PRIVACY
Privacy notice
This notice explains what the Stock Pocks game and this website collect, why, how long we keep it and what you can do about it. We have kept it short and plain.
Last updated: 3 October 2026
The short version
- The game is free. We do not sell your data, show ads or use tracking cookies. We count visits to this website from our own server logs, with IP addresses shortened, and delete those logs after 14 days.
- We collect what we need to run your account and the game, and nothing for marketing.
- On a Walk, your device sends your precise position and speed to our server so the game can check you are moving. The server keeps at most the latest one, in memory, for up to 30 seconds, and never saves it or your route.
- Street map tiles load through our own server, which never passes on your IP address. Camera features are optional and run on your device: camera pictures are never uploaded.
- You can download your data in the game and ask us to delete your account.
- Stock Pocks is for players aged 18 and over.
Who we are and how to reach us
Stock Pocks is run by the Stock Pocks game operator ("we" or "us"). We decide how the personal data described here is used.
For a general privacy question, ask in the official Stock Pocks Telegram channel. For a request about your own data, send a private /bug report to @stockpocksbot on Telegram. See the support page for how. Role mailbox: info@stockpocks.com, which is forwarded to our team; for account and data requests, send a private /bug report to @stockpocksbot on Telegram with your Request reference, so we can check the request is yours.
Staff never message you first. We will never ask for your recovery code, an AI helper access key, a password or a wallet recovery phrase.
What we collect and why
Your account
- The display name you choose, and the names you give your Pocks.
- Your recovery code, stored only as a one-way hash. We never keep the code itself, so we cannot show it to you again or restore it.
- Sign-in sessions: up to 5 at a time. A session stays open while you use it at least once every 30 days, and ends 90 days after you signed in at the latest.
- The time you confirmed you are old enough to play.
- If you choose to sign in with a crypto wallet: its public address, linked to your account. An account created that way is opened again by signing with the same wallet. We never ask for or store private keys or recovery phrases, and every payment feature is switched off.
- Requests you record under Your account, such as a request to delete your account, with their reference and status.
Why: to create your account, keep you signed in, let you get back in and handle your requests.
Your play
- Your Practice Pock and its care, Roam chapters (without coordinates), journal entries, discoveries, keepsakes, story cards and any crew contributions.
- Build briefs you take and the work you submit, and World contributions that are accepted.
- Points and leaderboard entries.
Why: this is the game. Without it we cannot save your progress.
Support and bug reports
What you send us through our Telegram bot or post in our Telegram channel. If you use our Telegram bot: your Telegram user and chat IDs, the text of a bug report while you write it, and the reports you confirm with their review status. If you email info@stockpocks.com, your message, your email address and anything you attach are forwarded to our team and kept for 30 days. Why: to help you and fix problems. Wallet requests in the bot are closed. Wallet requests sent before they closed (the wallet address and network you gave, and when you agreed) stay private to the owner until they are closed or you erase them, and a closed request is deleted 30 days after it closes. They do not put a wallet on the Genesis spot list.
Technical data and logs
When your browser talks to the game or this website, our servers and hosting providers see your IP address and basic request details such as the time, the address requested, the result and your browser type. We use them to deliver pages, keep the service secure and stop abuse, for example by limiting how many accounts can be created from one network. To stop one person taking many accounts, each sign-up leaves a scrambled network code: a one-way code of the network it came from (an IPv4 address, or the network part of an IPv6 address), made with a salt that changes every UTC day, never the IP address itself. The daily salt is deleted after 2 days and the codes after 30 days. We use them only for the sign-up limits per network and to review farming, and they are not in your data export. Other rate-limit counters are held in memory only. Server and security logs are kept for 14 days once log rotation is in place (by 31 October 2026); until then, some logs may be kept longer.
We also count visits in total from these logs: how many pages were viewed, which pages, which sites sent visitors, and the rough type of device and browser. This covers stockpocks.com and genesis.stockpocks.com. Before anything is written to the log, the last part of your IP address is removed, and cookies, sign-in details, the code in a share link and anything after a "?" in the address are never logged. We only look at totals, never at one visitor, and the logs are deleted after 14 days.
