Privacy Policy
DevCake AB operates Cube Jump and is responsible for the personal data described in this policy. For privacy questions or requests, email hello@devcake.se.
Optional analytics is off until you allow it. You can change or withdraw your permission at any time using .
1. Data we process
- When you sign in by email, we process your email address to send a sign-in link and identify your account. We store your account ID, player name, email-verification status, and account timestamps. Links work once and expire after ten minutes; their tokens are stored as hashes in our database. New email accounts start with the public player name Player, which you can change.
- When you sign in with Discord, we receive your Discord user ID, username or display name, email address, email-verification status, and avatar URL. We store an internal account ID, your chosen player name, account timestamps, and the Discord account link. Authentication also stores access and refresh tokens and their expiry information. We do not receive your Discord password.
- Account sessions can include a session token, expiry time, IP address, and browser information. We use session cookies to keep you signed in and short-lived authentication data to complete sign-in securely.
- Gameplay data includes player names, room membership, game mode, moves, match state, scores, game counts, and match timestamps. For ranked solo games, we also process a run ID, tower seed, and submitted jump inputs to check the score.
- Your browser stores settings such as sound preferences, player names, local best scores, unfinished games, ranked-run progress, your analytics choice, and a room code and rejoin token when applicable.
- Our hosting providers process connection and request information, which can include IP addresses, browser details, request times, and operational logs. If you contact us, we process your email address and the information in your request.
- If you allow analytics, Vercel Web Analytics processes page views, visit times, referring websites, approximate location, and browser, operating system, and device type. It uses no analytics cookies. We remove query strings and URL fragments from tracked page addresses, exclude account and API paths, and do not send player names, scores, Discord details, or custom gameplay events to analytics.
2. Why we use it
We use this data to provide the game, authenticate accounts, reconnect players to rooms, save and validate scores, display leaderboards, answer support requests, prevent abuse, and diagnose faults.
We use optional analytics to understand which pages people visit and which devices they use, so we can improve Cube Jump. We rely on your consent for this processing. Refusing or withdrawing analytics permission does not affect playing, signing in, or saving scores.
Where the GDPR applies, we process account and gameplay data to provide the service you request under our terms. We rely on our legitimate interests in keeping the game secure, fair, and reliable for abuse prevention and technical diagnostics. We process data to meet legal obligations where required. If a use requires consent, we will ask for it and you can withdraw it without affecting earlier lawful processing.
Email and Discord sign-in are optional. You can play as a guest without providing account information, but account-based rankings require sign-in. We request Discord's identify and email permissions for authentication. We do not request access to messages, friends, or server membership, and we do not sell personal data or use Discord data for advertising.
3. What other people can see
Other players in a room can see your player name and game activity. Public leaderboard responses include your player name, internal Cube Jump account identifier, score, and game count. Leaderboards currently display Solo and co-op Duo, Trio, and Quattro rankings. Choose a player name you are comfortable making public.
Your email address, Discord sign-in tokens, session credentials, and private connection details are not shown on leaderboards or in rooms.
4. Service providers and data sharing
We use Vercel to host the website, route account requests, and provide optional Web Analytics, Railway to run the game server and PostgreSQL database, Resend to deliver email sign-in links, and Discord to provide optional sign-in. These services process the data needed for their roles. Discord also processes your use of its services under its own privacy policy.
Resend processes the recipient email address, sign-in email content, and delivery information. Sign-in emails have open and click tracking disabled. Replies go to our support address. See Resend's privacy policy.
Vercel provides aggregated analytics reports. It derives a temporary visitor identifier from incoming requests and discards that identifier after 24 hours. See Vercel's Web Analytics privacy documentationfor details.
We share data with service providers as needed to operate Cube Jump, when you direct us to do so, or when required by law. Providers may process data outside your country, including outside the European Economic Area. For transfers that require safeguards, we rely on applicable adequacy decisions or standard contractual clauses. Contact us for information about the safeguards applicable to your data.
5. Storage and retention
- Account details, the Discord account link, and account scores are kept while needed to provide your account and rankings. We delete personal data when you request deletion or it is no longer needed, unless a legal obligation requires us to retain specific information.
- Sign-in sessions normally expire after seven days and can renew while you use the game. Signing out ends the current session. Temporary authentication records are used only for sign-in and security.
- Online room state is held temporarily on the game server. Rooms with no connected players are removed after about 30 minutes, and server restarts clear room state. Saved account scores are stored separately.
- Ranked solo runs can be submitted for 24 hours. The service removes run records older than seven days when it starts. Jump inputs are checked during score submission rather than kept as a permanent server-side replay history.
- Browser-stored data remains on your device until the game replaces or removes it, or you clear the site's browser data. Clearing it does not delete your server-side account or scores.
- We remember your analytics choice on this browser until you change it or clear the site's data. Vercel's current plan provides up to 12 months of aggregated report history. Withdrawing permission stops future analytics events; it does not remove statistics already included in aggregated reports.
- We keep support correspondence and operational records only as long as needed to resolve the request, investigate faults or abuse, or meet legal obligations. Hosting logs and any backups are also subject to the providers' retention and deletion processes.
6. Cookies, analytics, and security
Cube Jump uses essential sign-in cookies and browser storage for game preferences, saved progress, reconnection, and your analytics choice. We do not use advertising trackers. Blocking essential cookies prevents account sign-in; blocking local storage prevents saved local progress. Vercel Web Analytics starts only after you choose Allow analytics. Choose Necessary only to keep analytics off.
Use Cookie settings on the home or account screen, or on either legal page, to review or change your choice. You can also use the button near the top of this policy. If your browser cannot store your choice, it applies only for the current visit.
Production connections use HTTPS and secure WebSockets. Sign-in cookies are HTTP-only, and stored Discord OAuth tokens are encrypted. Access to account data is restricted to running and supporting the service. No method of storage or transmission can guarantee absolute security.
7. Your choices and deletion requests
You can change your public player name in the account screen, sign out, clear the game's browser data, and remove Cube Jump from Discord's authorized applications. Removing Discord authorization stops that authorization but does not by itself erase your Cube Jump account.
To request account deletion, removal of associated scores, a copy of your data, or a correction, email hello@devcake.se. Include your Cube Jump player name and enough information for us to identify your account. We may need to verify that you own the account. Do not send passwords, session tokens, or Discord access tokens.
Depending on the law that applies to you, you may also request restriction of processing or data portability, object to processing based on legitimate interests, and withdraw consent where we rely on it. We respond within the time limits required by applicable law, normally one month for GDPR requests. You can complain to your local data protection authority. In Sweden, this is Integritetsskyddsmyndigheten, IMY.
8. Children
Cube Jump is intended for people aged 13 or older, subject to any higher minimum age that applies locally. We do not knowingly collect personal data from children who are not eligible to use the game. A parent or guardian who believes a child has provided such data can contact us to request deletion.
9. Changes and contact
We will update this page when our data practices change and show the revised effective date. We will give additional notice of material changes where required. Privacy questions and requests can be sent to DevCake AB at hello@devcake.se.