Palworld OCG — Fanmade Simulator
Privacy Policy
Effective date: June 26, 2026 · Last updated: July 29, 2026
Summary: This is an unofficial fanmade simulator with free core gameplay and optional paid memberships for original analytical reports and service features. We collect the minimum data needed to run and improve the service: optional account data, match and tournament records, consent-based anonymous analytics, supporter access status, and pseudonymous human gameplay decisions used to develop a future computer opponent. The simulator does not collect payment-card information.
1. Who We Are
This website is an unofficial fanmade simulator for Palworld OCG, created and operated by Drakyr. Core gameplay is free; optional paid memberships provide access to original analytical reports and related service features. It is not affiliated with, sponsored by, or endorsed by Pocketpair, Inc. or the official Palworld card game publishers.
Contact: simonemarzorati.cc@gmail.com
2. Data We Collect
If you create an account (optional):
- Username — a nickname chosen by you. We recommend not using your real name.
- Password — stored exclusively as a cryptographic hash (PBKDF2-SHA256 with a random salt, 120,000 iterations). We never store your password in plain text and cannot recover it.
- Deck lists — card decks you save through the Deckbuilder.
- Friends list — usernames of players you add as friends.
- Match history and statistics — completed-match time, opponent username, mode, result, play order, final Life, turn count, mulligan use, end reason, Lucky Pals, and compact deck lists used by both players.
- Community Decklists activity — public/private deck visibility, likes, and an account-based or pseudonymous per-tab view key used to avoid counting the same deck view repeatedly.
- Optional Discord link — if you choose to connect Discord, we store your Discord user ID and username and use your server roles to synchronise supporter access. OAuth access tokens are used only during the linking request and are not stored.
- Supporter and tournament status — supporter access tier and tournament-win count associated with your simulator username.
We do NOT collect: email addresses, real names, dates of birth, IP addresses stored in the database, payment information, or device identifiers.
Anonymous analytics (only with your consent):
- We use Google Analytics 4 to understand how the simulator is used (e.g., how many matches are played, which features are popular).
- Analytics are loaded only after you accept cookies via the consent banner.
- All data sent to Google Analytics is anonymised — no usernames or personal identifiers are included in any analytics event.
Pseudonymous gameplay-learning data:
- During Scripted online, VS Bot, and Solo games, the simulator records human gameplay decisions to create a dataset for training and evaluating a future machine-learning computer opponent.
- Records can contain a random match/session identifier, game and card-catalog versions, game mode, turn and phase, acting player index, visible game state before and after the move, available controls, selected action, public log events, deck composition, and final match outcome.
- The dataset does not contain usernames, account identifiers, email addresses, chat messages, stored IP addresses, opponent hidden-hand identities, or deck order. The opponent's hidden hand is represented only by its card count.
- Only human actions from games using standard-legal decks are eligible for learning. Bot-generated actions, Tabletop choices, Tutorial choices, disconnected games, incomplete games, games without a final win or loss, and surrendered Solo/VS Bot games are excluded from training and readiness metrics.
- This first-party collection does not use advertising or analytics cookies and operates independently from Google Analytics consent.
3. How We Use Your Data
- To authenticate you and maintain your session (valid for 30 days).
- To store and synchronise your saved decks across devices.
- To enable social features (friends list, game invites, in-game chat).
- To provide match history, personal statistics, aggregated metagame reports, public Decklists, likes, and view counts.
- To compile aggregated simulator reports and provide membership-tier access to Meta Stats and Personal Stats.
- To link an account to Discord when requested and synchronise access associated with Discord server roles.
- To improve the simulator based on anonymous usage patterns (analytics).
- To train, validate, and measure a future machine-learning opponent using minimised, pseudonymous human gameplay records. No automated decision based on this dataset produces legal or similarly significant effects for players.
- To allow designated judge accounts to view and moderate live matches when requested (see Section 3a below).
We do not sell or rent account records, raw match histories, or personally identifiable information to subscribers. Paid members receive access to reports generated from aggregated simulator activity; they do not receive the underlying user database. Google receives consent-based analytics data as described above. The gameplay-learning dataset is stored by this site and is not sent to Google Analytics.
Chat and notifications: direct friend-chat messages are held temporarily in server memory (up to the latest 300 messages per conversation) and disappear when the server process restarts. Match chat is held with the live match state and is not copied into match history. Friend requests are stored until accepted or declined; game invites, alerts, presence, and judge calls are transient service data.
3b. Legal Basis for Gameplay-Learning Data
We process the minimised gameplay-learning records on the basis of our legitimate interest in improving the simulator and developing a more capable computer opponent. We limit this processing by excluding direct account identifiers, private communications, hidden opponent information, Tabletop choices, Tutorial choices, and bot-generated actions. You may object to this processing by contacting us using the address in Section 1.
