Data processing and retention
Privacy Policy
This policy explains what ScoreNet Arcade collects, why it is used, how it is protected, and how account deletion works.
Information ScoreNet Processes
When you create a Passport, ScoreNet stores a handle, display name, three-character initials, account status, profile visibility, timestamps, and a cryptographic hash of your recovery key. The plaintext recovery key is shown once and is not stored by ScoreNet.
If you choose Apple or Google sign-in, ScoreNet stores the provider name, the immutable provider account identifier, the applicable client identifier, and link/use timestamps. ScoreNet does not use provider email addresses to merge accounts and does not retain provider email or profile data. Apple refresh credentials are encrypted at rest only so ScoreNet can revoke them when you unlink or delete the Passport; Google sign-in requests identity access only and does not request offline access.
When you play, ScoreNet records cabinet identifiers, scores, run duration, score-session identifiers, submission time, validation version, and—when signed in—the Passport associated with the run. Competition, ranking-history, challenge-progress, streak, achievement, rivalry, friendship, block, notification, safety-report, and award records are stored when those features are used. Achievement and challenge progress is calculated from verified score history, cabinet coverage, rating, placements, rank movement, active scoring days, and competition participation.
Security and Operational Data
ScoreNet uses secure HttpOnly session cookies for browser authentication. Network addresses are not stored as raw IP addresses in the application database; the service uses rotating pseudonymous client hashes for rate limiting, integrity review, and abuse prevention. Basic page-view totals may be stored by day and path without a cross-site advertising profile.
Infrastructure and Sharing
ScoreNet is hosted using Cloudflare Pages, Workers, and D1 infrastructure. Data is processed by infrastructure providers only as needed to operate, secure, and deliver the service. Optional OAuth sign-in sends the authentication request to Apple or Google under the privacy terms of that provider; ScoreNet requests only the minimum identity scope required to verify the account. ScoreNet does not sell personal information to advertisers and does not provide advertisers access to private account credentials or private safety reports.
Retention and Deletion
Active account data is retained while a Passport remains active. Expired sessions, temporary rate-limit records, and rejection telemetry are periodically removed. A user may permanently delete a Passport from the Player Dashboard. Account identity, credentials, sessions, settings, and social links are removed; historical scores, achievement history, finalized standings, awards, and season records are retained only under a de-identified player identity to preserve competition integrity.
Contact
Privacy questions may be sent to privacy@playscorenet.com. Include the ScoreNet handle involved, but never email a recovery key.