Player Data Manual
Privacy Notice
Effective and last updated: 14 September 2026
Who runs SnakeBit
Ramy Moussally operates SnakeBit personally from Lebanon and is responsible for deciding how the player data described here is used. Privacy questions and requests can be sent to ramymoussally@gmail.com.
Data the game handles
- Device and essential site data: browser session credentials, consent choices, onboarding progress, control and audio settings, theme choices, local best scores, cached career information, and pending submissions. Most of this stays in browser storage until it is cleared.
- Player identity: a random account identifier, arcade initials, a four-character public player code, an optional public display name, and—only if a player chooses Save Player or Restore Player—an email address and verification records.
- Gameplay and competition: scores, mode, theme, control method, run statistics, Daily Run attempts and input replays used to verify results, Live VS room membership and verified results, career totals, rival records, optional Podium Watch preferences and alerts, and optional verified-rival VS challenge calls, responses, expiry, and mute choices.
- Optional push notifications: if a player connects Signal Relay on a device, SnakeBit stores that device's browser push endpoint, encrypted push keys, limited browser/device details, connection status, and delivery records. A Podium Watch notification may show the rival's public name, game mode, and rank change; a VS challenge notification may show the verified rival's public name and selected public battle rules on the device lock screen.
- Technical operations: IP address, browser/device details, request times, and error or security information may be processed in ordinary hosting, authentication, and network logs.
- Optional product analytics: only after explicit opt-in, SnakeBit may send page visits, session information, mode selections and run starts/completions to Google Analytics 4, including mode, control method, theme, ranked status and broad score/duration bands. Google also receives normal device and network information, may derive approximate location, sets analytics cookies, and can generate first-visit, session and engagement events. This is pseudonymous measurement, not anonymous counting.
- Analytics choice records: this browser stores your latest independent audience-counting and Google choices, their times, notice version and measurement purposes, and whether you used the startup screen or a Player switch. A separate local marker remembers that you answered the startup screen. These records contain no player ID or GA client ID and are not sent to Google or to a consent-record server. They remain until replaced by another choice or you clear site data. Audience opening requests include the notice version, not the local choice records. Older unversioned or superseded on preferences do not activate measurement under this notice.
Why data is used
SnakeBit uses essential data to provide and secure the game, restore a player when requested, synchronize preferences and career statistics, operate public leaderboards and Daily/VS competition, verify results, prevent duplicate or abusive submissions, deliver opted-in Podium Watch alerts and verified-rival VS challenge calls, diagnose failures, and protect the service.
Optional analytics is used to understand traffic, mode popularity, run completion and broad engagement patterns so the game can be improved. It is not used for advertising or ad personalization. The initial custom-event scope excludes tutorial, detailed VS lifecycle, install and exception tracking.
The legal grounds are providing the game features a player requests, SnakeBit's legitimate interests in operating a safe and reliable competitive service, compliance with legal obligations where applicable, and consent for optional basic audience counting and Google Analytics. Consent can be refused or withdrawn without losing access to the game.
What other players can see
Leaderboard and player-card surfaces may publicly show arcade initials, player code, optional display name, scores, rank, selected theme/control category, Daily results, and related public competition statistics. Email addresses and internal account identifiers are not public. Live VS opponents receive the identity and match information needed to run the room.
Arcade Announcer
The Arcade Announcer uses reusable message templates generated in batches with Google's Gemini service. Gemini does not receive an individual player's identity, email, or career history. SnakeBit selects a template and inserts that player's statistics inside the browser; Supabase records limited message-impression history to reduce repetition.
Service providers and transfers
SnakeBit uses Supabase for authentication, database, realtime, and server functions; Contabo-hosted infrastructure to serve the game; browser and operating-system push services to route notifications to connected devices; and Google Analytics only for opted-in analytics. A push provider receives the device endpoint and encrypted notification needed to deliver the alert. Google Cloud and Gemini are used to generate general announcer templates, not to profile individual players. These providers process data under their own security and data-processing terms and may process it outside the player's country. Where required, contractual and other lawful transfer safeguards are used.
SnakeBit does not sell personal data. Data may also be disclosed when required by law or when reasonably necessary to protect players, the service, or legal rights.
For Google's explanation of its processing, see How Google uses information from sites or apps that use its services. SnakeBit disables advertising personalization and Google Signals for this analytics integration.
