Garix.io
Back to Garix
Legal

Privacy Policy

Last updated: September 25, 2026 · Terms of Service →
This describes what data Garix actually collects and why, based on how the game is built today — sign-in via Google/Discord, your game profile and Coins, the social layer (friends, leaderboard, notifications), purchases through Stripe or PayPal, and what stays only on your own device (replays, local settings). Where something depends on backend infrastructure we can't verify from the game client itself, we say so explicitly instead of guessing.
1. Overview 2. Information We Collect 3. Signing In (Google/Discord) 4. Avatar & Incognito Mode 5. How We Use It 6. Payments (Stripe & PayPal) 7. Cookies & Local Storage 8. Third-Party Services 9. How We Share Data 10. Data Retention 11. Security 12. Your Rights & Choices 13. Children's Privacy 14. International Users 15. Changes to This Policy 16. Contact
Read the Terms of Service →

1. Overview

This Privacy Policy explains what personal data Garix.io ("Garix", "we", "us") processes when you play, how, and why. It covers the game client, your account, purchases, and the social features (username, friends, leaderboard, notifications). It should be read together with our Terms of Service.

2. Information We Collect

Account & profile

  • From Google or Discord when you sign in: your name, email address, a numeric provider account ID, and a profile picture URL. See §3.
  • Created by you in Garix: a public username (free, unique, one change allowed ever), optional paid custom nicknames, your team-color choice, and your uploaded skin images (see our Terms, §6).
  • Generated by playing: your level, XP, Coins balance, owned/pending skins, active boosts, and (if you were ever banned) a ban status and reason.

Social & activity data

  • Your friends list, pending friend requests (sent and received), and players you've blocked;
  • Your position on the public XP leaderboard;
  • In-app notifications (e.g. a friend request, a skin being approved, a coin transfer) — see §10 for how long these are kept;
  • Coin transfers you send or receive from friends (amount, timestamp, counterparty).

Purchase data

  • A record that you made a purchase (item, amount, coins granted, timestamp) — not your card number, which we never receive. See §6.

Technical & connection data

Like any online multiplayer game, our game servers necessarily see the IP address of every connection (for the WebSocket game connection itself, and for API requests to the account backend) — this is a baseline fact of running the service, used at least for abuse/cheat prevention and basic rate-limiting. We don't have visibility from the game client into exactly what server-side connection logs are kept or for how long; that should be confirmed and documented here by whoever operates the backend, rather than us describing specifics we can't verify.

What stays on your device only

Some data never reaches Garix's servers at all — see §7 for the technical detail:

Replays you record are saved entirely in your own browser's local storage (IndexedDB) — Garix never uploads, sees, or has access to your replay recordings. Deleting them from your library, or clearing your browser's site data, deletes them for good.

3. Signing In With Google or Discord

Garix doesn't have its own password system — you always sign in through Google or Discord's OAuth flow. We only request the minimum scope needed to identify you (basic profile info and email); we never see or store your Google/Discord password, and we don't get any ability to post, message, or act on your behalf on those platforms. After you sign in, we issue our own session token (a JWT, valid up to 7 days) that your browser sends back to us on later requests — see §7 for where that token lives.

4. Avatar Visibility ("Incognito Mode")

Your avatar (the profile picture pulled from Google/Discord at sign-in) is shown to other players in the leaderboard, friends list, friend requests, search results, and your public profile. You can hide it from everyone else at any time by clicking your own avatar — while hidden, other players see a generic placeholder instead, wherever your avatar would otherwise appear. This setting only affects what other players see:

Your own account view always shows your real avatar to you, regardless of this setting — "incognito" hides it from others, it doesn't delete or stop us from having it.

5. How We Use This Information

  • To create and operate your account, and let you play matches;
  • To run the social features you choose to use — friends, the leaderboard, notifications, coin transfers between friends;
  • To process purchases and credit the correct Coins to your account;
  • To moderate content (uploaded skins, usernames, nicknames) and enforce our Terms of Service, including investigating abuse, cheating, and ban appeals;
  • To keep the Service secure and functioning (rate limits, fraud/abuse prevention on coin transfers and purchases, debugging technical issues).

We do not use your data for third-party advertising, and — based on what's actually loaded by the game client today — we don't run third-party analytics or ad-tracking scripts. If that ever changes, this Policy will be updated to say so (see §15) before it does.

6. Payments (Stripe & PayPal)

Real-money purchases (Coin packages, the Starter Pack) are handled by one of two third-party payment processors, whichever you pick at checkout:

  • Stripe, a PCI-compliant payment processor. When you pay with Stripe, Garix opens Stripe's own hosted checkout page in a popup, and you enter your card details directly into Stripe's page, not ours.
  • PayPal. When you pay with PayPal, you log in and approve the payment in PayPal's own window. Garix never sees your PayPal login or the card or bank account linked to it.

