Privacy Policy
This Privacy Policy explains how Missroot (“we”, “us”, “our”) handles information when you play Please Stop the Rain (the “Game”) on Steam. The Game plays offline and keeps your progress on your own machine. One optional feature — Cloud sync, under Settings → Cloud — asks for an email address so the same progress can follow you to another machine. Everything below turns on whether you use it.
1. Summary
- The Game is playable start to finish without giving us anything.
- Cloud sync is opt-in. If you never sign in, the Game sends us nothing and we hold no data about you.
- If you do sign in, we hold your email address and your save record — and, beyond those, only the request logs our provider keeps (section 3).
- They are stored in the United States (see section 6).
- No analytics, no advertising, no tracking, and we never sell or share personal information.
2. What stays on your device
Whether or not you sign in, the Game writes to your own machine and we do not see any of it:
- The save record (
save.json) — stages cleared, best scores, kill and clear counts, playtime, daily-run results, pets, shop receipts, research notes. - Settings — volume, video options, key bindings, and the character and outfit you like. These are per-machine and are never synced.
- Cloud session — if you sign in, your sign-in tokens and the email you used are cached in the same per-machine settings store, so you stay signed in. Signing out deletes them from the machine.
If you enable Steam Cloud, Valve may also copy save.json
between your machines. That copy is between you and Steam under
Valve’s Privacy Policy;
it does not pass through us.
3. What Cloud sync stores
Signing in to Cloud sync creates an account for you on our backend. It holds:
- Your email address, plus the timestamps of your sign-ins. We use it to send the six-digit code and to recognise you next time. There is no password and we never ask for one.
- One copy of your save record — the same contents listed in section 2, stored as a single row and replaced each time you play. We keep no version history, though our provider’s routine database backups may hold a recent copy for a short while.
- Sign-in request logs, kept by our backend provider — the ordinary server-log metadata of a request, including the IP address it came from, so that abuse of the sign-in service can be blocked. We do not read these logs for any other purpose and they age out on the provider’s own schedule.
Beyond that: no name, no Steam ID, no record of how or when you play past what the save itself holds, and nothing you type outside the two sign-in fields.
4. Why we store it
Only to do the thing you asked for: carry your progress between your machines, and let you get it back if a machine dies. Under the GDPR the basis is performance of a contract with you (Art. 6(1)(b)) — you request the sync by signing in — and you can end it at any time by signing out and asking us to delete the record. We do not profile you and we make no automated decisions about you.
5. What we never collect
- No analytics, telemetry, crash reporting, or advertising SDKs in the Game.
- No advertising identifiers and no cross-app or cross-site tracking.
- No location, contacts, photos, microphone, or camera.
- No payment details — any purchase is handled by Steam, and we never see your card.
- We do not sell personal information, and we do not “share” it for cross-context behavioural advertising as those terms are used in California law.
6. Where it is stored, and who else touches it
We are based in South Korea, and the data described in section 3 is stored on our behalf in the United States (US West region). If you are in the EEA, the UK, or Korea, signing in transfers your email address and save record there — over an encrypted connection, at the moment you sign in and again each time the Game syncs. The recipient holds it for exactly as long as we do, which is until you ask us to delete it (section 9). The transfer happens because you asked for the sync, our providers are bound by their own data processing terms, and we pass your data to nobody else.
The companies involved, and nobody else:
- Supabase, Inc. — our processor, acting only on our instructions: it hosts the database and the sign-in service, and delivers the sign-in code by email. Reachable through its Supabase Privacy Policy.
- Valve Corporation — not our processor: Valve runs Steam on its own account, distributing the Game and, if you enable it, Steam Cloud. What it collects is governed by the Steam Privacy Policy.
- Cloudflare, Inc. — serves this website. Cloudflare Privacy Policy.
7. How long we keep it
Your email address and save record stay until you ask us to delete them — a save is only useful if it is still there years later, so we do not expire it. Signing out clears the session from that machine but leaves the record on the server, waiting for the next sign-in. To remove it, see section 9.
8. Your rights
Depending on where you live, you may have the right to access, correct, port, or delete your personal information, to withdraw consent where consent is what we relied on, to object to or restrict processing, and — in California — to know what we collect and to not be discriminated against for exercising these rights. We do not sell or share personal information, so there is nothing to opt out of.
To exercise any of them, email support@missroot.com from the address you signed in with — that is how we verify a request, since it is the only identifier your account has. We answer within 30 days. If you are in the EEA or the UK you may also complain to your local data protection authority; in Korea, to the Personal Information Protection Commission.
9. Deleting your data
On your machine: sign out under Settings → Cloud to clear the session, and delete the Game’s save folder (or uninstall the Game) to remove local progress.
On our server: email support@missroot.com from the address you signed in with and ask us to delete your account. We erase the email address and the save record together, within 30 days. The backups and request logs described in section 3 are not ours to erase by hand; they age out on our provider’s own schedule shortly after. The Game itself keeps working; it simply stops syncing.
10. Security
All traffic between the Game and our backend is encrypted in transit (HTTPS). Row-level security in the database means a save record can only ever be read or written by the account that owns it. Sign-in codes are single-use and short-lived. No system is perfect, but the data at stake is an email address and a list of stage clears.
11. Children
The Game is for a general audience and is not directed at children under 13, or under the higher age your own country sets — as much as 16 in parts of the EEA. The Game is sold only through Steam, whose Subscriber Agreement requires account holders to be at least 13. We do not knowingly collect personal information from children below the age that applies where they live; if you believe a child has signed in to Cloud sync, email us and we will delete the account.
12. Changes to this policy
If a future version adds anything that touches your data — purchases, leaderboards, analytics, or a different sign-in — we will update this page with a new effective date before that version ships, and say so in the patch notes.
13. Contact
Privacy questions, access requests, and deletion requests: support@missroot.com.
Personal information protection officer, as the Korean Personal Information Protection Act requires us to name one: Missroot, reachable at the email above.