Docs / Legal
Privacy Policy
Effective September 30, 2026 · Questions: privacy@fradiation.games · Terms of service
This policy explains what personal data Fradiation Games collects, why, who can see it, and what you can do about it. It covers the website at https://www.fradiation.games and the game domain containment.cloud. It goes together with our Terms of Service.
The short version
- You can browse and play without an account. Signing in with Discord or GitHub gives us your name, email address and profile image link.
- Some of what you do is public: your profile, your comments and your leaderboard scores.
- There are no ads, no analytics and no third-party trackers on the site. We don't sell personal data.
- We keep account data until you delete your account. There is no delete button yet, so you delete your account by emailing us.
The full policy follows.
Who we are and how to contact us
Fradiation Games runs Fradiation Games. In this policy, "we" and "us" mean Fradiation Games. We decide how the personal data described here is used, which makes us the "controller" of that data under data protection law.
Contact us at privacy@fradiation.games for any privacy question or request.
Games on the site are made by independent developers. A developer is responsible for anything their game collects on its own. See "Games made by other developers" below.
What we collect
Sign-in and account
You don't need an account to browse or play. You need one to rate, comment, keep your progress or upload games. When you sign in with Discord or GitHub, that provider sends us:
- your name;
- your email address;
- the web address of your profile image;
- your account ID at that provider;
- your username at that provider (your Discord username or your GitHub login name).
We ask each provider only for read-only access to your basic profile and your email address. We don't ask to post anything, and we don't ask for access to your repositories, servers, friends or messages. We never receive your Discord or GitHub password.
The provider also gives us sign-in tokens. We store them with your account record. We don't use them after you sign in to reach your Discord or GitHub account. You can withdraw our access at any time in your Discord or GitHub settings.
We use your email address to link accounts (if you sign in with both Discord and GitHub using the same email address, they become one account here), to recognize administrator accounts, and to reply if you email us. We don't show it to anyone. Your provider username is used only to suggest a handle when you set up your profile, and isn't shown to anyone.
When you sign in we create a session record. It holds a random session token, the time it expires, and the IP address and browser identifier (user agent) you had at that moment. We use it to keep you signed in and to investigate abuse. Signing in also creates short-lived records that protect the round trip to Discord or GitHub and expire within minutes.
Your profile
After you first sign in, you choose a handle and a display name. Your profile also holds an optional bio, your role (player, developer or administrator) and the date you joined. Your profile image is the one your Discord or GitHub account uses.
Activity on the site
If you have an account, we record:
- ratings you give to games;
- comments and replies you post, and likes you give to other people's comments;
- the rads you earn and what earned them, and the mutations (achievements) you unlock, on the site and in games;
- which games you played while signed in, one record per game per day, which we use to award rads and to decide who can vote in containment;
- your votes in containment (release or bury) and the weight your vote carried;
- your best score on each leaderboard of a game;
- reports you file about games: the game, the reason you pick and any note you write;
- the invite code you redeemed, if you are a developer.
If you don't have an account:
- The site counts plays with a short cookie so one browser isn't counted more than once in 30 minutes. The cookie is only a marker. It doesn't identify you, and we keep no record of who played.
- Your rads and unlocked mutations are kept in your browser only. We don't receive them. If you create an account later, the mutations you unlocked in your browser (only their IDs) are sent so they can come with you. Rads earned without an account are not transferred.
What is public
Some of your data is public by design. Anyone can see it, including people without an account and search engines:
- your handle, display name, bio and profile image;
- your rads, exposure level and mutations, the date you joined, and whether you are a developer or administrator;
- your comments and replies, shown with your handle, display name and image, and next to a comment, the rating you gave that game;
- your profile page at
/u/<handle>, which lists your recent comments and ratings and counts of your ratings, comments and likes received; - your name and score if you're near the top of a leaderboard;
- if you are a developer, the games you publish, with your handle and name, the cover image, description, patch notes and AI disclosure.
A game's average rating is shown as a total. The rating you personally gave a game is not hidden: it appears on your profile and next to your comments on that game.
Links to a profile or a game can show a preview image on other sites and apps. A profile's preview image includes the avatar, exposure level and rads. Search engines and other people can copy public pages, and we can't take those copies back.
The following is not public: your email address, your provider username and account ID, your IP address, your session records, your play history, your rads ledger, your reports, and your individual containment votes. Other players never see who voted which way, only the final totals.
