Pickkok

Privacy policy

Pickkok (pickkok.site) is a tournament service where you choose between image candidates to find your winner. This policy explains the personal data handled by the Pickkok administrator and the choices available to users.

1. Information processed when signing in

When you choose Google sign-in, Google provides your account identifier, email address, name, profile picture and email verification status. Supabase Auth uses this information, sign-in times and authentication session information to identify your account and keep you signed in. Pickkok does not receive your Google password.

Google sign-in requests only account identification, email and basic profile permissions. Sign-in information is used for account and session management, not advertising or marketing. You can play without signing in. Creating and saving tournaments requires sign-in.

2. Tournament and image storage

Tournament titles, descriptions, categories, candidate names and author account identifiers are stored in Supabase DB; candidate images are stored in Supabase Storage. During review, only the author and administrators can view submitted tournaments and images. They become public after approval. Authors may edit or delete content before its first approval, but not afterwards, even if it is unpublished. Review reasons and processing history are retained, and rejection reasons are shown to the author. Saves and signed-in users' completed plays are linked to their accounts for access on other devices. Copies of completed games and theme preferences may be stored in the browser.

In normal mode, the current bracket exists only in the play screen's memory and is not kept in browser storage. Streaming mode stores the host's account identifier, bracket and selections, participation codes and expiry times on the server for voting and automatic closing. Neither mode supports resuming after navigation, a refresh or closing the tab.

Authentication cookies keep you signed in, and Google Analytics cookies measure visits. Blocking cookies may prevent sign-in from persisting. Clearing site data removes browser copies and preferences, but does not delete tournaments, saves or completed plays stored in your account.

We use Google Analytics 4 (GA4), linked to Firebase, to understand and improve service usage. Without a separate consent banner, visits collect visitor and session identifiers, page types and view times, referring sites, browser and device information, approximate location and time spent. Analytics events do not include individual tournament or stream identifiers, search terms, URL queries or fragments, names, email addresses, signed-in account identifiers or form input. Google Signals and ad personalization are disabled.

GA4 user- and event-level data retention is set to two months, which differs from retention of aggregated reports. You can block or delete analytics cookies in your browser settings, or use Google's Analytics opt-out browser add-on. Blocking analytics does not prevent you from using tournaments. GA4 visit statistics are separate from tournament completion counts and rankings.

3. Retention and deletion

Saving a public tournament stores your signed-in account identifier, tournament identifier and save time in Supabase. Only you can see your saved list; others see only the total saves per tournament. Removing a save or deleting your account deletes the corresponding saved record.

Starting a public tournament prepares a tournament identifier and a random game identifier. After the final selection, the bracket is validated and play counts, candidate wins and match counts are aggregated. Public rankings show candidate totals, not accounts or individual choices. To prevent duplicate counting, game identifiers, tournaments, winners, starting rounds, completion times, match histories and result verification values are retained with the tournament's aggregates. Older browser-only tournaments are saved to the server only when the user chooses to import and submit them. Past browser completion records are not counted retroactively.

Streaming viewer votes store the account identifier, match identifier and chosen candidate in Supabase to enforce one vote per account. Hosts see only totals per candidate; other users' identities and individual votes are not disclosed. Once a match winner is confirmed, individual votes and the poll's candidate and winner information are deleted. Votes remain while a stopped or tied poll awaits a manual choice. Remaining votes are also deleted when the server detects the end of a stream or a disconnection. Ended codes retain only status information to prevent reuse and explain that voting has ended; choices and vote counts are not returned. Deleting a voter's account deletes their vote; deleting a host's account deletes that stream's progress and votes. Viewer votes do not count as tournament plays or personal completed plays.

Completing a public tournament that you started while signed in links the completed play to your account so that only you can view it on My Page. Personal records are retained while your account exists and deleted with your account. Candidate aggregates not linked to individuals are retained. Guest records and older records without account ownership are not automatically linked to a signed-in account.

Sign-in account information is retained while your account exists. You can review what will be deleted and delete your account at the bottom of My Page. Deletion removes account information, authentication sessions, saves and personal completed plays. Signing out alone does not delete your account.

After account deletion, submitted tournaments and candidate images retain their existing publication and review status, with author account and image ownership links removed. Total play counts, candidate rankings and completed results not linked to an account are retained. Signing up again does not automatically restore ownership of previous creations or personal completed plays. Content deletion requests can be sent to the contact below.

Browser-stored content and theme preferences remain in that browser until you delete them. Account deletion and clearing browser site data are separate actions. If you contact us, we process the email address and message needed to respond, then delete them once the inquiry has been resolved.

4. External services

  • Google: authentication of your chosen Google account and transfer of basic profile information; visit analytics through Firebase and Google Analytics. Analytics information is processed on Google's global infrastructure and may be processed outside your country. Google privacy policy
  • Supabase: storage and management of tournaments, candidates, images, author information, sign-in accounts, authentication sessions, saves, personal completed plays, public tournament play counts and rankings. Pickkok's Supabase project uses the Seoul region. Supabase privacy policy
  • Vercel: website hosting and server request processing. Vercel privacy policy

During authentication and website delivery, these services may process operational information such as IP addresses, browser information, request times and error logs. Information processed on external services' global infrastructure may be handled outside your country. Retention and protection of operational logs follow each service's policies.

5. Access, correction, deletion and inquiries

You can delete your account at the bottom of My Page. For requests to access, correct, delete or stop processing personal data, or if account deletion fails, use the contact below. We verify your identity to the extent needed to handle your request. You can also revoke Pickkok's access in your Google account's connected-app settings. Disconnecting Google alone does not delete an existing Pickkok account.

Privacy inquiries and data controller: Pickkok administrator
Email: whdtjr6889@gmail.com

6. Security and policy changes

Pickkok uses HTTPS and does not expose secret authentication keys in public code or users' browsers. When services or features that process personal data change, we will publish the changes and effective date on this page.

Effective date: October 3, 2026