Game Connect Social Privacy Policy
Policy version: 1.1
Effective date: August 7, 2026
Current operator: Malyk Parker
Privacy and data requests: support@gameconnectsocial.com
Public URL: https://gameconnectsocial.com/privacy
This Privacy Policy explains how Malyk Parker (Operator, we, us, or our) collects, uses, shares, retains, and protects information when you use the Game Connect Social public beta (GCS).
This policy describes the current public-beta product. It does not describe deferred features as active. GCS does not currently provide wagering, gambling, cash competitions, paid tournaments, financial services, native voice chat, native livestream or video hosting, creator payouts, official Steam/Xbox/PlayStation integrations, or an AI concierge.
1. Information you provide
Account and authentication information
We process your email address, account identifier, authentication method, account status, and security/session information. If you choose Sign in with Apple or another supported identity provider, we receive the provider account identifier and information the provider makes available, such as an email address or private relay address. We do not receive your Apple Account password.
Founding User beta access requests
If you request Founding User access on the public GCS website, we collect the email address you submit, your consent record, request and confirmation times, and the status of your request. We use this information only to confirm the address, manage controlled beta invitations, send beta-testing updates, and honor withdrawal requests. The form uses a keyed one-way hash of the request IP address for short-lived abuse limits; GCS does not store the raw IP address in the Founding User signup database.
Profile and gaming information
You may provide a handle, display name, biography, avatar, profile banner, favorite games, platform preferences, gaming identities, skill or experience descriptions, microphone preference, and visibility choices. Gaming identities are normally player-provided unless expressly marked verified.
User-generated content
We process content you create or submit, including posts, comments, reactions, photos and other supported media, Team materials, announcements, events, recruiting content, LFG descriptions, reports, and related metadata such as creation time and audience context.
Messages and communications
We process direct, Team, Game Space, Competitive Team, and Party messages; message attachments; participants; reactions; mentions; read state; and delivery metadata. We also process communications you send to support. Message content is not used for recommendation analytics or advertising.
Teams and community information
We process Team, Game Space, and Competitive Team membership and role data; applications and application messages; invitations; leadership scopes; recruiting responses; event RSVPs; moderation actions; lifecycle state; and records needed to preserve authorization and audit history.
Gameplay-coordination information
When enabled, we process coarse GCS Presence states, game and mode selections, platform and crossplay compatibility, Party-size preference, availability, LFG and Play Now requests, matching state, Party membership, invitations, ready state, session start/completion state, gaming identity disclosure within authorized Parties, and whether GCS-formed players choose to play together again.
GCS does not currently read console or PC activity through official Xbox, PlayStation, or Steam integrations and does not collect authoritative in-game statistics or game telemetry through those providers.
2. Information collected through use of GCS
Social and preference signals
We process Connections/follows, likes, comments, memberships, favorite games, blocks, mutes, notification preferences, recommendation feedback such as Not interested or See less, and the context needed to provide or explain feeds and recommendations.
The current public beta does not send general behavioral analytics to a paid or third-party analytics provider. A local analytics preference may appear in Settings, but no external analytics provider is connected. Synthetic recommendation evaluation is restricted to approved non-production fixtures; production behavioral event collection for that evaluation is disabled.
Notifications and device registration
If you enable push notifications, we process an Apple Push Notification service (APNs) device token, a random installation identifier, app build, push environment, notification preferences, delivery state, and badge/unread state. Notification previews may contain limited social or message context when your settings permit. Apple also processes push delivery information under its own terms and privacy policy.
Technical, security, and diagnostic information
GCS and its infrastructure providers may process IP address, request time, network and API metadata, app/build version, device or operating-system type, authentication events, session identifiers, error categories, and bounded diagnostic information needed to operate, secure, troubleshoot, and prevent abuse. GCS application diagnostics are designed to exclude passwords, access tokens, raw push tokens, private-message content, and other secrets.
GCS does not currently use a third-party advertising SDK, cross-app tracking, or a network crash-analytics provider. Operational infrastructure providers may maintain security and service logs under their normal retention controls.
Game-catalog information
We process game searches, selected game identifiers, favorites, platform and genre metadata, and provider attribution needed for the game catalog. GCS may send a controlled game search or catalog request from its server to RAWG. GCS does not send RAWG your email, private profile fields, device token, or message content. Approved provider identifiers, artwork URLs, and attribution may be stored in the GCS catalog.
3. How we use information
We use information to:
- create, authenticate, secure, restore, and delete accounts;
- provide profiles, posts, media, messaging, Connections, Teams, Game Spaces, Competitive Teams, notifications, Presence, LFG, Play Now, Parties, and gameplay coordination;
- enforce privacy, block, mute, membership, role, and audience controls;
- match compatible players and maintain truthful Party/LFG/session state;
- personalize and explain feeds, recommendations, game context, and gameplay opportunities using deterministic or otherwise disclosed signals;
- send transactional email and enabled push notifications;
- investigate reports, moderate content, prevent abuse, enforce rules, and preserve system and community integrity;
- diagnose failures, secure infrastructure, prevent fraud, and improve reliability and performance;
- comply with law, protect rights and safety, and respond to valid legal requests; and
- communicate policy, security, support, or material service updates.
We do not sell personal information. We do not use personal information for cross-context behavioral advertising, and we do not share it with data brokers.
