PRIVACY POLICY
A practical description of the information this project stores and uses.
This deployment does not use advertising trackers, hardware identifiers, IP geolocation, or commercial analytics, and it does not sell personal data.
Account and profile data
Local registration stores your email address, username, password hash, optional biography, optional avatar URL, account creation time, XP, level, wins, and losses. Plain-text passwords are not stored. Passwords are hashed with Argon2.
Google sign-in
If you choose Google sign-in, Google provides a verified email address, display name, and profile picture URL. The project stores those values to create or identify your account. Your Google password is never received.
Games and social features
The service stores game participants, moves, timers, results, and dates. It also stores friendships, pending friend requests, private chat messages, message senders, and timestamps. In-game chat is temporary and is not stored in the database.
Sessions and browser storage
Access and refresh tokens are stored in your browser local storage. The database stores a hash of each refresh token and its expiration time. Refresh sessions expire after seven days by default and can be revoked on logout. Use Logout and avoid shared browser profiles on shared computers.
Visibility and sharing
Other authenticated users can see your username, biography, avatar, online status, game statistics, XP, level, leaderboard position, and current game when applicable. Email addresses and authentication data are not included in public profiles. Data is not shared commercially. Google processes data separately when its optional sign-in flow is used.
Retention and choices
Project data is retained in the deployment database while the academic service remains available. The application currently has no self-service account export or deletion screen. You can edit your username and biography and remove friendships. Requests concerning account access or deletion must be directed to the team responsible for the current deployment.
Security and changes
The project uses HTTPS, authenticated API routes, password hashing, and hashed refresh tokens. No system can guarantee absolute security. This policy may be updated when features or stored data change; the date above identifies the current version.