Magic Random

PDPA · Privacy Notice

Privacy Policy

A clear explanation of what Magic Random stores, how it is used, and how you stay in control.

Randomizer data stays local; feedback is stored only when you submit it

Randomizers, history, and core settings stay in localStorage on your device. Feedback is the exception stored in a database as described below, alongside technical information and Google service data depending on your use and consent.

Core data stays local

Randomizers and history stay in localStorage

Feedback is submitted by choice

Your name, email, and message are stored only when you submit them

Google services require acceptance

Analytics, AdSense, and reCAPTCHA do not load until you accept

1. Information the site stores

Magic Random stores list names, choices, participants, prizes, draw results, in-list history, language, theme, accent color, and other settings in your browser's localStorage on your device.

The site has no account system and does not send randomizer content to a Magic Random database. Feedback is a separate feature and receives information only when you complete and submit its form.

The browser also stores your PDPA acceptance status so it can remember whether you accepted Google Analytics and Google AdSense.

2. Feedback and public comments

When you submit feedback, the site stores your display name, email, category, message, language, and submission time in PostgreSQL. Your name, category, message, time, and like count are public. Your email is not returned by the public API or displayed on the site.

Your email is used only if the operator needs to contact you about your feedback or report. Do not include passwords, financial or health information, or another person's personal information in your public name or message.

Before accepting feedback, the site requires Google reCAPTCHA and verifies its token on the server to prevent spam. Google may receive your IP address, browser and device information, and interactions needed for verification. The site does not store the reCAPTCHA token in the feedback database.

When you like feedback, the site creates a random visitor cookie and stores a one-way hash in the database to limit each browser to one like per comment. Pressing the button again removes the like.

3. Technical information

When you open the site, infrastructure and hosting providers may process basic request information such as IP address, browser type, time, and requested page to deliver the site, prevent attacks, diagnose errors, and maintain security.

This technical information is separate from the randomizer content stored on your device and is subject to the relevant provider's policies and retention periods.

4. Purposes and processing grounds

Essential storage is used so creating, editing, playing, and remembering settings work as you request. The consent record remembers your acceptance.

Feedback is processed following your submission and confirmation to publish comments, contact you, prioritize suggestions, investigate problems, and prevent abuse.

Before you accept, the site does not load Google Analytics, Google Ads, Google AdSense, or reCAPTCHA. After acceptance, Analytics operates for measurement, reCAPTCHA loads only on the Feedback page, and the AdSense script loads when configured by the operator. Ads can appear only after Google grants the applicable approval and ad inventory is available.

Technical information needed for security and delivery may be processed as necessary to provide the service, for legitimate interests, or to meet legal obligations, depending on the provider and applicable law.

5. Google Analytics, Google Ads, AdSense, and reCAPTCHA

When you press “Accept and continue,” the site loads Google Analytics 4 and updates consent. If AdSense is configured, its script may load while Google is reviewing the site, but an ad placement can appear only when the account and site are ready and an ad is available for that request.

When AdSense is allowed, Google may process cookies, device identifiers, IP address, visited URL, referrer, browser information, usage events, and campaign data for measurement, ad delivery, fraud prevention, and service improvement.

The site sends non-identifying events such as creating a randomizer and completing a result, together with randomizer type, option count, and language for usage and conversion measurement. These events do not include list titles, participant names, choice content, prizes, or draw results.

Google and its partners may use advertising cookies to serve ads based on prior visits to this site or other sites. You can manage or opt out of personalized advertising through Google Ads Settings.

Google reCAPTCHA is used only to prevent automated feedback submissions. Its result is short-lived, single-use, and does not replace validation of the other form fields.

Before acceptance, Magic Random uses only essential storage and does not load Google Analytics, Google Ads, Google AdSense, or reCAPTCHA scripts.

6. Retention

Randomizers, history, and settings remain on the device until you delete a list, clear data from Settings, clear site data in the browser, or uninstall the web app.

Your PDPA acceptance remains until you clear site data or the site needs to request consent again after a material change.

Feedback is retained for community display and product follow-up until the operator removes it, it is no longer needed for those purposes, or you request deletion through the privacy contact. The like cookie lasts for up to one year and can be removed by clearing site data.

7. External providers and transfers

Hosting and network providers may process technical information to deliver the site. Google receives information from Analytics, advertising services, and reCAPTCHA after consent and when the relevant feature is used. These providers may process information in other countries according to their infrastructure and policies.

Database and hosting providers process feedback to store it and serve the API on Magic Random's instructions, and may process it in other countries according to their infrastructure and terms.

Magic Random does not sell your randomizer content or share that content with advertisers.

8. Your rights and controls

Subject to applicable law, you may have rights to access, correct, erase, restrict or object to processing, receive or transfer data, withdraw consent, and complain to a supervisory authority.

Because core list data stays on your device and Magic Random has no user accounts, you can access, edit, export where available, or delete it directly through the site and browser settings. For information processed by Google, use Google's settings and request channels.

For feedback, you can contact the operator to request access, correction, or deletion. Use the same email address submitted with the feedback to help verify the request.

9. Security and precautions

Device-local storage reduces transmission of list content to a server, but anyone with access to your browser profile, device, extensions, or backups may be able to access it. Secure your device and do not place sensitive information such as passwords, health data, or financial data in randomizer lists.

This notice may be updated when features, providers, or relevant requirements change. The latest revision date appears below.

10. Operator and contact

This service operates under the name Magic Random. You can view, edit, or delete device-local list data directly through the site and browser settings. For data processed by Google, use Google's channels linked above.

Privacy contact: techelegance.company@gmail.com

Last updated August 29, 2026