Privacy
What PEAK3 Arena stores, why, and what it deliberately never collects.
The short version
- There are zero third-party analytics or advertising trackers on this site.
- PEAK3 does not sell personal data. There is no one to sell it to.
- Product telemetry is off by default and cannot be linked back to your account.
- Most of what is stored is your game data — boards, runs, results, streaks — so your progress survives a refresh.
- There is currently no self-serve account deletion or data export. Deletion is a manual request; see below.
Signing in
Accounts are optional. The implemented sign-in methods are Google OAuth (using PKCE), an emailed magic link, and email with a password, plus password reset by email. Sign in with Apple is not implemented. Google OAuth exists in the code but may not be switched on for a given deployment.
Anonymous Supabase sign-ins are disabled. Instead, guest play is identified by a first-party cookie named peak3_anon: it is HttpOnly, SameSite=Lax, cryptographically signed, and expires after 30 days. It exists so a guest can finish a run, reload the page, and still own their games. Clearing it ends that identity.
What is stored on an account
When you have an account, the service stores:
- Profile — handle, display name, bio, region, avatar key, and your public-profile and history-visibility flags.
- Settings — timezone and reduced-motion preference.
- Game state and results — for Peak Draft, 82-0 Peak Season, Daily Grid, Peak Duel and Run the Table.
- Daily completions — which day's board you have finished, so a daily game stays once a day.
- Challenges — the links you create to send a board or run to someone else.
- Progression — XP, level, streaks, achievements and personal records.
- Ranked records — your results in ranked modes.
All of it exists for one reason: so the game can show you your own progress and keep daily modes honest. Guest play stores the same game data against the peak3_anon identity rather than an account.
Product telemetry
Telemetry is off by default. When an operator enables it, it is deliberately built so that it cannot become a user profile:
- A closed allowlist of 21 gameplay event names. An event that is not on the list is dropped.
- A closed allowlist of property keys. Values are capped at 64 characters and may not contain spaces, so free text cannot be represented at all.
- The subject is stored only as an HMAC digest, and by design it cannot be joined back to your account or your game data.
- Events are retained for 90 days.
- It never collects email addresses, tokens, IP addresses, user agents, board answers, or player selections.
- It honours the Global Privacy Control signal, the Do Not Track header, and a
peak3:telemetryopt-out value in your browser's local storage.
Known gap, stated plainly: there is currently no opt-out button anywhere in the product. The opt-out exists and is honoured, but it has no user interface control yet — today it can only be set manually in local storage, or expressed through Global Privacy Control or Do Not Track. A visible control is owed.
No third-party analytics
There are zero third-party analytics or advertising SDKs in this application. No Google Analytics, no PostHog, no Plausible, no Segment, no Sentry, no Vercel Analytics. PEAK3 does not sell personal data, and it does not share it with ad networks — there are none integrated.
Cookies and browser storage
Cookies:
peak3_anon— first-party, HttpOnly, SameSite=Lax, signed. Identifies a guest's games for 30 days.- Supabase session cookies — set when you are signed in, so the session persists across page loads.
Local storage keys, all first-party and all readable and clearable by you in your browser's developer tools:
peak3_arena_progress— Peak Duel progress and local scores.peak3_draft_progress_v1— Peak Draft progress.peak3.daily-grid.archive— your Daily Grid archive and streak.peak3.daily-grid.rules-seen— legacy key recording whether you had seen the Daily Grid rules. It is now only read, never written; the walkthrough state lives inpeak3.tour.state.peak3.daily-grid.{boardId}— your in-progress board for a given day.peak3.run-the-table.active— your in-progress Run the Table run.peak3.tour.state— which guided tours you have already seen.peak3_ranked_match_{mode}— your active ranked match for a mode.peak3:telemetry— your telemetry opt-out, if you have set one.
Clearing site data removes all of the above, including the guest identity, which means guest game history stored against it is no longer reachable from that browser.
Third parties
Supabase provides authentication and the PostgreSQL database, and delivers magic-link and password reset emails. Account data and game data described above are stored there.
Web fonts are self-hosted: Google Fonts are downloaded at build time by Next.js and served from this site, so loading a page does not call out to a font CDN.
Retention, and how to request deletion
Account and game data are kept for as long as the account exists. Telemetry events, when telemetry is enabled at all, are kept for 90 days.
There is currently no account deletion endpoint and no data export endpoint. Neither feature exists in the product yet. Until they do, deletion is a manual request: contact us through the contact page with your account handle, and the request will be carried out by hand.
Guest data is a partial exception: clearing the peak3_anon cookie and your local storage detaches your browser from that guest identity immediately, though rows already written to the database remain until they are deleted by request.
Changes to this notice
This notice will be revised as the product changes and again after legal review. The version published here is the current one. Related reading: Terms of Use and Data Sources.