Privacy Policy
Last updated: 3 October 2026
Pixoot ("we", "us", "the game") is a browser-based pixel-art co-op RPG operated from pixoot.com. This privacy policy explains what data we collect, why we collect it (our legal basis under the GDPR), how long we keep it, and your rights. It covers the game, your account and the in-game chat.
We are the data controller for the data described here. We have not appointed a Data Protection Officer — our processing does not meet the legal threshold for one. Privacy questions: [email protected].
1. Data We Collect
1.1 Account Information
When you sign up with email and password, we store:
- Email address
- Password hash (scrypt, never stored in plaintext)
- Account creation date and last login timestamp
When you sign up with Google Sign-In, we store:
- Google account ID (subject identifier)
- Email address (if provided by Google)
We also store a nickname (display name) of 1-16 characters. This is the name shown beside your messages in chat; you can change it in Account Settings, and if you never set one we generate a unique Nick#1234567 for you. We never collect your real name, date of birth, phone number, or any other personally identifiable information beyond what is listed above.
We also record which Terms & Privacy Policy versions you accepted, and when — so we can prove which text applied to your account, and ask you to confirm a new version if the policy changes (see §11).
1.2 Game Data
We store your game progress server-side, including:
- Hero names, levels, equipped items, and inventory
- Map progress, quest state, and skill builds
- Cosmetic loadouts and in-game currency
This data is linked to your account and is deleted when you delete your account.
1.3 Chat
The game includes public chat channels (Global, LFG, Single player, Builds), staff-run read-only channels (FAQ, News) and a chat for your current co-op room. To keep chat usable and attributable:
- Who can chat: only logged-in accounts with a verified email address or a Google sign-in. Guests and anonymous players cannot send messages — there is no anonymous chat.
- What we store per message: the message text (max 200 characters), your nickname, your account ID, the channel, and the time it was sent.
- Who sees it: other players in that channel and game staff. A live notice above the chat input repeats this at the moment you use the feature.
- Room channels: only players holding a live slot in that co-op room can read or post in it; a room code alone never grants access.
- Retention: chat messages are kept for a rolling 90 days (configurable as
CHAT_RETENTION_DAYS) and then deleted automatically by a clean-up job that runs every 6 hours.
Moderation records. Every message the filters touch — obvious spam (blocked), banned-word hits, and borderline messages (rejected and flagged for review) — is recorded in a moderation log with the message text, the rules it matched, a spam score, your nickname and account ID, the action taken, and a truncated hash of your IP address (never the raw address, and only for linking related abuse from the same source). This log powers the admin "Spam" review view; it is pruned to keep approximately the newest 2,000 entries and rows older than 90 days are deleted automatically.
1.4 Local Storage (on your device)
Your browser stores game save data locally using localStorage. This includes:
- Active hero save snapshot (
pixoot_save_v1plus onepixoot_save_v1_<slot>key per hero) - Character slot registry (which heroes exist, names, active selection —
pixoot_chars_v1) - Guest credentials (for anonymous play —
pixoot_guest_creds) - Session tokens (JWT for staying logged in —
pixoot_session) - UI preferences (such as whether the side HUD is collapsed —
pixoot.hudCollapsed) - Crafting, cosmetics and loadout state: known recipes, consumable layout, equipped cosmetics and active visual effects, and companion cosmetics (
pixoot_recipes_v1,pixoot_consumables_v1,pixoot_cosmetics_v1,pixoot_active_fx_v1,pixoot_ally_cosmetics_v1) - Map/hero editor draft, if you have used it (
pixoot_editor_v1)
Two values are kept in sessionStorage (cleared when the browser tab closes) instead of localStorage:
- Pending Stripe Checkout session id (
pixoot.pendingCheckout) — stored only while a purchase is in flight, removed as soon as Checkout returns or is cancelled - Admin console sign-in token (
pixoot_admin_token) — only after logging into the staff admin console; it is never set for regular players
This data is strictly necessary to run the session you requested and never leaves your device unless you are connected to the game server. There are no other device-storage uses that require consent.
1.5 IP Addresses
We do not store raw IP addresses anywhere. They are hashed (SHA-256, truncated) before any storage and used only for:
- Rate limiting to prevent abuse
- Audit logging of authentication events
- Correlating related spam in the chat moderation log (see §1.3)
Hashed IPs are automatically deleted after 90 days by the same clean-up job. A hash is still personal data — we treat it as such; it exists only to stop abuse.
What the audit log actually contains: the event name (for example login, nickname_set), a timestamp, that truncated 16-hex-character hashed IP, the account's internal id, occasionally small non-identifying details of the action (such as the nickname you just chose), and — for sign-ups only — a 16-hex-character hash of your e-mail address (so the same address registering twice can be linked without ever storing the address itself). Raw IP addresses and raw e-mail addresses are never written to it.
