Gemmoa

Privacy Policy

Effective 18 August 2026 · Gemmoa (gemmoa.com)

In short

You can use all of Gemmoa without an account, and if you do, we receive no personal information at all. Signing in with Google is optional — if you sign in, we keep your email address, name and profile picture from that point on, and we save your Treasure Chest (your favourites) so it appears on your other devices. You can delete all of it at any time. Apart from that we use Google’s services for visit statistics and advertising, and cookies are used in the process.

1. What we store ourselves (whether or not you sign in)

While you use the site without an account, we do not record who did what. We keep only totals per game.
  • How many times a game was started, and total time spent — used only to sort which games are popular
  • Totals for likes and dislikes — we do not store who pressed them
  • What was typed into the search box, and how many results came back — used only to see which words find nothing, so we know what to add next. We do not store who typed it. It is deleted after 90 days

None of the above is stored together with your IP address or anything else that could identify you. So these records on their own cannot tell us who did what.

2. Signing in with Google (optional — added 13 August 2026)

This applies only if you press “Sign in with Google” in the top bar. Signing in exists for one purpose: so your Treasure Chest follows you when you change devices. If you never press it, everything on the site still works.

What we keep

  • Your Google account identifier — the value that lets us recognise you when you come back
  • Your email address, name and profile picture — used only to show who is currently signed in
  • Your Treasure Chest and your list of hidden games
  • When you first signed in and when you last visited — used only to clear out unused accounts
  • Gem records — Gems earned from surveys, when they were earned, and why. If a reward is reversed, that is recorded too

What we do not take

  • Your password — Google verifies you and we receive only the result. We never see your password
  • Date of birth, gender, phone number, address, payment details, contact lists, or anything in your Google Drive or Gmail
  • Your recently played list — this is never sent to our server, even when you are signed in (see “What is stored on your device” below)

How to delete it — press “Delete account” on the My account page and your account and the saved lists are deleted immediately, together. You do not need to ask us. (Signing out does not delete anything — sign in again and it is all still there.)

3. What is stored on your device (including cookies)

The following is kept inside your browser only and is never sent to our server. Clearing your browser’s site data removes it.
  • Your recently played list — never sent to our server, even when signed in
  • Whether you have already pressed like or dislike (so it is not counted twice)
  • View settings, such as whether the side menu is folded
  • Your Treasure Chest and hidden games — when you are not signed in. If you sign in, they are saved as described under “Signing in with Google” above

One thing is sent to our server — a device marker

When you press play, we also send one random string stored in this browser (gemmoa.dev.v1). It exists so that opening the same game several times counts only once in our popularity ranking, and for nothing else.
  • It is not linked to your name, e-mail or sign-in account. It is a random value with no meaning
  • Which game you opened is kept with this value for that day only, and is never used for advertising or tracking
  • Clearing your browser’s site data gives you a new value. Everything on the site keeps working

Cookies Gemmoa sets itself

The only cookie Gemmoa uses is the one that keeps you signed in. We do not use cookies for advertising or tracking.
  • gm_user — created only if you signed in with Google. It saves you from signing in again next time, and it expires after 180 days
  • gm_oauth — a temporary value used only during the 10 minutes of signing in. It disappears as soon as that finishes

If you would rather not — simply do not sign in, and these cookies are never created at all. If they already exist, sign out from the top bar, or clear them in your browser settings (Chrome: Settings → Privacy and security → Third-party cookies / Delete browsing data). Everything on the site still works without them — your Treasure Chest just will not follow you between devices. How to turn off advertising cookies is covered under “Advertising and visit statistics” below.

4. Advertising and visit statistics (Google)

  • Google AdSense — places advertising on the site. Google and its partners may use cookies to show you ads based on your previous visits. You can turn off personalised ads at Google Ads Settings, and personalised ads from other companies at aboutads.info.
  • Google Analytics (GA4) — we look at visit statistics, such as how many times each page was opened. What Google collects is governed by the Google Privacy Policy.
  • Microsoft Clarity — we look at where people click and where they stop. Your actions on the page are recorded (clicks, mouse movement, scrolling). We use this only to fix the site. What Microsoft collects is governed by the Microsoft Privacy Statement.

