Privacy Policy
This policy says what Pocket Nexus, Inc., a Delaware C corporation, collects when you use Pocket Studio at studio.pocket.nexus and the game addresses under it, why, how long it is kept and who handles it for us.
What we collect
- Your account. Your email address and the handle you choose. When you sign in with Google or with GitHub, that provider gives us four things and we ask it for nothing else: the identifier of your account with it, your name, your email address and the address of your profile picture. A sign-in code sent by email is kept in hashed form for five minutes.
- Counts of sign-in codes. So that the sign-in form cannot be used to fill someone's inbox, we count how many codes were asked for, by email address and by network address. Each count is stored under a keyed digest: the record holds neither the email address nor the IP address. A count runs for at most a day, and a daily job deletes it once that time is over.
- Your sessions. A cookie that says which Studio user your browser is, as a guest or with an account, and the record of that session on the server.
- What you make. Your room's settings, your projects, their builds and the plans they were compiled from, packages, the packages Pocket Studio makes from your builds, web builds, cover pictures and source files, and the command lines you link. What you publish is public, and the source of a game you publish is given to the people who remix it.
- Your membership. From Stripe: a customer identifier, a subscription identifier, the plan, whether a renewal is called off and the end of the time paid for. We do not receive or store card numbers.
- Offers. When we make an offer to people we can name, such as those who sponsored our founder on GitHub, we keep the list of who it is for: their GitHub user identifiers, and nothing else of them. An offer claimed with a code keeps a hash of each code, never the code. When an account claims an offer, we record which offer, which entry of its list it used, when, and the membership it gave. To check a GitHub offer, the account links its GitHub account, and we keep that link as we keep a GitHub sign-in.
- A log of events. That something happened in the Studio, such as the room being opened, a game started, the membership dialog shown or a package downloaded: the name of the event, the time, the Studio user identifier of the session it happened in, whether that is a guest or an account, the game or device concerned, the country Cloudflare reports for the request, and a coarse class of browser such as "chrome-desktop". The log holds no IP address, no email address and nothing you typed. The landing page counts a view with no identifier at all.
- Request logs. Cloudflare, which hosts Pocket Studio, processes every request and so sees your IP address and browser details. Its logs are used to run and secure the service.
Why
- To run your account, your room and your projects, and to show what you publish.
- To take payment for the membership and know whether it is active.
- To keep the service secure and to act on reports and misuse.
- To understand how the Studio is used: how many people reach each step from opening the room to becoming a member, so we can see where it fails them. The event log exists for this.
Where the law asks for a legal basis: running your account and membership is performance of our agreement with you; security and the event log are our legitimate interests; anything the law requires us to keep is a legal obligation.
How long
- Your account and what it holds: until you ask for its deletion.
- Events in the log: 13 months, then they are deleted.
- Sign-in codes: five minutes. The counts that limit them: at most a day, then the next daily clean-up deletes them. Sessions: until you sign out or they expire.
- Payment records: as long as Stripe and the law require.
Who handles it for us
- Cloudflare hosts the site, its database and its file storage, and delivers sign-in codes by email.
- Stripe takes payments and holds your payment details. Outside mainland China its service Link is the seller of the membership: it asks for your name and billing address to work out the tax, sends your receipts, and handles them under its own terms and privacy policy. To choose between the two, the checkout reads the country of your network address and your browser's time zone when you start a payment. The time zone is not stored.
- Google and GitHub are the two sign-in providers in use. When you choose one, it confirms who you are and gives us the four things listed above; we send it nothing about what you do in the Studio.
- PostHog, a product analytics service, receives a copy of the event log's records only when we switch that on. It is switched off today. The copy carries the same fields as the log and no email or IP address.
We do not sell personal information and we do not show advertising. We disclose information when the law requires it.
Cookies
Pocket Studio sets the cookies it needs to work: one for your session in the Studio, those of the sign-in system, and one that keeps the language you chose. It sets no advertising or cross-site tracking cookies and loads no third-party scripts. Your room remembers a few preferences, such as the laptop's theme, in your browser's local storage.
Your choices
- If your browser sends Global Privacy Control or Do Not Track, nothing your pages report is written to the event log. Things the server does for you, such as a sign-in, a payment or a download, are still recorded.
- You can ask for a copy of the information we hold about your account, for a correction, or for the deletion of your account and its contents, by writing to support@pocket.nexus from the account's email address. There is no button for this yet.
- You can cancel a membership yourself under Manage membership in your account menu.
Depending on where you live you may have further rights over your information, including the right to object to processing and to complain to a data protection authority.
Children
Pocket Studio is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, write to us and we will delete it.
Where it is processed
Pocket Nexus, Inc. is in the United States. Information is processed there and in the other countries where Cloudflare and Stripe operate.
Changes
When this policy changes in a significant way, we tell you in the Studio or by email before the change takes effect. The date above is the day of the current text. This policy describes what we do with your information; you are not asked to agree to it.
Contact
Pocket Nexus, Inc. Write to support@pocket.nexus.