Balatro on the Web logo
Balatro on the Web
Privacy policy
V9.1.1 Achievements Update
Privacy

What data the service stores

Learn what Balatro on the Web stores and why it is used.

Account data

The site stores your username, a hashed password, account timestamps, and authentication tokens needed to keep your session signed in. Passwords are not stored in plain text.

Profile data

If you choose to customize your account, the site stores optional nickname, bio, avatar, and equipped cosmetic state so your public profile and dashboard presentation remain consistent.

Gameplay and progression data

The service stores gameplay statistics, progression values, duel history, leaderboard metrics, Chips balance, quests, cosmetic inventory, and related timestamps so it can render your dashboard and public rankings accurately.

Feedback and audit data

Feedback reports are stored when you submit them. Some server-side audit checks also record hashed client metadata for integrity-sensitive actions such as cosmetic roll auditing.

Use of data
To authenticate players and keep sessions associated with the correct account.
To render player profiles, dashboards, duels, leaderboards, quests, and cosmetics.
To review bug reports, moderation issues, and feedback submissions.
To maintain integrity for public progression, duel systems, and economy systems.
Advertising and cookies

How advertising services may use browser data

The site includes Google AdSense publisher metadata and may load Google advertising scripts. Google and other third-party vendors may use cookies, web beacons, or similar browser storage to serve, measure, and limit ads based on visits to this and other websites. Users can review Google advertising settings in their Google account and can control cookies through their browser settings.

Advertising scripts are separate from account passwords and private save files. The application does not intentionally send passwords, raw save files, or private admin notes to advertising vendors. Public pages, browser metadata, IP-based request information, and ad interaction signals may still be processed by advertising providers according to their own policies.

Public profile visibility

Public player views can show display name, avatar, bio, equipped cosmetics, leaderboard placement, and duel summaries. They do not expose password hashes, authentication tokens, email addresses, private admin notes, or raw game save files.

Operational logs

Server logs may include request timing, health checks, session status, and integrity events used to diagnose outages or exploit reports. These logs are used to operate the service and are not intended as public profile content.