PalManager is self-hostable software. When you connect to a server, your data is processed and stored by that server's instance and controlled by its administrator (the "Operator") — for example, the operator of a server hosted at a *.palworldmanager.com address. This policy describes what the app and hosted consoles collect and how it's used; your Operator's own instance also serves this policy at /privacy.
Account & sign-in.Your in-game character name and — depending on how you sign in — either the one‑time link code exchange or the Steam ID that Steam returns to us when you use Steam sign‑in, plus the resulting session and remember tokens (valid up to 180 days). In the mobile app, tokens are stored in the operating system's secure keychain and sent as request headers. In a web browser, the same tokens are kept in strictly‑necessary cookies (pm_player and pm_remember) so that you stay signed in; they are never used for advertising or tracking.
Gameplay data. Your pals, inventory, technology, progress, bases, guild, map markers and similar game state. This is read from the Palworld server's save data — it already exists on your Operator's server; the Service presents it and caches it on your device for speed.
Store & wallet. Your credit balance, orders, crate history and marketplace listings live on the server. For top-ups we receive a purchase receipt from Apple or Google (platform + transaction ID) to verify it and credit your wallet; receipts are kept to prevent double-redemption and to process refund reversals. Web payments are processed by Stripe. Card numbers never reach PalManager.
Push notifications (optional). If you enable them, the app registers an Expo push token with the server so it can alert you about eggs, expeditions, raids and deliveries. Your notification preferences are stored server-side. The token is unregistered when you sign out or disconnect.
Discord (optional). If you link Discord, a one-time OAuth flow shares your Discord ID and username with the server so it can recognize you and auto-join you to the community guild. Unlinking in-app removes the link (it does not remove you from the guild).
Camera (optional). The QR scanner uses your camera solely on-device to read a connect code. No images are stored or uploaded.
No advertising identifiers, no third-party analytics or tracking SDKs, no contact lists, no precise location, no payment card details. The app's "demo mode" runs entirely on bundled sample data and sends nothing anywhere.
To sign you in and keep you signed in; to show your live server and character data; to operate the store, crates, marketplace, automations and inbox; to verify purchases and reverse refunded ones; to deliver the notifications you asked for; and to keep the Service secure and abuse-free. That's it.
Data is shared only with: your Operator's server instance (that's where it lives); Apple and Google, to verify in-app purchase receipts; Stripe, if you pay on the web; Discord, if you choose to link your account; and Expo's push infrastructure, if you enable notifications. Some in-game information — your character name, level, leaderboard standings, marketplace listings and crate-pull feed entries — is visible to other players on your server by design. We never sell personal data.
Sessions expire; remember tokens last up to 180 days and are revoked on sign-out. Gameplay data persists as long as the game server keeps its save. Wallet and purchase records are kept for the life of the instance for ledger integrity — on account deletion they are anonymized (tombstoned) rather than dropped, so the server's books still balance without pointing at you.
Sign out revokes the current device server-side and clears its stored credentials. Notification toggles (master, eggs, expeditions, raids, deliveries) control exactly what the server may send. Unlink Discord any time in Settings.
Delete your account from Settings → Danger zone. Deletion removes your sign-in link and devices, anonymizes the credit wallet and purchase records, and clears cached character data and inbox messages. Your Palworld game save on the server is untouched — it belongs to the game server. If you also want your in-game character removed, ask your Operator.
Tokens are stored in the platform keychain on device (iOS Keychain / Android Keystore) and sent over HTTPS as bearer headers. Purchase receipts are verified cryptographically server-side (Apple receipts against Apple's pinned root certificate; Google purchases against the Play Developer API). No system is perfectly secure — use a server run by someone you trust.
The Service is not directed at children under 13 (or the equivalent minimum age in your region), and follows the age rating of the app stores it's published on. Operators are responsible for who they invite to their servers. If you believe a child's data was collected improperly, contact the Operator and us and we'll help remove it.
We'll post any material changes here with a new effective date. Questions or requests: our Discord — or your Operator for data held on their instance.