Privacy Policy
Last updated: September 5, 2026
This Policy explains what information YouToStem processes, why it is used, where it may be stored, and the choices available to users and parents. Most games can be played without creating an account.
1. Scope and contact
This Policy applies to the YouToStem website, browser games, accounts, feedback, community submissions, and challenge features. YouToStem is responsible for the processing described here. Privacy questions and requests can be sent through our Feedback page or to K162000080@gmail.com.
2. Information stored on your device
Games may use local storage to remember progress, unlocked levels, best results, sound and theme settings, and anonymous challenge state. This data normally remains on your device and is not account synchronisation. You can remove it using your browser’s site-data controls, although doing so may reset progress and preferences.
3. Information you provide
- Optional account data: email address, display name, account creation time, and a salted one-way password hash. We do not store plaintext passwords or payment-card details.
- Third-party sign-in: if you choose Google or GitHub sign-in, we receive the provider account identifier, email address, and display name needed to create or locate your account. We do not receive your provider password.
- Profile and community data: profile text, avatar, follows, favourites, game/tool submissions, review status, and reports relating to community tools.
- Challenges: game name, level, display name, steps, completion time, result, and challenge timestamps when a server-backed challenge feature is used.
- Feedback: feedback type, message, optional email address, related game information, submission time, and the request IP address used for abuse prevention and investigation.
4. Information collected automatically
When you visit, hosting and security systems may process technical request data such as IP address, date and time, requested URL, browser/device information, and error or security events. Google Analytics may use first-party cookies or similar identifiers to measure page views, approximate location, device characteristics, and interactions. We do not intentionally send passwords, feedback text, or game-board contents to Google Analytics.
5. How and why we use information
We process information only as reasonably necessary to:
- provide games, accounts, sign-in, profiles, submissions, feedback, and challenge features;
- save preferences, authenticate users, and maintain service security;
- moderate submissions, prevent spam, fraud, cheating, and other misuse;
- understand aggregate usage, diagnose errors, and improve accessibility and performance; and
- comply with legal obligations and respond to valid requests.
Depending on your location and the feature involved, the legal basis may be performance of a requested service, legitimate interests in operating and securing YouToStem, consent, or compliance with law. Where consent is required, it may be withdrawn for future processing.
6. Cookies and similar storage
A secure, HttpOnly session cookie keeps registered users signed in; the current session is designed to expire after seven days. Temporary OAuth cookies help complete third-party sign-in. Local storage remembers game and interface settings. Analytics cookies or identifiers may be set by Google Analytics. Browser controls can block or delete cookies, but account sign-in and saved local progress may then stop working.
7. Service providers and external parties
Information may be processed by providers that support the relevant feature:
- Cloudflare: hosting, storage, delivery, and security infrastructure;
- Google Analytics: website measurement and aggregate usage reporting;
- Google or GitHub: only when you choose the corresponding sign-in option; and
- advertisers and linked websites: when an advertisement, embedded service, or external link is displayed or selected, subject to that party’s own privacy notice.
We may also disclose information when required by law, to protect users or the service, or as part of a business reorganisation with appropriate safeguards. We do not sell personal information for money.
8. Public information
Display names, avatars, profile text, approved community submissions, creator relationships, and challenge-related display names may be visible to other users. Do not include private contact details or another person’s personal information in public fields or submissions.
9. International processing
Our infrastructure and service providers may process information in countries other than the one where you live. Where applicable law requires it, we rely on recognised transfer mechanisms or other appropriate safeguards. Third-party providers independently describe their processing locations and safeguards in their privacy documentation.
10. Retention
Local game data remains until it expires, is replaced, or you clear browser data. Account and community records are retained while needed to provide the account or feature. Feedback, moderation, security, and challenge records are retained for operational, safety, dispute-resolution, and legal purposes, then deleted or anonymised when no longer reasonably necessary. Provider-controlled analytics retention follows our configured settings and the provider’s rules. Backup copies may persist for a limited period before routine deletion.
11. Your choices and rights
Subject to applicable law, you may request access, correction, deletion, restriction, or a portable copy of personal information, or object to certain processing. You may also withdraw consent and lodge a complaint with the relevant data-protection authority. We may need to verify a request and may retain information where legally required or necessary to protect others. To make a request, use the contact details in Section 1.
12. Children’s privacy
Core games do not require an account, and we do not knowingly require a child to provide personal information simply to play. A child below the applicable digital-consent age—including a child under 14 in China or under 13 where COPPA applies—must not create an account, upload content, join community features, or submit personal information unless a parent or guardian has provided the authorisation required by law. Parents and guardians may contact us to review, correct, or request deletion of a child’s information. If we learn that information was collected without required permission, we will take reasonable steps to delete it.
13. Security
We use reasonable administrative and technical safeguards, including access controls, signed session cookies, rate limiting, and one-way password hashing. No internet service is completely secure, so users should choose a unique password and promptly report suspected unauthorised access.
14. Changes to this Policy
We may update this Policy when features, providers, or legal requirements change. The latest version and effective date will be posted here. We will provide additional notice when a change materially affects registered users and doing so is reasonably practicable.
15. Contact us
For privacy questions, parental requests, or data-rights requests, use our Feedback page or email K162000080@gmail.com. Please describe the account or feature involved without sending passwords or other unnecessary sensitive information.