← Back to the game

Privacy Policy

osu!gacha · Last updated 14 August 2026

We do collect and store data about you, and this page says exactly what, why, who else sees it, how long we keep it, and how to get it deleted. We do not run ads, we do not use analytics or tracking pixels, and we never sell your data.

1.Who is responsible for your data

osu!gacha is operated by Damjan Klobucar, a private individual, not a company, running osu!gacha as a free non-commercial hobby project, based in Rijeka, Croatia. That makes Damjan Klobucar the data controller for the personal data described here, under the EU General Data Protection Regulation and Croatian data protection law.

For anything privacy related — access, deletion, corrections, complaints — email miztosu@gmail.com. We have not appointed a data protection officer, as we are not required to.

This policy was last updated on 14 August 2026 and applies from 14 August 2026.

2.What we collect

We keep the data set as small as we can. Everything below is either given to us by osu! when you sign in, generated by you playing, or produced automatically by the servers that host the Service.

CategoryWhat it isWhere it comes from
Account dataYour osu! user ID, username, avatar URL, and the fact that you signed in with osu!.osu! OAuth, "identify" scope only, when you sign in.
Game dataYour card collection (which players, whether shiny or signed, how many copies, when you first obtained each), your favourites, your available pack count and pack regeneration timestamp, and which promo codes you have redeemed and when.Generated as you play.
PreferencesYour cookie choice, dismissed announcements, and whether you turned pack animations off.Stored in your browser, not on our server.
Technical dataIP address, user agent, requested URL, timestamps and error traces in server and platform logs, used to keep the Service running and to detect abuse.Automatically, from your browser and our hosting providers.
CorrespondenceMessages you send us by email, osu! or Discord, and anything you include in them.From you, when you contact us.

3.What we do not collect

  • Your osu! password — the OAuth flow means we never see it.
  • Your email address, unless you email us yourself.
  • Payment or card details. Donations go through Ko-fi, which handles payments under its own privacy policy; we only ever see what Ko-fi shows a creator.
  • Analytics, advertising, fingerprinting or cross-site tracking data. There is no Google Analytics, no ad network and no tracking pixel on this site.
  • Special category data (health, beliefs, biometrics and so on). Please do not send it to us.

6.Who else sees your data

We do not sell, rent or trade personal data, and we do not share it for advertising. We use a small number of providers to run the Service, and they may only process data on our instructions.

ProviderWhat they doWhat they see
SupabaseHosts our database and the signature image storage.All account and game data stored by the Service.
Our hosting and CDN providerServes the site and runs the server code.Technical data such as IP addresses and request logs.
ppy Pty Ltd (osu!)Authenticates you and serves player avatars.That you signed in to a third-party app; your browser requests avatar images from their servers.
Ko-fiHandles voluntary donations, only if you choose to donate.Whatever you give them on their own site, under their privacy policy.
DiscordHosts our community server, only if you join it.Whatever you share there, under Discord's privacy policy.

We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, or to protect the rights and safety of players or the public. If the Service is ever transferred to someone else, data may transfer with it, and we will say so on this page beforehand.

7.What other people can see

  • Card share pages show the username and avatar of the collection's owner, the card, and when it was first obtained. Anyone with the link can open the page.
  • Your osu! username and avatar are already public on osu! itself.
  • Your full collection, pack count and promo history are not published by us.

8.International transfers

Our providers may process data outside your country, including in the United States. Where data leaves the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or another lawful transfer mechanism, together with the technical measures described below. You can ask us for details of the safeguards in place.

9.How long we keep it

DataRetention
Account and game dataFor as long as your account exists. If you ask us to delete it, we remove it from live systems without undue delay.
BackupsDeleted data may persist in encrypted backups for up to 30 days before those backups roll over.
Server and security logsTypically up to 30 days, longer only where we are investigating an incident.
Promo redemption recordsKept while your account exists, so a one-time code stays one-time.
CorrespondenceUp to 2 years, or longer where needed for a legal claim.
Data in your browserUntil you clear it, reject cookies, or the storage is overwritten.

Accounts that have been inactive for a long period may be deleted along with their game data.

10.How we protect it

  • The session cookie is encrypted and signed, marked HttpOnly and SameSite, and served over HTTPS only in production, so scripts cannot read it and it does not travel cross-site.
  • All traffic is served over TLS.
  • Database credentials with elevated privileges are only ever used server-side and are never exposed to the browser.
  • The OAuth flow is protected against cross-site request forgery with a one-time state value.
  • Access to production data is limited to the people who need it to run the Service.

No system is perfectly secure. If a breach happens that is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours where required, and tell affected players without undue delay.

11.Your rights

Depending on where you live, you have some or all of these rights over your personal data:

  • Access — get a copy of the data we hold about you.
  • Rectification — have inaccurate data corrected. Your username and avatar refresh from osu! when you sign in.
  • Erasure — have your account and data deleted.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on our legitimate interests, including the use of a player's public data on a card.
  • Portability — receive your account and game data in a structured, machine-readable format, or have it sent to another provider where technically feasible.
  • Withdraw consent — change your cookie choice at any time from the "Cookie settings" link in the footer, without affecting processing that already happened.
  • Complain — lodge a complaint with your local data protection authority. We would appreciate the chance to fix it first.

To exercise any of these, email miztosu@gmail.com from an address we can tie to your account, or message us from the osu! account you play with so we can confirm it is really you. We answer within 30 days, and it is free unless a request is manifestly unfounded or excessive.

Because we are established in Croatia, our supervisory authority is the Agencija za zaštitu osobnih podataka (AZOP). If you live elsewhere in the EU or the EEA, you can also complain to the data protection authority of your own country, or to the courts where you live.

12.Notice for United States residents

If you live in California, Colorado, Connecticut, Virginia or another state with a comprehensive privacy law, you have the right to know what we collect, to access, correct and delete it, and to appeal a refusal. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for targeted advertising or profiling, so there is nothing to opt out of. We do not discriminate against anyone who exercises these rights. Use the contact address above to make a request.

13.Children

The Service is not intended for children under 13, and we do not knowingly collect their data. If you are a parent or guardian and believe your child has an account, contact us and we will delete it and the data attached to it.

14.Cookies and local storage

We store a small number of strictly necessary items on your device, all of which are listed in the Cookie Policy. The game area stays locked until you accept them, because the Service cannot identify your collection without a session cookie.

15.Changes to this policy

We update this policy when the Service changes. The date at the top always shows the current version. If a change materially affects how we use your data, we will tell you in the game before it takes effect, and where the law requires it we will ask for your consent again.

16.Contact

Email miztosu@gmail.com, message us on osu!, or reach us in the Discord server.