Privacy
Updated 5 October 2026No ads, no tracking, no selling data.
Short version: if you never make an account, we store nothing about you. If you do, we store only what is listed here.
Without an account
Nothing is saved on our side. A Pokebox you build while signed out stays in your own browser (local storage) and never leaves your device. The offline feature keeps a copy of some pages in your browser cache. Clear your browser data to remove both.
With an account, we store
- Your email address (to log you in) and, if one is set, a display name.
- A bcrypt hash of your password. We never store or see the password itself.
- Your Pokebox: every Pokemon you add, with its level, IVs, moves, any nickname you give it, and your tags and favourite marks.
- Your saved parties (raid and Max Battle teams).
- The date the account was created, and the date you confirmed your email address (if you did).
- The invite code you signed up with, if you used one. Sign-up is open to everyone unless the owner switches it to invite-only; whenever a code is used we record which one, the email typed at sign-up and when. The owner of the site can see who joined with each code. If you delete your account the record keeps only that a code was used and the email typed, so the code's use count stays right.
- Your Pokebox extras: shiny, costume, background, Dynamax / Gigantamax and Max move levels, unlocked Mega forms with their Mega Levels, and the size class (XXS to XXL), when you set them.
- Your Pokedex marks: for each species and form you mark, whether it is registered, shiny, lucky, XXL, XXS, shadow or purified, and when you last changed it.
- Your theme choice (Light, Dark or Auto), when you pick one while signed in, so it follows you to other devices.
- Login cookies, only after you sign in or create an account (none of these are set before that):
authjs.session-token(a signed login token that keeps you signed in, about 30 days) andauthjs.callback-url(the page to return to after signing in, cleared when you close the browser). The sign-in library may also setauthjs.csrf-token(a safety token for its forms) on its own sign-in endpoints. All are essential, first-party and HttpOnly. There are no advertising or analytics cookies. - If you use Sign in with Google (optional): Google tells us your Google account ID, your email address and whether Google has verified it. We store the account ID and that email to link the sign-in to your PoGoBud account; we never receive your Google password or contacts, and we do not post anything to Google. While you are at Google, three short-lived security cookies prove the reply belongs to your browser:
authjs.pkce.code_verifier,authjs.stateandauthjs.callback-url(essential, first-party, HttpOnly, about 15 minutes). If you typed an invite code before pressing Continue with Google, it is kept for up to ten minutes inpogobud_google_invite(HttpOnly) and deleted once used. Deleting your account deletes the Google link; you can also remove PoGoBud's access at myaccount.google.com/permissions. - One preference cookie, signed in or not:
pogobud_themeholds only the theme you picked (light, dark or auto) so the page loads in that theme without a flash. It is set only when you choose a theme, holds nothing else, and is never used for tracking. - Sign-up and login throttling counters. To stop automated abuse we keep short-lived counters keyed by a one-way hash of your IP address and of the email typed. They cannot be turned back into an IP or email and expire within hours. Each sign-up form also carries a one-time code (stored the same hashed way, for at most two hours) so it cannot be replayed. Because of them, more than twenty sign-up attempts per hour from one connection, or five for one email, or ten wrong passwords in 15 minutes for one email, are refused for a while (the page tells you how long). The trade-off: someone who knows your email could lock it out of logging in for up to 15 minutes, but cannot get in.
- A typed-email cookie, only after a failed form. If a log-in, sign-up or reset form is refused, the email you typed is kept for ten minutes in an essential, HttpOnly cookie (
pogobud_typed_email) so the form can show it again; it is never put in the page address and is cleared when the form succeeds. A form refused only for being sent too quickly puts its own one-time form code (no personal data) in the page address so the next press works.
Features that store more, only when you use them
Email. Password-reset, email-confirmation and invite emails are sent through Resend, which receives the address and the message to deliver it. The links in those emails carry a random one-time token; we store only a one-way SHA-256 hash of it, with its expiry (one hour for a reset, 48 hours for a confirmation) and when it was used. No marketing email is ever sent.