Plaza is switched off
The in-game Plaza (chat) is off, so we collect no chat messages. If we ever switch it on, we will update this notice first.
Roam and your location
- Studio needs no location. You can play Roam at home without sharing where you are.
- Walk uses your location only while a Walk is open, and only after you allow it in your browser.
- Your precise position goes to our server while a Walk is open. Your device reads your location as precisely as it can and sends your recent positions, their accuracy and your speed to our server, so the game can check that you are moving. The map trail you see is drawn on your device and is not kept after the Walk.
- What the server keeps, and for how long. The server holds at most one position per open Walk, in memory only, and erases it after 30 seconds and whenever you pause or finish. Positions are never written to our database, logs, backups or your data export. The server stores only totals such as time, distance and counts.
- Roam records (without any coordinates) stay private to your account for up to 30 days and 30 outings. Roam reward records keep only the day, the Pock, who played it (you or your helper) and the counts, and stay while your account exists. Keepsakes and story cards you keep stay with your account.
- Street map tiles. During a Walk, streets are on by default and you can switch them off. Your browser loads the tiles through play.stockpocks.com. Our server fetches each tile on your behalf from Geoapify, an EU-hosted map tile service, or, as a backup, from the OpenStreetMap Foundation's tile service, under our own account and identification. It never passes on your IP address, cookies, account or route, and keeps no record of which squares you viewed. Geoapify and the Foundation see only which tiles our server requested (the approximate area shown), under their own privacy policies. Our server keeps a copy of each tile for about 7 days, so each tile is fetched about once a week, and it limits how fast tiles are requested. Map data © OpenStreetMap contributors.
- Pock World. The Pock World map look is worked out on your device from the map squares on screen. Nothing about it is sent.
Camera, 3D and Snap it
- The camera is optional. Your browser asks for camera permission separately from location, and you can refuse it or withdraw it at any time in your browser settings.
- Walk with your Pock and the discovery camera show your Pock over the camera picture, inside your browser only. Camera images are never recorded, stored, uploaded or sent to anyone. The camera stops when you leave the page, turn it off, or move faster than walking pace.
- 3D and AR. 3D Pock files load from our own site. AR runs in your browser or headset, which shows the camera picture itself: the game never receives those images and records nothing. On an iPhone, "view in your room" opens Apple's own Quick Look viewer. Glasses mode uses no camera.
- Snap it. On a Walk, a discovery can offer Snap it. If you see one of the everyday things it names nearby, you can snap it from where you are. Recognition runs on this device: only "spotted" and the kind of thing are sent, never the picture. Skipping is always fine. Before its first use, Snap it asks you to download its recognition files (about 6 MB) from the game's own site, and your browser may keep them for next time. It looks at one camera picture only when you tap Snap, and it refuses pictures with people, vehicles or road signs in view.
- Snaps on your Roam card. If you keep a snap for today's Roam card, a small crop around the object is kept on this device only, never uploaded, and deleted at the end of the UTC day. You see each snap before you share the card and can remove it.
Share your Roam and Genesis spots
This applies only while the Share your Roam campaign is open in the game, and only if you take part.
- Share cards are made on your device. A card shows your Pock, the discoveries you kept, any snaps you kept for it, a softened, turned shape of your walk (or a doodle instead) and your share code. The shape is drawn on your device from the Walk's trail, with the start and end cut off; only the shape is kept for the card, never the points. A card never shows a map, street names, distance, coordinates, the time of day or your account ID. A distinctive walk shape could in theory still be matched to a map, so you can switch to the doodle before you share. We don't receive the card image, and nothing is posted for you.
- If you ask for a Genesis spot (X posts only), we keep your share code, the link to your public post, the X account name on that post, the request's status and how it was checked, the rules version you agreed to, and the wallet you choose from the wallets linked to your account, with the result of an automatic check of that wallet's public record. We use them to run the campaign and the Genesis spot list.
- Checking a post. To check an X post, our server asks X's public embed service about that post link. Your IP address is not sent, and X's answer is not kept. Posts the automatic check cannot settle are reviewed by staff in a private Telegram chat that shows the post link, the X account name and your share code. Telegram handles those messages under its own terms.
