LEGAL
PRIVACY POLICY
Effective: June 16, 2025
This Privacy Policy explains what information PixlPit collects, how we use it, and the choices you have. We are committed to keeping your data minimal, safe, and transparent.
1. INFORMATION WE COLLECT
Account data: When you register, we collect your email address, chosen username, and a hashed password (stored securely via Supabase Auth — we never see your plaintext password).
Gameplay data: We store the pixel artwork you submit, your votes, XP points, streak count, badges, and battle participation history.
Usage data: We may collect browser type, approximate location (country level), and pages visited via server logs. We do not use third-party analytics trackers.
Local storage: Your in-progress drawing is saved to your browser's localStorage (pa_pixels) and your mute preference (pixlpit_muted). This data never leaves your device unless you submit it.
2. HOW WE USE YOUR INFORMATION
We use your data to: (a) operate the daily pixel battle and display leaderboards and profiles; (b) send account-related emails (email confirmation, password resets); (c) prevent abuse and enforce our Terms of Service; (d) improve the game experience.
We do not sell your personal data. We do not use your data for advertising.
3. INFORMATION WE SHARE
Your username and submitted artwork are public — they appear on leaderboards, the Hall of Champions, and your profile page.
Your email address is never displayed publicly.
We share data with the following sub-processors only to the extent necessary to operate the Service:
- Supabase — database, authentication, and file storage (EU/US servers).
- Netlify — hosting and edge network.
We may disclose data if required by law or to protect the rights and safety of our users.
4. DATA RETENTION
We retain your account data for as long as your account is active. If you delete your account (see Section 7), we delete your profile data within 30 days. Anonymized gameplay statistics may be retained indefinitely for game balancing purposes.
5. COOKIES
PixlPit uses a session cookie set by Supabase Auth to keep you signed in. We do not use advertising cookies or cross-site tracking cookies. You can clear cookies at any time via your browser settings, which will sign you out.
6. SECURITY
Passwords are hashed using bcrypt via Supabase Auth and are never stored in plaintext. All data is transmitted over HTTPS. We apply row-level security policies in our database so users can only access their own private data. However, no system is 100% secure — use a unique, strong password.
7. YOUR RIGHTS
Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion of your account and associated data; export your data in a machine-readable format; object to certain processing.
To exercise any of these rights, email support@pixlpit.com with “Privacy Request” in the subject line. We will respond within 30 days.
8. CHILDREN
PixlPit is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If we learn we have collected such data, we will delete it promptly. If you believe a child under 13 has registered, please email us at support@pixlpit.com.
9. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will notify registered users by email and post the revised policy here with a new effective date. Continued use of the Service after the effective date constitutes acceptance.
10. CONTACT
Privacy questions or requests: support@pixlpit.com
General support: support@pixlpit.com