Privacy Policy
Last updated: September 13, 2026
What Batchly collects, who can see it, and what you can do about it. Written to be read before you connect anything, not after.
Batchly started as a games site. It now also runs College Hub (your Canvas coursework, Google Calendar and email headers) and a workout tracker (training, food, sleep and progress photos). Those handle far more sensitive data than games do, and they are described in full below.
Four things worth knowing before you scroll. A Canvas access token is not read-only. The workout tracker is a shared group, and progress photos default to being visible to the other members. Several features send your content to an AI model. And email you send to support@batch-ly.com is stored, read by a model, and may be answered without a person seeing it. Each is explained in its own section.
- Overview
- Your account
- Games and progression
- College Hub: Canvas, Calendar and mail
- Google user data and Limited Use
- Workouts, food and progress photos
- Sleep log
- AI features and what they send
- Emailing support
- Diagnostics and error reports
- Who can see what
- Companies that receive your data
- Where it lives and how it is protected
- Keeping, disconnecting and deleting
- Your choices
- Cookies and local storage
- Children
- Changes to this policy
- Contact
Overview
Batchly is batch-ly.com, run by one person as a personal, non-commercial project. There is no advertising, no third-party tracking SDK, and nothing is sold or shared for marketing.
Most of the site works without an account. You can browse and play games signed out. You only create an account for cloud saves, leaderboards, achievements and a public profile.
The extra modules are not all open to everyone:
- College Hub is available to any signed-in account with a confirmed email address. Nothing is collected until you connect Canvas or Google yourself.
- College Hub grades are a further opt-in inside College Hub, off by default even once Canvas is connected. Turning it off again deletes what it stored.
- The College Hub AI assistant sits behind a separate invite list. Having College Hub does not give you the assistant.
- The workout tracker is invite-only: a small private group.
- The sleep log is available to any signed-in account with a confirmed email address. Nothing is recorded until you log a night yourself.
- The sleep helper (AI) sits behind its own invite list. Having the sleep log does not give you the helper.
“We”, “us” and “Batchly” mean the individual who operates the site. Using Batchly means accepting this policy.
Your account
- Sign-in details. Your email address and a password, or your Google account (name, email address, profile picture URL and Google account ID) if you use Continue with Google. Passwords are handled by our authentication provider and stored only as a hash; Batchly never sees or logs the plaintext.
- Profile. A display name, an avatar (an emoji emblem, or a photo you upload), an optional bio, and an equipped title and cosmetic loadout. Your avatar is never imported from Google; it is only what you set.
- Account ID. A generated UUID. It is public: it is the address of your profile page at
/u/<id>.
Your email address is never shown on a leaderboard or a public profile.
Games and progression
If you are signed in, playing writes: leaderboard scores (with the per-game details attached to a run), cloud saves, achievement unlocks, streaks, Watts balance and ledger, cosmetics you own, season and goal claims, notifications, and activity entries. Social features add follows, likes, ratings, comments, jam votes, challenge scores and referrals.
A cloud save is a snapshot of what a game stored in your browser for that game: progress, high scores, settings. Batchly does not inspect it.
If you turn on notifications, your browser hands Batchly a push address for that device (a delivery URL plus two keys), and it is stored so a notification can be sent to you. It identifies the browser installation, not you; turning notifications off removes it.
If you upload a game, the game's code, cover image, description and moderation history are stored, and are reviewed by the operator (and by an AI moderation step) before publication.
Once a game is published, its icon and cover appear on the downloads index, and its source file is offered there for download if you leave the “share the source” box ticked on the upload form. You can change that at any time on your creator dashboard, and games uploaded before 2 September 2026 are not listed for download unless their creator turns it on. To be straight about what that box does and does not do: an approved game's code is already sent to every player's browser in order to run, so the setting keeps no secret; it decides only whether Batchly advertises your file for download in your name.
You can also send feedback and bug reports. Those carry your message, optional contact details, the page you were on, device details you choose to include, any screenshots you attach, and, if you are signed in, your account and email.
College Hub: Canvas, Calendar and mail
College Hub is off until you connect something. It has two connections, and they are independent; you can use one without the other.
