Karkat's Arcade Privacy Policy
Last updated August 23, 2026
What we store
When you play, Karkat's Arcade stores a player profile, selected avatar items, platform wallet and membership state, game statistics, and any save data required by an experience. Signed-in accounts are linked to the identifier provided by Google through Supabase Authentication. We do not store your Google password.
How we use data
Data is used to run multiplayer sessions, restore your profile across devices, enforce owned cosmetics, and save experience progress. It is not sold or used for advertising.
Guests and retention
Guest profiles are stored so a returning browser can keep its profile. Inactive guest records and their associated game data may be deleted after 30 days. Signed-in data remains until the account owner deletes it or the service is discontinued.
Your controls
Signed-in players can download their Arcade data, sign out active devices, or permanently delete their Arcade account from Account & privacy. Account deletion removes the corresponding Supabase Auth user but does not delete the underlying Google account. Signing in again with the same Google account can create a new Arcade profile after the deletion-safety window described below has expired.
Deleting an Arcade account removes its profile, gameplay data, wallet, inventory, and entitlements. Payment, fulfillment, refund, dispute, and accounting records may be retained after their Arcade player link is removed where needed for financial reconciliation, fraud prevention, tax, or legal obligations. Payment-provider records are also subject to that provider's retention policy.
To prevent a stale login or an overlapping server deployment from recreating deleted data, the server temporarily retains two minimal deletion markers: a keyed, one-way fingerprint of the former authentication identifier and the former Arcade player UUID. These server-only markers contain no profile, email, gameplay, wallet, or purchase contents; they block reuse for at most 30 days and are then deleted.
The server also keeps limited security records such as authentication, session revocation, account export/deletion, billing, and developer authorization outcomes. These records do not store request bodies, access tokens, email addresses, provider subjects, or IP addresses. A signed-in player's data download includes the security events linked to that Arcade account. Deleting an account immediately removes that link, and the remaining pseudonymous security event is permanently deleted no later than 90 days after it was recorded.
Service providers
The site uses Cloudflare for frontend hosting, Render for the game server, Supabase for authentication and PostgreSQL storage, and Stripe and Link for hosted checkout, merchant-of-record payment and tax processing, billing, receipts, refunds, and order support. Karkat's Arcade does not receive your full card number. These providers process data needed to deliver the service under their own terms and privacy policies.
Contact
Questions or data requests can be sent to karkatsg@gmail.com. Payment and subscription details are covered by the Purchase & Membership Terms.