- Network codes. To stop one person taking many spots, each post check and each request leaves a scrambled network code: a one-way code of the network it came from, made with a salt kept for this campaign only, never the IP address itself. We use them only for the limits per network and to review farming. They are deleted when the campaign closes, they are not in your data export, and deleting your account unlinks them from it.
- What we never keep: the card image, your caption or post text, your IP address itself (only the scrambled network code) or your location.
- The published list. When the Genesis spot list is fixed, every wallet address on it is published in full, with the list's SHA-256 checksum (see What other players can see). Social account names and game accounts are never published.
- Share codes can be renewed at any time on the Share page in the game. Links of the form stockpocks.com/r/ followed by a share code open one fixed page on this website, which does not look the code up and keeps no record of it; its Play free link passes the code on to the game (see Referrals below).
- Referrals. If you open the game from a player's share link, the game keeps that share code in your browser tab for up to 2 hours (not in a cookie) and sends it when you create an account there. We then store the code with your new account, together with which player it belongs to. This is set once, when the account is created, and never changed; it is never added to an account that already exists. We use it only to count that player's referrals, which order the Genesis spot list when it is fixed. A referral counts only if your own share claim is accepted. To check that a referral is a different person, we compare your account's linked wallets and X account names with theirs, and one-way network codes of your sign-up, claim and post checks (never your IP address) with those of their share claim and post checks, and of their sign-up on the same day, and staff may review and leave out a referral that looks like one person using more than one account. The game does not show the other player who signed up with their code.
AI helpers
- An AI helper is optional. You choose the AI service and connect it with an access key you create.
- A helper can read the parts of your game you allow, such as journal, Roam and care details. By default it prepares drafts for you to approve. If you allow it, it can also act for you directly: feed or rename your Pock, play Studio Roam or send Build work automatically. Build work it sends is labelled as sent by your helper.
- What the helper reads and writes goes to the AI service you chose, under its own terms and privacy policy. We do not choose or control that service.
- We store each grant: the access key as a one-way hash, what it may do, when it was created and last used, and its expiry (at most 90 days). You can have up to 10 active helpers and can pause or revoke any of them at any time.
- We also store each helper's settings (the Pock it helps, its voice, behaviour and chattiness, its jobs, whether it may send automatically, when it may act, its daily draft limit, quiet hours and time zone, and earlier versions of these settings), the drafts it leaves in your Drafts tray, and records of what it did. The helper's diary in the game is built from those records; nothing in the diary is written by an AI.
- Helpers never get payment powers, never control a live Walk and never see your recovery code.
What other players can see
- The name shown on the leaderboard, and your points.
- Build work and World contributions that are accepted, with a maker's mark that can show your display name and whether your helper sent it or helped with it. World content also carries the account ID of its author.
- The Genesis spot list, if your wallet is on it. If a wallet linked to your account gets a Genesis spot (from sharing your Roam, or as a tester), its public address is published in the full list of spot wallets, sorted by address, with the list's SHA-256 checksum so anyone can check it. Social handles, display names and account IDs are never published in it. Once the list is fixed, a published address stays in it.
- Nothing else from your account, your journal or your Roam records. Plaza (chat) is off, so there are no messages to see.
Cookies and storage on your device
- Game: one strictly necessary sign-in cookie (plus a short-lived one while a wallet sign-in is in progress). Your browser's local storage keeps small settings and actions that have not been sent yet. If you use Snap it, your browser also keeps its downloaded recognition files, and snaps you keep for today's Roam card stay on this device until the end of the UTC day.
- This website: no cookies of our own. Our hosting provider may set a strictly necessary security cookie to block automated abuse.
- There are no advertising or analytics cookies, so there is nothing to consent to. If that ever changes, we will ask first.
