Privacy Policy
Last updated: September 29, 2026
This Privacy Policy explains what information watermelonuniverse.com (the "Site") collects, how it is used, and who it is shared with. This Site is not directed at anyone under 18 years old, and we do not knowingly collect information from minors.
1. Information We Collect
We collect information in a few ways:
- Analytics events. We use PostHog to capture pageviews, clicks (such as download buttons and outbound links), and the outcome of download requests (granted, denied, or failed, including a failure reason, step, and HTTP status where relevant). These events include the page URL, referrer, UTM parameters, and an anonymous session identifier.
- Download requests. When you request a game download, our API validates the request and, if approved, issues a time-limited signed URL to the file (hosted on Cloudflare R2). We log the outcome of that request (granted/denied/failed) in analytics, but we do not need — and do not intentionally collect — payment information for this flow.
- Patreon sign-in. If you choose to sign in with Patreon, we receive your Patreon user ID, name, email address, profile image, and current membership/tier status from Patreon via OAuth. We use this to identify you, unlock patron-gated content, and attribute your analytics events to your account instead of an anonymous visitor.
2. Cookies and Local Storage
When you first visit the Site, a banner asks whether you accept or decline analytics cookies. Until you choose — and if you choose Decline — analytics run in a light, anonymous mode: PostHog is loaded only to count pageviews, kept in your browser's memory rather than a cookie or local storage, and reset every time you load a page. In this mode we do not set a long-lived analytics cookie, do not run session replay, heatmaps, autocapture, or exception tracking, and do not build a profile of you. If you click Accept, PostHog switches to the full stack described below, starting from a brand-new anonymous ID rather than carrying over anything from the light mode. Your choice is remembered in your browser's local storage so we don't ask again. We use this simple accept/decline banner rather than a third-party consent-management platform.
Once accepted, the Site uses cookies and browser local storage for:
- Analytics (PostHog): an anonymous distinct ID and session ID, stored in a cookie and/or local storage, used to group your activity into sessions and, if you sign in, link it to your account.
- Authentication: a session cookie (via NextAuth) that keeps you signed in after connecting your Patreon account. This cookie is set independently of the analytics banner.
- Interface preferences: small local storage flags used for UI behavior, including your analytics accept/decline choice itself and remembering a dismissed banner.
Whether a more detailed cookie-consent flow is needed for your jurisdiction is a product decision the site operator plans to review separately from this draft.
3. Session Replay and Heatmaps
Session recording and heatmap capture, and client-side exception tracking, only run once you click Accept — never in the light, anonymous mode described above. Once accepted, our PostHog configuration has session recording and heatmap capture available, with all form inputs masked. Depending on project-level sampling settings, your session may be recorded for product-improvement purposes. We also capture unhandled client-side errors and exceptions to help us find and fix bugs.
4. IP Address and Approximate Location
Like most websites, requests to this Site necessarily pass through an IP address, which our hosting provider (Vercel) and our analytics provider (PostHog) may process to serve the page and to derive an approximate, city-level location for analytics. We do not sell or share raw IP addresses with third parties beyond what is needed to operate these services.
Other Watermelon Universe properties, such as game builds played in the browser, may be configured differently and are not necessarily covered by the statements in this section — this policy describes the watermelonuniverse.com website specifically.
5. Analytics Events We Capture
Examples of the events described above include, but are not limited to:
- Page views and outbound link clicks;
- Game download attempts, grants, denials, and failures;
- UTM campaign parameters and referrer information used to attribute traffic sources;
- Sign-in and account linking events.
6. Third Parties We Work With
- PostHog — product analytics, session replay, and error tracking. Traffic is routed through a reverse proxy at
a.watermelonuniverse.comso that ad blockers are less likely to drop events; server-side events go directly to PostHog. - Vercel — hosting, serverless functions, and edge network for the Site.
- Cloudflare R2 — object storage for downloadable game builds, accessed through short-lived signed URLs.
- Patreon — optional sign-in and membership/tier verification.
- itch.io, Steam, F95zone, DeviantArt, and similar platforms — when you follow a link off the Site, that platform's own privacy policy applies to whatever happens next.
7. Data Retention
We retain analytics data for as long as it is useful for understanding how the Site is used, and account data for as long as you keep your Patreon sign-in linked. We do not sell your personal data.
8. Your Rights
Depending on where you live, you may have rights to access, correct, or delete personal information we hold about you. To make a request, email watermelonuniverse582@gmail.com.
9. Children's Privacy
This Site is intended for adults and is not directed at anyone under 18 years old. We do not knowingly collect personal information from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
11. Contact
Questions about this Privacy Policy? Email watermelonuniverse582@gmail.com. See also our Terms of Service.