The Ancient Hatchery
Privacy notice
What the Hatchery records about you, why, and for how long.
In effect from 2026-09-21
1. Who is responsible
Pocket Dragons FZE LLC (“Pocket Dragons”, “we”) decides how and why the information described here is handled, and is the controller for it. Write to us about anything in this notice, and about any request concerning your own data — see section 10.
- Postal address
- Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
- Privacy, data rights and support
- [email protected]
2. What this notice covers
This notice covers the whole Pocket Dragons launch site: the Hatchery, the Keeper Ledger, the team page, these legal pages, and the onboarding that connects your X and Discord accounts and records the badges you earn.
It does not cover a mint, a marketplace, packs, balances, deposits, withdrawals, a treasury or a wallet. None of those is available, and each would need its own notice before it could be.
3. What we handle
There is no sign-up form, no newsletter and no email field anywhere on this site. Everything below arrives because you signed in with X, connected Discord, or made a request to the site.
From X, when you sign in.
- We ask X only to read your public profile and your posts, and we receive and store your numeric X user ID, your name, your username and the address of your profile image, together with the time your sign-in was last verified and the card design your account was dealt. Since 21 September 2026 we also store whether your X account holds X Premium (the verification tier X reports with your profile), because the Keeper-link quest counts only Premium accounts.
- The access token X issues is used during the sign-in exchange and is not stored.
- Signing you in sets the cookies listed in section 5.
From X, when a quest is checked.
- To confirm that you follow the launch account, we ask X for that account's followers and hold the numeric IDs. Those IDs belong to people who have never used this site: we hold no name, handle or profile for them and they are linked to no account here. They expire on the clock in section 8.
- To confirm the Keeper card you posted, we read that one post and check that it exists, that you wrote it, and that it carries an image. We do not read its text.
- We store the address of that post and a short record of the check.
From Discord, when you connect it.
- We ask Discord for the identify scope only, and receive and store your Discord user ID and the names on that account.
- Our own bot then asks Discord whether that account is a member of the Hatchery server and holds the Member role. It does not read your messages.
- We do not store the Discord access token, your avatar, the membership record itself, or your list of roles.
- We keep a record of that check — the account, the server and role asked about, the answer, and when it was made. Those records cannot afterwards be changed or deleted.
- While the weekly AMA runs in the Dragon Stage, our bot also records when your connected account joins and leaves that stage channel, for the Keeper quest that counts attendance. It keeps the times of those joins and leaves and the verdict for that AMA (how long you were present, and whether it counted). Accounts that are not connected to a Keeper here are not recorded, and nothing is recorded outside an AMA.
From a Keeper's link, if you arrive on one.
- A Keeper can share a link to this site that carries their own code. If you open it and later create an account here, that account is attributed to the Keeper whose link you followed, for the quest that rewards bringing new Keepers. Opening the link sets the pd_ref cookie in section 5; it holds the Keeper's code, not anything about you.
- That Keeper is shown, on their own quest board, that someone arrived on their link; once you finish the onboarding they see your X username and profile image and whether your X account holds X Premium — the same facts your public X profile shows. The attribution is removed if either account is deleted.
From your browser, on every request.
- Your IP address reaches our servers as the address of the request, and it is put to two uses: it is the key of a short rate limit, and it is one of the fields in the request log below. The rate-limit counters expire after five or fifteen minutes depending on the route; the log lines are kept for the period section 8 gives.
- Each response is logged with the method, the route, the status, how long it took, a request ID and the IP address. Credentials, query strings and sensitive fields are redacted before anything is written.
- Our hosting provider's edge sees every request before we do and sets a cookie of its own, listed in section 5.
From your device, kept on your device.
- The site reads what your browser reports about itself — its user agent, how much processing power and memory it has, and what its graphics can do — to choose which quality of the 3D chamber to draw. Those readings stay in your browser: nothing is stored, and the readings themselves are not sent to us.
- Once or twice per page the site sends us one anonymous line about how the chamber started: whether the 3D chamber drew or the still view was shown, the reason if it was the still view, which of three quality levels was chosen and which graphics backend drew it, and coarse facts chosen from short lists — the kind of browser, whether the page was open inside another app's browser (such as X or Telegram), the width of the screen in one of five bands, whether reduced motion or data saving was on, whether WebGL and WebGPU were available, how many retries there were, and how long the start took. It carries no identifier, no cookie and no address, and we keep only a daily count of how many starts fell into each kind.
