Privacy Policy

Last updated: 2026-09-30

Overview

We explain what data we collect, how we use it, and the rights you have.

Data We Process

  • Account data: username, email (via Cognito).
  • Gameplay data: inventory, stats, in-game actions.
  • Social data: your friend list, block list, and direct messages you exchange with friends. Direct messages are stored on our servers so they can be delivered while the recipient is offline, and are automatically deleted 30 days after they are sent. Posts on profile walls (short messages friends leave on each other's profiles) are stored so the wall's owner and their friends can read them, and are automatically deleted 90 days after they are posted. Abuse reports you submit (which may include a copy of a reported message) are also stored.
  • Moderation data: text rejected by the automatic filter (with the reason), delivered text flagged for review, reports you submit or that concern you, and sanctions (mutes, suspensions, bans) with the reason and who applied them. For banned guest sessions we store a one-way hash of the network address, not the address itself, for up to 7 days. Public chat is held in server memory for up to about 30 minutes so a report can include recent messages; it is not written to a database unless it becomes part of a report or flag.
  • Real-time media: camera video, microphone audio, and facial landmark coordinates (all optional, each requiring separate explicit consent). Transmitted peer-to-peer via WebRTC to other players in your session. Not stored on our servers.
  • Technical data: IP, device, logs for security and performance.

How We Use Data

To operate gameplay, networking, moderation, and feature toggles, and to keep players safe through automatic text filtering (prohibited language and personal-information patterns) and manual review. Camera, microphone, and facial landmark data are transmitted in real time between players in your session via peer-to-peer WebRTC connections (using PeerJS) and are not stored on our servers.

Friends & Direct Messages

You can add other registered players as friends and exchange private text messages with them. This is designed with privacy defaults in mind:

  • Direct messages can only be exchanged between players who have both accepted the friendship. There is no way to message strangers.
  • Friend requests can only be sent to players you have actually encountered in the game; there is no player search or directory.
  • Direct messages are stored on our servers only to deliver them (including while the recipient is offline) and are automatically deleted 30 days after sending. Message text is checked automatically by the filter before delivery. We do not read or log message content, except that a message you report, a message the filter rejects, and a message the filter flags for review are kept as moderation records.
  • Blocking a player prevents them from sending you friend requests or messages. The blocked player is not notified.
  • Profile wall posts can only be written and read by the wall owner's accepted friends. They are automatically deleted 90 days after posting; the wall owner can delete any post on their wall, and authors can delete their own posts. Wall posts go through the same automatic filter; we do not otherwise read or log wall post content.
  • The in-game online list shows only usernames and an active/hibernating status — no activity timestamps or "last seen" times.

Facial Landmarks (Google MediaPipe)

We use Google MediaPipe, a third-party library, to detect facial landmark coordinates in your browser. All facial processing happens locally on your device. Neither we nor Google receive your camera feed or raw biometric data through this processing. We do not store biometric data.

The MediaPipe library files are loaded from Google's servers when you enable this feature. These requests may be subject to Google's Privacy Policy (e.g. IP address logging by Google's CDN).

The resulting landmark coordinates (numerical point positions, not images) may be transmitted to other players in your session via peer-to-peer WebRTC connections for avatar animation. Facial landmark data may constitute biometric data under applicable data protection law (including GDPR Article 9). This feature is activated solely on the basis of your explicit consent.

  • Consent: You must opt in before enabling facial landmarks; you can revoke any time via the Settings menu in-game. Revocation immediately stops processing and transmission.
  • Video independence: You can enable landmarks without sending camera video; camera, microphone, and facial landmarks are separate consent choices.
  • Minors: We may restrict landmark features for underage users depending on region and applicable law.
  • Retention: We do not store landmark data. Landmark coordinates exist only during real-time transmission within your session.

Peer-to-Peer Connections (WebRTC)

Video, audio, and facial landmark data are transmitted directly between players using WebRTC (via PeerJS). This means:

  • Your IP address may be visible to other players in your session through WebRTC ICE candidates.
  • We use a relay server (TURN) when direct connections fail, but cannot guarantee that your IP address will never be exposed to other participants.
  • Media data travels directly between browsers and does not pass through or get stored on our servers.

Consent & Controls

Camera, microphone, and facial landmarks each require separate, explicit consent via an in-game consent prompt before activation. You can grant or revoke per-feature consent in-game via the Settings menu. We may require re-consent for material changes.

Withdraw Consent

You can withdraw consent at any time:

  • In-game: open Settings, then revoke Camera, Microphone, or Facial Landmarks. Revocation takes effect immediately, disabling the feature and stopping all associated data capture and transmission.
  • OS/Browser: you may also revoke camera/microphone permissions in your device or browser settings; the game will reflect the change.
  • Scope: withdrawal stops further capture, processing, and transmission of the affected feature. Since we do not store media or landmark data on our servers, there is no server-side data to delete.

Sharing

Data may be shared with the following parties:

  • Other players in your session: When you enable camera, microphone, or facial landmarks, that data is transmitted directly to other players via peer-to-peer WebRTC connections. Your IP address may also be visible to other participants.
  • Google: The MediaPipe library files are loaded from Google's servers. These CDN requests may expose your IP address to Google. See Google's Privacy Policy.
  • AWS: Account and gameplay data are processed via AWS services (Cognito, DynamoDB, etc.). Cross-border transfers are governed by AWS's regional configurations and applicable safeguards.

Retention

Gameplay/account data are kept while you have an account; media streams are ephemeral unless stated. Direct messages are automatically deleted 30 days after they are sent. Profile wall posts are automatically deleted 90 days after they are posted. Friend and block relationships are kept until you remove them or your account is deleted. Abuse reports are kept as long as needed for moderation and compliance. Other moderation records (rejected and flagged text, sanctions) are deleted after 90 days, except sanctions still in force; hashed network addresses expire with the block. Consent logs are kept for compliance.

Your Rights

Subject to your region: access, correction, deletion, portability, objection. Contact us to exercise rights. Deletion covers your social data too: friend relationships, block entries (including blocks referencing you held by other players), your direct-message conversations, and profile wall posts (both posts on your wall and posts you wrote on other players' walls). Moderation records may be kept for the remainder of their 90-day period after account deletion where needed for safety.

Contact

hello@substellar.io