This Privacy Policy explains how the operator of shinypokes.com (the “Service”, including when installed to your device as a web app) collects, uses, shares, and protects your information. Shiny Pokes is a personal-project tool that helps Pokémon players track shiny hunts. By creating an account or using the Service, you agree to this Policy.
The Service is operated by an individual (“we,” “us,” or “the operator”), not a company. For any privacy question or request, contact us at privacy@shinypokes.com. For users in the European Economic Area (EEA) and the United Kingdom, the operator is the “data controller” for your personal data.
We collect only what the Service needs to function. We do not ask for your phone number, mailing address, or payment card details.
a. Account information (from your sign-in provider)
You sign in with Discord, Google, or a sign-in link sent to your email. We do not store passwords — with email sign-in we email you a one-time link and keep only a hashed, expiring token, sent from our own mail server (no third-party email service). From OAuth providers we receive and store your email address, your display name, your profile image, and a provider account identifier used to keep you signed in; with email sign-in we store only your email address. Your email address is never shown publicly anywhere on the Service — other users see only the username and display name you choose.
b. Profile information (provided by you)
A chosen username and display name; an optional bio, favorite game, and banner Pokémon; and an optional custom avatar you upload.
c. Activity data you create
Your hunts (Pokémon, game, method, encounter and chain counts, timer duration, status, and whether the hunt was part of an event such as Safari Week), your catches (including nickname, nature, public/private status, and evolution history if you evolve a catch), your settings, community chat messages and the @-mentions you send or receive, Pokémon you add to event planning lists (e.g. a Safari Week wishlist), support messages and any image attachments you send, and feature ideas you submit. We also keep a per-day tally of your hunting activity (how many encounters you log each day) so we can show your hunting streak and weekly activity.
If you choose to answer the occasional feedback panel, we store your answer: which option you picked for how you found the Service (and the short line of text you type if you pick “somewhere else”), and any star rating and optional comment you leave. Answering is entirely optional and the panel can be dismissed. We store how you found the Service against your account only so that we never ask you again, and we record when the panel was last shown to you so it does not keep reappearing. Admins see these answers as counts only: how many people picked each option, and the average rating. Never against your name. Any text you type is shown to admins without your name attached.
d. Technical and log data
Like virtually all websites, our web server automatically records standard request logs that may include your IP address, browser type, and timestamps, used for security and debugging. The application itself does not store your IP address against your account.
e. Push notifications
If you enable push notifications, we store the push device token your device or browser provides (used only to deliver notifications, such as a support reply or when someone @-mentions you), along with your device platform and OS version, so notifications work reliably. You can turn notifications off in your device or browser settings at any time.
To create and maintain your account; provide core features (tracking hunts, recording catches, showing stats and badges); power community features according to your sharing settings; respond to support requests; maintain security and prevent abuse; and improve the Service.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We run no ad networks and no third-party analytics or tracking. We share information only:
a. Public and community features
Information you choose to make public — public catches, your public hunter page, and leaderboard standings — is visible to anyone and may appear in social-media preview images. If you enable your hunter page, it shows your total shinies, encounters and hours, and (unless you switch that section off) the hunts you have in progress: the Pokémon, game and method, a live encounter count that updates while you hunt, how long you have been hunting it, your average time per encounter, when the hunt started, and when you were last active. In addition, some community features are visible to other signed-in users: messages and @-mentions you post in community chat (which show your display name or username), catches you share into chat, and your active hunts on the live-hunts feed (which shows your handle unless you enable the “Anonymous Hunter” option). Aggregate, non-identifying event stats (for example, the most-planned Pokémon during Safari Week) may also be shown. See Section 6 for your controls.
b. Service providers
Sign-in providers (Discord, Google) authenticate you. We send no data of any kind to an AI provider. We fetch public Pokémon information and images from PokéAPI, Bulbapedia, and a public sprite repository — no personal data about you is sent to them. Our hosting provider stores all account and activity data.
The home page shows how many people are in our Discord. Our server asks Discord for that public count, not your browser, so nothing about you reaches Discord unless you click through to join. There is no Discord content embedded in the page.
c. Legal reasons
We may disclose information if required by law, to protect our rights or user safety, or in response to a valid legal request.
We use a single essential cookie: the authentication session cookie that keeps you signed in. It is strictly necessary, so no consent banner is required. We do not use advertising cookies, analytics cookies, tracking pixels, or third-party trackers.
Do Not Track: because we do not track you across other websites, our behavior is the same whether or not your browser sends a DNT signal.
Shiny Pokes is built to be private by default:
/h/{username} if you opt in.Depending on where you live, you may have the right to access, correct, delete, object to or restrict processing, and obtain a portable copy of your personal data, and to withdraw consent.
To exercise any other right, email privacy@shinypokes.com. We will respond within the timeframe required by applicable law and will not discriminate against you for exercising your rights.
If you are a California resident:
Where the GDPR or UK GDPR applies, we process your data to perform our contract with you (providing the account and features), with your consent (optional features such as making your profile public or using the AI assistant — you can withdraw consent anytime), and for our legitimate interests (keeping the Service secure, preventing abuse, and improving it).
We keep your account data for as long as your account exists. When you delete your account, your associated data is removed promptly. Server request logs are retained only briefly for security and troubleshooting. We may retain limited information where required by law.
The Service is hosted on servers located in the United States. If you access the Service from outside the United States — including from the EEA or United Kingdom — your information will be transferred to and processed in the United States, which may have different data protection laws than your country. Where required for such transfers, we rely on appropriate safeguards such as the Standard Contractual Clauses.
We protect your information with: no password storage (sign-in is handled entirely by Discord and Google); encryption in transit (HTTPS/TLS); validation of uploaded images by type, size, and file signature; access controls restricting support attachments and private catches to authorized viewers; and access-controlled server credentials. No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal data, we will notify affected users and any required authorities as the law requires.
The Service is not intended for children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, contact privacy@shinypokes.com and we will delete it. Users between 13 and the age of digital consent in their country should use the Service only with parental involvement where local law requires it.
The Service integrates with third-party services (Discord, Google, PokéAPI, Bulbapedia). Their handling of your data is governed by their own privacy policies, which we encourage you to review.
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide a more prominent notice. Continued use of the Service after changes take effect means you accept the revised Policy.
Questions, requests, or concerns about your privacy: privacy@shinypokes.com.