5. Game providers (external sites)

Games are not served from Gemmoa’s servers. They are loaded from the servers of the game distributors (GameMonetize · GamePix · Playgama) and displayed inside our page. When you start a game you connect to that company’s server, and that company may use its own cookies or advertising. That part is governed by each company’s own policy and is not under Gemmoa’s control.

6. How long we keep it · Who we entrust it to · Sharing with others

The totals described under “What we store ourselves” are kept for as long as we need them to run the service, and deleted once we no longer do. Search terms are deleted after 90 days. The sign-in information described under “Signing in with Google” is kept until you delete your account, at which point it disappears immediately along with your lists.

Companies we entrust work to (processing on our behalf · held outside Korea)

Gemmoa does not run its own servers. We rent services from the companies below. All of them are outside the Republic of Korea.
  • Neon (United States) — the database that holds the data described above. Its servers are in Singapore
  • Vercel (United States) — where the site runs. The servers that render the pages are in Seoul
  • Google (United States) — sign-in verification, advertising and visit statistics
  • Resend (United States) — handling mail to and from help@gemmoa.com. Its servers are in Tokyo
  • Cloudflare (United States) — used only to check that you are a person on the contact form. Your IP address is passed to them at that moment
  • CPX Research (Germany, Make Opinion GmbH) — surveys and Gem rewards. Only your member number is passed when you open a survey. Your name and email address are not sent

What we entrust is exactly what is listed above, and it is held for as long as those services are provided. If you would rather it did not leave, simply use the site without signing in — then no personal information goes out at all. If you have already signed in, you can delete it from My account.

Gemmoa does not sell your data or hand it to third parties. (The companies listed above carry out work on our behalf; that is not the same as handing your data to someone else.) What Google collects on its own account for advertising and statistics is governed by Google’s policy. We comply with requests under the law only to the extent the law requires.

7. Children

Gemmoa does not knowingly collect personal information from children under the age of 14. If we learn that such information has been stored, we will delete it — please tell us at help@gemmoa.com.

8. How we protect what you entrust to us

  • We never take a password at all. Google verifies you and we receive only the result — you cannot leak what you never held
  • The sign-in cookie (gm_user) is signed, so it becomes invalid the moment it is altered, and it is blocked from being read by JavaScript. Everything travels over an encrypted connection (HTTPS)
  • The admin screens and the data behind them are locked so that only the operator can reach them
  • We do not take what we do not need — the list under “What we do not take” above is exactly that

9. Data protection officer · Contact

  • Data protection officer — the operator of Gemmoa
  • Contacthelp@gemmoa.com

Send questions about this policy, or requests to see, correct or delete your data or to stop us processing it, to the address above. We will reply within 10 days of receiving it. (You can delete your account and your lists yourself, immediately, from My account — no request needed.)

⚠️ If you write to us, or use the contact form, the address and message you give us are stored in our inbox — we need them in order to reply. We delete them once the matter is closed.

If you need help regarding personal data in Korea, you can contact the Personal Information Infringement Report Centre (privacy.kisa.or.kr · 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr · 1833-6972).

What changed

  • 18 August 2026We added surveys that earn Gems. We now disclose that we keep Gem records, and that your member number is passed to CPX Research in Germany when you open a survey. Your name and email address are not sent.
  • 14 August 2026We disclosed the search records we keep, the cookies Gemmoa sets, the companies we entrust data to and where it is held, and added sections on the data protection officer and on security measures. An English version is published alongside. With the new contact form we also disclosed what the form collects and the use of Cloudflare to check that you are a person.
  • 13 August 2026Google sign-in was introduced, so we added what we keep and how to delete it.