Privacy Policy
Last updated: August 31, 2026
EmuDock ("we", "our", or "us") operates the EmuDock web application (the "Service") available at https://emudock.com — a browser-based retro game emulator that streams curated game software (and any required BIOS) to your browser and runs it locally. The Service is free to use; there are no paid plans, and we do not process payments. This Privacy Policy explains what information we collect when you use the Service, why we collect it, and the choices you have. By using the Service, you agree to the practices described in this policy.
1. Information We Collect
1.1 Account and authentication information
Accounts are managed using Supabase Auth. You may register and sign in using an email address and password, or you may sign in with Google OAuth.
When you sign in with Google, we may receive basic account information from Google, such as your Google account identifier, email address, display name, and profile image if supplied. Google sign-in is used for authentication only. We do not use the login flow to access your Google Drive, email, or any other Google services.
Connecting Google Drive for cloud saves is a separate, optional authorization flow that you initiate and control from your account settings (see "Cloud Saves" below). When you connect Drive, we request the narrowest Google scope needed (drive.file), which lets the Service create and manage its own "EmuDock" save folder and nothing else. We never browse, read, or access your other Drive files, and we never request access to your other Google services.
1.2 Application data stored in our database
We use Supabase PostgreSQL to store account-related application data, including profile information, settings and theme preferences, favorites, game-library metadata, recently played/history data, playtime and popularity records (aggregate and per-account), and other application-specific account data. We do not collect or store any payment information — there is nothing to pay for. This data is associated with your account and protected by row-level security.
1.3 Curated game content is streamed, never collected
Games (and required BIOS files) are delivered to your browser from our curated content library and run locally. The game/BIOS contents are never uploaded back to us and are never collected, read, or stored by us — they stream into your browser to run in the emulator and exist only in your browser's memory and cache. We may record non-content identifiers about the content you play (for example, catalogue IDs and content hashes) to operate the library, track playtime, and improve compatibility.
1.4 Your local files and saves stay yours
If you play a game from your own device, those files are processed in your browser and are not uploaded to our servers. Battery saves and save states are stored in your browser's local storage by default. Your personal emulator save data is not stored in our infrastructure unless you choose to connect cloud saves (see "Cloud Saves" below).
1.4 Cookies and session storage
We, and the authentication service we use, may use authentication/session tokens, cookies, or equivalent browser storage to keep you signed in and to operate the Service securely. See "Cookies and Session Storage" below.
2. How We Use Information
We use the information we collect to:
- create and manage your account and authenticate you;
- provide, stream, and operate the Service and its features (including the curated content library);
- track aggregate play activity (games played, playtime, popularity) to operate sorting, leaderboards, and compatibility improvements;
- remember your settings, preferences, and theme choices;
- maintain your favorites, game-library metadata, and recently played history;
- secure the Service, prevent abuse and fraud, and enforce our Terms of Service; and
- comply with legal obligations.
We do not sell your personal information, and we do not use it for advertising.
3. Infrastructure and Service Providers
To operate EmuDock, we rely on service providers that process information on our behalf or as part of the Service. These include:
- Supabase — authentication (Supabase Auth) and the application database (Supabase PostgreSQL). Supabase may also handle authentication-related email (for example, email confirmation or password reset) depending on the authentication flow.
- Cloudflare — DNS, hosting of the application (Cloudflare Workers), static asset delivery, CDN/caching, and R2 object storage. R2 is used for public game-related imagery such as box art and screenshots and for application assets. Game and BIOS files are not hosted by us: they stream to your browser directly from the external sources linked in our curated content catalogue (for example, public archives such as Vimm's Lair). Your private emulator save data is not stored in R2.
- Google — when you sign in with Google, Google processes the OAuth exchange in accordance with Google's Privacy Policy.
- Resend (planned) — EmuDock may use Resend or another transactional email provider for account-related email in the future. At present, authentication-related email is handled by Supabase.
Each provider processes information under its own privacy policy and, where applicable, on our instructions.
4. Cloud Saves (Google Drive)
EmuDock lets you optionally connect your own Google Drive to store personal emulator save data — battery/SRAM saves, save states, and related files. Cloud saves are available to all users at no cost.
Connecting Drive is a separate, optional authorization flow, distinct from signing in with Google. When you connect, we request the drive.file scope: the Service creates and manages its own "EmuDock" folder in your Drive, writes your save files there, and reads them back for cross-device restore. We do not access, list, or modify your other Drive files or folders.
Your save bytes are stored with Google under your own account, never in our infrastructure. We store only metadata about your saves (such as versions, checksums, and references to the files in your Drive) in our database. You can disconnect Drive or delete the EmuDock folder at any time; disconnecting stops future sync but does not delete files from your Drive automatically.
5. Cookies and Session Storage
To keep you signed in and to operate the Service securely, we use authentication tokens stored in your browser (for example, in local storage via Supabase Auth) together with standard session cookies where applicable. You can sign out at any time, and you can clear your browser's storage to remove these tokens. Blocking or removing them may prevent you from staying signed in.
6. Data Sharing
We share personal information only in the following circumstances:
- with service providers necessary to operate EmuDock (Supabase, Cloudflare, Google when you use Google sign-in, and a transactional email provider if and when one is used);
- where required by law, regulation, or legal process, or to protect the rights, property, or safety of EmuDock, our users, or others;
- in connection with a merger, acquisition, reorganization, or similar transaction, with notice where practicable.
We do not sell personal information.
7. Data Retention
We retain account data for as long as your account is active and as needed for the purposes described in this policy, after which we delete or anonymize it in line with our deletion process. Backups may retain data for a limited additional period.
8. Security
We apply reasonable technical and organizational safeguards to protect your information, including encrypted transport (TLS), restricted access to production systems, and database row-level security. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information. You can update account information through the Service, sign out at any time, and clear local data stored in your browser.
Account deletion: EmuDock does not yet offer self-service account deletion. To delete your account or request deletion of associated personal data, email us at privacy@emudock.com and we will process your request. Self-service account deletion is planned for a future release.
10. Children's Privacy
The Service is not directed to children under 13, or under the minimum age of digital consent in your jurisdiction, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.
12. Contact
If you have questions about this Privacy Policy or about how your information is handled, please contact us at privacy@emudock.com.