and rows older than 90 days are deleted automatically.

1.4 Local Storage (on your device)

Your browser stores game save data locally using localStorage. This includes:

Two values are kept in sessionStorage (cleared when the browser tab closes) instead of localStorage:

This data is strictly necessary to run the session you requested and never leaves your device unless you are connected to the game server. There are no other device-storage uses that require consent.

1.5 IP Addresses

We do not store raw IP addresses anywhere. They are hashed (SHA-256, truncated) before any storage and used only for:

Hashed IPs are automatically deleted after 90 days by the same clean-up job. A hash is still personal data — we treat it as such; it exists only to stop abuse.

What the audit log actually contains: the event name (for example login, nickname_set), a timestamp, that truncated 16-hex-character hashed IP, the account's internal id, occasionally small non-identifying details of the action (such as the nickname you just chose), and — for sign-ups only — a 16-hex-character hash of your e-mail address (so the same address registering twice can be linked without ever storing the address itself). Raw IP addresses and raw e-mail addresses are never written to it.

1.6 No Cookies, No Analytics

Pixoot does not use cookies, tracking pixels, or any analytics services. We do not use Google Analytics, Facebook Pixel, or any similar tracking tools.

The one third-party script on this site is Google's Sign-In library, and it is not loaded on every page view: your browser fetches it from accounts.google.com only when you open the sign-in form (the "Log in / Sign up" tab), and it is used for nothing but the "Sign in with Google" button. That request necessarily sends your IP address and browser user agent to Google; Google processes it under its own privacy policy. Until you open the sign-in form, no third-party scripts are loaded at all.

1.7 Payment Information

Optional cosmetics are paid for through Stripe Checkout. Stripe collects and stores your card details; Pixoot never receives or stores your full card number, CVC, or expiry date. We only keep:

Purchases require a verified email address and are recorded against your account. Nothing you buy is linked to a card number on our side.

2. How We Use Your Data — and Our Legal Basis

Under the GDPR we must name a lawful basis for each purpose:

PurposeLegal basis
Creating your account, saving game progress, enabling co-op playPerformance of a contract — Art. 6(1)(b)
Hosting and delivering chat messages you send (the chat feature you asked to use)Contract — Art. 6(1)(b), plus our legitimate interest in keeping channel history working — Art. 6(1)(f)
Spam and bot filtering, proof-of-work checks, moderation logs, hiding messages, temporary mutes and bans, protecting players and the service from abuseOur legitimate interests — Art. 6(1)(f): keeping chat usable and safe, preventing fraud and attacks
Transactional emails (verification, password reset, security notifications)Contract — Art. 6(1)(b)
Processing purchases and keeping purchase records for tax and consumer-protection lawContract and legal obligation — Art. 6(1)(b) and 6(1)(c)
Answering support, privacy and legal requests; defending legal claimsLegitimate interests / legal obligation — Art. 6(1)(f), 6(1)(c)

Our legitimate interests are: other players expect a usable, moderated chat; we do not process sensitive data through chat by design; chat is optional; and our safeguards are minimisation, hashed IPs, short retention, transparency, the right to object, and human appeal on moderation decisions.

What we do not do: no marketing emails, no profiling for advertising, no selling or renting data, and no sharing of chat content with other players' third-party services.

3. Automated Checks and What They Decide

Messages pass through automated checks before delivery. We tell you this here, as the GDPR requires for decisions with legal or similarly significant effects (Art. 22) and for meaningful information about the logic involved:

4. Chat Moderation

5. Third-Party Services

Your data is processed by the following services:

Each third-party service has its own privacy policy. We only share the minimum data necessary for each service to function. We do not sell or rent personal data, and we do not share your chat content with advertisers.

6. Data Retention

DataHow long
Registered account (email, nickname, game data)Until you delete your account
Chat messagesRolling 90 days, then deleted automatically
Chat moderation log (blocked / flagged messages, IP hash)Newest 2,000 entries; rows also deleted after 90 days
Guest accountsSoft-deleted after 90 days of inactivity, permanently removed 30 days later
SessionsExpire after 30 days; rows deleted 7 days after expiry
Auth tokens (verify/reset)Deleted 7 days after use or expiry
Hashed-IP rate-limit windowsDeleted after 90 days
Audit logsDeleted after 90 days
Purchase recordsKept for as long as your account exists, plus any period required by tax or consumer-protection law

All automatic deletions run in a clean-up job every 6 hours.

7. Your Rights (GDPR)

If you are in the European Economic Area (EEA) or United Kingdom, you have the following rights under GDPR:

We answer data requests within one month. We only ask for the minimum information needed to confirm the request comes from you — never identity documents for routine requests.

8. Children's Privacy

Pixoot is designed for a general audience. We do not knowingly collect personal information from children under 13. If you are under 13, do not create an account. In the EEA/UK, the required age for agreeing to this policy yourself ranges from 13 to 16 depending on your country — if you are below the age that applies where you live, a parent or guardian must agree for you. We rely on self-declaration and do not ask for age documents; if we become aware that a child below the applicable age has provided personal information, we will delete it promptly.

9. Data Security

10. International Transfers

Your data may be processed in countries outside the EEA (e.g., United States) by our hosting providers (Cloudflare, Hugging Face, Neon, Brevo, Stripe). Where data leaves the EEA/UK we rely on an adequacy decision where one exists (e.g., the EU-US Data Privacy Framework for certified providers), and otherwise on the EU Standard Contractual Clauses (Commission Decision 2021/914, with the UK Addendum where UK law applies) together with our providers' security measures. A copy of the applicable safeguards can be requested from [email protected].

11. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via the game or email before they take effect. The "Last updated" date at the top will always reflect the most recent revision. We keep a record of which version you accepted and when; when a new version takes effect we will ask you to confirm it again in the game.

12. Contact Us

For privacy-related questions or requests (including access, erasure and portability), contact us at:

[email protected]

To report a security vulnerability (not a chat report), contact [email protected] — this is also the address in .well-known/security.txt.

To report chat messages, players or illegal content, and for legal notices, see [email protected] (see Terms & Conditions).

This privacy policy is effective as of 22 September 2026, with payment processing added 27 September 2026, chat, moderation, legal bases, retention schedules and data-export rights added 27 September 2026, and the third-party script (Google Sign-In), Network Error Logging and local-storage inventory disclosures added 3 October 2026. Consent-version recording, the audit-log contents disclosure, the security contact address, password-change notification emails and the backup-residue note were added 3 October 2026.