Privacy Policy
Last updated 29 July 2026 · UK GDPR & Data Protection Act 2018
1. What we collect
- Account data — email, display name, and profile images you choose to upload (stored via Firebase Authentication and Firestore).
- Creation data — the game concepts (prompts) you submit, the blueprints and game code the AI produces for you, and the games you publish.
- Wallet & payment data — your ACU balance, ledger of top-ups and spends, and payout records. Card details go directly to Stripe; we never see or store card numbers. Payout destinations are stored tokenised.
- Usage telemetry — anonymous per-tab session events (game forged, playtest started, game played, link shared) used to run creator analytics and platform health. Telemetry uses random session ids, not tracking cookies.
- Technical logs — standard server logs (IP, user agent, timestamps) kept short-term for security and debugging.
2. What we use it for (lawful bases)
- Running the service you asked for — forging, hosting, and paying out (contract).
- Fraud prevention, moderation, and platform security (legitimate interest / legal obligation).
- Payment records and tax (legal obligation).
- Product emails you opt into (consent — withdraw any time).
We do not sell personal data, and we don't use your private prompts or unpublished games to train AI models.
3. Who processes it for us
| Processor | Purpose |
|---|---|
| Vercel | Website and API hosting |
| Google (Firebase / GCP) | Authentication, profiles, backend functions |
| Neon | Postgres database — financial ledger, wallets, hosted games |
| Stripe | Payments, subscriptions, payouts (independent controller for card data) |
| Anthropic | AI generation — your prompt text is sent to produce your blueprint/game |
Transfers outside the UK/EEA rely on the processors' standard contractual clauses / UK addendum.
4. How long we keep it
- Account and creation data — while your account is open, then deleted or anonymised within 90 days of closure.
- Financial ledger records — 6 years (UK tax and accounting law).
- Telemetry — aggregated; session-level events pruned within 13 months.
5. Your rights
Under UK GDPR you can ask for access, correction, deletion, restriction, portability, and object to legitimate-interest processing. Use the contact page; we respond within one month. If unhappy, you can complain to the ICO (ico.org.uk).
6. Cookies & local storage
We use local storage for your session, profile cache, and PWA offline shell — strictly functional, set without asking because the site cannot work without them.
Advertising cookies — only if you say yes. We use the Meta Pixel and the Google tag to measure which adverts actually bring creators here. Neither loads until you accept: before you choose, no third-party script is fetched, no request is made to Meta or Google, and no advertising cookie is set. Decline and none of it ever runs — the site behaves identically. You can change your mind by clearing this site's data in your browser, which brings the choice back.
Separately, and regardless of that choice, we count page views with our own first-party beacon. It stores nothing on your device and keeps only the host a visit came from, never a full address — so it is not something we ask consent for, and it is how we still understand our own traffic when you decline.
7. Children
Play is 13+; purchasing is 18+ (or guardian consent). We don't knowingly collect data from under-13s — tell us and we'll delete it.
8. Changes
We'll post updates here and date them; material changes get an in-product notice.