public record / privacy
Privacy Policy
Last updated: 18 August 2026
1. Who We Are
ChromeCreatures is operated by Gray Systems Ltd (company number 17149412), registered in England and Wales at 50 Essex Street, London, WC2R 3JF ("we", "us", "our").
For the purposes of UK GDPR and the Data Protection Act 2018, Gray Systems Ltd is the data controller for personal data collected through the ChromeCreatures website, web app, browser extension, and related services (the "Service").
If you have any questions about this policy or want to exercise your rights, contact us here or write to the address above.
2. What We Collect and Handle
We've tried to be specific here rather than vague. The Service handles the following categories of data. Some information is processed only inside the extension on your device; where we say that we receive or store information, it is sent to our servers.
Account data
- Email address (stored in plaintext so we can contact you)
- Password, stored only as a bcrypt hash — we never store or have access to your plaintext password
- Display name
- A generated agent ID (used for your public profile)
- Account creation timestamp
- The first ChromeCreatures campaign that led to your account, where applicable
Browser extension data
For each browser where you install and link the extension, we store:
- A unique install ID (UUID) per installation
- A SHA256 hash of the API token used by that install — the raw token is sent to your browser once at link time and never stored by us in recoverable form
- A device label you assign (e.g. "Work Laptop")
- A
last_seen_attimestamp, updated on every API call from that extension install - The last IP address and user-agent used by that extension install, so you can recognise unusual linked-device activity
If you set up a passkey (WebAuthn) to sign in, we also store the passkey's public key, credential ID, a device name you choose, and a sign count. The credential itself stays on your device; we only hold what's needed to verify a sign-in.
Website content processed locally
To decide whether a creature is eligible to appear and which category it belongs to, the extension locally evaluates the current hostname and path, page title, metadata, and a limited portion of visible page text. It also uses page layout information to place the creature overlay. This processing happens inside your browser.
We do not receive the raw URL, title, metadata, visible text, images, page contents, or layout information. The extension does not inspect form-field values, passwords, personal messages, clipboard contents, or keystrokes.
Work Mode and reminder data
Your Work Mode setting, reminder choice, reminder schedule, and badge state are stored and processed locally by the extension. If you choose a reminder, Chrome shows one local notification after the selected threshold. Work Mode never turns itself off automatically, and these notifications are not used for advertising, remote push messages, or creature-spawn alerts.
Browsing-related data (please read this section carefully)
Each time the extension considers spawning a creature on a page, it sends us a per-install HMAC-SHA256 hash of the page's domain (for example, a keyed hash of example.com). We store that domain hash, along with a timestamp, against every encounter and every creature you capture.
We want to be straightforward about what this means in practice:
- We do not receive the full URL, page content, page title, text, images, or anything else on the page.
- We do not receive your browsing history.
- The HMAC key is generated and stored locally by your extension. It is not stored in our database, so a database-only breach cannot run a simple public-domain dictionary against the stored domain hashes.
- This is still browsing-derived metadata, not anonymous data. A compromised browser extension install, your own device, or any future change that exposes the local HMAC key could make the hashes easier to interpret.
We also store normalised spawn coordinates (two floats between 0 and 1) representing where on the page a creature appeared.
Gameplay data
The Service permanently stores a fairly detailed record of your play. Specifically:
- Encounter history: the creature, the hashed domain, spawn coordinates, the creature's health, hit count, individual hit timestamps, capture attempts (including the exact success probability the server calculated), the outcome, and timestamps.
- Capture attempts: the item used, the creature's health at the moment of the attempt, the calculated success chance, the result, and the timestamp.
- Collection entries: the creature, the domain where it was caught, variant, level, XP, any nickname you give it, and when it was caught. If you release or process a creature, that collection entry is permanently deleted.
- Work slot activity: which creature is assigned to which slot, when, and when resources were last collected.
- Shop purchases: the item slug, any active buff expiry times, and your coin balance.
Technical and session data
- Session cookies for authentication (HttpOnly, Secure in production, SameSite=Lax)
- Server logs needed to operate and secure the Service (e.g. timestamps, request paths, error data)
First-party campaign measurement
Our own short links, such as chromecreatures.co.uk/PMG, let us measure whether a ChromeCreatures post or advert is useful. When one is opened, we record the campaign, timestamp, a coarse device category, referring hostname where supplied, whether the request appears automated, and a rotating daily pseudonymous fingerprint derived with HMAC-SHA256 from the connection IP address and user-agent. The raw IP address and full user-agent are not stored in the campaign-event table.
