What Agent Rotom stores, what stays in your browser, what a sign-in adds, and what the site deliberately does not collect.
Effective 2026-09-17
The calculator runs entirely in your browser. Your teams are saved on your device and are sent nowhere unless you choose to sign in.
No advertising is served on this site today, and the build contains no advertising code. If that changes, this page changes first — see Advertising.
The analytics on every page are cookieless — a visit count and Google Analytics, both set up to store no identifier in your browser — and no cookie is set unless you sign in. When the app itself breaks, an error report goes out — Error reports says what is in one.
Agent Rotom runs this site as a personal project, and is the one person responsible for everything described on this page. For anything here, including a request to see or delete what is held about you, write to [email protected].
Signed out, the app keeps five things in your browser's local storage, and reads none of them from a server:
agentrotom.profile.v1 — the trainer name you typed and the language you chose.agentrotom.teams.v1 — the teams you have built.agentrotom.builder.v1 — the team you are drafting in the builder and the opponents you set it against, so closing the tab does not lose the work.agentrotom.deleted.v1 — the ids of teams you deleted, so a delete on one device is not undone by another.agentrotom.onboarding.v1 — which first-run tours you have already seen.Clearing site data for agentrotom.com in your browser removes all five. Nothing about them is recoverable afterwards, by us or by you.
The site also installs a service worker so it keeps working offline. It caches the pages and files you have visited, on your device, and sends nothing.
Signing in is optional. It uses Google or Discord; there is no password, so there is no password to store or lose. What signing in writes to the database, in full:
Google and Discord each receive the fact that you signed in to Agent Rotom, because that is what an OAuth sign-in is. What they do with that is governed by their own privacy policies.
Two further rows exist only if you use the supporter tools, and are described under the supporter tools below.
Signed out, no cookie is set. Not one — there is no consent banner here because there is nothing to consent to until you sign in.
Signing in sets a session cookie. It is httpOnly, so no script can read it; sameSite: lax, so it is not sent from another site; and secure everywhere except a local development server. It is scoped to this site with no subdomains, it expires after thirty days, and it is refreshed at most once a day. It exists to keep you signed in and is not a tracking surface.
The sign-in also sets one more cookie, for about five minutes. It holds a signed random value that is checked against the one Google or Discord hands back, which is what stops somebody else's sign-in being finished in your browser. It is gone before you are signed in, and these two are the only cookies this site sets.
Signing out clears the session cookie.
Google Analytics 4 is on, and it is set up to store nothing in your browser. The property is G-KZQ29MJTSY, and the tag runs with client_storage set to none: it sets no cookie, writes nothing to local storage, and keeps no identifier from one page load to the next. The practical consequence is that it cannot tell a returning reader from a new one, and neither can the operator — every page load is counted on its own. What reaches Google is the page being viewed, the address you arrived from, and what any server can read off the request itself, including the approximate location of your IP address and your browser and device.
The app reports three things about itself, and nothing about what you build. They are: which tab you moved to inside the calculator, that a share link was asked for and how that turned out, and that a shared link was opened at the other end. Every value sent is one fixed word chosen from a list written into the source — never a team, a Pokémon, a spread, a search, or anything else you typed. Tab changes are reported because they never appear in the address bar, and so are invisible to Google otherwise.
The site is hosted on Cloudflare Pages. Cloudflare handles every request as the host and keeps the request logs any host keeps.
Cloudflare Web Analytics is enabled. It counts page views, referrers and country. It sets no cookie, stores no identifier, and does not fingerprint or follow visitors between sites.
The app reports its own crashes. This site is static documents on a CDN with no server of its own behind them, so a page that breaks in your browser leaves no trace anywhere and nobody would ever hear of it. The reporter is Sentry, run by Functional Software, Inc. in the United States, and that is where a report goes.
A report carries the error and the place in the code it came from, the address of the page you were on, your browser and its language, and a short trail of the clicks and page changes just before it. No name, no account and no email address is attached, and request bodies are switched off, so a team on its way to being saved is never inside one. Sentry's servers see the IP address a report is sent from, as any host must in order to receive it; it is not stored on the report.
Nothing is sent on an ordinary visit. The part of a tool like this that pings on every page view — session tracking — is switched off, so your browser reaches Sentry only when something has actually gone wrong. A report is deleted 30 days after it arrives.
