Snarky's
Draft placeholder text for development — needs legal review before launch.

Privacy Policy

Last updated: October 5, 2026

This Privacy Policy explains what [LEGAL ENTITY NAME], [ENTITY TYPE, e.g. a Delaware corporation — COUNSEL TO CONFIRM] ("Snarky's", "we", "us") collects when you use Snarky's, why, who we share it with, and the rights you have over it. It should be read together with our Terms of Service.

1. What we collect

From you, when you create an account.Email address; a password (we store only a salted hash of it, never the password itself); or, if you continue with Google or Apple, your provider account id and the name/email they share with us. During setup we also collect a username, optional display name and bio, an avatar, a self-reported birth year (used only to confirm you're 13 or older — see Children), and optional favorite genres.

What you make.Your prompts, the games and versions built or edited from them (code, art, audio, 3D models), the back-and-forth messages in a project's build history, comments you post, and titles/descriptions/tags you write.

Automatically, as you use the Service.A signed session identifier (cookie); for guests, an anonymous guest identifier (cookie); an anonymous visitor id used for play counts and leaderboards (cookie); play-session data (which game, how long, from where — e.g. feed/search/direct link, whether on desktop or mobile, completion/score, and a room code if it was a multiplayer session); your browser's user-agent string; and a hashed network prefix of your IP address (never the full IP — see Security) used to apply free-trial and abuse limits per network/device.

Payments and payouts.If you buy a plan, credits, a game, or an in-game item, Stripe processes your payment details directly — we receive a Stripe customer id, subscription id, and payment reference, never your full card number. If you're a creator receiving payouts, Stripe collects your bank/identity details through its own onboarding; we store only your Stripe Connect account id and whether it's enabled for charges/payouts.

App-store publishing credentials.If you publish to the Apple App Store or Google Play, you give us an API credential for your own developer account (an App Store Connect API key, or a Google Play service-account key). It's encrypted at rest (AES-256-GCM) and used only to act on your behalf for packaging and submission; it's never shown back to you or anyone else once saved.

Social activity. Likes, saves, follows/followers, comments, notifications, and reports you file or that are filed against your content.

What we do not collect on our servers: your in-game saves. Per-game save data (the progress a specific game stores through its save API) lives only in your own browser's local storage, keyed to that game, on the device you played it on. It's handed to the sandboxed game at load time without ever being sent to our servers or database. Clearing your browser data, or playing on a different device, loses that save — we have no copy of it to restore.

2. How we use it

If you're in the UK or EEA, we rely on one or more of these legal bases for each use above:

4. Sharing your information

We don't sell your personal information for money. We share it only with the service providers ("processors") who help us run the Service, each only for the purpose below, plus anyone you direct us to share it with (for example, a store you choose to publish to):

Each processor is contractually limited to using your information to provide its service to us, not for its own independent purposes, except as that provider's own policy discloses for its own account holders (for example, if you separately have your own Google, Apple, Anthropic, OpenAI, Stripe, or Cloudflare account).

5. AI processing disclosure

Building and editing games on Snarky'sis inherently an AI feature: the text you type to describe or change a game, plus technical context needed to do the job (your game's current source code, its plan, and — when repairing a bug — the runtime error it produced), is sent to an AI model provider (currently Anthropic, OpenAI, or Google, depending on configuration and plan tier; a non-AI offline fallback is used only in local development) to generate the response shown to you. Requesting game art sends a text description to an image-generation model (OpenAI or Google).

We log the prompt text, which provider/model handled it, token counts, and cost for every AI call, for billing, abuse prevention, and debugging. A rule-based filter screens prompt and output text for prohibited categories (see Terms — AI-generated content) before and after generation; AI responses are not reviewed by a human before being shown to you. Each AI provider processes the data we send it under its own API terms, which govern how long that provider itself retains it — we don't control that retention beyond our contract with them.

Prompts and generated game content can include personal information if you choose to type it in (for example, naming a real person in your game's text) — avoid including anyone else's personal information in a prompt unless you have the right to share it.

6. Cookies and local storage

These are the cookies the Service actually sets. We don't use third-party advertising or cross-site tracking cookies.

Local storage (not a cookie, and not sent to us).Each game's save data is written to your browser's localStorage, under a key specific to that game, entirely client-side. We never receive, store, or back up this data — see Section 1.

