Creator Gacha

Privacy

Last updated 8 August 2026

The short version

Creator Gacha is a folder of static files — HTML, CSS and JavaScript — served by a CDN and run entirely in your browser. There is essentially nothing on our side to store anything in, which is why the rest of this page is mostly a list of things that do not happen.

The single piece of server-side code in the whole project is a two-player lobby, and it holds the state of one match for ten minutes. It is described in full below. Nothing else you do here reaches a server of ours.

What we collect

Nothing, with one narrow exception. No accounts, no sign-in, no analytics, no tracking pixels, no advertising, no cookies, no local telemetry of any kind. Play on your own and we do not know that you visited.

The exception is the two-player lobby, added 8 August 2026 and reworked 15 August 2026 so both players build their team at the same time rather than one after the other. If — and only if — you start a battle against another person through this lobby, a small service of ours holds, for ten minutes, the state of that one match: whether it was accepted, how many distinct cards each side owns (a single number — never which cards), and, once each side locks in, the five cards they chose to field. It exists so the two of you can see each other arrive, build against a shared clock, and start together, rather than passing codes back and forth by hand. It is never sent your name, an account, or your collection beyond the five cards you chose to field and a count of how many you own, and nothing it holds is linked to you between matches. Single-player battles never touch it, and if it is unreachable the game falls back to the original copy-paste flow. See What your browser contacts below.

Your YouTube API key

The game does not ask you for one. Cards ship with the site, so there is nothing to set up and no key to supply. A developer-only Live mode still exists behind a URL flag, and if a key is ever entered there, this is what happens to it:

Closing or reloading the tab discards it.

Your collection

Cards you pull are saved in your browser's localStorage, on your device. They are never transmitted anywhere. They are not readable by us, and they do not sync between your devices — a collection is per-browser.

You can delete it at any time with the "Clear collection" button on the main page, or by clearing site data in your browser. A copy of your data that you have no way to remove is not really yours, so the button is part of the promise rather than a convenience.

What your browser contacts

Each of those sees a request from your browser and applies its own privacy policy, which we do not control. That is the honest boundary of what this page can promise.

Creator data on the cards

Cards are built from public YouTube channel statistics — subscriber, view and video counts, channel name and profile picture. They are refreshed on a fixed cadence and the published snapshot is never older than 30 days, matching YouTube's cap on stored statistics.

If you are a creator and want off, you are off. Write to ashish.barthwal.cs@gmail.com and you will be removed from every set within 7 days, with no questions asked and no proof of identity required. The removal is permanent: your channel id goes on a denylist that blocks it from every future build, so it cannot quietly return the next time cards are sourced.

Children

This is not a service directed at children, and it collects nothing from anyone. There is no monetisation of any kind in the game — no purchases, no currency, no paid pulls, no ads.

Changes

If this policy changes, the date at the top changes with it. The full revision history is public in the project's git log.

Contact

ashish.barthwal.cs@gmail.com

← Back to the game