POCKET64 Privacy Policy
Last updated: August 5, 2026
Bloom Studio Inc. (the "Operator") handles user information in connection with the POCKET64 web service (the "Service") as described in this Privacy Policy.
1. Information we collect or process
The Operator collects or processes the following information to provide the Service.
1.1 Account and authentication information
- An identifier associated with your Google account
- Your name or profile name, email address, email-verification status, and profile image provided by Google
- Tokens and other authentication information issued in connection with OAuth authentication
- Your POCKET64 user ID, generated or user-selected display name, and guest or Member status
- Session identifiers and session creation, update, and expiration information
The specific information obtained from Google depends on the Google consent screen shown to you and the OAuth permissions in effect at that time.
1.2 Game and progression information
- The game played, score, date and time of play, and duration or frame count
- The seed used for a run, score identifier, and daily and weekly aggregation keys
- Personal bests, XP, rank, medals, and leaderboard position
- Frame-numbered taps, drags, and other in-game input events submitted to validate a score
Input events are processed to replay a run on the server and validate its score for anti-cheating purposes. For an accepted score, the verified input-event sequence is stored with the seed and frame count in a compact, versioned replay format so that the run can be replayed later and its integrity maintained. Input events from rejected submissions are not stored as replay data. If the score has a public sharing URL, or is selected as the source of a signed custom challenge, the sequence may be delivered to visitors' browsers to replay the run and, on the public sharing page, create a shareable video on their device.
1.3 Device, network, and environment information
- IP address
- User agent and browser and device information
- Request time, requested resource, response status, errors, and security-related logs
- Identifiers and settings stored in cookies, local storage, or other browser storage
- Signals collected from your browser to distinguish automated access (through Cloudflare Turnstile, described in Section 5; it runs **when a game page opens**, so it also runs if you leave without starting a run, and normally requires no action from you)
- When Vercel Web Analytics is enabled: page-view time, a redacted requested path, dynamic route, referrer, filtered UTM parameters, approximate country or region, operating system, browser, device type, and analytics-script version
- Aggregated by day in the Service's existing database: product-event name, locale, game identifier, guest or Member status, referrer host, UTM parameters, shared-challenge type, challenge result (win, loss, or tie), and count
When enabled, Vercel Web Analytics uses no third-party cookies and processes page views as anonymous aggregate data using a hash generated from the incoming request. Information identifying that visitor session is discarded after 24 hours. Shared-score and signed custom-challenge URLs are changed to `/s/[scoreId]` and `/c/[challengeId]`, respectively, before transmission, so raw identifiers are not sent. For its own funnel measurement, the Service stores no individual events; it increments a count for the same day, event, and attributes in its existing database. That payload contains no URL, cookie, email address, name, display name, user ID, IP address, authentication data, or in-game input-event sequence. The referrer is limited to a host or origin. UTM values are retained only when they match an operator-configured list of reusable, low-cardinality campaign labels; values resembling email addresses, unique click or recipient identifiers, and unconfigured values are discarded.
1.4 Communications
If you contact us, exercise a privacy right, or report a bug, we may collect your name, email address, the content of your request, identity-verification materials, and other information needed to respond.
2. How we use information
The Operator uses information to:
- create guest sessions, authenticate users, register Members, and manage accounts;
- provide games; verify and save scores; and calculate personal bests, XP, ranks, and medals;
- create and display daily, weekly, and all-time leaderboards;
- transfer guest data to a Member account;
- generate shared-score pages and social-sharing images;
- detect, prevent, investigate, and respond to cheating, bots, excessive requests, unauthorized account use, and other violations;
- troubleshoot, maintain, understand use of, improve, and develop the Service;
- respond to communications, verify identity, and handle privacy-rights requests; and
- enforce the Terms, resolve disputes, comply with law, and respond to legal process.
The Operator uses its own anonymous aggregate funnel counters and, when configured, Vercel Web Analytics, but does not use user information for behavioral advertising, third-party ad delivery, or advertising-oriented analytics services such as Google Analytics.
