Ctrl K

Privacy Policy

Last updated: 22 August 2026

TeioStep is a free, unofficial fan tool for Umamusume: Pretty Derby, operated by a private individual. This policy explains what data the site handles and why. It collects as little as possible.

1. What we collect

•  Account: your username and password. The password is stored only as a salted hash, so it cannot be read back.

•  Discord sign-in (optional): only your Discord user ID. We request the minimum "identify" scope. We do not receive or store your email, avatar, real name, or Discord password. Your Discord username is read once to suggest an account name and is not kept afterward; the ID is all that links your TeioStep account to Discord.

•  Content you create: decks, support and character rosters, and race plans you choose to save, so they follow your account across devices.

•  On your device: preferences (theme, toggles) and unsaved working state, kept in your browser's local storage. This stays on your device unless you sign in and save.

•  Technical: standard server logs (IP address, browser user-agent, request time) for operating and securing the service, and one encrypted sign-in cookie (about 30 days).

•  Discord bot, per server: if the TeioStep bot is on a Discord server, it counts how often each of its commands is used there. That is the server's ID, name and member count, the command name, and the hour. It does not record who used a command, which channel it came from, or anything from your messages, so these counts are not tied to you.

2. The Capture App

The Capture App is a separate Windows program you download and run yourself. It reads the game's Umamusume Details window off your own screen and writes what it read to your own disk. It does not touch the game's files, its memory or its network traffic, and it sends no captures, screenshots or usage data anywhere.

•  What reaches us: the app fetches character, support card and skill icons from TeioStep so it can draw what it captured. Those are ordinary requests for public images, and they appear in our server logs like any other request, with the IP address, user-agent and time described above. They carry no account, no cookie and nothing about what you captured.

•  What stays on your machine: everything else. The screenshots and the records read from them are files on your PC until you choose to import them here.

•  If you import them: importing uploads the file you picked, screenshots included, because the review shows you the picture behind every value it is unsure about. Reading the text off them runs on our server. The upload is held only while the import panel is open and is deleted when you close it; what is kept afterwards is the records you chose to save, under your account, and not the screenshots.

3. How we use it

We use this data only to run the service: to sign you in, save your builds, and protect against abuse. The bot's per-server counts are used to see where the bot is worth keeping and which commands are worth working on. We do not show ads, build advertising profiles, or sell your data.

4. Who else processes it

•  Neon hosts the database (EU region) that stores your account and saved content.

•  Discord is involved only if you use Discord sign-in; that exchange is governed by Discord's privacy policy.

•  Our hosting provider runs the server the site is served from.

We do not sell or share your data for marketing.

5. Cookies

The only cookie is an essential, encrypted sign-in cookie that keeps you logged in. There are no analytics or advertising cookies.

6. Where data is stored

Account and saved data are stored in a database hosted in the European Union.

7. Retention

Account and saved content are kept while your account exists. Server logs are kept only briefly and then rotated. The bot's per-server counts are kept for 180 days. If your account is deleted, its data is removed.

8. Your rights

Under the GDPR you can request access to, correction of, export of, or deletion of your data, and object to certain processing. Account deletion is currently handled on request; contact us using the details below and we will action it.

9. Security

Passwords are stored hashed, traffic is served over HTTPS, and the sign-in cookie is encrypted. No method of storage or transmission is ever completely secure.

10. Children

The service is not intended for anyone under 13 (or the higher minimum age required in your country or by any sign-in provider you use).

11. Changes to this policy

We may update this policy from time to time. The "last updated" date above will change when we do.

12. Contact

Privacy questions or data requests (including account deletion): luca@trenz.de.

An unhandled error has occurred. Reload 🗙

Connection lost. Reconnecting to the server…

Couldn't reconnect. Retry

Your session has expired. Reload the page