3a. Judges and Match Moderation
A small number of trusted accounts are designated as judges by the site operator. Judge accounts have access to a "Spectate" feature that is not available to regular players:
- Judges can open the live board of any ongoing match in a read-only view — they cannot make moves, but they can see both players' cards in hand, field, graveyard, and exile, and the match's in-game chat and log.
- Judges can post messages into a match's in-game chat, visibly tagged with their username (e.g. "[Judge] username"), so both players know a moderator has joined the conversation.
- Any player can send a "Judge Call" during their match. This sends a notification to all judge accounts identifying the two players and the match involved, so a judge can step in.
This moderation access exists solely to resolve disputes and enforce fair play, and is limited to accounts explicitly granted judge status by the site operator. Judge activity (spectating, chat messages, dismissed judge calls) is not separately retained once the match ends.
4. Data Storage and Security
- Account data and the separate compressed gameplay-learning dataset are stored server-side and are accessible only to the server process and site operator.
- All passwords are hashed before storage and cannot be reversed.
- Sessions use cryptographically random tokens (256-bit) and expire automatically 30 days after login.
- The site is served over HTTPS in production environments.
Local game recovery: while a Solo or VS Bot game is active, one compact recovery snapshot is stored in your browser's IndexedDB so it can be resumed after a refresh or service restart. It is not uploaded to the server, contains no game log or chat, is replaced as play progresses, and is deleted when the game finishes or a new local game is started. You can also remove it by clearing this site's browser data.
5. Cookies
We use two types of cookies:
- paltcg_session — an authentication cookie set when you log in. It is
HttpOnly, SameSite=Lax, and expires after 30 days. This cookie is strictly necessary for the login feature and does not require consent.
- Google Analytics cookies (
_ga, _ga_*) — set only if you accept analytics via the cookie banner. These cookies collect anonymous usage data and are governed by Google's Privacy Policy.
When logged in, the current consent-policy version may be stored with your account so your choice can be restored after login if the browser clears local data. You can review or withdraw analytics consent at any time through Cookie preferences in Settings or use your browser's privacy controls. For full details on every cookie we use, see our Cookie Policy.
6. Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights:
- Right of access — you can request a copy of the data we hold about you.
- Right to rectification — you can contact us to correct inaccurate data.
- Right to erasure — you can delete your account at any time directly from the simulator's main menu. This permanently removes your account record, saved decks, likes, friend relationships/requests, match-history rows, Discord link, and active login sessions from our servers.
- Right to object — you can reject analytics cookies via the cookie banner at any time.
- Right to lodge a complaint — you can contact your local Data Protection Authority. For Italy: Garante per la protezione dei dati personali.
Gameplay-learning objection: You can contact us to object to this processing. Because the dataset deliberately excludes usernames and account identifiers, we may need relevant match/session information and may be unable to locate records that can no longer be linked to you.
To exercise any right not available through the in-app interface, contact us at simonemarzorati.cc@gmail.com.
7. Data Retention
- Account data is retained until you delete your account.
- Session tokens expire and are purged automatically after 30 days.
- Completed-match history and the statistics derived from it are retained with the account until account deletion. Aggregated metagame reports may incorporate other players' retained match records.
- Direct friend chat is memory-only and retained only until displaced by the 300-message conversation limit or until the server process restarts. Live match chat and transient invitations/notifications expire with their live server state.
- Gameplay decisions are first held in compressed per-session staging. Only standard-legal sessions ending in a win or loss are copied to the final learning dataset; disconnected, nonstandard, draw, abandoned, and other non-binary outcomes are deleted instead. Incomplete staging expires after 48 hours. Staging and final files share a rolling 900 MiB storage ceiling; after stale staging is removed, the oldest remaining files are deleted first when necessary.
- We reserve the right to delete accounts that have been inactive for more than 2 years.
8. Third-Party Services
- Google Analytics 4 — used for anonymous usage statistics with your consent. Google Privacy Policy · GA Opt-out
- Discord — contacted only when you choose to link or refresh Discord access, using Discord OAuth and guild membership/role APIs. Discord Privacy Policy
- Buy Me a Coffee — hosts optional support and membership checkout and processes recurring payments under its own terms and privacy policy. The simulator does not receive your payment-card details. Buy Me a Coffee Privacy Policy · Terms
9. Children
This service is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has created an account, please contact us for immediate deletion.
10. Changes to This Policy
We may update this policy as the service evolves. The effective date at the top of this page will reflect any changes. Continued use of the simulator after an update constitutes acceptance of the revised policy.
← Back to Simulator