1.6 No Cookies, No Analytics
Pixoot does not use cookies, tracking pixels, or any analytics services. We do not use Google Analytics, Facebook Pixel, or any similar tracking tools.
The one third-party script on this site is Google's Sign-In library, and it is not loaded on every page view: your browser fetches it from accounts.google.com only when you open the sign-in form (the "Log in / Sign up" tab), and it is used for nothing but the "Sign in with Google" button. That request necessarily sends your IP address and browser user agent to Google; Google processes it under its own privacy policy. Until you open the sign-in form, no third-party scripts are loaded at all.
1.7 Payment Information
Optional cosmetics are paid for through Stripe Checkout. Stripe collects and stores your card details; Pixoot never receives or stores your full card number, CVC, or expiry date. We only keep:
- The Stripe Checkout Session and payment intent identifiers
- What was bought, for how much, and when
- Which account it was attached to
Purchases require a verified email address and are recorded against your account. Nothing you buy is linked to a card number on our side.
2. How We Use Your Data — and Our Legal Basis
Under the GDPR we must name a lawful basis for each purpose:
| Purpose | Legal basis |
|---|---|
| Creating your account, saving game progress, enabling co-op play | Performance of a contract — Art. 6(1)(b) |
| Hosting and delivering chat messages you send (the chat feature you asked to use) | Contract — Art. 6(1)(b), plus our legitimate interest in keeping channel history working — Art. 6(1)(f) |
| Spam and bot filtering, proof-of-work checks, moderation logs, hiding messages, temporary mutes and bans, protecting players and the service from abuse | Our legitimate interests — Art. 6(1)(f): keeping chat usable and safe, preventing fraud and attacks |
| Transactional emails (verification, password reset, security notifications) | Contract — Art. 6(1)(b) |
| Processing purchases and keeping purchase records for tax and consumer-protection law | Contract and legal obligation — Art. 6(1)(b) and 6(1)(c) |
| Answering support, privacy and legal requests; defending legal claims | Legitimate interests / legal obligation — Art. 6(1)(f), 6(1)(c) |
Our legitimate interests are: other players expect a usable, moderated chat; we do not process sensitive data through chat by design; chat is optional; and our safeguards are minimisation, hashed IPs, short retention, transparency, the right to object, and human appeal on moderation decisions.
What we do not do: no marketing emails, no profiling for advertising, no selling or renting data, and no sharing of chat content with other players' third-party services.
3. Automated Checks and What They Decide
Messages pass through automated checks before delivery. We tell you this here, as the GDPR requires for decisions with legal or similarly significant effects (Art. 22) and for meaningful information about the logic involved:
- Inputs: your message text (repetition, capitalisation, punctuation, links and URL shorteners, promotional phrases, emoji/mention floods, gibberish word-salad, duplicate copies of the same message), your send rate, how new your account is, and whether the same text is arriving from several accounts at once.
- What can happen automatically: a message whose score reaches the spam threshold is rejected (never delivered) and recorded for human review — logged as flagged when it is borderline or blocked when it is clear spam. Clear spam additionally remembers the text for 30 minutes (identical reposts from any account are filtered too) and earlier copies of the same text are hidden from the channel. Repeated blocks can trigger a temporary mute (by default 5 minutes after 3 blocks in 15 minutes). Messages below the threshold are delivered normally.
- What we do not do: no automated decision that produces legal effects (no account bans, no access restrictions to the paid parts of the service) without human review.
- Your recourse: every automated message tells you why it was stopped, and you can ask for human review of any action by writing to [email protected].
4. Chat Moderation
- Automated filters (banned words, spam score, rate limits, a one-time human-verification puzzle) run on every message; staff review flagged messages and reports in an admin console.
- Moderation actions are: blocking a message, hiding a posted message (soft-delete; staff can restore it), a temporary chat mute, and account suspension or ban.
- Reasons are given in the interface when an automated filter stops you, and on request for staff actions.
- Reporting: to report a message, nickname or player, email [email protected] with as much detail as you can (channel, approximate time, what happened). We assess reports and illegal-content notices fairly, promptly and without arbitrary decisions, and tell you the outcome.
- We do not commit to monitoring all chat ourselves; automated filtering plus reports is how moderation happens.
5. Third-Party Services
Your data is processed by the following services:
- Google — OAuth authentication (Google Sign-In). When you open the sign-in form, your browser downloads Google's Sign-In script directly from
accounts.google.com(sending your IP address and user agent to Google), and the sign-in button talks to Google to prove who you are. Google acts as an independent controller for the sign-in itself and has its own privacy policy. - Brevo — Transactional email delivery (verification, password reset, and a plain-text security notification when your password is changed or reset so you know if someone else did it)
- Cloudflare — Website hosting and API gateway (CDN, DDoS protection). Cloudflare's Network Error Logging (NEL) and error reporting are enabled: on a failed request your browser may send Cloudflare a small report (the URL, your IP address, user agent, and the network error) so we can see and fix outages. These reports are used for reliability monitoring only — not for advertising or analytics.