Because every cookie we set is required for the Service to function (there's nothing optional to consent to), we don't show a cookie-consent banner; you can still block or delete cookies in your browser settings, which will sign you out and may stop guest trials or anonymous play tracking from working.

7. Retention

We keep account data for as long as your account is active. If you delete your account, directly identifying fields (email, username, display name, bio, avatar, birth year, password, OAuth links) are removed or anonymized immediately and your sessions are revoked — see Terms — Termination for exactly what happens to your games. Financial records (purchases, ledger entries, subscriptions) are retained as accounting/legal records tied to an account id for as long as applicable law requires, even after deletion.

Operational logs that aren't directly identifying on their own — for example AI generation logs, moderation-check records, and play-session rows — don't currently run on an automatic deletion schedule; they're retained until we manually purge them or until deletion of the account they're tied to removes the identifying link. We're flagging this honestly rather than promising a retention window we don't yet enforce in the product.

8. Security

Passwords are hashed (bcrypt) and never stored in plain text. Session tokens are signed and HTTP-only. Developer-account credentials you connect for app-store publishing are encrypted at rest (AES-256-GCM) and only decrypted server-side when needed to act on your behalf. IP addresses used for abuse/trial limits are stored only as a one-way hash of a network prefix, never as the full address. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

9. International data transfers

Snarky's and the service providers listed in Section 4may process and store information in countries other than the one you're in, including the United States. Where applicable law requires a specific safeguard for such a transfer (for example, Standard Contractual Clauses for transfers out of the EEA or UK), we rely on the mechanism our processor provides for that purpose.

10. Children

Snarky'sdoes not knowingly collect personal information from children under 13, consistent with the U.S. Children's Online Privacy Protection Act (COPPA). Account creation requires confirming a birth year showing you're 13 or older; this is self-reported and not independently verified. Anyone, including a child, can play a public game as a guest without giving us any personal information beyond the anonymous, cookie-based identifiers in Section 6.

If we learn that an account was created by, or that we've otherwise collected personal information from, a child under 13, we will anonymize/delete the directly identifying account fields as described in Section 7 and, where feasible, the account itself. A parent or guardian who believes their child under 13 has provided us personal information can contact [PRIVACY CONTACT EMAIL] to request its removal.

11. Your privacy rights

EEA / UK (GDPR & UK GDPR). You have the right to access, correct, delete, restrict, or receive a portable copy of your personal information, to object to processing based on legitimate interests, and to withdraw consent where processing is based on it. You can lodge a complaint with your local data protection supervisory authority at any time.

California (CCPA/CPRA).California residents have the right to know what personal information we've collected, to access or delete it, to correct inaccurate information, and to limit use of sensitive personal information. We do not sell personal information for money, and we do not "share" personal information for cross-context behavioral advertising(we don't run third-party ad or tracking pixels), so there is currently no sale/share to opt out of. We won't discriminate against you for exercising any of these rights.

Other U.S. states.If you're in a state with its own comprehensive privacy law (for example Virginia, Colorado, Connecticut, Utah, or others as they take effect), you have similar rights to access, correct, delete, and port your personal information, and to opt out of targeted advertising, sale, or certain profiling — none of which this Service currently does beyond what's described in this Policy.

12. How to exercise your rights

While signed in, you can download a full export of your account data (profile, games, plays, likes, comments, purchases, credit history and notifications) from Settings → Privacy & data, and delete your account from the same page. For any other request — correction, restriction, a copy in a different format, or a question about what we hold — email [PRIVACY CONTACT EMAIL]. Because these tools are tied to your logged-in session, that login is how we verify you're the account holder; for a request made by email instead, we may ask for information to verify your identity before acting on it.

13. Do Not Track

Some browsers send a "Do Not Track" signal. Because we don't run third-party cross-site advertising trackers to begin with, we don't currently change our behavior in response to that signal — there isn't a separate tracking system for it to turn off.

14. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we'll give notice (for example, by email or an in-product notice) before it takes effect. The "Last updated" date at the top always reflects the current version.

15. Contact / Data Protection Officer

[LEGAL ENTITY NAME], [ENTITY TYPE, e.g. a Delaware corporation — COUNSEL TO CONFIRM]
[LEGAL ENTITY ADDRESS]