3. Information made public
- A Member's display name, game, score, position, rank, medal, and similar information may be publicly visible on leaderboards.
- A shared-score URL may display a user's display name, game, score, and rank and, for a verified replay, may provide the run's input sequence to visitors' browsers for playback and on-device video generation. If the URL is posted to an external service, that service may copy, cache, or redistribute the information under its own systems and policies.
- Guests generally do not appear on public leaderboards. If guest scores are transferred during registration, those scores may become eligible for leaderboards after registration.
4. Cookies and local storage
- The Service uses essential cookies to maintain signed-in and guest states, complete OAuth authentication, prevent abuse, and protect security. An authentication session may last up to 90 days. A short-lived session cache may be stored in a cookie to improve performance.
- To prevent automated bulk access, the Service issues a signed cookie to a browser that has passed a bot check, recording only that fact. It lasts up to 12 hours and contains no account information, profile information, or other information about you personally. Its value can, however, act as an identifier distinguishing requests from the same browser. The cookie is signed against the IP address it was issued for, so it stops being accepted if that address changes — when a mobile device switches networks, for example — and the next successful check issues a different value. A single browser therefore does not necessarily hold one value for the whole 12 hours. Cloudflare may also use cookies or other browser storage to operate Turnstile.
- The Service stores a game identifier and personal-best value in `localStorage` to show a per-game personal best on initial display. When a server-side record is available, the server-side value controls.
- You can remove cookies and local storage through your browser settings. Removing or disabling them may cause loss of access to guest results, signed-in status, the initial personal-best display, or other features.
- The Service does not currently use advertising or analytics cookies. The optionally enabled Vercel Web Analytics does not use cookies either. Before introducing such cookies, the Operator will update this Policy and obtain any consent required by applicable law.
5. Service providers and integrations
The Operator uses or integrates with the following providers as necessary to operate the Service:
| Provider | Primary role | Information that may be processed |
|---|---|---|
| Google | User authentication through Google OAuth | Authentication request, Google account identifier, profile information, and authentication tokens |
| Vercel | Hosting, content delivery, networking, operational logs, and, when enabled, cookie-free Web Analytics for page views | IP address, user agent, request information, data transmitted to and from the Service, and, when enabled, the page-view data described in Section 1.3 |
| Neon | Production database | Account, session, score, progression, verified replay input events, anonymous daily event aggregates, and other information stored in the database |
| Cloudflare | Bot detection (Turnstile), preventing bulk account creation and resource abuse by automated means | IP address, user agent, signals collected from the browser, and the outcome of the challenge |
Each provider may handle information under its contract terms and privacy policy. The Operator selects and oversees providers using contracts and other measures appropriate to the nature of the processing.
6. Disclosure to third parties
The Operator does not disclose personal data to a third party except:
- with your consent;
- as required or permitted by law;
- when necessary to protect a person's life, body, or property and obtaining consent is difficult;
- when especially necessary to improve public health or promote the sound development of children and obtaining consent is difficult;
- when cooperation with a government authority performing duties under law is necessary and obtaining consent may interfere with those duties;
- in connection with a merger, acquisition, business transfer, or other succession; or
- when processing by a service provider, joint use, or another arrangement is not treated as third-party disclosure under applicable data-protection law.
The Operator does not sell personal information.
7. International processing and transfers
Providers used by the Service may process or store information in countries or regions outside Japan. The Operator takes measures required by applicable law, such as entering into appropriate contracts and reviewing providers' security practices. Where the law requires disclosure of a processing country, the foreign legal system, or safeguards in place, you may request that information using the contact details in Section 13.
If information about a user in the EEA, United Kingdom, or another jurisdiction is transferred internationally, the Operator will use an available lawful transfer mechanism where required, such as an adequacy decision, standard contractual clauses, or another safeguard recognized by applicable law.
