Privacy Policy
Last updated: 7 August 2026
1. Information We Collect
When you use BattleLab, we may collect the following information:
- Account data: If you sign in via Discord or Google, we receive your username, email address, and profile image from the OAuth provider. We do not receive or store your password.
- Pseudonymous username: BattleLab assigns you a generated username (an adjective paired with a Pokémon name). This pseudonym is what appears publicly on scenarios you create — not your real name or email.
- Anonymous sessions: If you use BattleLab without signing in, we generate a random token stored in your browser's localStorage so your work is saved to you. If you later sign in, that anonymous work is transferred to your account.
- Usage data: We keep aggregate scenario play counts and standard server logs (request and error logs used for reliability and abuse prevention). We may also use a privacy-focused, cookieless analytics service that counts aggregate page views without identifying you, and an error-monitoring service that records technical details of crashes (such as the error message, the page, and your browser type) so we can fix bugs. We do not run advertising trackers, sell your data, or track you across other websites.
- Scenarios: Any scenarios you publish are stored on our servers and visible to other users under your pseudonym.
2. How We Use Your Information
We use your information to provide and improve BattleLab, authenticate your identity, save and display the scenarios you create, and keep the service reliable and free from abuse. We do not sell your personal information to third parties.
3. Cookies & Local Storage
BattleLab uses cookies for authentication sessions (via Auth.js) and localStorage for anonymous session tokens and UI preferences. We do not use third-party tracking cookies. See our Cookie Policy for details.
4. Data Retention
Account data is retained as long as your account exists. Anonymous session data is retained until it is merged into an account at sign-in, or until the session becomes inactive. You may request deletion of your data through the feedback link in the site footer.
5. Third-Party Services
BattleLab uses the following third-party services:
- Discord and Google for OAuth authentication
- Turso for database hosting
- Pokémon Showdown sprites served from play.pokemonshowdown.com
- When enabled, a privacy-focused, cookieless analytics provider (aggregate page counts only) and an error-monitoring provider (crash diagnostics only)
6. Children's Privacy
BattleLab is not directed at children under 13. We do not knowingly collect personal information from children under 13.
7. Changes to This Policy
We may update this privacy policy from time to time. Significant changes will be reflected by updating this page and its "last updated" date.
8. Contact
If you have questions about this privacy policy, reach us through the feedback link in the site footer.