Canvas
You paste a Canvas personal access token that you create yourself in Canvas. Batchly then reads, on a sync:
- Your Canvas profile (to confirm the token works and name the account)
- Your active courses: id, name, short name, term, colour and course URL. If you have switched grades on, this same request also asks for your course totals; if you have not, it does not.
- The assignments in those courses, with your own submission record attached
Those are the only three Canvas endpoints the code calls, and all three are reads. College Hub has no write path to Canvas anywhere in it.
Being exact about the assignment call, because “reads” and “keeps” are not the same thing: the request asks Canvas to include your submission, and Canvas's reply to that carries your grade whether or not anything wants it. For as long as College Hub has existed nothing wanted it: there was no column for a score, and the grade was dropped as the reply was parsed. That changed on 2 September 2026; Grades, below, is the whole of the new position.
Be clear about what a Canvas token is. Canvas has no read-only option and no per-feature permissions. A personal access token carries the full permissions of the account that made it; it can submit work, change your profile, and anything else you can do in Canvas.
College Hub only ever reads. But that is our choice in our code, not a restriction Canvas puts on the token. If you would rather not take that on, do not connect Canvas. The rest of the hub still works. You can delete the token from Canvas at any time and it stops working immediately.
Grades
Grade tracking is off unless you turn it on, in College Hub, on the Grades card. It is off for every account that already existed, because those accounts connected Canvas under a version of this policy that promised no score was kept, and a promise is not something to withdraw quietly. While it is off, the sync does not ask Canvas for your course totals at all, writes no score, and blanks any grade field it finds.
If you turn it on, this is the whole of what is stored, and the list is the whole list:
- Per assignment: your score, the grade Canvas displays for it (a letter, a percentage, or “complete”), and whether it was excused.
- Per course: the current percentage and current letter grade Canvas computes for you, whether that course hides its total, and when grades were last fetched.
Not stored: your final grade, your score before any late penalty, submission comments, rubric or per-question detail, and anything about anyone else. Canvas offers all of those in the same replies; none of them has a column.
Grades are not sent to the AI assistant. The assistant rebuilds what it knows from the database on every question, and its list of fields does not include any of the ones above. Your deadlines, class times and mail subjects do go to the model (see the AI section), and your grades do not.
Turning it off is a deletion. Switching the Grades card off erases the stored scores and course totals in the same action, immediately, rather than hiding them. Disconnecting Canvas goes further and deletes the whole coursework cache, described under Keeping, disconnecting and deleting.
One thing this cannot do: show you a grade Canvas will not state. Instructors can hide a course total, and a course with nothing graded yet returns the same silence, so College Hub says which of those it is when it knows and says it cannot tell when it does not. It never fills a missing grade with a zero.
Google Calendar
If you connect Google, College Hub reads your calendar list and then the events on every calendar in it (including calendars shared with you or that you subscribe to) for a window from 7 days ago to 28 days ahead. It stores each event's title, start and end, all-day flag, location, link, and the event's full description text. If your calendar descriptions contain private notes, meeting links or dial-in details, those are stored.
Two details that cut in opposite directions, so both are here. Hiding a calendar inside College Hub changes what is displayed; it does not stop that calendar being fetched. But guest and attendee lists are not stored at all (no column holds them), so who else was invited to your events does not end up in the database.
College Hub can show course-related mail. It searches your Gmail with a query you write and control in College Hub's settings, and stores, for each match: the sender's name, the sender's address, the subject line, the date, the message and thread ids, read/archived state, and which course it matched.
Message bodies are never requested and never stored. The sync calls Gmail with format=metadata and an explicit header list of exactly From, Subject and Date. No body is asked for, and the mail table has no column that could hold one; a database test enforces that, failing the migration if a body, snippet, payload or content column is ever added. Only the three headers above are read out of Gmail's reply; anything else it returns alongside them is discarded in memory and never written down.
To be equally clear the other way: a subject line is content. Subjects can be sensitive on their own: grades, health, money, discipline. Those are stored, and they are included in what the AI assistant sees if you use it. Write your mail query narrowly.
The rest of College Hub
You can also enter your class meeting times and locations by hand, set an available-hours-per-day figure, and record or accept workload estimates per assignment. Sync status rows record when the last sync ran and, if it failed, the error text, which can quote a hostname or an upstream API response.