Trainer profile. If you fill it in, we store your trainer name, level, team, friend code, start date, favourite Pokemon, medal tiers, city and country, and what you like to play, each with who can see it (only you by default). A field set to Anyone is shown on your public page /trainer/<name>, which only exists while your trainer name is shared with Anyone. Your email and account are never shown there. Your trainer level also sets the default attacker level on the raid counters.
Share links. When you create one, we store a random, unguessable token tied to your account, whether it shares your Pokebox or one saved party, any label you give it, when it was made, how many times it was opened and when it was last opened. Anyone who has the link can see a live, read-only view of that Pokebox or party (the Pokemon and their details, including nicknames). The view does not show your email or account. The page is not indexed by search engines. You can revoke a link at any time and it stops working at once; deleting your account removes every link too.
Push notifications. If you turn them on, we store what your browser gives us to reach it: its push endpoint address and the encryption keys that go with it, the server key it was registered under, the browser description (user agent) and when we last sent to it. We also store the bosses you follow and a record of which alerts were already sent, so you do not get the same one twice. Turn notifications off in your browser or the site and the subscription is removed; deleting your account removes all of it.
Feedback you send
Send feedback works with or without an account. When you send it we store: the kind (bug, idea or data is wrong), your message, the email address only if you type one (so we can reply; it is prefilled when you are signed in but you can clear it), the path of the page it was sent from (no query string), the app version, the time, and a screenshot only if you attach one (shrunk in your browser to a small JPEG and kept in our database, not on any third-party storage). Nothing else about you or your device is attached, and it is not linked to your account. The owner reads it in a private Inbox and is emailed a copy through Resend. Feedback stays until the owner has dealt with it; once marked done it is deleted after 90 days. To have yours deleted sooner, write to hello@pogobud.com. To stop automated abuse the form uses the same hashed, short-lived throttling counters and one-time form code described above (at most five sends an hour per connection).
Where it is kept
The site runs on Vercel, and the database is a Neon Postgres database. Like any host, Vercel keeps standard server logs (such as your IP address and the page requested). We do not sell, share or give your data to anyone else.
Once a day the whole database is copied into an encrypted backup, kept for 30 days in PoGoBud's private GitHub repository so your data can be recovered after an accident. An account you delete disappears from the live site immediately and from the backups when the last copy that still holds it expires, at most 30 days later.
Boss, event and Rocket schedules are read once a day by PoGoBud's own server from the official Pokemon GO news and a few public Pokemon GO schedule sites (credited on the licenses page, linked from About). Your browser never contacts those sites through PoGoBud, and nothing about you is sent to them.
Export and delete it yourself
On your account page you can download everything stored for you as one JSON file, change your password, or delete the account. Deleting removes your email, password hash, Pokebox, parties, trainer profile, Pokedex marks, theme choice, linked Google sign-in, email tokens, share links, followed bosses, push subscriptions and alert records permanently and immediately. The download also lists a linked Google sign-in (its email and when it was linked, never the Google account ID).
No tracking, no ads
There are no ads, no tracking pixels, no third-party analytics and no third-party scripts that follow you around. Your data is used only to run the features above.
To see which pages are used, PoGoBud counts page views itself: each page shown adds one to a counter for that page and day (for example “/raids, 5 October: 42”). Nothing about you goes with it: no cookie, no IP address, no account, no device or browser details, and the address is cut off before any “?”. Browsers that send Global Privacy Control or Do Not Track are not counted at all.
When a page breaks, the error message and the page it happened on are recorded so the bug can be fixed, after anything that looks like an email address, token or IP address has been removed. Error reports carry no account or device details either.
Questions
PoGoBud is a hobby project run by one person. If something here is unclear, ask whoever shared the link with you, or delete your account any time from the account page.