Privacy

Privacy & data — short version first

Pokékipe is an analytics tool for competitive Pokémon, not a data-collection product. We designed the account system and the Box so that we need almost nothing from you to make the site work.

TL;DR

  • You can use every feature of Pokékipe without creating an account at all.
  • If you do create an account, sign-in is through Google or Discord OAuth only — we never see, store or handle your password.
  • Your teams and preferences live in your browser, not on our servers.
  • We do not sell your data. Analytics and ads only load if you explicitly accept the cookie banner — reject and nothing third-party runs.

What data does Pokékipe collect?

As little as possible. Pokékipe only needs information that is strictly required to make the features work. Concretely, two cases:

If you do not sign in

We collect nothing that identifies you. The site works fully: meta browsing, Pokémon profiles, Team Builder, Box, Compare, Replay Analyzer, Scouting, Timeline — all of it. Your teams and preferences live entirely in your browser (see "Local storage" below).

If you sign in with Google or Discord

We receive the minimum OAuth payload: a stable account identifier, a display name and an email address. We store that tuple so we can recognise you next time you sign in. That is it — no birthday, no phone number, no address, no payment data, nothing else.

Account creation: OAuth only, no passwords

Pokékipe does not offer password-based sign-up. The only way to create an account is through Google OAuth or Discord OAuth. Concretely:

  • We never see your Google or Discord password.
  • We do not store any password, hash or not.
  • We cannot "leak" credentials we do not have — the login surface belongs to Google and Discord.
  • If you lose access to your Google or Discord account, you lose access to your Pokékipe account. We cannot reset it manually.

This is a deliberate design choice. Running our own password database would be the biggest privacy and security risk on the project, for a feature (custom passwords) that almost nobody asks for.

What is stored in your browser?

Pokékipe is local-first. The following data lives in your browser's localStorage and never leaves your device unless you explicitly export or share it:

  • Your Box — every team you save, with its archetype, format, grade and notes.
  • Your display preferences — language, default format, sprite style, theme, accent colour, display font, role-detection threshold.
  • Recent searches, collapsed panels and other UI state.
  • A short-lived session token if you are signed in, used to keep you logged in between visits.

Clearing your browser's site data for pokékipe.com wipes all of the above. Private/incognito mode wipes it automatically when you close the window.

Cookies

Pokékipe uses one essential cookie — the session cookie that keeps you signed in — plus a tiny localStorage flag that remembers your cookie-banner choice so we don't ask again on every visit. Both are strictly necessary and load before any consent decision.

Anything beyond that is gated behind the consent banner you see on first visit. If you reject (or never decide), nothing else loads. If you accept, Google Analytics and Google AdSense initialize so we can measure traffic and serve the non-intrusive ads that fund the project. You can change your mind any time by clearing site data — the banner reappears. We do not use Facebook Pixel, TikTok Pixel, or any other tracker.

Third parties

Pokékipe talks to a small, fixed list of third-party services — all for features you can see on the site:

  • Google & Discord — only when you explicitly click "Sign in with Google" or "Sign in with Discord". Each of them handles its own login page and privacy policy.
  • Pokémon Showdown (play.pokemonshowdown.com, replay.pokemonshowdown.com) — used to fetch Pokémon sprites and replays you paste into the Replay Analyzer. Your browser loads these directly.
  • Smogon (smogon.com) — source of the monthly usage statistics that power every analytics page. Pokékipe ingests them server-side; your browser never calls Smogon directly.
  • GitHub user-content CDN (raw.githubusercontent.com) — fallback host for some sprite assets.

Each of these is contacted only for the stated purpose. We do not share your account data with any of them.

Your rights

You are in control of the data you entrust to us. Regardless of where you live, you can:

  • Access your data — the OAuth payload we stored is limited to identifier, display name and email. If you want a copy in writing, ask us on Discord.
  • Delete your account — from the Account page, Danger Zone section. Deletion is immediate and irreversible. Your locally-stored Box is not affected — it lives in your browser. (Create an account)
  • Export your Box — from the Box itself, you can copy any team back out as a Showdown paste. Your teams belong to you. (Open the Box)

We do not sell your data

We do not sell, rent, trade or license any personal data. We do not build advertising profiles. We do not share your account information with advertisers, brokers or "partners". Pokékipe's revenue will come from non-intrusive ads and voluntary donations — see the Pricing page for details — never from selling you. Pricing.

Is Pokékipe GDPR compliant?

Yes. Pokékipe is operated from the European Union and follows the General Data Protection Regulation (GDPR / RGPD). Concretely, this translates into five guarantees:

  • Data minimisation — we collect only the OAuth payload strictly required to sign you in (identifier, display name, email). Nothing else.
  • Lawful basis — processing relies on your explicit consent when you click "Sign in with Google" or "Sign in with Discord", and on our legitimate interest in running the service.
  • No profiling, no cross-site tracking, no advertising identifiers tied to your account. Google Analytics and AdSense load only after you accept the consent banner; rejecting blocks them entirely.
  • Rights of access, rectification, erasure and portability — the Account → Danger Zone lets you delete your account in one click. For access or portability requests, contact us via Discord or Support.
  • No transfer outside the EU other than the strictly necessary hops to Google / Discord OAuth endpoints (standard contractual clauses apply).

Analytics and advertising scripts (Google Analytics, Google AdSense) are wired through an explicit opt-in cookie banner — they are blocked by default until you accept, in line with the EU consent-before-tracking requirement.

Changes to this page

If we change how Pokékipe handles data, we will update this page and announce the change on Discord before it takes effect. The last significant update is shown in the page header.

Contact

Questions, concerns or data requests? The fastest channel is our Discord server. For formal requests you can also reach us through the Support page. Discord · Support