Where the Canvas token and Google tokens are kept
Both live in one table that is locked down harder than anything else on the site. It has row-level security on with zero policies and no grants at all to signed-out or signed-in users. That means it cannot be read through the public API by anybody, including you, the row's owner. Only server-side functions using the service role can read it.
What the app can ask about that table, precisely: whether Canvas is connected, whether Google is connected, the address of your Canvas site, and the expiry date you set on the Canvas token. Never a token value. Two more calls can write to it (saving a Canvas token, and clearing one), and both act only on your own row.
Honest limit on that: the tokens are stored as ordinary text. They are protected by access control and by the database provider's encryption of the disk they sit on. They are not separately encrypted by Batchly at the application level.
Google user data and Limited Use
Sign in with Google and College Hub's Google connection are two different things and ask for different permissions.
- Signing in with Google uses only the basic scopes
openid,emailandprofile. It is used to create and sign you into your Batchly account, and to pre-fill your display name. Nothing else. - Connecting Google inside College Hub is a separate, explicit consent screen that requests two more scopes:
calendar.readonly: to read your calendars and the events in the window described above, so College Hub can show your week alongside your assignments.gmail.readonly: a restricted scope. It is used only to fetch the From, Subject and Date headers of messages matching your own search query, so College Hub can show course mail next to the course. It is not used to read bodies, send mail, or change anything in your mailbox.
Google's tokens are requested with offline access so a sync can run without you being present. You can disconnect from inside College Hub, which asks Google to revoke the token, or from myaccount.google.com/permissions.
One honest wrinkle. The consent request is sent with Google's include_granted_scopes option, which means any permission you granted this app before stays attached to the new token. College Hub used to ask for read-only Drive file metadata; that was removed on 26 August 2026 because no code ever called Drive. Narrowing what is asked for does not retract what was already given, so if you connected before that date, the old permission can still sit on your grant until you remove the app at myaccount.google.com/permissions. Nothing in Batchly calls the Drive API.
Batchly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
Specifically, and in keeping with Limited Use:
- Google user data is used only to provide and improve the user-facing College Hub features described above, which are prominent in the interface.
- It is not transferred to anyone except as needed to provide those features with your consent, to comply with law, or in connection with a merger or acquisition where users are notified. The one such transfer that exists today is the College Hub assistant sending your context to an AI provider, and it is opt-in and described in the AI section.
- It is never sold or transferred to advertising platforms, data brokers or information resellers, and never used to serve advertising of any kind, including personalised, retargeted or interest-based ads.
- It is never used to determine credit-worthiness or for lending purposes.
- It is not transferred, sold or used to create, train or improve any machine-learning or artificial-intelligence model. Asking a model a question is not training it: the AI features described below send context to a provider to get an answer back, and the providers used are under terms that do not train on it.
- No human reads it, except with your affirmative agreement (for example, when you ask for support and send us the detail), where it is necessary for security or to investigate abuse, to comply with law, or where the data has been aggregated and anonymised for internal operations.
The operator ensures that anyone acting on Batchly's behalf, and any successor to it, complies with the Google API Services User Data Policy.
Workouts, food and progress photos
The workout tracker is invite-only. If you are in it, these are the things it records, all entered by you:
- Workouts: start and end time, a title, and free-text notes.
- Sets: exercise, weight and unit, reps, duration, distance, RPE, warm-up flag, completion time. Exercise names you create are shared with the group's exercise list.
- Progress photos: the image itself, plus pose, caption and date.
- Nutrition: calories, protein, carbs, fat, a note and the date.
- Commitments: a weekly session target, allowed misses, and if you set one, a stake amount in money and where a forfeit would go. Nothing is charged; this is a tracker, not a payment.
- Screenshot imports: the screenshot you attach. It is sent to an AI provider to be read (see the AI section) and, when you confirm the entry it produced, the image is kept in private storage attached to that entry.
- Body measurements: bodyweight, body-fat percentage, waist, chest, arm, thigh, hips, neck and calf. Listed for completeness and because the capability is built, but stated plainly: no part of the app writes a measurement today and none has ever been recorded. If that changes, the group-by-default rule below would apply to it and this page will be updated first.
