← Back to Shiny Pokes

Privacy Policy

Effective May 27, 2026 · Last updated August 27, 2026

This Privacy Policy explains how the operator of shinypokes.com (the “Service”, including when installed to your device as a web app) collects, uses, shares, and protects your information. Shiny Pokes is a personal-project tool that helps Pokémon players track shiny hunts. By creating an account or using the Service, you agree to this Policy.

1. Who we are

The Service is operated by an individual (“we,” “us,” or “the operator”), not a company. For any privacy question or request, contact us at privacy@shinypokes.com. For users in the European Economic Area (EEA) and the United Kingdom, the operator is the “data controller” for your personal data.

2. Information we collect

We collect only what the Service needs to function. We do not ask for your phone number, mailing address, or payment card details.

a. Account information (from your sign-in provider)

You sign in with Discord, Google, or a sign-in link sent to your email. We do not store passwords — with email sign-in we email you a one-time link and keep only a hashed, expiring token, sent from our own mail server (no third-party email service). From OAuth providers we receive and store your email address, your display name, your profile image, and a provider account identifier used to keep you signed in; with email sign-in we store only your email address. Your email address is never shown publicly anywhere on the Service — other users see only the username and display name you choose.

b. Profile information (provided by you)

A chosen username and display name; an optional bio, favorite game, and banner Pokémon; and an optional custom avatar you upload.

c. Activity data you create

Your hunts (Pokémon, game, method, encounter and chain counts, timer duration, status, and whether the hunt was part of an event such as Safari Week), your catches (including nickname, nature, public/private status, and evolution history if you evolve a catch), your settings, community chat messages and the @-mentions you send or receive, Pokémon you add to event planning lists (e.g. a Safari Week wishlist), support messages and any image attachments you send, and feature ideas you submit. We also keep a per-day tally of your hunting activity (how many encounters you log each day) so we can show your hunting streak and weekly activity.

If you choose to answer the occasional feedback panel, we store your answer: which option you picked for how you found the Service (and the short line of text you type if you pick “somewhere else”), and any star rating and optional comment you leave. Answering is entirely optional and the panel can be dismissed. We store how you found the Service against your account only so that we never ask you again, and we record when the panel was last shown to you so it does not keep reappearing. Admins see these answers as counts only: how many people picked each option, and the average rating. Never against your name. Any text you type is shown to admins without your name attached.

d. Technical and log data

Like virtually all websites, our web server automatically records standard request logs that may include your IP address, browser type, and timestamps, used for security and debugging. The application itself does not store your IP address against your account.

e. Push notifications

If you enable push notifications, we store the push device token your device or browser provides (used only to deliver notifications, such as a support reply or when someone @-mentions you), along with your device platform and OS version, so notifications work reliably. You can turn notifications off in your device or browser settings at any time.

3. How we use your information

To create and maintain your account; provide core features (tracking hunts, recording catches, showing stats and badges); power community features according to your sharing settings; respond to support requests; maintain security and prevent abuse; and improve the Service.

4. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We run no ad networks and no third-party analytics or tracking. We share information only:

a. Public and community features

Information you choose to make public — public catches, your public hunter page, and leaderboard standings — is visible to anyone and may appear in social-media preview images. If you enable your hunter page, it shows your total shinies, encounters and hours, and (unless you switch that section off) the hunts you have in progress: the Pokémon, game and method, a live encounter count that updates while you hunt, how long you have been hunting it, your average time per encounter, when the hunt started, and when you were last active. In addition, some community features are visible to other signed-in users: messages and @-mentions you post in community chat (which show your display name or username), catches you share into chat, and your active hunts on the live-hunts feed (which shows your handle unless you enable the “Anonymous Hunter” option). Aggregate, non-identifying event stats (for example, the most-planned Pokémon during Safari Week) may also be shown. See Section 6 for your controls.

b. Service providers

Sign-in providers (Discord, Google) authenticate you. We send no data of any kind to an AI provider. We fetch public Pokémon information and images from PokéAPI, Bulbapedia, and a public sprite repository — no personal data about you is sent to them. Our hosting provider stores all account and activity data.