- Hugging Face — Game server hosting (Docker container)
- Neon — PostgreSQL database hosting (this is where chat messages and moderation records are stored)
- Stripe — Payment processing for cosmetic purchases (your card details are handled by Stripe and never reach us)
Each third-party service has its own privacy policy. We only share the minimum data necessary for each service to function. We do not sell or rent personal data, and we do not share your chat content with advertisers.
6. Data Retention
| Data | How long |
|---|---|
| Registered account (email, nickname, game data) | Until you delete your account |
| Chat messages | Rolling 90 days, then deleted automatically |
| Chat moderation log (blocked / flagged messages, IP hash) | Newest 2,000 entries; rows also deleted after 90 days |
| Guest accounts | Soft-deleted after 90 days of inactivity, permanently removed 30 days later |
| Sessions | Expire after 30 days; rows deleted 7 days after expiry |
| Auth tokens (verify/reset) | Deleted 7 days after use or expiry |
| Hashed-IP rate-limit windows | Deleted after 90 days |
| Audit logs | Deleted after 90 days |
| Purchase records | Kept for as long as your account exists, plus any period required by tax or consumer-protection law |
All automatic deletions run in a clean-up job every 6 hours.
7. Your Rights (GDPR)
If you are in the European Economic Area (EEA) or United Kingdom, you have the following rights under GDPR:
- Right of access: you can request a copy of all data we hold about you — including the chat messages you sent and your purchase history. Use the "EXPORT MY DATA" button in Account Settings (instant JSON download), or contact us.
- Right to erasure: delete your account at any time in Account Settings. This removes your account, characters, chat messages and moderation-log rows from the live database immediately. Encrypted database backups are separate and may retain a residual copy of deleted rows until they rotate out — they are not served to anyone and expire on the database provider's backup retention window. Limited exceptions: purchase records we must keep for tax/consumer law, and audit entries that hold only an unlinked identifier for their remaining retention period.
- Right to rectification: change your nickname in Account Settings; for email address changes, contact us.
- Right to data portability: the "EXPORT MY DATA" feature provides your account, characters, sent chat messages and purchases as machine-readable JSON (Arts. 15 & 20).
- Right to object: you may object to processing based on legitimate interests (such as the moderation log). Contact us and we will stop unless we demonstrate compelling grounds.
- Right to withdraw consent: where we process on consent, you may withdraw it at any time (deleting your account withdraws everything).
- Right to complain: you may lodge a complaint with your local data protection supervisory authority in your country of residence, and you may go to the courts.
We answer data requests within one month. We only ask for the minimum information needed to confirm the request comes from you — never identity documents for routine requests.
8. Children's Privacy
Pixoot is designed for a general audience. We do not knowingly collect personal information from children under 13. If you are under 13, do not create an account. In the EEA/UK, the required age for agreeing to this policy yourself ranges from 13 to 16 depending on your country — if you are below the age that applies where you live, a parent or guardian must agree for you. We rely on self-declaration and do not ask for age documents; if we become aware that a child below the applicable age has provided personal information, we will delete it promptly.
9. Data Security
- Passwords are hashed using scrypt (N=16384, r=8, p=1) — an industry-standard key derivation function.
- All communication is encrypted via HTTPS/WSS.
- IP addresses are hashed before storage — raw addresses are never written to the database.
- Access tokens expire after 15 minutes; refresh tokens expire after 30 days.
- Admin access to chat and account data is token-protected; secret columns (password hashes, tokens, IP hashes) cannot be read through the admin interface.
10. International Transfers
Your data may be processed in countries outside the EEA (e.g., United States) by our hosting providers (Cloudflare, Hugging Face, Neon, Brevo, Stripe). Where data leaves the EEA/UK we rely on an adequacy decision where one exists (e.g., the EU-US Data Privacy Framework for certified providers), and otherwise on the EU Standard Contractual Clauses (Commission Decision 2021/914, with the UK Addendum where UK law applies) together with our providers' security measures. A copy of the applicable safeguards can be requested from [email protected].
11. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via the game or email before they take effect. The "Last updated" date at the top will always reflect the most recent revision. We keep a record of which version you accepted and when; when a new version takes effect we will ask you to confirm it again in the game.
12. Contact Us
For privacy-related questions or requests (including access, erasure and portability), contact us at:
To report a security vulnerability (not a chat report), contact [email protected] — this is also the address in .well-known/security.txt.
To report chat messages, players or illegal content, and for legal notices, see [email protected] (see Terms & Conditions).