Three, and none of them is there to follow you between sites. The fonts, the artwork, the sprites and the data files all come from agentrotom.com. What does not: the visit-counting beacon described above and Google Analytics, both of which load on every page — the Analytics tag from googletagmanager.com, sending what it measures to google-analytics.com — and the error reporter, which your browser contacts only when something has broken. All of them see the IP address the connection comes from, the way any host does.
Everything else is something you start: signing in sends you to Google or to Discord, and connecting the supporter tools to an AI assistant opens the sign-in flow described below.
No advertising is served on this site today. No ad network's code is in the build, no ad cookie is set, and no reader's browser contacts an ad server because of this site.
Advertising is being considered. If it is introduced, this page will be updated before the first ad is served, and the update will name the network, say what cookies or identifiers it sets, and link to the way out. Readers in the EEA and the UK will be asked for consent through a certified consent platform before any personalised ad is served.
The paragraph below is a draft for the day ads ship, and it must not be published before they do. It is shown here so the wording is settled in advance; it is not a description of the site as it stands.
Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this site or to other sites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and other sites on the internet. You can opt out of personalised advertising in Google's Ads Settings, and you can opt out of a third-party vendor's use of cookies for personalised advertising at aboutads.info.
The meta board is built by reading public Pokémon Showdown replays and folding the teams in them into a list of distinct builds. Two choices in how that is stored are worth stating, because they are the difference between a corpus about teams and a corpus about people — and one further thing is worth stating because the tables do record it:
No account identity is kept, hashed or otherwise. Not the player's Showdown name, not a hash of it, not a salted hash of it. There is nothing in the table a name could be recovered from or checked against, because nothing derived from one was ever written.
Times are kept to the day, on purpose. Each build and each team composition records the first and last day it was seen, and no clock time is stored against either. A precise timestamp on a rarely-seen team narrows it to a handful of public battles and from there to a person; a day does not.
For each day, the corpus also records how that day went. For a given build or team composition and a given day it was played, one row counts the sightings; how many of those came from a battle log complete enough to say anything further; and, of those, how many reached a result, how many were won, how many were rated, and how many were tournament rather than ladder games. It also counts how many of those logs recorded a final turn number, and adds those numbers together. On a day when a build was seen once, that row therefore describes one battle: whether it was rated, whether it was won, and how many turns it lasted. Nothing in it names or points to a player.
Separately: nothing you build in the calculator is sent anywhere. The analysis of your team happens in your browser, on your device, and there is no event, no ping and no telemetry behind it. Two things can leave, and neither of them is your team. One is an error report when the page itself breaks, which carries the fault — see Error reports. The other is a bug report, if you choose to send one: the button on the profile tab opens a draft in your own mail program, prefilled with which build and regulation the app is on, the language you are using, whether you are signed in but never who, how many teams you have (a count, not the teams), the size of your browser window and its pixel density, whether the app's offline cache is active, your browser's user agent, and the time the draft was opened. It is a draft: you read it, you edit it, you delete any line of it, and nothing is sent until you send it.
Agent Rotom offers an MCP server, so a supporter can query the same data from an AI assistant, and list, save and delete their own stored teams through it. It runs separately from the site and is reached only with a bearer token, and it keeps four things: whether your account may use it at all — your account id, the date that entitlement runs out if it has one, where it came from, and a per-account call limit where one has been set; the granted authorisation — your account id, your email address and the scopes you approved; a count of how many calls your account has made today, so one heavy reader cannot starve the rest; and a daily count of anonymous client registrations, which is a number with no identity attached to it.
If you do not use it, none of the above exists for you.
Where the law where you live gives you rights over your data — to see it, correct it, take it elsewhere, or have it erased — those rights apply, and the address above is how to use them.
This site is a competitive-play tool and is not directed at young children. No age is asked for anywhere on it, and none is stored: no account is required to use the site, and nothing about a reader is collected unless they sign in.
Signing in is possible only through a Google or a Discord account, and each of those services sets its own minimum age. If you are a parent or guardian and believe a child has signed in here, write to [email protected] and the account, and the teams saved against it, will be deleted.
When this notice changes materially, the date at the top of the page moves and the change is described here. A change that introduces a new recipient of your data — an advertising network above all — will be published before it takes effect, not after.
2026-09-17 — Google Analytics was switched on, set up to place no cookie and to store no identifier in your browser. It was described here before the tag shipped; Analytics says what it sends and what it cannot do.
2026-09-17 — A bug report button was added to the profile tab, which opens a draft in your own mail program and sends nothing on its own; What is deliberately not collected says exactly what the draft contains.
Questions: [email protected].