8. Retention
The Operator retains information only for as long as needed for the purposes described in this Policy or as required by law. The principal criteria are:
- Member account, score, and progression data: while the account exists and, after deletion, for a reasonable period needed for legal compliance, dispute resolution, abuse prevention, and backup management
- Guest accounts and scores: until transfer to a Member account, a verified deletion request, or operational deletion of data no longer needed after session expiration
- Authentication sessions: generally up to 90 days from creation, but potentially shorter following sign-out, account deletion, or a security response
- IP addresses used for rate limiting: for the short rate-limit window and the period needed for abuse prevention; the current system progressively deletes expired counters
- The bot-check cookie: up to 12 hours from issuance, and potentially less if the IP address it was issued for changes. Retention on Cloudflare's side is governed by its own privacy policy.
- Input events submitted for score validation: only the events consumed by a successful verified run are retained with its score for public replay and on-device video generation under the same criteria as the corresponding Member or guest score. Rejected submissions and events after the run has ended are not persisted as replay data; operational and security logs do not contain the input-event sequence.
- Vercel Web Analytics (when enabled): the hash identifying a visitor session is discarded after 24 hours. Retention of anonymous aggregate results depends on the Operator's Vercel contract and plan.
- Anonymous daily event aggregates: for as long as needed to understand and improve use of the Service. No individual event, visitor identifier, or session identifier is stored.
- Browser local and session storage: local storage until you clear the Service's site data; session storage holding UTM values and the referrer host until that tab session ends
- Communications: for the time needed to respond and handle potential legal claims
Information in backups or a provider's operational logs may be deleted later under the applicable provider's retention cycle.
9. Security
The Operator uses reasonable organizational and technical safeguards designed to prevent unauthorized access, use, disclosure, loss, destruction, or alteration. These measures include access controls, management of authentication credentials and signing keys, protection of communications, server-side score validation, rate limiting, bot detection, and appropriate provider selection.
No internet transmission or electronic storage system can be guaranteed completely secure. If you identify a security issue, contact the Operator under Section 13.
10. Your rights
Depending on applicable law, you may have rights to request notice of the purposes of use, access, correction, completion, deletion, suspension of use, erasure, cessation of third-party disclosure, or access to records of third-party disclosure concerning your information.
If you are in the EEA or United Kingdom, you may also have rights under applicable data-protection law to access, correct, or erase personal data; restrict processing; receive portable data; object to processing; and withdraw consent for processing based on consent. You may also lodge a complaint with the supervisory authority where you live.
To make a request, contact the Operator under Section 13. The Operator may ask you to verify your identity through account information or another reasonable method to prevent impersonation. Where permitted by law, the Operator may charge a fee or decline all or part of a request and will explain the reason where reasonably possible.
11. Legal bases for processing
For users in the EEA, United Kingdom, and other places requiring legal bases to be stated, the Operator principally processes information on the following bases:
- Performance of a contract: to provide accounts, games, scores, leaderboards, and sharing features
- Legitimate interests: to secure, operate, troubleshoot, improve, and protect the fairness of the Service and prevent abuse, provided those interests are not overridden by your rights and interests
- Legal obligation: to comply with law and lawful requests from courts or government authorities
- Consent: to provide an optional feature for which applicable law requires consent; you may withdraw that consent prospectively at any time
The Service does not make decisions based solely on personal data that produce legal or similarly significant effects on users. Score validation, ranking, and medal calculations under game rules are entertainment functions within the Service.
12. Children under 13
The Service is not directed to children under 13, and children under 13 may not use it. If the Operator learns that it has collected personal information from a child under 13, it will take reasonable steps to verify the situation and delete the information unless retention is required by law. Contact the Operator under Section 13 if you believe this may have occurred.
13. Contact, complaints, and requests
- Operator: Bloom Studio Inc.
- Email: pocket64@googlegroups.com
To request account deletion, contact us from the email address used to register or provide information that reasonably identifies the relevant account.
14. Changes to this Policy
The Operator may revise this Policy to reflect changes in the Service or applicable law. If a change is material, the Operator will give advance notice of its effective date and substance by posting it in the Service or through another reasonable method.