Progress photos, nutrition and body measurements are health data. In most privacy regimes they are a sensitive category, and Batchly treats them as one. Photos and import screenshots go into private storage buckets, not the public ones used for avatars and game covers.
The workout tracker is a shared group, and sharing is the default. It is one group, not per-person friend lists: everyone invited can see everyone else.
Always visible to the whole group, with no setting to turn it off: your workouts (including their titles and your notes) and every set you log.
Visible to the whole group unless you mark the entry private: your progress photos and your nutrition entries. Both default to group-visible. If you upload a progress photo and change nothing, the other members can see it. The upload form and the food form each carry a checkbox that makes that entry yours alone; you have to tick it, per entry, at the moment you save.
Yours alone: your commitments and stakes, and your screenshot imports.
Sleep log
Open to any signed-in account with a confirmed email address. It records the night's date, bed time, wake time, a 1–5 quality rating and free-text notes, and only once you enter them.
Sleep entries are readable only by the account that wrote them, enforced in the database rather than only in the page (not by the workout group, and not by other people using the sleep log). That rule is what made it safe to open the log to everyone: it has never been a shared space, and opening the door did not create one. Administrators are not an exception to it either; the note below about direct database access still applies, and it is the only route by which the operator could ever see an entry.
The sleep helper (the AI you can ask about your own nights) is separate and is granted account by account. If it is not switched on for you, the helper is not offered and the server refuses the request; the log itself is still yours to use.
AI features and what they send
Five features can send your content to a language model. Four of them run only when you press something; the fifth, support email, runs the moment your message arrives. Two providers are used: a self-hosted model (a Qwen model on the operator's own hardware, reachable only by the site's servers) and the Anthropic Claude API. Where a feature tries the self-hosted model first and falls back to Claude, that is stated.
| Feature | What is sent | Where it goes |
|---|---|---|
| Site AI assistant | Your messages and the page you are on, the game catalogue and play tips, and, if you are signed in, your own profile summary: display name, level, XP, global rank, Watts balance, streak, how many achievements you have, the titles of games you uploaded, and the games you have played. Your email address is not included. | Self-hosted model; Claude API if it is offline. |
| College Hub assistant (separate invite list) |
Your question, plus your courses, upcoming and overdue assignments, class schedule, this week's calendar events, and recent mail: sender names, sender addresses and subject lines. Rebuilt on the server from your own rows; the app cannot send someone else's. Calendar events go in as title, time and location only; the event description is deliberately left out. Grades are left out too: assignment points possible is included, your score is not, and neither is any course total. | Whichever provider the operator has configured: the self-hosted model or the Claude API. It can also be set to none, which switches the assistant off rather than falling back to anything. |
| Workout / nutrition screenshot import | The image you attach, so the numbers can be read out of it. | Claude API only. The self-hosted model cannot read images, so there is no fallback. If you go on to confirm the entry, the image is also kept in a private bucket attached to it; deleting the entry removes the file straight away, and deleting the workout or nutrition day it belongs to removes it through a clean-up job that normally runs within ten minutes (see Keeping, disconnecting and deleting). |
| Sleep helper (granted account by account) |
Your recent sleep entries: dates, bed and wake times, quality ratings and the free-text notes you wrote on them. No site or game context. Nothing is sent unless the helper is switched on for your account and you ask it something. | Self-hosted model; Claude API if enabled and it is offline. |
| Support email (mail you send to support@batch-ly.com) |
Your address, the subject and the text of your email. Read the Emailing support section before you write to us: this one runs without you pressing anything. | Self-hosted model; Claude API if it is offline. |
The self-hosted model runs on a machine the operator's family controls. Data sent to it does not leave that machine, and it is not used to train anything.
Requests to the Claude API are sent under Anthropic's commercial API terms, under which Anthropic states it does not train its models on data submitted through the API. Anthropic is a third party with its own policies; if you are not comfortable with that, do not use the features in the table.
