Paint Off ← Back to game

Privacy Policy

Last updated: 5 June 2026

Paint Off ("we", "us") is a real-time multiplayer drawing-and-guessing game at paintoff.app. This policy explains what we collect, why, and the choices you have. You can play as a guest without an account; signing in is optional.

Information we collect

  • Guest play. A random device identifier stored in your browser, a display name you choose, an avatar you draw, your game scores and stats, the drawings you make, and chat/guess messages you send during a game.
  • Account sign-in (optional). If you sign in with Google, Apple, or Facebook, that provider sends us your name, email address, and (where available) profile picture after you authorize it. We store an account record, display name, avatar, email, and your plan tier.
  • Technical data. Your IP address (used transiently for abuse prevention and rate limiting) and a secure, HttpOnly session cookie (po_session) that keeps you signed in.

How we use your information

  • Run the game: matchmaking, rooms, drawing sync, chat, and scoring.
  • Show leaderboards, profiles, badges, and (where enabled) a community gallery.
  • Optional AI features: when you choose to "generate AI art" from a drawing, that image is processed to create an illustrated version.
  • Keep the service safe: moderation, anti-cheat, and rate limiting.

Cookies & local storage

We use a single essential cookie, po_session, to keep you signed in. It is HttpOnly, Secure, and SameSite=Lax. We also keep a few items in your browser's local storage that are needed for the game to work — your guest player ID, your sign-in token, and your locally earned badges/stats. We do not use advertising or cross-site tracking cookies.

Analytics & your choices

We use Cloudflare Web Analytics to understand basic, aggregate usage — things like how many people visit, which pages they view, and which links bring them to the game. It is cookieless, stores nothing on your device, and does not fingerprint you or track you across other websites.

Because it does not store or read anything on your device, Paint Off does not need a cookie-consent banner — but you stay in control. We automatically respect your browser's Global Privacy Control and Do Not Track settings, and you can opt out on this device at any time:

Analytics are ON — cookieless and anonymous.

Service providers

We share the minimum data needed with processors who run the service on our behalf:

  • Cloudflare — hosting, database (D1), object storage (R2), and cookieless Web Analytics.
  • OpenRouter — only when you opt in to AI art/assist; the relevant drawing is sent to generate the result.
  • Google, Apple, Facebook — only if you choose to sign in with them.

We do not sell your personal information.

Public content

Some content is public by design: leaderboard display names, and drawings you submit to the community gallery (when that feature is enabled). Don't include anything private in a drawing, name, or chat message.

Data retention & deletion

We keep your data while your account/profile is active. You can request deletion at any time — see our Data Deletion page.

Children

Paint Off is not directed to children under 13, and we do not knowingly collect their personal information.

Changes

We may update this policy; we'll revise the "Last updated" date above and, for material changes, provide a notice in the app.

Contact

Questions or privacy requests: [email protected].

paintoff.app · Privacy · Data Deletion