Country lookup and attribution: Where country lookup is used, SnakeBit uses a locally hosted database: IP Geolocation by DB-IP, licensed under CC BY 4.0. No visitor IP is sent to DB-IP for lookup.
How long data is kept
- Browser data remains until the player clears site data, changes a setting, or the game replaces an obsolete value.
- Player identity, career, leaderboard, Daily, and verified VS records are generally kept while the service operates or until a valid deletion request is completed, because they preserve player history and competitive integrity.
- After account deletion, public competitive records may be retained without the account link—including score and the public arcade identity shown when the result was earned—where needed to preserve fair historical standings.
- Temporary room, pending-event, and operational records are removed or expired when no longer needed. Security records may be kept longer when required to investigate abuse or comply with law.
- Push subscriptions are kept while Signal Relay remains connected on that device. They are disabled when the player disconnects the device or the push provider reports that the subscription is no longer valid, then removed after 30 days. Successful delivery records are removed after 30 days; failed or revoked delivery records are removed after 90 days for troubleshooting and abuse prevention.
- For opted-in Google Analytics, the selected GA4 retention settings are fourteen months for user-level data and two months for event-level data, with reset-on-new-activity enabled for user-level data. New activity renews the retention period for the user identifier, so regular activity can extend its retention beyond fourteen months from the first visit. Standard aggregated GA4 reports may remain available longer.
Player choices and rights
Podium Watch, VS Challenge Calls, and Signal Relay are off until the player opts in. Podium Watch and VS Challenge Calls are separate account-level preferences; Signal Relay is connected separately on each device and requests system notification permission only when Connect This Device is pressed. A player can disconnect that device, disable either topic, or mute and later unmute challenge calls from an individual verified rival. Notification permission can also be withdrawn in browser or device settings.
At startup, both optional measurement systems stay off until you choose. ALLOW BOTH & PLAY enables both; PLAY WITHOUT ANALYTICS leaves both off. Customize choices lets you enable either independently, with neither preselected. Your game works the same either way. We remember your choice on this browser or installed app. Clearing site data or a material notice change can show this screen again.
Google Analytics is optional. Where configured, Google stays off in every region, including unknown locations, until you affirmatively enable it at startup or under Player & Info → Player → Google Analytics. Turning this switch off refuses all Google measurement. Disabling it stops future collection and removes accessible SnakeBit GA cookies from that browser; it does not automatically erase earlier reporting. A Global Privacy Control signal also prevents Google measurement. If your choice cannot be saved, Google stays off for that page.
Basic audience counting also requires your explicit choice, including when country cannot be determined. It counts app openings, approximate country, approved source/campaign categories and browser versus installed-app mode. It does not store visitor IPs, player IDs or gameplay history in audience records, or join these counts to Google Analytics. Opening-only deduplication receipts become eligible for deletion after 48 hours and daily aggregates after 90 days; daily cleanup normally removes them within a further 24 hours, and a cleanup failure can delay removal. Turn off Allow basic audience counts in Player settings to withdraw; the choice is saved on that device and does not affect gameplay. Existing refusals and Global Privacy Control are respected. This is an independent control: choosing Google on or off does not change basic audience counting. Neither uses a regional default-on rule. The measurement notice version is 2026-09-14-startup-choice-v1.
Staging testing: When configured on staging.snakebit.io, first-party audience counting uses the same explicit startup or Player choice and records counts in a separate staging namespace, with the same fields and retention described above. A staging GA test build uses a separate Google Analytics QA property, only after explicit choice. It sends page views, session information, mode selections and banded run start/completion details, with debug reporting enabled. Google may also generate session and engagement events. Advertising features are disabled. A production-only build on staging sends no Google data. Turning Google Analytics off stops subsequent analytics collection independently of basic audience counts.
Depending on local law, a player may ask for access, correction, deletion, restriction, objection, or a portable copy of personal data, and may withdraw consent. Send the request to ramymoussally@gmail.com with enough information to locate and verify the player account. A player may also complain to their local data-protection authority.
Children
SnakeBit is not directed to children under 13, and SnakeBit does not knowingly request personal information from them. A parent or guardian who believes a child has provided personal information should contact SnakeBit so it can be reviewed and deleted where appropriate.
Notice changes
This notice may be updated when the game or its data practices change. Material changes will be dated here and, when appropriate, announced in the game. A changed contact email will be reflected on this page.