Conversations themselves are not stored as transcripts. For each of these features, what the database keeps is a row holding your account id and a timestamp: enough for the rate limits to work, and nothing of what was said. The one AI log that holds more is the operator's own: when an admin uses the description-writing tool, a row records the feature, the game and that admin's email address.
Separately, a game you submit is passed to a model for automated moderation, and the operator can use a model to draft a game's description from its code. Both try the self-hosted model first and fall back to the Claude API.
Emailing support
The address at the bottom of this page is not a plain mailbox, and you should know that before you use it. Mail to support@batch-ly.com goes through this, every time:
- It arrives at Amazon's mail service, which stores the raw message (headers, text and attachments) in a private storage bucket belonging to the site.
- The sender address, subject and body text are sent to a language model, which drafts a reply and decides whether a person needs to see it.
- If the model is confident it can answer and has not flagged the message, that reply is sent back to you automatically, with no human involved.
- Otherwise the message and the draft are forwarded to the operator's personal Gmail account for a person to handle.
- Mail that looks machine-generated (bounces, no-reply senders, automated reports) is not drafted, answered or forwarded at all. The raw copy is still retained.
The model is instructed to hand certain things to a person rather than answer them itself: anything about account deletion, data access or a privacy or legal request; anything about payments; security reports; and anything involving another person, such as harassment or abuse. So a deletion request reaches a human. It is still read by a model on the way, and it is still stored.
If that is not acceptable for what you need to send (and for some requests it reasonably will not be), say only that you would like to be contacted, and the rest can be arranged another way.
Diagnostics and error reports
Batchly runs no third-party analytics or tracking SDK: no Google Analytics, no advertising pixel, no Sentry. It does keep three small first-party diagnostic logs, and it is worth being precise about what is in them, because an earlier version of this policy said there was nothing at all.
- Product events. Four events only: opening a game, copying an embed code, starting a remix, and submitting a report. Each row stores the event name, a small properties object, the page path, and a random per-tab id that is regenerated whenever you open a new tab. There is no account id on these rows, by design.
- Performance. Page-speed measurements (LCP, INP, CLS, FCP, TTFB) with the page path. No account id, no session id.
- Errors. When something breaks, the error message (up to 2,000 characters), the source, up to 8,000 characters of stack trace, the page path and your browser's User-Agent are recorded, and if you are signed in, your account id is attached. Rapid duplicates are collapsed. This exists so bugs get found and fixed.
All three are write-only from the browser: the database accepts inserts from anyone and returns rows only to an administrator.
One thing that is not a log but is worth naming here. So the site can show how many people are on it, your browser joins a shared live channel while you have Batchly open. Signed in, the identifier it announces on that channel is your account id, the same id that is already public as your profile address. Signed out, it is a random per-tab id. Nothing else is broadcast, and nothing is stored, but it does mean another visitor could work out which accounts are online right now.
Beyond these, our hosting and CDN providers receive the ordinary request information any website receives: IP address, User-Agent, and the URLs you load.
Who can see what
| Data | Who can see it |
|---|---|
| Display name, avatar, bio, account id, level, titles | Anyone, including signed-out visitors |
| Leaderboard scores, achievements, published games, comments, ratings | Anyone |
| A published game's source file, offered for download on /downloads | Anyone, if its creator left source sharing on |
| Account email, cloud saves, wallet and cosmetics | You only |
| College Hub: courses, assignments, calendar events, mail headers, settings | You only |
| College Hub grades: assignment scores and course totals (stored only if you opt in) | You only. Not sent to any AI model. |
| Canvas and Google tokens | Nobody through the app (server functions only) |
| That you are online right now | Anyone on the site: by your account id, if you are signed in |
| Workouts, sets and exercise names | Everyone in the workout group. No opt-out. |
| Progress photos, nutrition | Everyone in the workout group by default; you only, if you tick private on the entry |
| Commitments, stakes, screenshot imports | You only |
| Sleep entries | You only |
| Feedback, bug reports, subscriber emails, error logs, analytics | The site operator only |
| Mail you send to support@batch-ly.com | An AI model, then the site operator (see Emailing support) |
These are enforced in the database itself with row-level security, not only in the interface. The operator, as the person who runs the database, can technically reach anything stored in it, which is true of every site, and worth saying plainly rather than implying otherwise.