If you then create or sign in to an account, we may associate that account with its first campaign and report aggregate milestones such as registration, extension linking, first encounter, and first capture. A later campaign does not overwrite the original attribution. We do not use this information for personalised advertising or cross-site tracking.
Campaign source codes are passed in the page URL to the agent portal. We do not place an analytics cookie or save campaign identifiers in browser local storage.
YouTube and Instagram publishing data
We operate a private, single-user social publishing console for ChromeCreatures marketing. It is not available to ordinary player accounts. When the authorised operator approves a field recording, the console may process:
- The approved video file, title, description or caption, tags, selected YouTube privacy setting, and scheduled publication time
- OAuth or access tokens for the ChromeCreatures YouTube channel and Instagram professional account, stored only on our server and never displayed publicly
- The connected channel or professional-account identifier and username
- Provider-generated media IDs, publication status, permalink, and basic performance counts such as views, likes, and comments
The console uses the YouTube Data API and the Instagram Platform API. It does not read private messages, contacts, unrelated videos, unrelated Instagram media, or personal account activity. YouTube API data is handled in accordance with the YouTube API Services Terms of Service and Google's Privacy Policy.
What we don't receive or monitor
To make the boundaries clear, we do not receive or monitor:
- Raw page content, titles, metadata, text, images, or any full URL
- A readable list of your browsing history or raw domains; the server receives only the per-install domain hash described above
- Keystrokes, mouse position, or general user activity
- Third-party analytics or advertising tracking — our limited first-party campaign measurement is described above and does not inspect browser content
- Payment data — there are currently no real-money transactions, and we do not use a payment processor
3. How and Why We Use Your Data
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and authenticating your account | Email, password hash, display name, agent ID, session cookies, passkey data | Contract |
| Running gameplay (encounters, captures, collection, work slots, shop) | Gameplay data, collection entries, coin balance | Contract |
| Selecting eligible creature categories and rendering the browser overlay | Hostname, path, page title, metadata, limited visible text, and page layout processed only on your device | Contract |
| Sending transactional emails (welcome email, password reset) | Email, display name, password reset URL | Contract |
| Recording where creatures spawn and were caught (domain hash + spawn coordinates) | Domain hash, timestamps, spawn coordinates | Legitimate interests — this is core to how the game works, but we acknowledge the privacy trade-off described in Section 2 |
| Securing the Service, preventing abuse, debugging | Technical logs, last-seen timestamps, token hashes, security events, admin audit records, last extension IP/user-agent | Legitimate interests |
| Complying with law | Any of the above | Legal obligation |
| Publishing approved ChromeCreatures recordings to our own social accounts and reporting their delivery status | Approved media and copy, publication schedule, provider media IDs and basic performance counts | Legitimate interests — operating and promoting ChromeCreatures |
| Measuring which ChromeCreatures campaigns lead to visits and gameplay milestones | Campaign code, timestamps, coarse device, referring hostname, bot indicator, rotating daily pseudonymous fingerprint, and first-campaign account attribution | Legitimate interests — understanding and improving our own marketing without third-party analytics |
We do not sell your personal data, and we do not use it for advertising or profiling.
Our use of information handled by the browser extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use this information only to provide or improve ChromeCreatures' single purpose, do not transfer it except for approved uses needed to operate or secure the Service or comply with law, and do not use it for unrelated purposes, personalised advertising, creditworthiness, or lending.
4. Who We Share Data With
We use a small number of third-party services, listed here so you know exactly who touches your data:
- Microsoft Azure (Graph API) — used only to send transactional emails (welcome emails and password resets). Microsoft receives your email address, display name, and (for resets) a password reset URL. Microsoft acts as a data processor on our behalf.
- Cloudflare — provides DNS, traffic routing, security filtering, and the encrypted tunnel used to deliver and protect the Service. Cloudflare may process IP addresses, request headers, requested hostnames and paths, and other technical connection data as a data processor.