- Everything the site remembers between visits is listed in section 5.
What we do not do.
- Apart from the anonymous start-up line described above, there is no analytics, no advertising pixel, no session recording and no error-reporting service anywhere on this site.
- We send you no email. The service has no way to write to you.
- No third-party script, font or image is loaded from another host. Everything the page draws, avatars included, is served from our own origin.
4. Why we use it
| Purpose | Information |
|---|---|
| Sign you in and keep you signed in | Your X identity and the sign-in cookies |
| Check the quests and award badges | Your X identity, the post you submit, the follower check, the Discord membership check, and the quest, badge and score records that result |
| Give you your Keeper card, and publish the Keeper Ledger | Your name, username and avatar from X, your Keeper number, your card design, your badges and when they were awarded, and the dated record of your permission for your name and picture to be used on the card |
| Count the Keeper quests: | Your Discord account's joins and leaves of the Dragon Stage while an AMA runs, the Keeper link you arrived on, your X verification tier, and the rhythm you play on the incubator (the times of your presses, sent only when you play it) |
| Keep the service standing, and keep the quests honest | Your IP address as a rate limit key, request logs, and the verification and audit records behind each badge |
| See how often the 3D chamber fails to draw, and why, so it can be fixed | The anonymous start-up line in section 3, kept only as a daily count per kind |
| Answer you | Whatever you send us and the account it concerns |
Nothing here is used for advertising, for profiling, or for an automated decision that produces a legal effect. The one automated decision the service makes is whether a quest is verified, and where it cannot be decided automatically a person on the team decides it instead.
5. Cookies and browser storage
The site sets no advertising or analytics cookies, so there is no consent banner to dismiss. Everything below either signs you in and keeps that sign-in safe, delivers a feature you asked for by following a Keeper's link, or is a preference kept in your own browser that never reaches us.
| Cookie | Purpose | Lifetime |
|---|---|---|
| dragon_ | Your signed-in session. Holds a signed token naming your account and your X ID. Not readable by scripts. | 30 days |
| x_ | Protect the X sign-in against interception and remember where to send you back to. | 10 minutes, cleared when sign-in finishes |
| dc_ | Tie the Discord connection to the Keeper who started it, and remember where to return. | 10 minutes, cleared when the connection finishes |
| pd_ | An encrypted receipt proving the trailer code was entered. | 30 days by default, renewed while you keep using the site |
| pd_ | Set only when you open a Keeper's link. Holds that Keeper's code — nothing about you — so an account created on this device can be attributed to them. Not readable by scripts. | 30 days |
| _ | Set by our hosting provider's edge for bot mitigation, not by this site. We cannot disable it from here. | 30 minutes |
| Key | Purpose | Lifetime |
|---|---|---|
| pd: | Remembers that this device had a session, so the page can choose its wording while it asks the server. | Until a signed-out answer clears it |
| pd: | Resume the journey where you had reached. | Until the journey is reset |
| pd: | Records that a badge has already been shown, so it is not shown twice. Holds the time it was awarded. | Until cleared |
| pd: | Skips the opening cinematic on a later visit. | Until cleared |
| pd: | Remembers the sky and weather you chose. | Until cleared |
| pd: | Remembers whether you turned the sound on. | Until cleared |
| pd: | A local trace of the last few start-up steps, for diagnosing a chamber that will not draw. It is never uploaded. | Rolling, until cleared |
| pd: | The trailer code you typed, reused in the same tab. | The browser tab |
| pd: | The quest board page you were on. | The browser tab |
| pd: | A Blinky says sequence you cleared that could not be reported at the time (the times of your presses). It is sent to us on your next visit, then removed. | Until it has been reported |
| pocket-dragons: | When the site may next ask about a verification in progress. | The browser tab, cleared when it expires |
6. Who receives information
| Recipient | What they receive | Why |
|---|---|---|
| DigitalOcean, LLC (United States) | Everything the service processes: the application, its database and its cache in the provider's NYC3 region, and the runtime logs | Hosting. They act on our instructions as our processor. |
| Cloudflare, as DigitalOcean's edge | Request metadata, including your IP address, and the bot-mitigation cookie | TLS termination and denial-of-service protection in front of the hosting. |
| X Corp. | The sign-in exchange, and the checks described above | X is the identity provider and the subject of two quests. |
| Discord Inc. | The connection exchange, and our bot's membership question about your Discord ID | Discord is the identity provider for the community quest, and hosts the community. |
| Anyone who opens the Keeper Ledger | Your name, username, avatar, badge count and award time — until you ask to come off it; see section 9 | The Ledger is public by design, and leaving it is one switch on your own record. |
Your use of X and of Discord is governed by their own terms and notices, not by this one. We do not sell information, share it for advertising, or hand it to anyone else for their own purposes. If a court or a competent authority compels disclosure we will comply with the law and, where the law allows, tell you.
