Back to player search

Privacy Policy

Effective date: September 22, 2026

Brawl Status KR does not collect personal information unnecessarily and processes only the minimum information needed to provide and improve the service.

Information we collect

  • The Brawl Stars player tag entered by the user
  • Public game profile and recent battle history retrieved through the official API
  • Basic access logs for service security and error response
  • Email address and inquiry content when a user sends an inquiry email

How we use information

  • Search player records and display recent battle history
  • Calculate accumulated win rates by brawler and recommendation statistics by map
  • Fix errors, prevent abusive requests, and improve service stability
  • Respond to inquiries and review feature improvements

Cookies and advertising

If account features are enabled, a session cookie required for authentication may be used after Google sign-in. If advertising services are provided, ad providers may use separate cookies or similar technologies; users can restrict or delete optional cookies in browser settings.

Third-party services

Brawl Stars API or an API proxy may be used to retrieve player information and battle history. External infrastructure such as Vercel and GitHub may be used to operate and deploy the site.

Owned-skin auxiliary lookup is disabled by default. Only when the operator explicitly enables it may the public player tag searched by the user be sent to Brawlace; Jina Reader is used after a direct lookup failure only if its fallback is separately enabled. When a full owned-skin lookup succeeds, the result may be cached in the same browser's localStorage for up to 24 hours; this cache is not used when the supplemental provider is disabled.

Catalog information for maps, modes, brawlers, and events is retrieved from BrawlAPI, and these requests do not send the player tag entered by the user. Some images, including brawlers, maps, and badges, are loaded remotely from the Brawlify CDN, so the user's browser may send image requests to that CDN.

Retention period

No automatic TTL deletion is currently applied. Battle history and statistical data are retained while the service operates to provide the service and maintain statistical quality, and may be deleted when the service ends, operational data is reset, or a verified record request is handled. Inquiry emails are retained for the period needed to handle the inquiry and respond to disputes.

Because ownership cannot be verified from a public player tag alone, automatic deletion is not provided. Requests concerning records are reviewed individually by the operator through the contact information below.

Contact

For privacy-related inquiries, contact seunghunbag76@gmail.com.

Optional accounts and Mini Game sync

Account features are disabled by default. If enabled, we process the private email address and Google subject returned for sign-in, an internal user ID, nickname, optional default player tag, session cookie, and Mini Game personal bests. Email and Google identity are not public. A default tag does not prove game-account ownership or authorize changes to battle records. Existing browser records are merged only after you choose import; queued records may be held in account-scoped browser storage. Google provides sign-in, and hosting and database providers may process data to operate the service. Account profile and cloud records are deleted from the active service database when an account deletion request is completed. Backup and deletion-manifest retention windows must be configured, and signed deletion manifests are reapplied during restore. Accounts remain disabled until the actual retention values are approved and disclosed. Public profiles and rankings are not part of this account feature. Google sign-in does not verify age or provide parental consent. Age and regional eligibility rules must be explicitly configured; we store only the user's eligibility attestation, not their date of birth or country. A parental-consent workflow is not currently supported. For request limits and abuse prevention, we also store short-lived HMAC hashes derived from account IDs and trusted request IP addresses. Rate-limit rows contain hashes rather than original values. Once a limit window ends, its row no longer affects request decisions; scheduled maintenance physically deletes expired rows, which may remain in the database until that job runs. Account features are available to users aged 16 or older in all countries. A guardian-consent process is not supported. Users who do not meet this requirement can still use guest features, including player search and Mini Games. Before Google sign-in, confirm that you meet these account requirements. Your date of birth and country of residence are not stored in the account database. The approved launch retention settings are 7 days for backups and 14 days for deletion manifests. Accounts will only be enabled after encrypted storage and expiry cleanup are configured and verified.