GAMEPACK.

Effective July 12, 2026

Privacy Policy.

This policy explains what GamePack handles when you use the website, iPhone app, Android app, online rooms, and nearby Plane Mode.

The short version

GamePack collects the information needed to run accounts, rooms, purchases, custom packs, support, security, and basic product analytics. We do not run third-party ads, sell personal information, or use gameplay to build advertising profiles.

Questions and privacy requests can be sent to contact@thesis.do.

Information you provide

  • Account information: display name, email address, authentication credentials, and profile details. If social sign-in is available and you choose it, the provider sends the basic account information needed to sign you in.
  • Gameplay information: room code, player name, game settings, scores, cards, submissions, game actions, custom pack text, and timestamps needed to run an online room.
  • Account features: saved custom packs, waitlist status, promo or access code redemptions, and account entitlement status.
  • Support: messages, screenshots, purchase context, and other details you choose to send when asking for help or reporting a bug.
  • Safety reports: report reason, room code, reporter account or room-player identifier, the player or content reported, a limited content excerpt, details you provide, incident time, submission time, and review or enforcement status.

Device, network, and local information

GamePack may process IP address, browser or app version, operating system, device type, request timing, diagnostic details, and security events. We use this information to deliver the service, diagnose problems, limit abuse, and protect rooms and accounts.

The web and native apps create a random app-specific device identifier for room continuity, duplicate-player protection, and optional humor memory used by advanced bots. That identifier is not an advertising identifier. Web local storage and native device storage may also keep a player name, room credentials, preferences, saved local content, and entitlement state needed by the app. You can clear local data through browser controls, device settings, or by removing the app.

To protect hosted native features, the iPhone app may use Apple App Attest and the Android app may use Play Integrity plus an app-generated Android Keystore public key. GamePack processes the resulting app, device-integrity, installation, challenge, and signing information to detect modified apps, replay, and entitlement abuse. Raw attestation proofs and native bearer tokens are used transiently for verification and are not stored in the GamePack database.

Online rooms and Plane Mode

In an online room, GamePack servers receive the room setup, player names, app-generated device identifiers, game actions, submissions, and custom content needed to keep every participant in sync. Other players can see public room information such as names, scores, prompts, and revealed plays. Private hands and unrevealed submissions are only sent where the game requires them.

In Plane Mode, supported devices send gameplay information directly among nearby participants. GamePack servers do not receive the nearby gameplay session when it stays offline. The host and other participants necessarily receive the room information required to play, and copies already delivered to another person's device cannot be recalled.

Purchases and promo codes

iPhone purchases are processed by Apple through StoreKit. Android purchases are processed by Google through Google Play Billing. Those stores handle payment credentials and provide GamePack with product, transaction, verification, and entitlement information needed to unlock or restore Pro. GamePack verifies this information with Apple or Google and stores keyed digests and bounded entitlement metadata, not the raw native purchase proof. GamePack does not receive your full payment card number from Apple or Google.

A promo redemption records a keyed one-way code identifier, the account or native installation that redeemed it, the unlock granted, and the redemption time. Native redemption also stores the platform, installation identifier, a one-way claim proof and credential digests, bounded entitlement metadata, and a revocation status so Online Pro access can be refreshed or withdrawn. Plaintext redeemable promo values, raw refresh credentials, and raw network addresses are not kept in the promo tables. This prevents errors, supports unlocks, and helps investigate abuse.

AI pack generation

When you choose to generate a custom pack, GamePack sends the theme, game type, requested Standard or After Dark tone, and relevant existing pack text to an AI model provider. The current generation flow uses Anthropic Claude through the Vercel AI model gateway. Do not put names, secrets, or other sensitive personal information in a generation theme or custom card.

Analytics

The production website uses Vercel Analytics to understand page use and technical performance. This can involve page, referrer, browser, device, and approximate network or location information made available with a web request. We use these measurements to improve GamePack, not to serve targeted ads.

How we use information

  • Provide accounts, games, rooms, saved packs, and Pro features.
  • Authenticate users and restore valid purchases or code unlocks.
  • Keep participants synchronized and personalize game behavior.
  • Generate custom content when requested.
  • Answer support requests and investigate bug reports.
  • Receive and investigate safety reports, enforce the Community Standards, prevent duplicate reports, and limit report spam.
  • Prevent spam, fraud, cheating, attacks, and service abuse.
  • Measure reliability and improve the product.
  • Comply with law and enforce the Terms of Service.

Safety reports and blocking

In-app safety reporting requires either a current room capability for a room incident or a signed-in account for a service issue. GamePack uses one-way technical identifiers to enforce report idempotency and rate limits without storing a raw room capability or client-provided idempotency key. Report evidence can contain offensive material or personal information supplied by the reporter, so only include context that is necessary to understand the incident.

Blocking is intended to give the person using the app immediate control over their experience. A local or nearby block may remain on that device and may not automatically synchronize across platforms. Blocking does not submit a report, and reporting does not automatically remove material already delivered to another participant's device.

When information is shared

We share information with service providers only as needed for their work, including hosting and infrastructure providers, database and authentication services, analytics, AI model processing, email support, and Apple or Google for purchases. Those providers process information under their own terms and privacy commitments.

We may also disclose information if reasonably necessary to comply with law, protect a person, investigate abuse, enforce our terms, or complete a business transaction involving GamePack. We do not sell personal information and do not share it for cross-context behavioral advertising.

Retention and deletion

Account details, saved packs, and account unlock records are generally kept while the account remains active. Online room, security, support, and diagnostic records may remain for a reasonable operational period. Some records may be retained longer when required for fraud prevention, transaction integrity, dispute resolution, legal compliance, or the safety of the service. Safety reports and enforcement records may be retained after a room or account ends when reasonably needed to prevent repeat abuse or document a decision. We do not promise automatic room or report deletion on a fixed schedule.

You can request deletion of your GamePack account and associated data from the Account Deletion page. We may ask you to verify control of the account. Store purchase records held by Apple or Google are governed by that store, and data already shared directly with other Plane Mode participants cannot be removed from their devices by GamePack.

Security

We use reasonable technical and organizational safeguards, including encrypted transport, scoped room credentials, access controls, and rate limits. No internet or peer-to-peer service can guarantee perfect security. Protect room links, device access, and account credentials, and contact us if you think something has gone wrong.

Children and adult content

GamePack is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact us so we can review and delete it. After Dark content is intended only for adults age 18 and older. Hosts are responsible for choosing an appropriate deck for the group.

Your choices and policy changes

You can edit your display name, sign out, clear local storage, choose not to use AI generation, block players where that control is offered, and request account deletion. Depending on where you live, you may also have rights to access, correct, delete, restrict, or receive a copy of personal information. Email us to make a request. We may retain limited safety and transaction records when applicable law permits or requires it.

We may update this policy as GamePack changes. We will update the effective date and provide additional notice when a change is material. Continued use after an update means the new policy applies to future use, subject to rights provided by law.

Contact

For privacy questions or requests, email contact@thesis.do.