Privacy Policy
osu!gacha · Last updated 14 August 2026
We do collect and store data about you, and this page says exactly what, why, who else sees it, how long we keep it, and how to get it deleted. We do not run ads, we do not use analytics or tracking pixels, and we never sell your data.
1.Who is responsible for your data
osu!gacha is operated by Damjan Klobucar, a private individual, not a company, running osu!gacha as a free non-commercial hobby project, based in Rijeka, Croatia. That makes Damjan Klobucar the data controller for the personal data described here, under the EU General Data Protection Regulation and Croatian data protection law.
For anything privacy related — access, deletion, corrections, complaints — email miztosu@gmail.com. We have not appointed a data protection officer, as we are not required to.
This policy was last updated on 14 August 2026 and applies from 14 August 2026.
2.What we collect
We keep the data set as small as we can. Everything below is either given to us by osu! when you sign in, generated by you playing, or produced automatically by the servers that host the Service.
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Your osu! user ID, username, avatar URL, and the fact that you signed in with osu!. | osu! OAuth, "identify" scope only, when you sign in. |
| Game data | Your card collection (which players, whether shiny or signed, how many copies, when you first obtained each), your favourites, your available pack count and pack regeneration timestamp, and which promo codes you have redeemed and when. | Generated as you play. |
| Preferences | Your cookie choice, dismissed announcements, and whether you turned pack animations off. | Stored in your browser, not on our server. |
| Technical data | IP address, user agent, requested URL, timestamps and error traces in server and platform logs, used to keep the Service running and to detect abuse. | Automatically, from your browser and our hosting providers. |
| Correspondence | Messages you send us by email, osu! or Discord, and anything you include in them. | From you, when you contact us. |
3.What we do not collect
- Your osu! password — the OAuth flow means we never see it.
- Your email address, unless you email us yourself.
- Payment or card details. Donations go through Ko-fi, which handles payments under its own privacy policy; we only ever see what Ko-fi shows a creator.
- Analytics, advertising, fingerprinting or cross-site tracking data. There is no Google Analytics, no ad network and no tracking pixel on this site.
- Special category data (health, beliefs, biometrics and so on). Please do not send it to us.
4.Why we use it, and our legal basis
Where the GDPR or UK GDPR applies to you, we rely on the following legal bases.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating your account, keeping you signed in, and loading and saving your collection | Account data, game data, session cookie | Performance of the contract you enter into by accepting the Terms (Art. 6(1)(b)) |
| Storing information on your device, including the session cookie and local storage | Cookies and local storage | Your consent (Art. 6(1)(a) and the ePrivacy rules), which you give through the cookie prompt and can withdraw at any time |
| Protecting the Service against abuse, exploits, cheating and attacks; enforcing the Terms | Technical data, account data, game data | Our legitimate interests in a working, fair and secure game (Art. 6(1)(f)) |
| Fixing bugs, restoring data after an incident, and improving the game | Technical data, game data | Legitimate interests (Art. 6(1)(f)) |
| Building the card pool from public osu! player profiles | Public player data | Legitimate interests in running a fan game, balanced against the players' rights, with an unconditional removal right (Art. 6(1)(f)) |
| Answering your messages and handling privacy requests | Correspondence, account data | Legitimate interests, and compliance with our legal obligations (Art. 6(1)(c)) |
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
5.Players featured on cards
The card pool is built from public osu! profile data — user ID, username, avatar, country and follower statistics — for the most followed players, sourced through Mutualify. Signed cards additionally use a signature image that the player concerned gave us to use.
If you are featured and would rather not be, tell us and we will remove your card, avatar and signature from the game. You do not need to give a reason, and we will not ask for one. Email miztosu@gmail.com or message the osu! account linked in the footer.
6.Who else sees your data
We do not sell, rent or trade personal data, and we do not share it for advertising. We use a small number of providers to run the Service, and they may only process data on our instructions.
| Provider | What they do | What they see |
|---|---|---|
| Supabase | Hosts our database and the signature image storage. | All account and game data stored by the Service. |
| Our hosting and CDN provider | Serves the site and runs the server code. | Technical data such as IP addresses and request logs. |
| ppy Pty Ltd (osu!) | Authenticates you and serves player avatars. | That you signed in to a third-party app; your browser requests avatar images from their servers. |
| Ko-fi | Handles voluntary donations, only if you choose to donate. | Whatever you give them on their own site, under their privacy policy. |
| Discord | Hosts our community server, only if you join it. | Whatever you share there, under Discord's privacy policy. |
We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, or to protect the rights and safety of players or the public. If the Service is ever transferred to someone else, data may transfer with it, and we will say so on this page beforehand.