Companies that receive your data
Batchly does not sell your personal information and does not share it for advertising. It relies on a small set of providers, each receiving only what it needs.
- Supabase: the database, authentication and file storage. Everything described in this policy that is stored is stored here, except mail sent to support@batch-ly.com and the standalone OVERCLOCKED high-score board, which AWS stores (see Emailing support). The project is hosted in the United States (AWS
us-east-2). - Amazon Web Services: hosts and delivers the site from S3 and CloudFront, so AWS receives ordinary request data. The app's API also now runs through
api.batch-ly.com, a CloudFront distribution in front of the database, so your API requests transit AWS as well. AWS additionally: receives and stores mail sent to support@batch-ly.com (see Emailing support); runs the server-side Python used by certain “Server” Python games, which receives files you upload to those games and your sign-in token; and runs the standalone OVERCLOCKED high-score board (score plus the name you type; no account needed). - Google: the identity provider for Sign in with Google; the source of Calendar and Gmail-header data if you connect College Hub to it; the font CDN, which sees your IP and User-Agent when page fonts load; and the operator's personal Gmail, which receives support mail that gets escalated to a person. There is also an admin-only export that can push account, leaderboard and feedback data to the operator's own private Google Spreadsheet. Nothing schedules it (it runs only if an administrator triggers it by hand), and it is disclosed because the capability exists.
- Anthropic: receives the content listed in the AI table for the features that use the Claude API, including workout and nutrition screenshots.
- The self-hosted “Spark” model host: a machine owned and run by the operator's family, reachable only from the site's servers. Receives the AI content listed for the features that route to it.
- Lovable: the email delivery API used by the site's mail queue. Receives the recipient address and the message content at send time. Sign-up confirmation emails are sent by Supabase's authentication service.
- jsDelivr: the CDN that serves the in-browser Python runtime. It sees your IP and User-Agent when a Python game loads. No account data reaches it. A community-uploaded game is additionally permitted to load code from unpkg and esm.sh; if the game you open does that, those CDNs see your IP and User-Agent too. Community games run walled off from your session and cannot read your account.
- Stripe: not currently receiving anything. Payment features (creator tips and a supporter membership) are built but ship switched off behind a feature flag that is set to off. No payment has been taken and no card data has ever reached Batchly. If that changes, this policy will be updated first, and Stripe would handle card details directly; Batchly would never see them.
- Legal and safety: information may be disclosed where required by law, or to protect the security and integrity of the site and its users.
Where it lives and how it is protected
Data is held in a Supabase project in the United States, delivered through AWS. Both encrypt data in transit over HTTPS and at rest as part of their managed infrastructure.
Access is enforced at the database level rather than only in the app, so a bug in the interface does not open a door. Concretely: your saves, settings and College Hub data are readable only by your account; the workout rules are exactly as described above; credentials are in a table with no user-facing access at all; and the diagnostic tables accept writes but return nothing to anyone except the operator.
Progress photos and import screenshots are in private storage buckets. A member of the workout group can retrieve another member's photo only when the matching row is one this policy says they can see.
Passwords are never stored or logged in readable form; the authentication provider keeps only a hash.
No online service is completely secure. Batchly is a personal project run by one person, not a company with a security team. That is a real limitation, and it is a reason to think about what you connect. If you would rather not have coursework or health data in one hobbyist's database, use the parts of the site that do not need it.
Keeping, disconnecting and deleting
Account data is kept while your account exists. Feedback is kept while it is useful. Announcement emails are kept until you unsubscribe. Provider request logs follow those providers' own retention policies.
Disconnecting is not the same as deleting, so here is exactly what each one does today:
- Disconnecting Canvas deletes the stored token and the whole coursework cache it filled: every course row, every assignment row (including any grades stored under the opt-in above) and the deadlines sync record. Nothing Canvas-derived is left behind. (This is stronger than an earlier version of this page described; the page was behind the code.) Your hand-typed timetable is yours rather than Canvas's, so it stays.
