Privacy Notice · Pixel Port

Pixel Port privacy notice

Notice version
privacy-2026-08-26
Policy version
privacy-policy-3.0
Revised
2026-08-26
Effective date
2026-08-26
Contact
privacy@pixelport.gg

Pixel Port uses optional telemetry to improve compatibility, diagnose failures, and make the app better for everyone. Compatibility telemetry, structured rich diagnostics, experience analytics, account personalization, and commercial research are all shown on when you review these settings. You can change every switch before continuing or later in Settings.

Marketing emails is a separate, account-scoped choice. That choice is not one of the five telemetry purposes, starts off and unselected, and is granted only when you affirmatively select it in the privacy review or account settings.

Turning optional purposes off does not remove core catalogue, install, or play functionality. Data needed to complete an action you request—such as signing in, fetching the catalogue, requesting a game, contacting support, or starting a privacy job—is service data and is not reused as analytics.

Starting positions

The current review presents these starting positions:

PurposeStarting position
Compatibility telemetryOn
Rich diagnosticsOn; current diagnostic facts stay local, and excerpts/files require confirmation
Experience analyticsOn
Account personalizationOn
Commercial researchOn; server processing and output remain disabled pending separate review

Every first-time user, and every existing user who reviewed an earlier revision, sees this review once. The switches are a draft until you press Continue. For an existing user, an earlier stored choice remains stored and is the authoritative saved choice while the review is open; the draft does not silently rewrite it. Pixel Port pauses optional network transport and signed-in account restoration until the review is completed. A first-time user likewise sends no optional telemetry before continuing. After Continue, optional transport starts only after the server acknowledges the exact choices, policy version, notice version, and notice digest.

If you continue without changing a new starting position, Pixel Port records that value as a "Pixel Port default". If you change a switch, it records the resulting value as "your choice". The displayed defaults never convert an earlier refusal into a grant merely because the app was updated; they become the new recorded choices only when you continue through the review.

Compatibility telemetry is not mandatory for any tier of Pixel Port. If it is off when you press Continue, Pixel Port shows a confirmation warning before saving. Core functionality and the ability to contact support remain available, but Pixel Port may not have enough telemetry to diagnose a bug or crash, so support and fixes may have less context or take longer. The warning is not shown when compatibility telemetry is on.

Optional purposes

You can grant or withdraw each purpose independently:

  • Compatibility telemetry: coarse install, launch, render, outcome, duration, app ID, chip family, macOS major version, runtime major version, and recipe hash.
  • Rich diagnostics: structured failure facts. The current client has no automatic rich-diagnostics transport, so those facts stay local. A panic excerpt, full log, filenames, or support attachment also stays local unless you preview it and separately confirm that upload. Turning this setting on does not automatically upload diagnostic facts, excerpts, or files.
  • Experience analytics: app opens, browse transitions, game views, and install-funnel events. Pixel Port does not collect session replay, keystrokes, or viewed content.
  • Account personalization: connects activity already permitted under another purpose to your signed in account. Signing in does not change this purpose's setting either way. Turning it off stops the linking at once and starts the unlink, and the purposes you left on continue unlinked.
  • Commercial research: lets eligible contributions already covered by your other purpose choices be used in reviewed, thresholded aggregates. It adds no collection fields and does not permit raw or pseudonymous records to leave Pixel Port. This setting starts on, but recording it does not activate commercial processing or output. The server-side feature stays disabled pending a separate legal, privacy, and release review.

Optional telemetry is pseudonymous, not anonymous. Pixel Port uses separate random subjects for each primary purpose. Subjects expire after 30 days and rotate after consent-scope changes, linking, unlinking, account changes, sign-out, reset, or deletion. Installation security credentials and account-device identifiers are independently generated and are not analytics identifiers.

Recipients and processing

Cloudflare provides the Worker, D1, KV, R2, Access, rate-limiting, and delivery infrastructure. Apple, Google, and Valve/Steam process data when you choose their sign-in, distribution, or game services. GitHub distributes releases. Other processors are not enabled unless the processor inventory, contract, deletion path, retention, manifest, and notice impact are approved first.

Operational logs contain route templates, status/reason codes, latency buckets, policy/schema versions, and aggregate job health. They must not contain bodies, query strings, raw IP addresses, subjects, account/provider/device identifiers, contact text, filenames, crash excerpts, credentials, cookies, authorization headers, or exact external URLs. Worker/application error logs expire after 7 days. Short-lived rate-limit material is a keyed digest, not raw IP, and expires after 2 minutes.

Retention

Navigation events expire after 30 days; compatibility outcomes and feedback after 90 days; rich diagnostics after 30 days; unfulfilled requests after 180 days; fulfilled requests and personal notices 90 days after fulfillment/dismissal; generated export archives after 24 hours; account and device records on account closure; and consent evidence 730 days after withdrawal or closure by default. An account email remains an identity record for the life of the account. An email-marketing preference remains while the account is open, and its consent evidence expires 730 days after withdrawal or account closure by default. The complete engineering schedule is in RETENTION.md. Retention can be shortened by an approved change. A legal hold must be named, time-limited, scoped, owned, and reviewed.