7. Where information is processed
The application, its database and its cache run in DigitalOcean's New York region. Requests reach them through that provider's edge network, which also caches and serves the static parts of this site from locations around the world, so the machine that first answers you may be nowhere near New York.
Because those systems are in the United States, that transfer is made under the European Commission's adequacy decision of 10 July 2023 for the EU–US Data Privacy Framework, under which DigitalOcean is certified together with the UK Extension to it, and our agreement with DigitalOcean already incorporates the European Commission's Standard Contractual Clauses of 4 June 2021 and the UK International Data Transfer Addendum, which carry the transfer instead if that certification lapses or the adequacy decision ceases to apply. Write to us and we will send you a copy of them.
X and Discord decide for themselves where they process what they receive; their own notices describe it.
8. How long we keep it
Some of what the service holds expires on a clock. The rest is kept for as long as your Keeper account exists, because it is the account. Where there is no fixed period, the criterion is stated instead of a number.
| Information | Kept for |
|---|---|
| Rate-limit counters keyed by IP address | Five or fifteen minutes, depending on the route, after which they are deleted automatically |
| Sign-in and connection cookies, and the replay records that protect them | Ten minutes |
| Your session cookie | Thirty days, or until you sign out |
| The trailer-code receipt | Thirty days by default, and re-issued while you are still using the site, so an unbroken visit keeps it alive for longer |
| Your Dragon Stage attendance during an AMA (the joins and leaves, and the verdict) | As long as your Keeper account exists; deleted with it |
| The daily count of how the 3D chamber started (section 3) | Indefinitely. It is a count per day and per kind, holds nothing about any one visitor, and cannot be traced back to you |
| The Keeper link you arrived on (the attribution to that Keeper) | As long as both Keeper accounts exist; removed when either is deleted |
| The follower IDs read from X | Up to seven days from the last page read, whether the check finished or was interrupted. A finished check stops being reused after fifteen minutes by default. Expired entries are deleted automatically. |
| Cached Keeper avatars and composed Keeper cards | Twenty-four hours and five minutes respectively, in the server's memory only |
| Your account, badges, Keeper number, score history and quest records | As long as your Keeper account exists. They are what the Ledger and your card are made of. Ask for deletion and they go seven days later, and within 30 days at the outside — see section 10. |
| The record that you took yourself off the Ledger, or that you agreed to your picture being used on your card | As long as your Keeper account exists. Each is stored as the date you asked, because a date is what lets us show that we honoured it. |
| A recorded deletion request | Until it is carried out, which removes it along with the account, or until you cancel it. A cancelled request is kept as the record that it was cancelled, for as long as the account is. |
| Verification records and the audit log | As long as we need to be able to show why a badge was awarded or refused. A Keeper's verification records go when their account is erased; the audit entries remain, because they cannot be edited. |
| Server logs, including the IP address on each line | Not kept as an archive. Our hosting provider holds runtime logs only for the deployment that is currently running, and we forward them nowhere. When a deployment is replaced its log lines, and the IP addresses in them, are gone. |
| Database backups | Seven days. The database is backed up daily and can be restored to any point in the previous seven days. Anything older is deleted by the provider. |
9. The public Ledger and your Keeper card
When you have finished the quests the current phase requires, your Keeper record appears on the Keeper Ledger. The Ledger shows your rank, the name and username from your X profile, your avatar, how many badges you hold and when the first was awarded. It does not show your score, your Keeper number, your Discord account, or any internal identifier.
Your avatar there is served from this site rather than from X, so opening the Ledger does not tell X who is reading it. Each row also links to your public X profile, which is a link you follow, not a request your browser makes on its own.
Appearing there is automatic when you finish; staying there is not. Coming off the Ledger is a switch on your own Keeper record, not a favour, and it reaches all three of the public places your name and picture can come out of this site: your row leaves the public page, your photograph stops being served from here, and the record behind your card address stops carrying your name and your picture too.
