3JSGames · Legal & Trust
Privacy
What the platform stores, what is public, and how account cleanup works.
Version 1.0-draft · Last updated 2026-09-05 · Effective pending approval
Who handles your data
Operator identity and the privacy contact destination require configuration and review. This is a factual product draft, not a claim of GDPR, DSA, COPPA or other legal compliance. Legal bases, international-transfer arrangements and rights-handling procedures require operator/legal review.
Authentication and profiles
Authentication stores account identifiers, email and provider-linked authentication data. OAuth providers can supply names and avatar information. New profile defaults use a neutral player identity; existing public names are preserved until the account holder edits them.
Your chosen username, display name, avatar, bio and website are public profile information. Authentication email and credentials are not public profile fields. Creators do not receive player emails through the platform SDK.
Content and participation
Published games, thumbnails, descriptions and creator metadata are public. Comments, leaderboard entries and public profile activity can also be visible. Likes and play history are stored to support account features and discovery. Do not place secrets or sensitive information in public content.
Cloud saves and game-specific JSON data are associated with a player and game. Multiplayer features store memberships, match participation and ratings as well as temporary room/presence state. Cosmetics store account entitlements and selected loadouts. Games determine some submitted field contents; avoid unnecessary personal data.
Reports, appeals and operations
Reports may include an account identifier, an optional reply contact, the affected URL, an explanation and IP notice declarations. These are available to authorized operators, not a public report feed. Affected users can access their decision notices and appeals without seeing private operator notes.
Security controls process pseudonymous rate-limit keys and operational request information. Audit records document privileged actions and preserve content snapshots. Acceptance records store user ID, policy revision, acceptance time and source; they do not add IP addresses or user agents.
Infrastructure and access
The repository integrates Supabase for authentication/database and some storage, Cloudflare R2/CDN paths for build artifacts, and hosted application delivery and diagnostics. Actual enabled providers, hosting regions, contracts and vendor-managed retention must be confirmed for the deployed environment.
Operators and processors need access to relevant data to host games, support accounts, investigate abuse and maintain the service. No sale of personal information or advertising integration is described or activated by this foundation.
Export, deletion and retention
Account settings provide a staged account deletion workflow with an export preparation step. This is not a promise of a separate instant export endpoint. Cleanup may require retries and retained evidence is handled separately from public account data.
The export includes your persisted multiplayer memberships, match participation and ratings, cosmetics and loadout, as well as your acceptance records, decision notices and appeals. It excludes other players' records, shared room snapshots and transient messages. Deletion closes affected temporary rooms, removes your persisted multiplayer/cosmetic rows and clears relevant user links. Existing evidence-retention rules still apply.
Reports, moderation/audit evidence, security records and restricted financial facts may remain after an account is deactivated or deleted. Vendor backups and logs have separate retention that has not been verified here. No universal deletion deadline or backup-erasure guarantee is stated. Browser storage on your device may need to be cleared separately.
Your choices and unresolved decisions
Edit public profile information through account tools, limit what you share in games, use the analytics control, and use the account deletion/export workflow. A configured privacy destination is still required for other privacy requests.
No age collection or verified audience policy exists in this foundation. The intended audience, children's-data handling, applicable rights and retention schedule remain operator/legal launch decisions.
Optional play analytics
Off. Allow optional page-view and engagement measurement. Basic play counts work with either choice, using a separate per-game cookie lasting 30 minutes to prevent duplicate counts. You can change your choice here at any time.