YOUR TIME. YOUR SKYLINE.
Privacy in City Jumper
Last updated September 13, 2026.
You can play City Jumper without an account. Signing in lets you save progress and earned cosmetics. City Jumper has no advertising, and we do not sell player information.
What the game saves
- Classic guest scores: when you submit a classic rooftop score, we save the nickname you choose, score, distance, obstacles cleared, stage, run duration, submission time, and a run identifier. Submitted nicknames and run results can appear on the public classic leaderboard. Choose a nickname you are comfortable sharing. Guest stage, map and challenge runs do not create named account leaderboard entries.
- Daily Rush comparisons: online Daily Rush results can contribute to an anonymous score distribution for that date. We keep one best verified result per account or guest browser, including failed runs. The public graph shows score-range counts rather than names or individual guest identifiers. Your own best score and placement are shown to you. The comparison uses a pseudonymous entry for each daily date; account identity and guest browser identity are not published in the graph.
- Daily attempts and optional feedback: we count newly registered Daily Rush attempts and their verified completed, failed or quit outcomes. Repeat attempts count separately; these totals are not unique-player or retention measurements. If you choose to send feedback after a played attempt ends, we save your difficulty and readability choices, an optional encountered row and a revision with that run. You can update the response from its result screen. Only grouped counts are public, including how many ended attempts were eligible to respond. Earlier untracked registrations are excluded. Feedback never changes scores or rewards and is not joined across daily courses to track you.
- Player accounts: we save an internal player identifier, your chosen public nickname, gameplay totals, personal records, achievements, earned cosmetics, and equipped appearance. The game API uses your identity provider's verified identifier to associate these records with you.
- Creator maps: we save your draft geometry, title, description, version history, playtest completion receipts, and submission status. Submitted versions are visible to you and the reviewer; approved versions, creator nicknames, and account-linked map records are public. Review decisions, reasons, and reviewer identifiers are retained for moderation. Guest map runs do not create named map leaderboard entries. Approved creator collections group public maps using a separate opaque creator identifier. When signed in, you can save up to 100 favorite map identifiers to your account; these private favorites sync across devices and stay separate from guest favorites.
- Map and challenge verification: the game sends bounded jump-input timing to verify completed maps, rooftop trials, and daily courses. Stored receipts include the course version, daily date where applicable, completion time, hits, and a replay fingerprint used to recognize retries. Completed account runs can award map badges or challenge medals. Account challenge records display your public nickname, time, hits, and medal; guest finishes do not create named challenge records. Practice lessons stay on your device and do not submit scores.
- Sign-in: Microsoft Entra External ID manages Google sign-in and emailed one-time codes. Microsoft processes your sign-in email and identity information. If you choose Google, Google shares the basic identity information requested on its sign-in screen with Microsoft. City Jumper does not receive your Google password or request access to your Gmail messages, files, or contacts.
- Service operation: hosting and identity providers process connection details and security logs needed to operate the service. Our rate-limit records use short-lived, keyed identifiers derived from the requesting address rather than storing a raw address in leaderboard records.
Storage on your device
The game uses browser storage for preferences such as sound and your nickname, favorite community-map identifiers, daily personal bests, and recovery copies of unsaved creator-map edits associated with the signed-in player and draft revision. Guest favorites and device bests remain on this device. Signed-in map favorites are stored privately on the server; the game does not automatically copy guest favorites into an account. Session storage holds sign-in state, temporarily retains unconfirmed stage results with their original run owner for exact retry, and can retain a completed endless guest run while you sign in so you can add that run to your account. Up to five pending rooftop-trial finishes per runner are retained in local storage with their original course, private retry credential and exact jump-input request, including after a tab closes. They stay until accepted or explicitly discarded; cleanup removes the credential and inputs. Older tab-session trial requests migrate without changing their original owner or proof. Course exports contain only the title, description, and geometry; importing creates a separate private draft. Clearing browser storage removes these local preferences and recovery copies; it does not delete maps or scores already submitted to the server.
Optional missed-row practice keeps one recent City Rush or Daily Rush encounter on this device for up to seven days. It contains the course, row, speed, pickup state and original runner association, without sign-in or retry credentials. It is replaced by a later missed row and expired data is removed when read. Practice stays local and submits no gameplay or feedback. Clearing browser storage removes this practice copy.
For anonymous Daily Rush comparisons, we use a signed first-party browser cookie containing a random identifier, valid for 30 days. It is HttpOnly, so page JavaScript cannot read it. We do not use device fingerprinting to identify a runner. A different browser, a cleared or expired cookie, or a different account can create a separate entry. The graph therefore counts account or browser entries, not guaranteed unique people. Changing or clearing the cookie does not remove a result already included in a daily distribution.
How information is used and retained
We use game records to save progress, display rankings, award cosmetics, prevent duplicate rewards, and troubleshoot the service. Game and account records remain stored until removal is requested or the service is retired. Temporary guest-run claims are limited by their run registration. Infrastructure and identity security logs follow the providers' applicable retention settings.
Personal replays and friend challenges
Accepted jump recordings can stay on this device for up to 30 days, with eight recordings per runner, 32 per device, up to 16 unfinished captures and a 6 MB overall limit. They contain course identity and accepted inputs, without sign-in or retry credentials. Remove them in Replays & friends. Expired optional recordings are cleared when you next open that library or capture a run. Exact creator-finish recovery requests are stored separately with their original owner until accepted or explicitly discarded; clearing them can prevent a pending finish from being recovered.
Publication is optional and requires the account that earned the result. If you choose to publish, the server verifies the complete recording and saves your chosen public alias, course identity, score and accepted inputs. Anyone with the link can read them for up to 30 days. Remove a shared replay or friend challenge in Replays & friends. Removal or expiry stops public playback and new challenge runs; already accepted private results remain recoverable. Replay input chunks are deleted on removal, expiry access or bounded cleanup during publication/library use. A minimal removed identifier prevents old links from being revived.
Friend challenges pin one course and keep separate scoreboards. Account participants appear under their existing public player nickname; guests can play without a named board entry. These runs do not award official progress or change daily comparisons. An optional OBS browser link reads the public challenge scoreboard every ten seconds. Replay aliases and friend boards are separate from anonymous daily comparison subjects.
Service providers
The game and its records are hosted on Microsoft Azure. Sign-in is handled by Microsoft Entra External ID and, when you select it, Google. Their handling of information is described in the Microsoft Privacy Statement and Google Privacy Policy.
Your choices and contact
You can keep playing as a guest, sign out, change your public nickname in the wardrobe, or stop submitting scores. To request access to or removal of your City Jumper account or submitted records, contact ehayestrainer@gmail.com. We may need to verify that the account or run belongs to you before changing it. Account and identity-provider deletion are handled together when requested; clearing browser storage alone does not perform either action.