Privacy Policy
apps/web/lib/legal-identity.ts — the DMCA agent address and the governing-law section are not effective without them.Who holds this data
Mckay Hardester, doing business as Playbeam Studio, is responsible for the data described here (the “controller,” if you are reading this under the GDPR).
What we store
This is the whole of it — the studio keeps as little as it can:
- Your account: your email address, a one-way hash of your password (never the password itself), and the date you agreed to these terms and to which version. If you signed in with GitHub, we store that the account is linked to that provider and the email address it gave us — nothing else from your profile there.
- Your projects: the games you build, saved as files so you can export and keep them.
- Your published games: a public copy of a game at the moment you chose to publish it, served at its link until you take it down.
- Your plan: whether you are on the studio plan, which billing interval you chose, how many of the free build prompts you have used, and Stripe’s identifiers for your customer record and subscription. Your card details go directly to Stripe and never touch our servers.
- Sessions: a signed-in session is kept as a hash of a random token; the token itself lives only in your browser’s cookie.
We do not ask for your name or your address. If you buy the studio plan, your card is entered on Stripe’s own checkout page — the studio itself never sees or stores a payment card.
Why we are allowed to hold it
Under the GDPR, our basis is performance of a contract: each item above is something without which the service cannot do what you asked it to. An account with no email cannot be signed into; a project with no stored file is not saved.
What we do not do
We do not sell your data, and we do not share it for advertising. We do not use browser cookies to track you across other sites; the only cookies the studio sets are the one that keeps you signed in and, for visitors who have not signed in, one that keeps your in-progress work attached to you. There is no analytics service, no advertising pixel, and no third-party tracker in this site.
Who else processes it
We use a small number of services to run the studio. They act on our instructions, and each one receives only what its job requires:
- Railway — hosting. Holds everything above, because it runs the servers and the disk.
- Anthropic, OpenAI, Google, or xAI — whichever AI provider you choose to connect. That provider receives your prompt and the relevant parts of your scene when you ask the studio to build something. Only the provider you connected receives anything, and none of them receive your email address or your Playbeam password.
- GitHub — only if you choose to sign in with it, and only to confirm who you are.
- Resend — email delivery. Receives your email address, and only when a message has to reach you: today that is a password reset you asked for. We do not send marketing email, so there is nothing here to unsubscribe from.
- Stripe — payments, only if you buy the studio plan. Receives your email address and your card details (the latter directly, on its own pages), and tells us whether your subscription is active. We never see the card.
- Poly Haven, Kenney, poly.pizza, Sketchfab — asset libraries. They receive a request for a 3D model when the studio fetches one. They do not receive anything about you.
These providers are based in the United States, so using the studio involves your data being processed there.
AI processing
When you ask the studio to build something, your prompt and the relevant parts of your scene are sent to an AI provider named above to generate the result. Do not put secrets or sensitive personal information into a prompt. Once a prompt has been sent, it is subject to that provider’s own handling of it, and we cannot recall it.
You sign in with the provider directly, through the provider’s own sign-in page. We never ask you to enter your provider password into Playbeam, and it never passes through us. The provider’s own software keeps its sign-in details on your device, in its own files. An API key you paste into the studio instead is held in the studio’s memory only — never written to disk, and never sent to your browser.
Published games are public
Anything you publish is public and reachable by anyone with the link. Treat a published game as something the whole world can open.
How long we keep it
Projects and published games are kept until you delete them, and your account is kept until you delete it. Deleting your account removes your account record, your projects, your published games, and every signed-in session, at the time you ask. Sessions expire on their own. We keep no separate archive of deleted work, so deletion is not reversible — export anything you want to keep first.
Your choices and rights
You can delete a project, take a published game down, export your work, and delete your account and everything with it, all from the studio itself.
Depending on where you live, you may also have the right to ask what we hold about you, to have it corrected, to receive a copy in a portable form, to object to or restrict what we do with it, and to complain to your data protection authority. The export and delete features above are the fastest route to most of these; for anything else — a contact route for these requests is being set up. We do not charge for this and we will not treat you differently for asking.
Children
The studio is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has created an account, tell us and we will delete it.
Changes
When this policy changes materially we update the version shown at the top of the page.