7.What other people can see
- Card share pages show the username and avatar of the collection's owner, the card, and when it was first obtained. Anyone with the link can open the page.
- Your osu! username and avatar are already public on osu! itself.
- Your full collection, pack count and promo history are not published by us.
8.International transfers
Our providers may process data outside your country, including in the United States. Where data leaves the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or another lawful transfer mechanism, together with the technical measures described below. You can ask us for details of the safeguards in place.
9.How long we keep it
| Data | Retention |
|---|---|
| Account and game data | For as long as your account exists. If you ask us to delete it, we remove it from live systems without undue delay. |
| Backups | Deleted data may persist in encrypted backups for up to 30 days before those backups roll over. |
| Server and security logs | Typically up to 30 days, longer only where we are investigating an incident. |
| Promo redemption records | Kept while your account exists, so a one-time code stays one-time. |
| Correspondence | Up to 2 years, or longer where needed for a legal claim. |
| Data in your browser | Until you clear it, reject cookies, or the storage is overwritten. |
Accounts that have been inactive for a long period may be deleted along with their game data.
10.How we protect it
- The session cookie is encrypted and signed, marked HttpOnly and SameSite, and served over HTTPS only in production, so scripts cannot read it and it does not travel cross-site.
- All traffic is served over TLS.
- Database credentials with elevated privileges are only ever used server-side and are never exposed to the browser.
- The OAuth flow is protected against cross-site request forgery with a one-time state value.
- Access to production data is limited to the people who need it to run the Service.
No system is perfectly secure. If a breach happens that is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours where required, and tell affected players without undue delay.
11.Your rights
Depending on where you live, you have some or all of these rights over your personal data:
- Access — get a copy of the data we hold about you.
- Rectification — have inaccurate data corrected. Your username and avatar refresh from osu! when you sign in.
- Erasure — have your account and data deleted.
- Restriction — ask us to pause processing while a dispute is resolved.
- Objection — object to processing based on our legitimate interests, including the use of a player's public data on a card.
- Portability — receive your account and game data in a structured, machine-readable format, or have it sent to another provider where technically feasible.
- Withdraw consent — change your cookie choice at any time from the "Cookie settings" link in the footer, without affecting processing that already happened.
- Complain — lodge a complaint with your local data protection authority. We would appreciate the chance to fix it first.
To exercise any of these, email miztosu@gmail.com from an address we can tie to your account, or message us from the osu! account you play with so we can confirm it is really you. We answer within 30 days, and it is free unless a request is manifestly unfounded or excessive.
Because we are established in Croatia, our supervisory authority is the Agencija za zaštitu osobnih podataka (AZOP). If you live elsewhere in the EU or the EEA, you can also complain to the data protection authority of your own country, or to the courts where you live.
12.Notice for United States residents
If you live in California, Colorado, Connecticut, Virginia or another state with a comprehensive privacy law, you have the right to know what we collect, to access, correct and delete it, and to appeal a refusal. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for targeted advertising or profiling, so there is nothing to opt out of. We do not discriminate against anyone who exercises these rights. Use the contact address above to make a request.
13.Children
The Service is not intended for children under 13, and we do not knowingly collect their data. If you are a parent or guardian and believe your child has an account, contact us and we will delete it and the data attached to it.
14.Cookies and local storage
We store a small number of strictly necessary items on your device, all of which are listed in the Cookie Policy. The game area stays locked until you accept them, because the Service cannot identify your collection without a session cookie.
15.Changes to this policy
We update this policy when the Service changes. The date at the top always shows the current version. If a change materially affects how we use your data, we will tell you in the game before it takes effect, and where the law requires it we will ask for your consent again.
16.Contact
Email miztosu@gmail.com, message us on osu!, or reach us in the Discord server.