Skip to content

Privacy Policy

Last updated September 22, 2026

This policy explains what packs.haruhime.moe collects, why, and what stays on your own device.

What we store

Only if you sign in with osu!:

  • your osu! user ID, username, avatar URL, and country, which osu! sends us when you sign in;
  • session records that keep you signed in;
  • packs you choose to save: the pack name, beatmap IDs, slot layout, visibility, and any export links you choose to record on a pack (for example a Google Drive folder link or a magnet link).

If you don't sign in, we don't keep an account or any profile about you. Our host (Vercel) keeps standard request logs, such as IP address and browser type, for security and operations.

What we never store

  • Files. No beatmaps, audio, images, or videos ever pass through or rest on our servers.
  • Google and Microsoft access tokens. When you upload to Google Drive or OneDrive, the sign-in happens in your browser and the token lives only in that browser tab. Tokens are never sent to our servers.
  • The contents of your Drive or OneDrive.

Google user data

The Google Drive export requests only the drive.file scope, which lets the service see and manage files it creates for you and nothing else in your Drive. We use it only to create the pack folder, upload files you selected, and set the sharing link you asked for. Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We don't transfer, sell, or use Google user data for advertising, and no person at our end reads it.

Requests your browser makes to others

When you build or export a pack, your browser requests beatmap data and files directly from the beatmap mirror (mirror.hinamizawa.ai) and cover images from osu!'s CDN (assets.ppy.sh). Those services see your IP address and browser details, under their own policies. When you upload to Google Drive or OneDrive, your browser talks directly to Google or Microsoft.

Data on your device

Pack drafts are kept in your browser's IndexedDB, and downloaded beatmap files are cached in your browser's private file storage so a second export doesn't download everything again. This data stays on your device. You can delete it anytime with the "clear local data" button or by clearing site data in your browser.

Service providers

  • Vercel hosts the website and runs its server functions.
  • MongoDB Atlas stores the account and pack data listed above.
  • osu! (ppy Pty Ltd) handles sign-in.

We don't use analytics or advertising trackers, and we don't sell personal data.

Deleting your data

You can delete your account from your account page. That deletes your user record, sessions, linked osu! account record, and every pack you saved. You can also email us to ask for deletion.

Changes

We may update this policy. The "last updated" date above changes when we do.

Contact

contact@haruhime.moe