Content you post
You can post comments and replies (up to 2,000 characters), report notes (up to 1,000 characters) and playtest feedback (up to 4,000 characters). Comments are public. Report notes go to us only. Playtest feedback goes to the game's developer.
Developer data
If you are a developer, we also store your game details (title, description, cover image, engine and AI disclosure), your builds (the game files, patch notes, sizes and checksums), the mutations and leaderboards you define for a game, your playtest settings (a note and up to five questions for testers), and the API tokens you create for uploading from a terminal (a name, which games each one reaches, when it expires, when it was last used and when it was revoked). We store only a one-way hash of each token, never the token itself. When you connect a coding agent through the browser sign-in, we store the agent's registration (the name, website and return address it gives itself), your permission for it, and the tokens it uses (short-lived access tokens and a refresh token, linked to your account and session), until you remove the agent on your dashboard. Game files and covers are stored with Cloudflare and are served to everyone who plays or views the game. Don't put personal data or secrets in a build.
Playtest data
A playtest is a private link (/t/<token>) a developer shares to get feedback on a build. Anyone with the link can play, with or without an account, unless the developer has limited the playtest to signed-in players. When you press Start on a playtest, we create a playtest session and record:
- your browser name and major version, such as "Chrome 140";
- your operating system family, with the major version for iOS and Android;
- whether the device is a phone or tablet;
- your screen width, height and pixel density;
- the name of your graphics card or graphics chip, as your browser reports it;
- the number of processor cores and, in browsers that report it, the approximate amount of device memory;
- active play time, counted only while the tab is visible, and how many errors happened;
- a timeline of events: errors the game hit (message and technical details), moments the game marked on purpose, achievements and scores the game tried to record (these are logged on the timeline and do not count toward your account), and when the feedback panel was opened;
- a random session key that lets the page keep updating the session.
If you leave feedback, we also store your reactions (how fun, how hard, whether you would play again), your answers to the developer's questions, any notes you write, the prompt the game showed if it opened the panel, and the guest name you typed, if any.
If you are signed in, the session and feedback are linked to your account, and the developer sees your handle. If you are not signed in, they are linked to a random ID stored in a cookie called fradiation_tester (see the table below), and the developer sees that ID and the guest name you typed. Your guest name is also remembered in your browser so you don't retype it.
This data is visible to the developer of that game and to site administrators. We don't store your IP address in playtest sessions. Device details are used only to help a developer understand a bug ("crashed on Safari 18 on an iPhone"). We don't use them to identify or track you elsewhere.
What games exchange with the site
When you play a game on the site while signed in, the site tells the game that you are signed in and gives it your handle and display name. It also tells the game whether it is running live, in a developer's preview or in a playtest. The game can then ask the site, through our SDK, to unlock one of its mutations for you, record a score for you, mark a moment in a playtest, report an error to the developer during a playtest, or open the feedback panel. In live play, the site records unlocks and scores against your account, and scores can appear on a leaderboard. In a developer's preview they are checked but not kept. In a playtest they are logged for the developer and not kept.
The game does not receive your email address, your cookies or your session. It cannot read other data from the site. The site does not give games access to your camera, microphone or location.
Games made by other developers
Games made by other developers run in a sandbox on their own address (<game>.containment.cloud), which is separate from the site. Each game has its own address, so games can't read each other's data.
A game can store data in your browser under its own address, for example save files. A game can also contact servers run by its developer. Those servers would see your IP address and whatever the game sends them. A game can open links or new windows to other sites.
That data is not collected by us and is not covered by this policy. The developer is responsible for it. Our Terms of Service require developers to give players their own privacy notice before their game collects personal data. A few games published by the operator itself run directly on the site instead of on their own address.
Technical and log data
Like any website, our hosting providers process technical data when your browser connects: your IP address, browser and device type, the pages or files you request, the time, and the address that referred you. Vercel handles requests to the website. Cloudflare handles requests for games and cover images on containment.cloud. They keep logs to deliver the service, protect it from attacks and fix faults. Our own servers also write error logs when something breaks. Our sign-in service limits repeated requests using your IP address, held in memory.
Your browser also contacts other parties in two cases:
- Profile images are loaded straight from Discord's or GitHub's image servers, so those providers can see that your browser asked for the image.
- Games load from Cloudflare, and can contact their own developers' servers, as described above.
The site's own code, fonts and images are served from our own domains.
What we don't do
- We don't show ads.
