At Rhythmio (“Rhythmio,” “we,” “us,” or “our”), player privacy is fundamental to our engineering ethos. We operate under a principle of strict data minimization: we only collect information that is technically essential to deliver zero-latency web gameplay, maintain competitive ladder integrity, and safeguard multiplayer matches.
We do not sell your personal data, and we do not profile your behavior for commercial advertising. This Privacy Policy explains what information we collect, how it is used, where it is stored, and your rights regarding your data across rhythmio.net and play.rhythmio.net (the “Service”).
1. Information We Collect
1.1 Account & Identity Information
When you register or log in using third-party OAuth authentication (such as Discord or Google), we receive:
- Provider Subject Identifier: A unique alphanumeric token issued by the OAuth provider.
- Email Address: Used solely for critical security alerts, account verification, and account recovery.
- Public Profile Information: Your chosen display handle and avatar image URL.
Note: Rhythmio never receives, processes, or stores your third-party account passwords or financial details.
1.2 Gameplay & Competitive Match Telemetry
To facilitate real-time multiplayer duels, calculate rating points (RP/MMR), and verify competitive fair play, our servers process:
- Match Results: Final score, maximum combo, accuracy percentage, difficulty level, and judgement breakdown (KOOL, COOL, GOOD, MISS).
- Replay Data: High-resolution input event timelines (hardware key-down/up timestamps and offset variances), verified against server match seeds to detect automated botting or macro manipulation.
- Matchmaking History: Lobby participation records, matchmaking queue durations, and disconnect flags.
1.3 Technical & Hardware Metrics
When connecting to our web client and WebSocket nodes, our infrastructure automatically processes:
- Network Telemetry: IP address (used strictly for geographic matchmaking routing, ping estimation, and DDoS rate-limiting; masked or hashed in persistent logs).
- Client Environment: Browser engine version, operating system family, and user-agent string for compatibility diagnostics.
- Audio/Visual Calibration Specs: Hardware audio sample rate (e.g. 44.1kHz / 48kHz) and display refresh rate ceiling (60Hz–360Hz+) to ensure glitch-free audio scheduling buffers.
2. Local Storage vs. Cloud Synchronization
Rhythmio is engineered to keep as much data on your local device as possible:
2.1 Stored Exclusively on Your Device (IndexedDB & LocalStorage)
The following information remains strictly within your browser’s local sandbox and is never transmitted to Rhythmio servers without your explicit initiation:
- Key bindings (custom keyboard layouts for 4K, 5K, 6K, and 7K modes).
- Universal and per-song audio offset calibration values (milliseconds).
- Visual preferences: note scroll speed (HiSpeed), lane skin styling, and background brightness dimming.
- In-progress custom beatmaps and audio files loaded into the local chart editor.
- Offline guest score histories and practice room records.
2.2 Synchronized with Rhythmio Cloud Servers
The following data is synced to our secure cloud databases:
- Authenticated player profiles (handle, avatar, rating tier, rank badge).
- Verified ranked leaderboard submissions and global skill percentiles.
- Published community beatmap charts and chart metadata.
3. Cookies & Session Identifiers
Rhythmio employs a privacy-first approach to cookies:
- Strictly Necessary Session Tokens: We use cryptographically signed, secure HTTP cookies (
HttpOnly,Secure,SameSite=Lax) solely to authenticate your login session acrossrhythmio.netandplay.rhythmio.net. - No Third-Party Ad Cookies: We do not deploy third-party advertising cookies, social tracking pixels, or cross-site commercial profiling scripts.
4. How We Use Your Data
We process your data exclusively for legitimate operational purposes:
- Matchmaking & Gameplay: Establishing low-latency WebSocket connections and matching players within equivalent MMR brackets.
- Leaderboards & Statistics: Calculating accurate global rankings, accuracy percentiles, and profile history.
- Anti-Cheat & Security: Analyzing replay input timelines against deterministic server seeds to detect automation scripts, macro injectors, or client manipulation.
- Service Reliability: Monitoring server load, diagnosing audio clock dropouts, and defending against denial-of-service attacks.
- Community Protection: Enforcing our Terms of Service and investigating reports of harassment or ranking abuse.
5. Information Sharing & Third-Party Processors
We never sell, rent, trade, or monetize your personal information. We only share information with trusted third-party service providers who assist in operating our platform, bound by strict data processing and confidentiality agreements:
- Cloud Infrastructure & Hosting: Cloud server providers and edge network routing services for hosting databases and WebSocket game nodes.
- Authentication Providers: Discord and Google, strictly to authenticate your identity via secure OAuth 2.0 protocols.
- Legal Compliance: We may disclose information if required by a valid court order, warrant, subpoena, or applicable law, or to protect the safety and integrity of our players and systems.
6. Google API Services User Data & Limited Use Disclosure
Rhythmio (“the Application,” hosted at https://rhythmio.net and https://play.rhythmio.net) integrates Google Sign-In via OAuth 2.0 to offer players a secure, passwordless authentication option. This section provides complete disclosures regarding how we access, use, store, protect, and share Google user data.
6.1 Google User Data Accessed
When you authenticate using Google Sign-In, our application requests access only to basic profile identity scopes (openid, profile, email). We access the following categories of personal data:
- Google Account Identifier (
sub): A unique alphanumeric token used as your internal player account key. - Primary Email Address (
email): Used for security alerts, account verification, and account recovery notifications. - Display Name (
name): Used to suggest an initial in-game player handle (which you can change at any time). - Profile Picture URL (
picture): Used to display your player avatar in matchmaking lobbies, matches, and public leaderboards.