The home page shows how many people are in our Discord. Our server asks Discord for that public count, not your browser, so nothing about you reaches Discord unless you click through to join. There is no Discord content embedded in the page.

c. Legal reasons

We may disclose information if required by law, to protect our rights or user safety, or in response to a valid legal request.

5. Cookies and tracking

We use a single essential cookie: the authentication session cookie that keeps you signed in. It is strictly necessary, so no consent banner is required. We do not use advertising cookies, analytics cookies, tracking pixels, or third-party trackers.

Do Not Track: because we do not track you across other websites, our behavior is the same whether or not your browser sends a DNT signal.

6. Your privacy controls

Shiny Pokes is built to be private by default:

  • Your public hunter page is off by default — it is only listed at /h/{username} if you opt in.
  • You can share publicly while hiding your display name (“Anonymous Hunter”).
  • You can keep your hunter page but hide what you are hunting right now, so the live encounter count and hunt timings are not shown.
  • Each catch can be marked public or private; private catches never appear on leaderboards, the feed, or share pages.
  • You can change your username, display name, bio, avatar, and settings at any time.
  • Images you send to support are visible only to you and an administrator.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, object to or restrict processing, and obtain a portable copy of your personal data, and to withdraw consent.

  • Download your data: use the “Download my data” button in Settings → Account to get a complete JSON export.
  • Delete your account: you can permanently delete your account and all associated data yourself from Settings → Danger Zone. This is irreversible.
  • Correct your data: most data is directly editable in Settings.

To exercise any other right, email privacy@shinypokes.com. We will respond within the timeframe required by applicable law and will not discriminate against you for exercising your rights.

8. California privacy rights (CCPA/CPRA & CalOPPA)

If you are a California resident:

  • Categories collected: identifiers (email, username, provider account ID), internet activity (your hunts, catches, and in-app actions), and user-generated content (chat, support messages, uploaded images).
  • Sale/sharing: we do not sell your personal information and do not share it for cross-context behavioral advertising, so no “Do Not Sell or Share” action is required.
  • Your rights: to know/access, delete, correct, and not be discriminated against. Submit requests to privacy@shinypokes.com.
  • Shine the Light: we do not share personal information with third parties for their own direct marketing.

9. Legal bases for processing (EEA/UK users)

Where the GDPR or UK GDPR applies, we process your data to perform our contract with you (providing the account and features), with your consent (optional features such as making your profile public or using the AI assistant — you can withdraw consent anytime), and for our legitimate interests (keeping the Service secure, preventing abuse, and improving it).

10. Data retention

We keep your account data for as long as your account exists. When you delete your account, your associated data is removed promptly. Server request logs are retained only briefly for security and troubleshooting. We may retain limited information where required by law.

11. Where your data is stored / international transfers

The Service is hosted on servers located in the United States. If you access the Service from outside the United States — including from the EEA or United Kingdom — your information will be transferred to and processed in the United States, which may have different data protection laws than your country. Where required for such transfers, we rely on appropriate safeguards such as the Standard Contractual Clauses.

12. Security

We protect your information with: no password storage (sign-in is handled entirely by Discord and Google); encryption in transit (HTTPS/TLS); validation of uploaded images by type, size, and file signature; access controls restricting support attachments and private catches to authorized viewers; and access-controlled server credentials. No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal data, we will notify affected users and any required authorities as the law requires.

13. Children's privacy

The Service is not intended for children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, contact privacy@shinypokes.com and we will delete it. Users between 13 and the age of digital consent in their country should use the Service only with parental involvement where local law requires it.

14. Third-party links and services

The Service integrates with third-party services (Discord, Google, PokéAPI, Bulbapedia). Their handling of your data is governed by their own privacy policies, which we encourage you to review.

15. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide a more prominent notice. Continued use of the Service after changes take effect means you accept the revised Policy.

16. Contact us

Questions, requests, or concerns about your privacy: privacy@shinypokes.com.