Who else handles data
We do not sell your personal data and we do not share it for advertising. Some services handle data for us or alongside us:
- the company that hosts the game server, and the company that hosts this website and its content delivery network;
- Geoapify, an EU-hosted map tile service, and, as its backup, the OpenStreetMap Foundation's tile service: both receive street map tile requests from our server only, never your IP address;
- the public IPFS gateway ipfs.io: when the game shows the art of a Genesis Pock, your browser loads that image from ipfs.io, which sees your IP address and the image requested, under its own terms;
- X's public embed service, which our server asks about the post links given for Genesis spots, without your IP address;
- our domain's email forwarding service, which passes email sent to info@stockpocks.com on to our team;
- Telegram, when you use our bot or channel to contact us, and for the private staff chat that reviews Genesis spot posts, under its own terms;
- the AI service you choose for an AI helper.
We may also share data if the law requires it, or to protect players and the service from harm.
How long we keep things
- Account and game records: while your account is in use. We will delete accounts that have not been used for 12 months.
- Sign-in sessions: 30 days after last use, 90 days at most. AI helper grants: until you revoke them or they expire (at most 90 days). AI helper settings, drafts and activity records: while your account exists.
- Email to info@stockpocks.com: 30 days.
- Sign-up network codes: 30 days, with their daily salt deleted after 2 days. They are never the IP address itself.
- Roam records: up to 30 days and 30 outings. Roam reward records (only the day, the Pock, who played it and the counts): while your account exists. Walk positions: never stored; at most 30 seconds in memory.
- Server and security logs: 14 days, once log rotation is in place (by 31 October 2026). Until then, some logs may be kept longer.
- Website visit logs: 14 days.
- Backups of the game and of our Telegram bot: 30 days, once automatic expiry is in place (by 31 October 2026). Until then, backups may be kept longer. Deleted data can stay in a backup until that backup expires.
- Bug reports in the Telegram bot: open reports until they are dealt with. Closed reports, and drafts you stop writing, are deleted 30 days after their last change. You can delete yours at any time with /erase_confirm. The bot also keeps a count of your submissions for 24 hours to stop floods. Older wallet requests stay private to the owner until they are closed or erased, and are deleted 30 days after they close.
- Share your Roam: requests that are turned down or withdrawn are deleted 30 days after the decision. When the campaign closes, post links and X account names are removed 90 days later; share codes, entries and list results are deleted 90 days later; and audit records, which hold no post or account names, 180 days later. Staff review messages in the bot are deleted 30 days after the decision. Network codes from post checks and requests, and their campaign salt, are deleted when the campaign closes. Referral records (the code an account was created with and whose it is, and the referral counts fixed with the list) are deleted with the other campaign records 90 days after the campaign closes, or earlier when either account is deleted; the network code of a sign-up made with a share code is deleted when the campaign closes. If you delete your account, its campaign records are deleted too (a deletion asked for while the list is being fixed is done once the list has been exported), but a wallet address that is already on the fixed Genesis spot list stays on the published list and in the fixed list files.
Your choices and rights
- Download your data: in the game, under Your account.
- Delete your account: in the game, open Your account and record a deletion request. Then send a private /bug report to @stockpocksbot on Telegram and paste the Request reference the game shows. That reference is how we find your account and know the request is yours; we never delete an account on a display name alone. We handle deletion by hand within 30 days. Copies in backups are deleted when those backups expire.
- Fix something: you can rename a Pock you have in the game. For anything else, send /bug to @stockpocksbot.
- Depending on where you live, you may also have rights to access, correct, object to or restrict how we use your data, and to complain to your data protection authority. Ask us first and we will try to help.
Children and minimum age
Stock Pocks is for players aged 18 and over. Every sign-up asks you to confirm your age. We do not knowingly collect data from anyone younger. If we learn that an account belongs to someone under that age, we delete it. If you are a parent or guardian and think your child has an account, send /bug to @stockpocksbot and we will remove it once we can identify it.
Keeping your account safe
Recovery codes and AI helper access keys are stored only as one-way hashes, and sign-in cookies cannot be read by page scripts. Because we never keep your recovery code, we cannot restore a lost one. Keep it somewhere private, and never share it with anyone, including people who say they are staff.
No payment details
Stock Pocks is free to play, and we collect no payment details, bank details or identity documents.
Changes to this notice
If we change how we handle data, we will update this page and say so on our Telegram channel before the change applies.