Eligible raw rows may be rolled into privacy-reviewed daily aggregates before deletion. External cells require at least 100 distinct commercially eligible contributors, contribution bounding, sparse-cell suppression, no stable contributor key, and a release review. Previously delivered de-identified aggregate releases generally cannot be adjusted per person; raw or pseudonymous downstream copies are prohibited.

Choices and rights

Withdrawal is effective locally as soon as your choice is saved. Pixel Port then cancels queued work, rotates/deletes the affected local subject, and reconciles with the server. If offline, the UI shows cleanup as pending and does not claim the remote link or data was removed.

Every recorded choice carries its origin. A value you set yourself is recorded as "your choice"; a shipped starting position you left alone is recorded as a "Pixel Port default". Settings shows the origin beside each purpose, and your privacy export includes it. A default is therefore never presented to you—or counted by Pixel Port—as a switch you affirmatively changed yourself.

The one-time review marker is stored separately from the purpose choices. Until that marker records that you continued through this notice, prior saved choices remain intact but optional transport and signed-in account restoration stay paused. Completing the review records the displayed choices under this notice. An untouched starting position has default provenance; a changed position has user provenance.

The Privacy Center provides local inspection, export, telemetry deletion, account closure, link status, and privacy-job status. Server exports and deletions are authenticated, idempotent jobs that cover current and historical subjects, requests/notices, diagnostics, support, account devices, provider identities, links, object storage, and affected unreleased aggregates. A deletion tombstone is installed before the job is acknowledged so retries cannot resurrect deleted data.

Unlinking and deletion are different. Unlink removes the active account bridge and identified derivatives; deletion erases the selected historical data. Sign-out alone does not imply deletion and does not silently disconnect the separately disclosed Steam connector.

Email and marketing

Pixel Port offers a separate account preference called Marketing emails. It starts off and unselected. Leaving it unselected is a refusal, not a Pixel Port default grant. Pixel Port may use an email address for marketing only after you affirmatively select this preference in the privacy review or account settings. A selection made before sign-in remains pending and may be granted only after authenticated account reconciliation. This choice has no effect on the five telemetry purposes, core features, transactional account or security messages, or support replies.

Signing in with Apple or Google may pass Pixel Port an email address, often a private relay address. Pixel Port stores it as account identity data. An explicit email-marketing grant permits Pixel Port to reuse that address for product updates, game compatibility news, and special offers. It does not permit Pixel Port to connect the address to telemetry subjects, sell it, share it for another company's advertising, or infer permission from sign-in or any telemetry choice.

You can withdraw in account settings. Withdrawal stops future marketing sends after the request is processed and does not affect your account. Account closure removes the active preference. Pixel Port keeps consent and withdrawal receipts for the period described above so it can enforce the choice and answer consent questions. Before any sender is activated, every marketing message must provide a working unsubscribe control backed by an enforced suppression path.

At this notice's effective date, no marketing email delivery provider or mailing system is enabled. Pixel Port may record the account preference, but does not send marketing email in this release. A delivery system cannot be activated until its processor, security, unsubscribe/suppression, retention, export, deletion, account-closure, and notice impacts pass separate privacy, legal, and release review.

Tracking and external sale

Pixel Port does not track people across other companies' apps or websites, declares no tracking domains, and sets NSPrivacyTracking to false. It does not sell or license raw, row-level, pseudonymous, linked-account, diagnostic, contact, request, or security-credential data. Marketing email, if later enabled, may not contain open pixels or cross-site/cross-app tracking under this notice.

Changes

A material change to fields, purpose, linkage, recipients, or retention advances the policy major version and requires affected choices to be reviewed under fail-closed transport. A notice revision that changes how choices are presented may keep the policy version while requiring an explicit one-time review marker. A notice change never silently overwrites a stored choice. Change history:

  • privacy-2026-08-26: presents compatibility telemetry, structured rich diagnostics, experience analytics, account personalization, and commercial research on; keeps server-side commercial processing/output disabled pending separate review; requires every first-time and existing user to complete the review once; pauses optional transport and signed-in account restoration until Continue; explains choice provenance and the compatibility support tradeoff; confirms that excerpts, logs, filenames, and attachments are never automatic; and introduces a separate, account-scopedemail_marketing preference that starts unselected and requires an affirmative choice. Marketing delivery remains disabled pending its own review.
  • privacy-2026-08: states the starting position of each purpose, including account personalization starting on from Pixel Port 0.4.5; adds the origin ("your choice" or "Pixel Port default") recorded with every decision; states that no email or marketing system exists.
  • privacy-2026-07: v2 purpose choices, rotating purpose subjects, signed ingestion, data-rights jobs, retention, admin controls, processor inventory, and macOS privacy manifest.

The privacy-2026-08-26 revision advances the policy version to privacy-policy-3.0 because it adds the identified, account-scoped email_marketing purpose and permits reuse of an account email only after a separate affirmative choice. It also deliberately requires one review of the five telemetry starting positions. Previous telemetry choices remain stored and authoritative while that review is open, and optional transport stays paused until you continue. Email marketing remains off unless you separately select it.