Last updated 29 August 2026. The companion data policy lists every stored field.
The short version
gmichi.fun is a site of free browser games. You can play everything without an account. To appear on a leaderboard you pick a name; that name, your scores and two random ids are all a guest leaves behind. If you create an account, we also hold the email address and password you register with, in Amazon Cognito, so you can sign in on another device. We do not sell, share or trade any of it, and there are no ads.
Who runs this
gmichi.fun is run by its developer, who you can reach on X at @lil_runnr. That is also the contact for anything in this policy: a question, a correction, or a request to see or delete what is held about you.
What is collected, and why
- As a guest: the leaderboard name you type, your personal best in each game, the time it was set, and two random identifiers your browser generates (one so a submission overwrites your own row and not someone else's, one so the page can highlight your row). Purpose: to run a leaderboard. Nothing here identifies you as a person unless the name you choose does.
- With an account: the handle you choose, your email address, your password (stored by Amazon Cognito as a hash; this site never sees it after your browser sends it to Cognito over HTTPS), whether the email was verified, and the times you signed in. Purpose: to let you sign in, to send you a verification or password-reset code, and to give you a leaderboard name nobody else can post under. The email is used for those codes and nothing else - no newsletters, no marketing.
- Your IP address is seen by the servers that answer every request, as with any website. The leaderboard API keeps it for about two minutes to limit how fast one address can post scores, then it expires. It is not attached to your scores or your account.
- Analytics. The site includes Google Analytics, configured with IP anonymisation on and advertising features off, and switched off entirely for browsers that send Do Not Track or Global Privacy Control. It records page views and a handful of game events (a game opened, a run scored). It does not receive your name, email or scores. If the analytics id has not been configured it makes no request at all.
What is not collected
No advertising identifiers, no fingerprinting, no tracking pixels, no third-party scripts. The site does not ask for your location, contacts, camera or microphone, and its security policy tells the browser to refuse them. Game saves - the Michidex, the Meowney Printer bank, a Michordle streak - live in your browser's storage and never leave it.
Where it lives
On Amazon Web Services in the United States (us-east-1): scores in a DynamoDB table, accounts in a Cognito user pool, the site itself on S3 and CloudFront. Amazon's own handling of that infrastructure is covered by the AWS privacy notice. If you are in the EU or UK, that means your data is transferred to the US; the legal basis for holding it is your consent, which you give by picking a name or creating an account, and which you can withdraw by deleting them.
Third parties that see your requests
- Amazon Web Services - hosts everything (see above).
- Amazon Cognito - your browser talks to it directly to sign up, sign in and reset a password, so Amazon sees those requests.
- Google Analytics - when configured and not opted out, as above. Google's policy.
- DexScreener - the $michi price shown in the navigation bar is fetched from api.dexscreener.com, which sees your IP address as part of that request. No other data goes with it, and the site works without it. Their site.
Nobody else. The site loads no fonts, scripts, images or media from anyone but itself.
Cookies and browser storage
The site sets no cookies of its own. It uses localStorage
for your personal bests, name, ids, sound setting, game saves and, if
signed in, your session tokens. Google Analytics, when it is enabled, sets
its own cookies to recognise a returning browser.
How long it is kept
Leaderboard rows stay until you beat them, delete them, or the site shuts down. An account stays until you delete it. Error logs from the leaderboard service are kept for 14 days and do not contain names, emails or IP addresses. Rate-limit records expire after about two minutes.
Your rights, and the buttons that exercise them
- See it: everything held about an account is shown on the account page after signing in - handle, email, and every best. A guest's data is the name and bests visible on the boards and in this browser.
- Delete it: the account page has a Delete account button that removes the Cognito user and every score it holds, and a Remove my scores button for guests. Both are immediate.
- Correct it: a guest can change their name at any time. An account's handle is fixed; contact us for anything else.
- Anything else - access in a portable form, a complaint, a question - contact @lil_runnr. If you are in the EU, UK or a jurisdiction with a data protection authority, you also have the right to complain to it.
Children
You must be 13 or older to create an account. Guests do not give us any personal data beyond a self-chosen name, but if you believe a child under 13 has registered, contact us and the account will be deleted.
Security
Everything is served over HTTPS. Passwords are handled entirely by Amazon Cognito. The scores API verifies a signed session token before it treats a submission as yours, and a player's private write key is never returned by any endpoint. Leaderboard scores themselves are computed in your browser and cannot be authenticated - so treat the boards as a game, not a record.
The $michi price and buy links on this site are provided for interest. This site is not affiliated with any exchange, does not hold funds, and never asks for a wallet. Nothing on it is financial advice.
Changes
If this policy changes in a way that matters, the date at the top moves and the change is noted on the what's new page.