Either way, Garix's servers receive back only what's needed to credit your purchase: a confirmation that the payment went through, its amount, and the processor's order or payment reference. We never receive your full card number. Each processor handles your payment information under its own privacy policy, linked above.

The PayPal button in the Shop is loaded from PayPal's servers, but only when you open the Coins section of the Shop. Once it loads, PayPal receives the standard technical data any embedded script does (such as your IP address and browser user-agent), under PayPal's own policy.

7. Cookies, Local Storage & Similar Technologies

Garix doesn't use tracking or advertising cookies. It does use your browser's built-in storage, entirely for making the game itself work:

  • localStorage — your session token (so you don't have to sign in every visit), and your local game/UI preferences (graphics, camera, chat, HUD, hotkeys, and similar settings), which are never sent to us — they configure your own client;
  • IndexedDB — your recorded replays (see §2), stored and played back entirely on your device.

Clearing your browser's site data for Garix removes all of this — including signing you out and deleting any local replays.

8. Third-Party Services

To load and run, the Garix client requests resources from a handful of third-party providers:

  • Google Fonts (fonts.googleapis.com/fonts.gstatic.com) — serves the typefaces used in the interface;
  • jsDelivr, cdnjs, and BootstrapCDN — serve a few open-source JavaScript libraries the client depends on (e.g. the Pixi.js rendering engine, jQuery, Bootstrap, toastr notifications).

Loading a resource from any of these providers exposes basic request metadata (like your IP address and browser user-agent) to that provider, the same way it would for any website embedding a font or script from a public CDN — subject to their own privacy policies, not ours. We chose these specifically because they don't require an API key or account tied to you, and as far as we can determine, none of them are used by Garix for tracking or advertising purposes.

Beyond that, see §3 (Google/Discord sign-in) and §6 (Stripe and PayPal) for the providers that do receive data about you directly, as part of using their service.

9. How We Share Data

We don't sell your personal data. We share it only as needed to run the parts of the Service described above:

  • With Google/Discord, as part of the OAuth sign-in flow itself (they already have this data — we're the recipient, not the sender, in this relationship);
  • With Stripe or PayPal (whichever you choose), to process a purchase you initiate;
  • With other players, for the information that's inherently public in a social/multiplayer game by design: your username, level, XP, leaderboard rank, in-match chat messages, and your avatar (unless hidden — see §4);
  • If required by law, subpoena, or a good-faith belief that it's necessary to protect the rights, safety, or property of Garix, our players, or the public.

10. Data Retention

  • Notifications are automatically deleted 14 days after creation — this is an actual scheduled backend job, not a placeholder.
  • Replays live only in your own browser (§2, §7) until you delete them or clear site data — we hold none server-side.
  • Account, profile, and purchase records are kept for as long as your account exists, so the game and your purchase history keep working correctly.
Retention periods for raw connection/server logs, and how long data is kept after you request account deletion (§12), are backend operational decisions this document can't responsibly invent — [server log & post-deletion retention windows — to be provided by whoever operates the backend].

11. Security

We use industry-standard measures appropriate to the data involved — for example, authenticated API access via short-lived session tokens rather than storing passwords ourselves (we never have your Google/Discord password to begin with), and delegating payment-data handling entirely to Stripe and PayPal rather than touching it ourselves. No online service can guarantee perfect security; if you believe your account or data has been compromised, contact us (§16) right away.

12. Your Rights & Choices

  • Access & correction — most of your account data (username, nickname colors, skins, settings) is directly visible and editable in the game itself;
  • Avatar visibility — toggle "incognito" any time, see §4;
  • Friends & blocking — remove a friend or block a player any time, from the Friends panel;
  • Deletion — request deletion of your account and associated data by contacting us (§16).
There's currently no self-service "delete my account" button in the client — deletion requests have to go through manual contact (§16) rather than an in-app flow. If Garix serves players in regions with a formal legal right to access/export/delete data (e.g. GDPR, CCPA), a self-service flow and a defined response-time commitment should be built and documented here rather than assumed.

13. Children's Privacy

Garix is intended for users aged 13 and older (see our Terms, §2) and we don't knowingly collect personal data from children under that age. If you believe a child has created an account or provided us data in violation of this, contact us (§16) so we can remove it.

14. International Users

Where Garix's servers and data are actually hosted (and therefore which country's law and which cross-border-transfer safeguards apply, e.g. EU Standard Contractual Clauses) is backend infrastructure information not visible from the game client — [hosting region / cross-border transfer basis — to be provided by the operator].

15. Changes to This Policy

We may update this Policy as Garix's features change — for example, when a new feature starts collecting a new kind of data. We'll update the "Last updated" date above when we do. Material changes affecting how we use previously collected data will be called out clearly, not buried in a routine update.

16. Contact

For privacy questions, data requests, or anything in this Policy, email us at support@garix.io.

You can also reach us through our official Discord server. For formal data requests, please use email.

If a Data Protection Officer is legally required given where Garix operates, their contact details should be added here too.
© 2026 Garix.io · Terms of Service · Back to the game