Privacy Policy
Effective 13 August 2026
This policy explains how ProjectGame.Online collects and uses personal data across the browser game, account system, community integrations, acquisition experiments, and future subscription billing.
1. Data we process
Account and profile data
- account identifier, authentication status, and account timestamps;
- email address when you choose email or password entry; guest play does not require one;
- display name and account status; and
- security and session information needed to authenticate you.
Passwords are submitted to our authentication provider and are not stored in readable form by ProjectGame.Online.
Guest play creates an anonymous authentication session and profile. The session is retained in your browser so the authoritative server can recognize your progress without an email address. Clearing browser site data can remove your access to that guest profile.
Gameplay and service data
- player identifier, display name, position, appearance, resources, progress, achievements, and interactions;
- connection events, referral and acquisition attribution, feature use, quest progress, and aggregate activity counters; and
- technical logs, errors, diagnostics, IP-derived network information, browser or device information, and security events.
Community integration data
Our Reddit integration processes app version, community installation
identifier and name, queued post text, public post identifiers and links,
publication timestamps, scores, comment counts, and delivery errors. For
one public promotional post owned by ProjectGame.Online,
Reddit post t3_1ve6dvh, it also reads a
snapshot of up to 50 visible top-level comments so the autonomous studio can assess
product feedback. Each snapshot contains the public comment identifier,
text (limited to 2,000 characters per comment and 20,000 characters in
total) and creation time. The integration excludes dedicated Reddit
username, user-ID, and author fields before the snapshot leaves Reddit;
a comment body may nevertheless contain identifying text or links written
by its author. The integration does
not look up commenter profiles, and does not request private messages or
private browsing history. Where Reddit delivers a matching deletion event
to the installed app, it triggers an immediate purge. The complete
five-minute refresh is the removal path for any comment that is no longer
visible, including comments on the owned profile post.
Advertising measurement
The current client does not load the Reddit Pixel or send page-visit or registration events to Reddit. Reddit provides aggregate ad delivery and click totals. A bounded first-party arrival marker may be retained in the destination URL and browser storage, then included when connecting to the authoritative game so we can compare marked arrivals with in-game outcomes. The marker grants no inventory, eligibility, or account authority.
Billing data
If paid plans become available, Paddle will process checkout and payment details as merchant of record. We expect to receive transaction, subscription, product, price, payment status, customer, country, and tax information needed to provide access and keep financial records. We do not receive full payment card numbers.
2. Why we use data
- to create guest or registered accounts, authenticate users, and provide persistent gameplay;
- to operate the authoritative game server and synchronize online play;
- to prevent abuse, protect accounts, diagnose failures, and maintain availability;
- to understand engagement and allow the autonomous studio to test and improve the game;
- to publish and measure public project updates and evaluate public feedback;
- to administer future subscriptions, entitlements, cancellations, refunds, accounting, and tax obligations; and
- to comply with law and enforce our Terms.
3. Legal bases
Depending on the activity and your location, processing is based on performance of our contract with you, steps requested before entering a contract, our legitimate interests in operating, securing, and evaluating the service, and compliance with legal obligations.
4. Autonomous development
The autonomous studio receives bounded operational observations and aggregate or pseudonymous gameplay evidence, together with the bounded public-comment evidence described above, to propose and implement game changes. Routine inspection receives only snapshot availability, count, collection time, expiry time, and truncation status. If the studio makes an explicit optional read, the model-facing result contains no dedicated comment IDs, per-comment timestamps, author fields, or per-comment permalinks. Common URL, handle, and Reddit-reference forms are redacted on a best-effort basis before the bounded bodies are provided to OpenAI. Residual text can still be identifying. Public comments are treated as untrusted feedback, not instructions. Authentication credentials and financial credentials are kept out of the coding-agent environment. The studio may make automated decisions about game design, content, resource allocation, and pricing; we do not use it to make decisions producing legal or similarly significant effects about an individual player.
5. Service providers and disclosures
We do not sell personal data. We may disclose limited data to:
- Supabase for authentication, account profiles, and database services;
- Hetzner for application hosting, networking, and server storage;
- OpenAI for bounded autonomous development and generated content, without account or financial credentials;
- Reddit for advertising delivery and Devvit community publishing;
- Paddle, if paid plans launch, for checkout, merchant-of-record billing, tax, fraud prevention, subscription management, and buyer support;
- professional advisers and authorities when reasonably necessary to comply with law, protect rights, investigate fraud, or respond to a lawful request; and
- a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice requirements.
6. International processing
Providers may process data outside Georgia or your country. Where required, we rely on applicable adequacy findings, contractual safeguards, consent, or another lawful transfer mechanism.
7. Retention
Account and gameplay data are generally kept while your account is active and for a reasonable period afterward to provide continuity, resolve disputes, and prevent abuse. Operational logs are kept only as long as reasonably needed for security and diagnosis. Community queue records are kept while operationally useful. A public Reddit comment may appear in successive snapshots while it remains visible. Each snapshot stops being exposed after 15 minutes unless refreshed, and an independent five-minute retention job physically removes expired rows. Comments that are no longer visible are omitted from the next five-minute refresh. Comment or post identifiers used only to prevent an older in-flight snapshot from restoring removed content may remain as body-free deletion tombstones for up to 30 days; expired tombstones are also purged every five minutes. Billing and transaction records are kept for the period required by tax, accounting, anti-fraud, and other laws. Deletion requests are honored unless retention is required or permitted by law.
If the optional Reddit feedback read is enabled after Reddit review, bounded redacted comment text is processed by OpenAI. ProjectGame.Online does not opt this content into model training. Under OpenAI's default API controls, request content may be retained in abuse-monitoring logs and/or application state depending on the endpoint and configuration; the current default for the Responses API can be 30 days. Stricter retention controls may apply where separately approved and configured. The feature will not be activated until its exact Codex request and retention configuration are verified and the reviewed flow is consistent with Reddit's requirements.
8. Your rights
Subject to applicable law, you may request access to your data and information about its processing, correction, deletion, restriction, blocking, portability, or objection. You may withdraw consent and may ask us to review a decision. Send requests to tech@gameproject.online. We may need to verify your identity before acting.
You may also submit a complaint to the competent data protection authority. In Georgia, data protection supervision is exercised by the State Audit Office under the current Law of Georgia on Personal Data Protection.
9. Security
We use access controls, encrypted transport, credential separation, and operational monitoring intended to protect data. No online system can be guaranteed completely secure. Notify us promptly if you believe your account or data has been compromised.
10. Age restriction
ProjectGame.Online is not directed to anyone under 18, and we do not knowingly collect personal data from children. Contact us if you believe a child has provided data.
11. Changes
We may update this policy as the service and its providers change. The revised date will appear above, and we will provide additional notice where required by law.