- We don't sell, rent or trade personal data.
- We don't use third-party analytics, advertising or tracking cookies, pixels or scripts on the site.
- We don't track you across other websites.
- We don't send marketing email.
- We don't make decisions about you based only on automated processing that have legal or similarly significant effects.
Cookies and browser storage
The site keeps a small amount of data in your browser. We use it to run features you asked for: staying signed in, remembering your settings, remembering you as a guest tester, and making the site load fast. None of it is used for advertising or to track you.
There are five kinds:
- Sign-in cookies. They keep you signed in and protect the sign-in process.
- The guest tester cookie. It is set only if you use a playtest link without signing in.
- The play counter cookie. It is set when you start a game, lasts 30 minutes, and lets us count one play per browser per game in that time. It contains no personal data.
- Local storage. It holds your sound and screen-effect settings, progress you earn before signing in, and the guest name you typed on a playtest.
- The offline cache. A service worker stores the site's static files and an offline page so the site loads quickly and shows a page when you're offline. Pages themselves always come from the network.
Here is the full list of what the site stores:
| Name | Type | What it's for | How long |
|---|---|---|---|
better-auth.session_token | Cookie | Keeps you signed in. | 7 days, renewed while you use the site |
better-auth.session_data | Cookie | A signed copy of your session, so pages don't look it up every time. | 5 minutes |
better-auth.* (sign-in) | Cookie | Protects the round trip to Discord or GitHub while you sign in. | Minutes, during sign-in only |
played_<game> | Cookie | Counts your play of a game once, so reloading doesn't inflate its play count. | 30 minutes |
fradiation_tester | Cookie | On playtest links only: remembers you as a guest tester, so your feedback history follows you. | 1 year |
fradiation:site | Local storage | Your sound and CRT settings, and progress you earn before signing in. | Until you clear it |
fradiation:tester-name | Local storage | On playtest links only: the name you gave as a guest tester, so you don't retype it. | Until you clear it |
fradiation:cookies | Local storage | Remembers that you've seen the cookie notice. | Until you clear it |
Offline cache | Service worker | The site's static files and offline page, so it loads fast and works without a connection. | Until the next version replaces it |
You can delete cookies, local storage and the offline cache in your browser settings. If you do, you will be signed out and you will lose your settings and any progress earned without an account. Games on their own addresses can store their own data too, and your browser settings cover that as well.
How we use your data, and why
Where the law asks us to name a legal basis, these are ours:
| What we do | Why | Legal basis |
|---|---|---|
| Sign you in, keep your session, and run your account and profile | To provide the service you asked for | Contract |
| Show your ratings, comments and scores, award rads and mutations, and run containment votes | To provide the features you use | Contract |
| Pass playtest data and feedback to the game's developer | To let you test and give feedback, and to let developers fix problems | Contract and legitimate interests |
| Keep the site secure, prevent abuse, spam and cheating, moderate content, and fix bugs | To protect the site, its players and developers | Legitimate interests |
| Process and log requests at our hosting providers | To deliver the site and keep it running | Legitimate interests |
| Answer legal requests and copyright notices, and keep records the law requires | To follow the law | Legal obligation |
When we rely on legitimate interests, we weigh them against your rights and collect as little as we can. You can object to processing based on legitimate interests (see "Your rights").
We don't use consent as a legal basis for anything today, because we don't collect anything optional that would need it. If that changes, we will ask first, and you'll be able to withdraw your consent at any time.
Who we share data with
Service providers. These companies process data on our behalf to run the site:
- Vercel hosts the website and runs its server code. It handles every request to the site, so it sees IP addresses and request details.
- Neon hosts our database. It holds the account, profile, activity, content, developer and playtest data described in this policy.
- Cloudflare stores game files and cover images (R2) and serves games and covers on containment.cloud through its network and Workers. It sees IP addresses and request details of anyone who loads a game or a cover.
- Discord and GitHub provide sign-in. They know when you sign in to Fradiation Games. What they collect is covered by their own privacy policies.
Developers. The developer of a game receives the playtest data and feedback for that game. Anything a game does with the handle and display name we give it, and with anything it collects itself, is the developer's responsibility.
The public. Anyone can see the public information described above.
Administrators. Administrators appointed by the operator can see account, activity and report data as needed to run the site and handle reports.
Legal requests and protection. We may share data if the law requires it (for example a valid court order), or to protect the rights, safety or property of our users, the public or ourselves, or to investigate fraud and abuse. Where the law allows, we'll tell you first.
