Privacy
Plain language · 15 August 2026 · version 2026-08-15.v2
This notice explains the data used to run the public beta, answer messages and keep the service safe.
Who is responsible
The Public Lives Game team controls the data described here. Questions, access requests and deletion requests go to hello@publiclivesgame.com or the contact page.
Joining the public beta
We keep your normalised email, 18+ self-attestation, the time you made it and the account state needed to provide access. Self-attestation confirms what you told us. It is not identity or age verification.
Operational email and optional updates
Passwordless sign-in requires us to email you a time-limited access link. Those account messages are necessary to provide the service. Occasional development updates are a separate, optional choice that starts unchecked. You can withdraw that choice without losing account access.
Abuse prevention
Our hosting and authentication providers (Netlify and Supabase) may process network information such as an IP address for short rate limits, fraud prevention and service security. We do not use that information for advertising.
Accounts and city records
Supabase Auth processes your email and sign-in credentials. Your resident's actions can create city records such as posts, trades, court outcomes and headlines. The game separates private account information from records designed to be visible to other residents.
Beta and Public Lives Lab feedback
Signed-in beta players can privately send bug reports, ideas and follow-up messages; invited Lab testers can also send friction notes and take part in the wider Lab. For each beta feedback submission, we store the case number, account, accepted Beta Terms version, acknowledged Privacy Notice version, acceptance time and the minimum evidence needed to investigate. Raw submissions stay private. Only a staff-written, de-identified item can appear on the public Lab board.
Community Helper recruitment
Existing adult players can volunteer to apply for a flexible, unpaid Community Helper role. We use the linked account and resident, desk preferences, motivation, relevant experience, an impartiality response, general non-binding availability and timezone, acknowledgements, review notes and decision history. We do not ask for a legal name, postal address, phone number, CV, health information or criminal-record information on the initial form. Owner and authorised Operators can review this private record. We use the account's current email only for operational recruitment and onboarding messages; it is not copied into the recruitment record.
Diagnostics and screenshots
You preview and independently choose every diagnostic before sending it. The permitted fields are the route pathname without its query, viewport and broad browser or device family, build, current game month, your own relevant game identifiers and an opaque error-correlation ID. Up to three private PNG, JPEG or WebP screenshots may be attached. We never intentionally capture cookies, tokens, sessions, page HTML, DOM snapshots, private messages, clipboard contents or unrestricted logs and network traffic.
First-party gameplay measurement
To understand whether the beta is clear, reliable and worth returning to, we record broad game-area visits, phone/tablet/desktop layout, action outcomes and existing game events. We do not record query strings, exact routes with personal identifiers, page contents, messages, exact viewport sizes or full browser fingerprints. Account-linked activity is kept for 30 days, then only de-identified daily counts and release comparisons may remain.
Lab experiments, support and credit
Voluntary missions record consent, admission, exposure, withdrawal and your response so a bounded test can be interpreted honestly. A support signal is stored once per account and shown only as an aggregate; small reason buckets are folded into Other. Public contributor credit is separately opt-in and can be removed without revoking a privately earned cosmetic entitlement.
Messages to our public address
If you email us, authorised staff may retain the message and attachments for up to 12 months so we can answer support, safety, privacy, press and general enquiries. We do not add correspondence addresses to marketing lists.
What we do not do
We do not sell personal data, run third-party advertising trackers or ask for information the beta does not need. Access to signup and safety information is restricted and auditable.
Retention and your choices
We keep signup and account data only while needed to provide the beta, meet legal duties and protect the service. Lab private bodies, diagnostics, messages and image objects are erased 90 days after a case closes, unless a scoped legal or security hold applies. Community Helper answers, preferences, availability and private review notes are erased 180 days after a decline, withdrawal, unprogressed acceptance or completed onboarding. Declined and withdrawn recruitment records are unlinked from the account after that cooldown. While helper access exists, only the account/access link, current agreement receipts and necessary security audit remain. Account erasure removes eligible private material earlier and anonymises retained source or credit links. De-identified counts and non-identifying audit history may remain. You can access, correct or request deletion of your data, withdraw a new Helper form while it is new, withdraw from a mission, remove support or public credit, and withdraw optional email updates by contacting us.