Privacy Policy
Last updated 29 July 2026 · UK GDPR & Data Protection Act 2018
1. What we collect
- Account data — email, display name, and profile images you choose to upload (stored via Firebase Authentication and Firestore).
- Creation data — the game concepts (prompts) you submit, the blueprints and game code the AI produces for you, and the games you publish.
- Wallet & payment data — your ACU balance, ledger of top-ups and spends, and payout records. Card details go directly to Stripe; we never see or store card numbers. Payout destinations are stored tokenised.
- Usage telemetry — anonymous per-tab session events (game forged, playtest started, game played, link shared) used to run creator analytics and platform health. Telemetry uses random session ids, not tracking cookies.
- Technical logs — standard server logs (IP, user agent, timestamps) kept short-term for security and debugging.
2. What we use it for (lawful bases)
- Running the service you asked for — forging, hosting, and paying out (contract).
- Fraud prevention, moderation, and platform security (legitimate interest / legal obligation).
- Payment records and tax (legal obligation).
- Product emails you opt into (consent — withdraw any time).
We do not sell personal data, and we don't use your private prompts or unpublished games to train AI models.
3. Who processes it for us
| Processor | Purpose |
|---|---|
| Vercel | Website and API hosting |
| Google (Firebase / GCP) | Authentication, profiles, backend functions |
| Neon | Postgres database — financial ledger, wallets, hosted games |
| Stripe | Payments, subscriptions, payouts (independent controller for card data) |
| Anthropic | AI generation — your prompt text is sent to produce your blueprint/game |
Transfers outside the UK/EEA rely on the processors' standard contractual clauses / UK addendum.
4. How long we keep it
- Account and creation data — while your account is open, then deleted or anonymised within 90 days of closure.
- Financial ledger records — 6 years (UK tax and accounting law).
- Telemetry — aggregated; session-level events pruned within 13 months.
5. Your rights
Under UK GDPR you can ask for access, correction, deletion, restriction, portability, and object to legitimate-interest processing. Use the contact page; we respond within one month. If unhappy, you can complain to the ICO (ico.org.uk).
6. Cookies & local storage
We use local storage for your session, profile cache, and PWA offline shell — strictly functional. No third-party advertising cookies.
7. Children
Play is 13+; purchasing is 18+ (or guardian consent). We don't knowingly collect data from under-13s — tell us and we'll delete it.
8. Changes
We'll post updates here and date them; material changes get an in-product notice.