Privacy policy
Last updated: July 21, 2026
What NoaRanks is
NoaRanks (noaranks.com) is a fan-made, non-commercial public leaderboard site for Pet Simulator 99. It ranks players and clans across supported statistics, shows rank history and comparisons, and generates shareable images. NoaRanks is an independent project — it is not Roblox, not BIG Games, and not an official Pet Simulator 99 service.
Where the data comes from
- The official public Pet Simulator 99 API — player statistics that each player has chosen to expose through their own public-view settings on the BIG Games Database, plus public clan information. This is the source for almost everything on the site.
- Public Roblox APIs — usernames, display names, and avatar thumbnails for players and clan members shown on the site.
- Optional BIG Games authorization — a read-only connection an individual player can approve for their own account (described below). This is the only data NoaRanks receives that is not already public.
NoaRanks has no user accounts and no sign-in of its own. It does not use Roblox OAuth and never asks for any password.
What is public on NoaRanks
For each ranked player, the site publishes:
- Roblox username, display name, and avatar thumbnail
- Supported leaderboard values (for example Rebirths, Playtime, Eggs Hatched)
- Ranks, ties, percentiles, and rank movement between crawls
- NoaScore (a score derived from top-10 finishes) and comparison results
- Rank history for roughly the last 30 daily crawls
- Clan membership, war contribution, and other public clan data
Player-comparison share images (1080×1080 cards showing usernames, avatars, and summary results) are generated on request and stored on a public image host so shared links keep working. Data that is missing for a player is shown as missing — it is never presented as zero.
Identity on this device
"Selecting who you are" on NoaRanks is a device-local preference stored in your browser. It personalizes highlighting, the My Ranks page, and pins. It is not an account, it involves no authentication, and it is never uploaded — clearing your browser storage removes it.
Optional BIG Games authorization
You can optionally authorize NoaRanks against your BIG Games account to sync your own stats — including participating in leaderboards without enabling any public views on the BIG Games Database. If you do, NoaRanks requests exactly one read-only permission:
player-data:pet-simulator-99:profile:read
which covers progression, currencies, statistics, mastery, achievements, and zones. Sign -in happens on BIG Games' own website; your BIG Games password is never sent to NoaRanks. The authorization is optional, separate from anything else on NoaRanks, and revocable at any time — from your BIG Games "Connected apps" page or with the "Disconnect & remove my synced data" button on NoaRanks. Authorizing NoaRanks does not enable or change your public-view settings on db.biggames.io, and NoaRanks calls no endpoint that could change them. NoaRanks does not control, and makes no promises about, the separate privacy settings and data practices of BIG Games or Roblox — BIG Games processes the data covered by an approved scope as the API provider, under its own policies.
For players who are not publicly listed, NoaRanks additionally verifies account control with a one-time code you place in your own Roblox profile description (visible to you, checked once, then discarded) before any authorized data is attributed to your name.
Wartime strategy data stays private
NoaRanks is built so competitive players can join leaderboards without exposing strategic information. NoaRanks never requests these BIG Games permissions, enforced in code and by automated tests:
player-data:pet-simulator-99:inventory:readplayer-data:pet-simulator-99:trades:readplayer-data:pet-simulator-99:booth:readplayer-data:pet-simulator-99:mail:read
That means enchant loadouts, equipped pets, inventory contents, individual item identifiers, trades, booth contents, mail contents, ultimate loadouts, and hoverboards are never requested and never intentionally displayed. Only supported extracted leaderboard values, ranks, history, and related public results are published. (If a player separately chooses to make views like inventory public on the BIG Games Database, aggregate totals from that public data — such as total RAP — may appear on leaderboards; that visibility is controlled entirely by the player's own BIG Games settings, not by NoaRanks.)
Raw data and extracted metrics
Authorized profile data is processed server-side, in memory only. NoaRanks extracts an explicit allowlist of numeric leaderboard values and discards the raw response. Raw payloads are never stored, logged, sent to analytics, embedded in images, or exposed through any API endpoint. OAuth access tokens are stored server-side only, encrypted at rest (AES-256-GCM), in a database that public clients cannot read, and are never sent to the browser or written to logs.
Cookies and local storage
- bg_session (cookie, up to 30 days) — set only if you connect BIG Games; identifies your connection so you can refresh or disconnect. HttpOnly and secure.
- bg_oauth (cookie, 10 minutes) — a random one-time value used during the BIG Games sign-in handshake to bind it to your browser; cleared when the handshake ends.
- Local storage — your device-local identity selection, pinned boards, last-visit baselines, recently viewed boards, and the
nr_notrackanalytics opt-out. None of it is uploaded.
NoaRanks uses Vercel's anonymous, cookie-less analytics (page views and web-vitals performance metrics). Setting nr_notrackin local storage disables the site's own event reporting. There are no advertising or cross-site tracking cookies.
Abuse prevention
To limit abuse of image generation and the BIG Games sign-in flow, NoaRanks rate-limits requests using a truncated one-way hash of the request's IP address, held briefly in server memory. Raw IP addresses are not stored by NoaRanks itself; standard server logs of our hosting provider may process IPs as described in their own policies.
Service providers
- Vercel — website hosting, serverless functions, and anonymous analytics
- Supabase — the site's Postgres database
- Backblaze B2 — storage for generated share images
- Roblox — public identity and avatar APIs
- BIG Games — the official Pet Simulator 99 API and the optional authorization service
Retention and deletion
- Leaderboard values are replaced by each daily crawl; rank-history snapshots are kept for roughly the 30 most recent crawls, older ones are deleted automatically.
- BIG Games access tokens expire after at most 30 days. Sign-in handshake records last 10 minutes and are cleaned up continuously.
- If you disconnect, or revoke NoaRanks on BIG Games, syncing stops and the stored token is deleted. Data that existed only because of your authorization (private-player leaderboard values and history) is deleted as well — immediately on disconnect, and within seven days of a revocation on BIG Games (revoked tokens are detected on the next sync attempt or by an automatic check that runs at least weekly). Data that comes from your own public BIG Games views republishes from public data at the next crawl and is unaffected by disconnecting.
- Generated share images are immutable public files; new data produces new images rather than editing old ones.
- Rankings that already appeared in third-party screenshots or shared images are outside NoaRanks' control.
Your choices and requests
You can disconnect BIG Games at any time on your My Ranks page, revoke NoaRanks from your BIG Games Connected apps, clear device-local data in your browser, and opt out of analytics with nr_notrack. To request access, correction, or deletion of data about you — including removal from leaderboards — email the contact below with your Roblox username. Requests are handled promptly.
Security
NoaRanks uses read-only upstream access, minimal permission scopes, encrypted token storage, deny-by-default database access for public clients, and automated security tests. No online service can guarantee absolute security; NoaRanks minimizes what it holds so there is little to lose.
Children
NoaRanks displays game statistics and does not knowingly collect personal information beyond what is described above. The optional BIG Games authorization should only be used by players who meet the age requirements of Roblox and BIG Games. A parent or guardian can request removal of a child's data using the contact below.
Changes to this policy
Changes are posted on this page with an updated "Last updated" date. Material changes to what the BIG Games authorization covers would be reflected on the authorization screen itself before you approve anything.
Contact
Privacy questions and deletion requests: noahseslar@gmail.com