- Google / YouTube — receives recordings and their approved metadata when we publish to the ChromeCreatures YouTube channel. Google returns the media ID, publication status, permalink, and basic channel-owned video statistics used in our private console. See Google's Privacy Policy.
- Meta / Instagram — temporarily retrieves an approved recording through an expiring signed URL and receives its caption when we publish to the ChromeCreatures Instagram professional account. Meta returns the media ID, publication status, permalink, and basic engagement counts.
That's it. We do not use:
- Any third-party analytics or product-analytics platforms
- Any third-party advertising or tracking services
- A payment processor (no real-money transactions)
We may also disclose data where required by law, court order, or to protect our legal rights or the safety of others.
5. Public Profile
Each account has a public agent profile, viewable by anyone who knows your agent ID, showing:
- Your display name
- Your join date
- Total creatures caught and seen
- Counts by rarity
Your public profile does not expose any browsing data, domain hashes, encounter history, or other private gameplay records.
6. Cookies and Local Storage
The web app uses only strictly necessary cookies — session and authentication cookies needed to keep you signed in. These are set as HttpOnly, Secure (in production), and SameSite=Lax. We do not use analytics, advertising, or non-essential cookies, so no cookie consent banner is shown.
Campaign source codes travel in the URL between our public site and agent portal. They are not stored in a cookie or browser local storage.
The extension stores its install ID, API token, per-install HMAC key, cached spawn configuration, recent spawn cooldowns, and Work Mode and reminder settings in your browser's extension storage. You can clear the linked-install data by unlinking the extension, and clear all extension-local data by uninstalling it.
7. How Long We Keep Data
We want to be honest about this:
- Account and gameplay data is currently retained indefinitely until you ask us to delete it. We do not currently run automated deletion jobs.
- Releasing or processing a caught creature permanently deletes that specific collection entry from our database.
- You can revoke individual extension installs and delete passkey devices yourself from your account settings. Doing so removes the associated install records or passkey credentials.
- There is currently no self-serve account deletion flow. If you want your account deleted, contact us here and we'll process the request. We expect to add a self-serve deletion option in future.
- Social-provider access tokens are retained only while the relevant ChromeCreatures account remains connected. The account owner can revoke Google access from their Google Account permissions or revoke Meta access from Instagram's Apps and Websites settings. Revoked credentials are no longer usable and are removed from our server when the connection is removed.
- YouTube and Instagram status and performance data is refreshed regularly while displayed. Provider-sourced data that can no longer be refreshed is deleted within 30 days. Our own original video files and copy are not provider-sourced data and may remain in the internal release archive.
- Individual first-party campaign click events are deleted automatically after 90 days. Daily aggregate campaign counts may be retained indefinitely.
- An account's first-campaign attribution is retained with the account until the account is deleted or the data is otherwise anonymised.
If you exercise your right to erasure (see Section 9), we will delete or anonymise your personal data within one month, except where we're required to keep certain records for legal reasons.
8. Security
We take reasonable technical and organisational measures to protect your data, including:
- Passwords stored only as bcrypt hashes
- API tokens stored only as SHA256 hashes; the raw token is shown to your extension once at link time and is not recoverable from our database
- Browsing-domain metadata stored as per-install HMAC-SHA256 hashes rather than raw domains or unsalted public hashes
- Session cookies set as HttpOnly, Secure (production), SameSite=Lax
- HTTPS enforced in production
No system is perfectly secure, and you're responsible for keeping your password and any device that's linked to your account safe.
9. Your Rights
Under UK GDPR you have the following rights in relation to your personal data:
- Access — request a copy of the data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — ask us to delete your data (also known as "the right to be forgotten")
- Restriction — ask us to limit how we use your data
- Objection — object to processing based on legitimate interests
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent — where we relied on consent for a specific purpose
To exercise any of these rights, contact us here. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have mishandled your data.
10. International Transfers
Microsoft Azure, Cloudflare, Google, and Meta may process data outside the UK. Where data is transferred outside the UK, we rely on appropriate safeguards (such as adequacy regulations or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses).
11. Children
The Service is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to us, contact us here and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. For material changes (for example, adding a new category of data collection or a new processor), we'll notify you by email or in-app.
13. Contact
For privacy questions, data requests, or to exercise any of your rights, contact us here.
Post: Gray Systems Ltd, 50 Essex Street, London, WC2R 3JF