If the site changes hands. If the site is transferred to someone else, your data may go with it. The new operator would have to follow this policy or tell you about changes first.
We don't share your data with anyone else.
International transfers
Our providers are mainly based in the United States, and they may process data there and in other countries where they operate. If you are in the European Economic Area, the United Kingdom or Switzerland, this means your data can leave your region. Where that happens, the transfer relies on safeguards such as standard contractual clauses, or equivalent safeguards, as offered by the provider. You can ask us for more information at privacy@fradiation.games.
How long we keep data
- Account, profile, activity and content: until your account is deleted. Once you ask, we delete the account and the data linked to it within 30 days. That includes your profile, ratings, comments, likes, votes, scores, rads, mutations and sign-in records.
- Session records: removed when you sign out, and deleted with your account. An expired session may stay in the database until the account is deleted.
- Comments you delete: they disappear from the site at once. Our database keeps a copy marked as deleted, and we remove it when your account is deleted or sooner if you ask us to.
- Playtest data: for as long as the game's playtest exists, and then it is deleted with it. Closing a playtest does not delete its data. Your guest tester cookie lasts one year. If you left feedback as a guest and want it deleted, email us the game, the approximate time and the name you used, and we'll remove it if we can identify it.
- Playtest feedback after account deletion: if you leave feedback while signed in and then have your account deleted, the feedback is disconnected from your account but its text can stay in the developer's inbox. Tell us if you want specific items removed.
- Games you publish: deleting your account does not remove your games automatically. Tell us whether you want them taken down when you ask.
- Build files: kept and deleted under the retention rules on the builds page. In short, a game keeps the files of its live build, its playtest build, any pinned builds and its newest few builds. Other builds lose their files after a set period once they are no longer needed. A game taken down by an administrator can have all its files deleted.
- Reports: kept with the game's records until the game or your account is deleted.
- Logs: kept by our providers for the periods in their default settings. We don't set a longer period.
- Backups: our database provider keeps backups for a limited time. Deleted data drops out of backups when they expire.
- Anything we must keep: we may keep some data longer if the law requires it or if we need it to settle a dispute or enforce our terms.
Your rights
Under data protection law, including the GDPR and the UK GDPR, you have the right to:
- Access. Ask for a copy of the personal data we hold about you.
- Correction. Ask us to fix data that's wrong or incomplete.
- Deletion. Ask us to delete your data.
- Portability. Ask for the data you gave us in a common, machine-readable format.
- Objection. Object to processing based on our legitimate interests.
- Restriction. Ask us to pause the use of your data while a question about it is settled.
- Complaint. Complain to a data protection authority, for example the one where you live or work. You can also contact us first, and we'll try to put it right.
To use any of these, email privacy@fradiation.games. Write from the email address linked to your account, and give your handle. We may ask you to confirm it's you. We reply within 30 days. If a request is complex and we need longer, we'll tell you why. There is no charge, unless a request is clearly unfounded or excessive.
There is no self-service account deletion yet. To delete your account, email us. We delete it within 30 days. You can delete your own comments yourself at any time.
If you live in a US state with a privacy law, you may have similar rights to know, correct and delete your data. We handle those requests the same way. We don't sell personal data or share it for advertising.
Children
You must be at least 13 to have an account. In places where the law sets a higher age for agreeing to the use of your personal data, you must be that age, or have a parent or guardian's permission. In parts of the European Union, that age can be up to 16.
We don't knowingly collect personal data from anyone younger than the minimum age. We don't check your age. If you think a child has created an account without permission, email us and we'll delete it.
Some games contain mature content. The site does not restrict games by age.
Security
We protect your data in these ways:
- the site and games are served over HTTPS;
- you sign in through Discord or GitHub, so we never see or store a password;
- session cookies are marked so scripts on the page can't read them, and are sent only over HTTPS on the live site;
- games run in a sandbox on separate addresses and can't reach your session or account data;
- game uploads are checked against what the developer said they'd upload before they go live;
- access to our database and hosting accounts is limited to the operator.
No system is perfectly secure, so we can't promise that nothing will go wrong. If a breach affects your personal data in a way the law requires us to tell you about, we will.
Changes to this policy
We may update this policy. We will post the new version on this page with a new effective date. If a change is significant, we'll put a notice on the site before it takes effect.
Effective date
This policy is effective September 30, 2026.