Last updated: 31 August 2026
1. Scope
This Privacy Policy explains how RuMai handles information when you use the RuMai website or Discord bot. RuMai is an unofficial fan project and is not affiliated with SEGA, maimai, Google, Discord, or other services linked from the app.
2. Information we collect
Depending on the features you use, RuMai may handle:
- account information such as username, display name, email, password hash, locale, region, and account timestamps;
- Google or Discord account identifiers and the profile information returned during sign-in or account linking;
- maimai profile information, avatar URL, ratings, play counts, titles, imported peaks, scores, play dates, combo values, and related tracking data;
- scores, notes, profile content, group membership information, invitations, join requests, rival data, and submitted song aliases;
- photos or other files that you upload for score entries or profile features;
- Discord user IDs, command inputs, link information, and bot interaction data; and
- session, locale, theme, and game-region cookies or related technical information needed to operate the service.
3. maimai NET and Aime data
NET import and Aime login are optional. If you use them, RuMai may receive profile and score information from maimai DX NET and may temporarily handle or store the cookie, token, or SEGA credential needed to perform the requested import. These credentials are used to communicate with the relevant SEGA or maimai services, not as RuMai login credentials.
NET secrets are encrypted at rest by the application. Do not submit another person's credentials, and do not share Aime guide URLs containing a temporary passcode. You can use RuMai without enabling NET import.
4. How we use information
RuMai uses information to:
- create and secure your account and session;
- provide sign-in, account linking, and email verification;
- import, calculate, display, and compare your scores and achievements;
- operate groups, invitations, rival comparisons, aliases, and Discord bot commands;
- store uploads and generate requested share images;
- send service and verification emails; and
- protect the service, investigate abuse, and maintain backups.
5. Sharing and visibility
RuMai does not make every piece of account data public. Group members can see the group information and rival results that the group features expose. Profile information, avatars, generated images, and uploaded content may be visible to other signed-in users or group members according to the feature used.
Discord commands and generated B50 or share images may be visible in the Discord channel where they are used. Administrators may access account information when needed to operate, secure, or support RuMai.
6. Service providers and external services
RuMai relies on third parties to provide parts of the service. This may include Google OAuth, Discord OAuth and Discord Gateway, email delivery, SEGA and maimai DX NET endpoints, and catalog or image hosts. Those services receive information according to the requests you make and their own terms and privacy policies.
RuMai also retrieves public song, chart, jacket, and version data from community and official catalogs. These catalog requests are separate from your private score and account data. Information may be processed or stored in countries different from where you live.
7. Cookies and security
RuMai uses an HTTP-only session cookie to keep you signed in and preference cookies for language, theme, and game region. Server-side sessions expire and are removed when they are no longer valid. Cookies can be controlled through your browser, although disabling the session cookie will prevent account features from working.
RuMai uses scrypt password hashing and application encryption for stored NET secrets, along with access controls for account and group data. No online service can guarantee absolute security. If you believe credentials or private information were exposed, contact RuMai promptly and change the affected third-party credentials.
8. Retention and deletion
RuMai keeps information while it is needed to provide the feature, maintain account security, resolve disputes, or meet operational requirements. Expired sessions and temporary login records are removed according to their expiration handling.
You can request account deletion through account settings or the support channels. Account deletion removes live account records supported by the deletion flow, including stored credentials and most associated score data. Backups, operational logs, support records, uploaded files, or copies already shared with other users may remain for a period of time. Content shared in Discord is also subject to Discord's retention and deletion behavior.
9. Your requests
Depending on applicable law, you may ask to access, correct, delete, or receive an explanation about personal information held by RuMai. We may need to verify account ownership before processing a request. We may also retain information where necessary for security, fraud prevention, legal obligations, or legitimate operational purposes.
To contact us, use the About page, the RuMai Support Discord by contacting djcaitlyn_, or the RuMai Report GitHub repository. Do not include passwords, tokens, cookies, or other secrets in a public issue.
Developer
RuMai is developed and maintained as an independent fan project.
Contact djcaitlyn_ on the RuMai Support Discord. Public bug reports and feature requests can also be submitted to the RuMai Report GitHub repository.
10. Changes to this policy
This policy may change when RuMai's features, providers, or legal obligations change. The effective date above will be updated when material changes are published. Using RuMai after an update means you acknowledge the revised policy.