Our own servers act within about thirty seconds, which is how long the Ledger is cached for. A copy already handed to a cache between us and a reader can be shown for about thirty seconds after that, so the honest outside figure for a stranger is about a minute.
It deletes nothing. Your badges, your Keeper number and your own view of your rank are exactly as they were, and only you can see them. Your card is not taken away either: the same address still opens it and it still downloads, composed without the photograph and the name, because those two things are precisely what you asked us to stop showing. Going back on is the same switch the other way, and brings both back.
Write to [email protected] to have it set. The control that lets you throw the switch yourself, while signed in, is being added to this site; until it is here a person at that address does it, and this notice will say so the day that changes.
Your Keeper card is composed on our server from your X profile and your badge record, and downloaded to your device. Your picture and your display name are yours, and putting them on an image that carries our name is something we would rather ask about than assume, so we keep a record of that permission: when you gave it, the wording you agreed to, and — if you take it back — when you did that.
Withdraw it and we stop composing your card, including from any card address already given out, within about thirty seconds. What we cannot reach is a card already saved or posted. Finishing the quests is what asks for the card today; the separate consent this record is built for is switched on with the control described above.
The address of a card is long, unguessable, and does not expire while your permission stands: anyone you give that address to can open that card, so treat it as you would a link to a photograph. Posting the card to X is something you do yourself, in your own X client.
10. Your rights
Three of these are switches on your own Keeper record rather than judgement calls. Each is recorded the moment you set it, and reaches the public pages within the window section 9 describes:
- Coming off the public Keeper Ledger, or going back on. Section 9 says exactly what that removes and what it leaves alone, and it reaches your photograph and your card record as well as your row.
- Giving or withdrawing permission for your X picture and display name to be used on your Keeper card.
- Asking for your Keeper account to be deleted, and cancelling that request during the seven days it stays cancellable.
When you ask for deletion we record the request and take you off the public Ledger in the same breath. That half does not wait for anything: you stop being published the moment you ask. The request then stays yours to call off for seven days, and nothing is erased before they are up, by us or by anyone. After that it is carried out, within 30 days of the day you asked and usually much sooner, and it cannot be undone.
The erasure takes the account itself and everything hanging off it: your badges and your Keeper number, your quest and verification records, your score history, and with them your card, which can no longer be composed at any address it was given. Your Keeper number is not handed to anyone else afterwards; it simply stops existing. What remains is the audit entries described below. Asking twice does nothing but show you the request you already made. Cancelling stops the deletion; it does not put you back on the Ledger, because that is a separate decision and yours to make.
Today all of these are asked for at [email protected], along with a copy of what we hold about you, a correction, an export, or an objection to something we do. Say which Keeper account you mean; your X username is enough. We will check that the request comes from you before we act, and we will tell you what we did and what we could not do. A deletion asked for that way is recorded in the same queue and carried out by the same mechanism, by a person rather than by the clock, and the 30 days hold either way. The signed-in controls for the three switches above are being added to this site.
There are limits, and they are worth stating plainly:
- We cannot delete a post you made on X, or anything X and Discord hold about you under their own notices. Their own tools do that.
- The audit entries recording why a badge was awarded or refused cannot be edited or deleted; that is what makes them worth keeping. When your account is deleted those entries remain, and we will say what they still show.
- Copies of a public Ledger row or a Keeper card that someone else has already saved are beyond our reach, as is a card you have already downloaded or posted.
If you are in the European Economic Area or the United Kingdom you can also complain to your national data protection authority. We would rather you told us first, so that we can put it right.
11. Age
The Hatchery has no age gate of its own and asks for no date of birth. It is reached through X and Discord, and you must meet whatever minimum age those services require of you in your country; those are the floors that apply here.
If you believe a child has created a Keeper account, write to us and we will remove it.
12. Security
Sign-in cookies are set so that scripts cannot read them, and sessions are signed. Traffic between the site and its database and cache is encrypted, and every route that can be abused is rate limited.
No system is perfectly safe, and we will not claim otherwise. Do not put credentials, identity documents or anything else sensitive into a public post, a quest submission or an ordinary support message.
13. Changes to this notice
When what the service does changes, this notice changes with it, and the effective date at the top changes too. If a change matters to you we will say so on the site rather than quietly editing the page.
