Skip to content
AwakePlay / Privacy

Your data should have a clear destination.

This policy follows the current AwakePlay code and service providers. It explains why we process data, how long we keep it, and how to ask us to close or delete it.

Last updated: October 7, 2026. Operator: the independent AwakePlay project.

Scope

This policy covers awakeplay.com, play.awakeplay.com, creator sign-in and management pages, fixed previews, publishing CLI/Skill/SDK, and the static web game service. Code, links, and third-party services inside an individual work may have their own policies.

Data we process

Account and sign-in

Your email sends a one-time sign-in code and identifies your account. Codes expire after 5 minutes and browser sessions last up to 7 days. Your chosen display name and avatar may be stored. Login sessions may include IP and User-Agent security metadata for abuse prevention and troubleshooting.

Agent authorization

An explicitly authorized agent connection stores a hashed token, scopes, creation and expiry times, and last-use time. Agent tokens last up to 7 days and can be revoked from the account page.

Works and media

Publishing stores the work name, versions, static files, icon, poster, and required release metadata for hosting, previews, sharing, updates, and rollback. Public pages and link-addressable previews send runtime files to the visitor's browser.

Anonymous analytics

Game pages may collect best-effort anonymous access data: views, a per-work random visitor identifier kept for about 30 days as an HMAC digest, device category, source hostname, version, and redacted resource or script errors. We do not store the raw User-Agent, full referrer URL, query parameters, player input, error messages, or stack traces. There are no analytics cookies or cross-work device fingerprints.

  • DNT=1 and GPC=true skip analytics.
  • Set localStorage.setItem('awakeplay:analytics:disabled','1') or use “Turn off anonymous analytics” on the play page to stop later reports.
  • Visitor, device, and source details last about 30 calendar days; error details about 7 days; daily rollups about 90 days. Cumulative view/error counters are not automatically cleared each day.
  • Fixed previews are separated from formal releases and do not identify players.

Purposes and content rights

We use data to provide sign-in, publishing, previews, sharing, version management, storage, abuse prevention, maintenance, security, and anonymous product feedback. You or the lawful rights holder keeps rights in uploaded work. You are responsible for having the rights needed to publish it and for disputes caused by the work. AwakePlay uses it only as needed to host, preview, transmit, share, and operate the service; without separate consent, we do not use it for model training, sale, or independent reuse.

Work responsibility and plaza review

Ordinary share links and the Play Center are separate paths. A creator may opt a published work into Play Center review; only an approved version appears in the directory. Approval does not guarantee that a work is lawful, safe, or suitable for everyone.

Reviewers may approve, return for changes, or remove a directory listing. Removing a listing does not automatically delete work files or disable an ordinary share link. We handle specific reports according to current platform capabilities and applicable law.

Service providers

Cloudflare Workers, D1, and R2 host pages, databases, and objects. Resend sends sign-in email through a verified sending domain. These providers may process data in the regions where their infrastructure operates. Game scripts do not receive creator sessions, agent tokens, or creator data APIs.

Closing and deleting data

You can revoke agent connections, sign out browser sessions, turn off anonymous analytics, pause access, clean old versions, or move a work to the seven-day trash window. Work deletion is not account deletion and does not automatically mean that all player data or cumulative analytics are gone.

There is currently no self-service account closure, complete export, or “delete all personal data” button. Send a request to mashiro@awakeplay.com with the account email and requested scope. We will verify the request and reply with the data covered, any retention reason, and the next steps. Do not send codes, agent tokens, or signed URLs.

Security and changes

We use HTTPS, HttpOnly session cookies, Origin/CSRF checks, owner and scope checks, and separate creator management from anonymous content delivery. No online service is perfectly secure. Read the security reporting page before sending a report. We update this page when data use or deletion practices materially change and describe the scope of the change. Rights and duties required by applicable law are not excluded by this page.