- Disconnecting Google asks Google to revoke the token, deletes every stored Google token field, and deletes the cached calendar list, calendar events and mail rows (sender names, addresses and subject lines included), along with the calendar and mail sync records. One caveat remains: the upstream revoke is best-effort, so if Google does not confirm it, the app says so and tells you to finish the job at myaccount.google.com/permissions. (An earlier version of this page said the mail rows survived a disconnect. They no longer do.)
- Deleting your account removes your profile and every row keyed to you. That does include all College Hub coursework, calendar and mail rows, the stored Canvas and Google credentials, and every workout, nutrition and sleep record; those all fall with the account automatically. It also erases the files you uploaded: your profile picture, the covers of your community games, feedback screenshots, progress photos and workout or nutrition import screenshots, plus For Claude drops for administrators. The deletion does not go ahead until those files are gone; if some cannot be removed, nothing else is deleted and you are asked to try again. What it does not do, stated because it would otherwise surprise you:
- Cached copies of public images can linger. Profile pictures and game covers are public, so a copy already held by the delivery network, a browser or a feed reader can take a while to expire after the file itself is erased. The site's public game feed (
feed.xmlandfeed.json) also keeps a published game's title, your display name and its cover link until the site is next rebuilt. - Administrators only: files attached to posts on the internal admin message board stay with those posts, which other administrators still use.
- Mail you sent to support is not removed by deleting your account. Ask and it will be.
- The Google grant is not withdrawn. Deleting the account destroys the stored token, which is also the only thing that could have been used to call Google's revoke endpoint. Remove Batchly at myaccount.google.com/permissions yourself. The same is true of a Canvas token: delete it in Canvas.
- Cached copies of public images can linger. Profile pictures and game covers are public, so a copy already held by the delivery network, a browser or a feed reader can take a while to expire after the file itself is erased. The site's public game feed (
To delete your account, or to ask for anything above to be removed sooner, email the address in Contact from your account email.
Your choices
- Do not connect what you do not want stored. This is the strongest control you have. Canvas, Google, the workout tracker and every AI feature are opt-in, and the rest of the site works without them.
- Narrow your mail query. College Hub only fetches what your own Gmail search matches. Make it specific.
- Leave grades off, or turn them off again. Connecting Canvas does not switch grade storage on; that is a separate choice on the Grades card, and switching it back off deletes the scores it had stored rather than hiding them.
- Mark health entries private. Progress photos and nutrition each have a private checkbox at the moment you save them, and it defaults to sharing. Remember that workouts and sets have no private option at all.
- Set an expiry on your Canvas token. The connect form asks for one and suggests 90 days. Canvas will not let you make the token itself weaker, so this is the strongest limit available on it.
- Edit or delete your entries. Anything you entered you can change or remove.
- Access and edit your profile: display name, avatar and bio, on your Profile page.
- Revoke tokens at the source. Delete the token in Canvas; remove Batchly at myaccount.google.com/permissions. Both work whether or not you also disconnect in Batchly.
- Unsubscribe from announcement emails using the link in any of them.
- Ask for a copy, a correction or a deletion of your data by email.
Cookies and local storage
No tracking or advertising cookies, and in ordinary use the site sets no cookies at all.
Your browser's local storage is used to keep you signed in (your session token), to remember your light/dark choice and which notices you have dismissed, to hold a score captured before you signed up, to keep a list of games you recently played, to hold an unsubmitted game draft you were writing, and to keep each game's own saved progress. Session storage holds the random per-tab id used by the four product events and by the online-count channel. These stay on your device; the session token is sent only to Batchly's own backend.
Children
Batchly is a general-audience site, not directed to children under 13, and does not knowingly collect personal information from them. If you believe a child has created an account or submitted personal information, contact us and it will be deleted.
Changes to this policy
This policy is updated as the site changes. When it is, the “Last updated” date at the top changes and the new version is posted at this same URL. Significant changes may also be announced on the site. If a change would newly send your data somewhere it does not go today, this page will say so before it happens.
Contact
Questions, data requests, corrections or account deletion: support@batch-ly.com.
Read Emailing support first. Mail to that address is stored, read by an AI model, and may be answered automatically. Privacy, deletion and legal requests are always routed to a person, but they are read by the model on the way there, so do not put anything in that message you would not want processed that way.
Batchly is operated by an individual as a personal project.
← Back to Batchly