Privacy Policy
Last updated: September 20, 2026
Summary
Mai-Score reads your own maimai DX NET score page, a KONAMI score CSV that you explicitly select, or KONAMI PLAY DATA pages you explicitly ask it to collect. Your data is processed in your browser and remain local by default. If you explicitly connect Google Drive, your Studio history can be synchronized to your private Drive app-data folder. There is no Mai-Score account, no analytics, and no advertising. The one case where a request reaches our server is song cover art, described under Cover art below.
KONAMI page collection and score imports
On supported DanceDanceRevolution, SOUND VOLTEX, and beatmania IIDX e-amusement pages, the Extension can collect the visible text, fields, and tables from PLAY DATA pages that your current browser session is allowed to open. Collection starts only when you press the collection button, stays within the current game’s PLAY DATA area, and reports paid or sign-in-gated pages as unavailable. It does not read your password, cookies, payment fields, or hidden paid data. IIDX and SDVX can also import an official CSV you explicitly select; the original file is not uploaded or retained.
What the extension reads
When you open the popup on DX NET, the extension reads the authenticated home page once to show whether you are signed in and, when available, your player name. When you click Update Studio or the collect-only action, it requests your Best-50 pages from whichever maimai DX NET you are signed in to — maimaidx-eng.com (International) or maimaidx.jp (Japan) — using the session you already have open, and reads:
- your in-game player name and official rating
- your Best-50 chart entries: song title, difficulty, level, achievement, and cover image name
- if you enable Include Full Records, your played-chart best results from five International DX NET difficulty pages, including achievement and FC/AP/FS/FDX status
- an optional rolling recent-play list for Session tools, including local play time, chart, achievement, DX score, and visible result flags; the extension does not keep the opaque DX NET play-log identifier
The extension does not read your SEGA password, payment details, or any page other than the score pages it needs. It never transmits your DX NET session cookie anywhere; the cookie is attached by the browser to requests aimed at that same site and nowhere else.
Where your data is stored
- Your language preference is kept in the extension’s local storage on your device.
- Collected scores keep one latest maimai collection, one latest KONAMI CSV import, and one latest KONAMI page collection in the Extension’s local storage so closing and reopening the popup does not discard your work. When you open Studio, the selected result is also placed in session storage under a single-use token and handed to the Studio tab. That handoff entry expires and is removed; session storage is cleared when the browser closes.
- In Studio, your most recent snapshot and history are saved in your browser’s IndexedDB so the page survives a reload. They stay on your device, and Clear local data in Studio deletes the local copy.
- Full Records are loaded only after you select a JSON file or enable the Extension’s Full Records option. The complete chart list is retained in the latest local browser snapshot and in local history so level completion and observed best-score history survive a reload. If you opt in to Google Drive sync, Full Records snapshots and version totals are included in the same private history document. Repeated chart observations are deduplicated into a shared pool to keep that document compact.
- Recent plays are stored with their Studio snapshot in local history and, if you enable Google Drive sync, in the same private history document. Session summaries, weakness prescriptions, practice lists, and share-card images are generated in your browser. A share card contains the player name, summary, and coaching rather than the complete score list, Google data, or opaque DX NET play-log ID, and leaves the device only when you explicitly download or share it.
- Optional Google Drive sync is enabled only after you choose Connect Google Drive in Studio. After that choice, a one-click Studio update synchronizes the newly saved snapshot automatically while the connection remains active. On desktop, an already-authorized Mai-Score Extension can continue to proxy the request. On mobile or another browser without the Extension, Studio uses Google’s account chooser and requests the same limited
drive.appdatascope directly. The short-lived web access token stays in the current tab’s session storage so a page reload can remain connected; it is not saved in IndexedDB, persistent localStorage, or a Mai-Score server, and is removed on expiry or disconnect. Both paths store one history document in the hidden app-data folder of your own Drive. Google processes and stores this copy under your Google account and its privacy terms.
We do not operate a database of user scores, and the optional Drive copy does not pass through or remain on a Mai-Score server.
Cover art
Exported images include song cover art, which is not part of your score data and has to be fetched separately.
- When you arrive from the extension, the extension fetches the covers itself and embeds them before handing data to Studio. No cover request reaches our server.
- When you load a JSON file into Studio manually, Studio requests the covers through
/api/asseton our server, which relays them fromshama.dxrating.net. In this case our server sees which cover images were requested, along with the ordinary information any web server receives: IP address, timestamp, and user agent. It does not receive your player name, rating, or achievements. This proxy only accepts a fixed allowlist of image hosts and paths.
Studio is hosted on Vercel, which processes standard request logs on our behalf as part of serving the site.
What we do not do
- We do not sell your data. History is transferred to Google only when you explicitly enable Drive sync.
- We do not use your data for advertising, profiling, or credit assessment.
- We do not use your data for anything unrelated to the export, progress, completion, and sync features you request.
- We do not run analytics or tracking scripts in the extension or in Studio. Studio loads Google Identity Services only to open the account chooser when you request Drive access.
Permissions the extension asks for
- storage — save your language preference, latest local score results, and the single-use Studio handoff.
- downloads — save the image or JSON file you asked to export.
- identity — request Google consent, obtain the limited Drive token, and revoke it when you disconnect.
- maimaidx-eng.com and maimaidx.jp — read your own score pages, International or Japan.
- p.eagate.573.jp — when you request it, read accessible DDR, SDVX, or IIDX PLAY DATA pages using your existing browser session; credentials, cookies, and payment fields are never copied.
- shama.dxrating.net — fetch song cover art for the export.
- www.googleapis.com — synchronize the optional history document in Drive app data.
- oauth2.googleapis.com — revoke the Google grant when you disconnect.
Removing your data
Use Clear local data in Studio to delete Studio snapshots and history, and uninstall the extension to remove its stored preferences and latest score results. ChoosingDisconnect Google Drive in Studio revokes the active web or Extension grant and clears the local token; it does not silently delete data. Use the separateDelete cloud history action in Studio to permanently delete the Mai-Score history file from Drive app data. That action does not delete local browser history. Because nothing is kept on Mai-Score servers, there is no Mai-Score account or server-side score database to delete.
Changes
If this policy changes, the date at the top of this page changes with it. Material changes will also be noted in the project’s release notes.
Contact
Questions or reports can be raised as an issue on the Mai-Score GitHub repository.