Rhythmio does not request, access, or store your Google account password, contacts, Google Drive files, calendar, or any sensitive Google Workspace data.
6.2 How We Use Google User Data
We process your Google user data solely to provide and improve user-facing features of Rhythmio, including:
- Authenticating your identity and establishing your session without storing passwords.
- Creating your player profile and displaying your avatar in multiplayer lobbies and leaderboards.
- Synchronizing your gameplay records, rating points (RP), and custom settings across devices.
We do not use Google user data for any purposes other than providing and improving these user-facing gaming features.
6.3 Prohibited Uses & Transfer Restrictions
In strict adherence to the Google API Services User Data Policy:
- No Data Sales: We do not sell, rent, lease, or trade Google user data to third parties, data brokers, or advertising networks.
- No Targeted Advertising: We do not use, transfer, or disclose Google user data for targeted advertising, personalized advertising, retargeting, interest-based advertising, user advertising, or creating marketing databases.
- No Credit or Lending Uses: We do not use Google user data for determining credit-worthiness or for lending purposes.
- No AI / ML Model Training: Google user data is not used to develop, improve, or train generalized machine learning (ML) or artificial intelligence (AI) models, including non-personalized AI/ML models.
- Third-Party Disclosures: We do not transfer or disclose Google user data to third parties, except to secure cloud infrastructure hosting providers (such as encrypted database hosting) strictly required to operate the service. All service providers are bound by strict data processing and confidentiality agreements.
6.4 Data Protection & Security Mechanisms
Security procedures are in place to protect the confidentiality, integrity, and security of your data:
- Encryption in Transit: All data exchanged between your browser and our servers is encrypted using industry-standard TLS 1.3 / HTTPS and WSS protocols.
- Encryption at Rest: Databases storing account tokens and profile identifiers are hosted in isolated private networks with AES-256 storage volume encryption.
- Access Controls: Access to production databases is strictly limited to authorized engineering personnel using multi-factor authentication (MFA) and least-privilege access controls.
6.5 Data Retention and Deletion
- Retention Period: We store your personal information for a period of time that is consistent with our operational business purposes. We retain your Google user data only for the length of time needed to fulfill the purposes outlined in this privacy policy while your account remains active.
- Account & Data Deletion: You may request the deletion of your personal data at any time:
- Submit an account deletion request through your in-game profile settings or by emailing
privacy@rhythmio.net. - When your account deletion request is processed, all associated Google user data—including email address, OAuth subject ID, display name, and avatar URL—is permanently deleted and destroyed from our active databases within 30 days.
- Submit an account deletion request through your in-game profile settings or by emailing
- Revoking Google Access: You can revoke Rhythmio’s access to your Google account at any time via Google Account Permissions.
6.6 Limited Use Compliance Statement
Rhythmio’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Data Retention & Account Deletion
7.1 Retention Period
We retain your personal account data for as long as your account remains active to provide continuous leaderboard standings and progression history.
7.2 Account Deletion (“Right to Erasure”)
You have the right to delete your account at any time:
- You can trigger an account deletion request through your profile settings or by contacting
privacy@rhythmio.net. - Upon deletion:
- All personal identifiers—including email address, OAuth tokens, avatar URL, and user handle—are permanently wiped from our active databases within 30 days.
- To maintain the integrity of public tournament brackets and historic leaderboard records, completed match outcomes and replays will be anonymized (attributed to an anonymous retired player ID) rather than corrupting past match histories.
8. Your Privacy Rights (GDPR, CCPA & International)
Depending on your country of residence (including the European Economic Area, United Kingdom, and California), you possess specific statutory rights regarding your personal information:
- Right of Access: You can request a copy of the personal data we store about you.
- Right to Rectification: You can correct or update inaccurate profile data.
- Right to Erasure: You can request the permanent deletion of your personal records.
- Right to Restrict Processing: You can request that we restrict processing under specific conditions.
- Right to Data Portability: You can request your data in a structured, commonly used, machine-readable format.
- Non-Discrimination: We will never discriminate against you for exercising your privacy rights.
To exercise any of these rights, please contact our team at privacy@rhythmio.net.
9. Security Safeguards
We implement modern, multi-layered technical and organizational security measures to protect your data:
- Encryption in Transit: All communication across
rhythmio.netandplay.rhythmio.netis encrypted using TLS 1.3 / HTTPS and WSS protocols. - Database Security: Databases are hosted in isolated private networks with encrypted storage volumes at rest and role-based access restrictions.
- Token Security: Session cookies are signed with strong cryptographic secrets and protected against cross-site scripting (XSS) and cross-site request forgery (CSRF).
10. Children’s Privacy
Rhythmio is not directed to children under 13 years of age (or under 16 within the EEA). We do not knowingly collect or solicit personal information from children. If we discover that we have inadvertently collected personal data from a minor without verifiable parental consent, we will immediately delete that information and suspend the associated account. If you believe a child has provided us with personal data, please contact privacy@rhythmio.net.
11. Policy Updates
We may revise this Privacy Policy periodically to reflect architectural updates, regulatory requirements, or feature releases. When revisions are made, the “Last Revised” date at the top of this document will be updated. We encourage players to review this page periodically to stay informed about our data protection practices.
12. Contact Information
If you have questions, concerns, or privacy requests regarding this Privacy Policy or our handling of your data, please contact us:
- Data Protection Inquiries:
privacy@rhythmio.net - General Support:
support@rhythmio.net - Discord Community: Discord Server