4. When information is visible to others
Information is shared according to the feature and audience you choose:
- public profiles, public posts, public Teams, and public game activity may be visible to other users or visitors as the feature permits;
- Connections/follows, likes, comments, and other interactions may identify you to the relevant audience;
- Team and Game Space information is visible according to membership, management, scope, and content-visibility rules;
- messages and Party chat are available to authorized participants;
- LFG, Presence, Party, and gameplay-session information is shown only where current eligibility, privacy, block, and lifecycle rules allow; and
- reports and moderation records are restricted to authorized reviewers.
Blocking or muting changes supported future interactions, but it cannot erase copies another person already received or control activity outside GCS.
5. Service providers and third parties
We disclose information to service providers only as reasonably necessary for the services they perform. Current or beta-ready providers may include:
- Supabase for authentication, Postgres database, file storage, Realtime, and server-side functions;
- Apple for Sign in with Apple, APNs, app distribution, TestFlight, and device-platform services;
- Google if Google sign-in is offered and you choose it;
- Resend for transactional email;
- RAWG for controlled server-side game-catalog search and attribution; and
- Squarespace for domain registration and DNS; and
- GitHub Pages for the public GCS website and legal pages.
These providers may process technical identifiers and network information under their contracts and privacy terms. GCS may also link to third-party games or platforms. Information you provide directly to those services is governed by their policies.
Stripe code and payment database foundations may remain in the engineering repository, but paid service activation and user payment collection are not part of the current public beta. GCS does not currently collect payment-card or purchase information from beta users.
We may disclose information when reasonably necessary to comply with law, legal process, or enforceable requests; protect users, the public, the Operator, or GCS; investigate abuse; or complete a lawful reorganization or transfer of GCS. A future transfer to a newly formed entity would require appropriate notice and an updated policy; no such entity is the current operator.
6. Recommendations and automated processing
GCS may use explicit favorites, Connections, follows, Team/Game Space membership, content metadata, gameplay preferences, recent GCS sessions, and feedback controls to rank or recommend content and gameplay opportunities. These systems are intended to be deterministic and explainable during the beta. They do not make legal, financial, employment, or other similarly significant decisions about you.
Private messages, email addresses, raw device tokens, authentication tokens, payment data, and precise location are excluded from recommendation inputs.
7. Retention
We keep information only as long as reasonably necessary for the purposes in this policy:
- account, profile, social, content, message, Team, and gameplay-coordination information is generally retained while the account or relevant feature record remains active;
- unconfirmed Founding User requests expire after 30 days; confirmed requests are retained while the beta access program remains active or until the requester withdraws;
- withdrawing a Founding User request immediately removes the stored email address; a pseudonymous email hash and withdrawal time may be retained for up to 12 months to prevent unwanted re-enrollment and document the withdrawal;
- keyed Founding User request rate-limit hashes expire after 48 hours and do not contain the raw request IP address;
- short-lived Presence and active matching state expire or become unavailable under their lifecycle rules;
- explicit recommendation feedback may expire according to the control used; current design limits are up to 365 days for Not interested and 90 days for See less, and users may reset supported suggestions earlier;
- approved non-production raw recommendation-evaluation events expire after 30 days; they are not enabled for production users;
- completed account-deletion request records may be retained for up to three years without email, content, provider credentials, tokens, or a continuing user identifier, to demonstrate fulfillment and investigate operational failures;
- moderation, security, fraud-prevention, and Team audit records may be retained or anonymized for as long as reasonably necessary to protect users, enforce rules, resolve disputes, or comply with law; and
- deleted information may persist temporarily in restricted backups and provider logs until overwritten under normal backup and security-log schedules. It is not restored to active service except when needed for disaster recovery, security, or legal obligations.
Retention may be extended when reasonably necessary for an active report, investigation, dispute, legal hold, or enforceable legal obligation. When the reason ends, we delete or anonymize the information unless another legitimate reason applies.
8. Account deletion
You may initiate deletion directly in **Settings > Privacy & Data > Delete Account**. GCS records an authenticated, idempotent request, displays a completion deadline, and signs the device out. Fulfillment may take up to 30 days.
The deletion process is designed to:
- remove the Supabase authentication account and refresh sessions;
- remove the public profile, posts, comments, messages, reactions, Connections, preferences, notifications, Presence, LFGs, gameplay participation, and other account-linked records where removal is required;
- remove user-owned avatars, banners, post media, message attachments, and other owned files through the storage service;
- invalidate push registration and active gameplay state;
- revoke Sign in with Apple authorization when a usable authorization token is available, or instruct the user how to revoke access manually if automatic revocation is not technically available; and
- delete, transfer, archive, or anonymize Team/community responsibilities as needed to avoid leaving an active Team without responsible ownership.
Some limited records may be retained or anonymized when legitimately necessary for safety, security, moderation, Team audit integrity, dispute resolution, fraud prevention, or law. Retained records are restricted and are not used for recommendations or marketing. Shared recipients may retain content they copied or exported outside GCS.
For a deletion-status question, contact support@gameconnectsocial.com from the email associated with the account when possible.
9. Your choices
Depending on the feature and applicable law, you may:
- edit supported profile and gaming identity information;
- manage Presence visibility, notification preferences, message previews, and device-level push permissions;
- block or mute users and report content or conduct;
- choose whether to join a Team, LFG, Party, or gameplay session;
- withdraw a Founding User beta access request through the link provided in the confirmation email or by contacting support;
- use recommendation feedback and reset controls when available;
- remove supported content or request account deletion; and
- request access, correction, or deletion by contacting support@gameconnectsocial.com.
Apple notification authorization is separate from in-app preferences. Turning off an in-app category does not change iOS permissions, and changing iOS permissions does not necessarily change every in-app preference.
We may need to verify your identity before responding to a privacy request. We will not discriminate against you for exercising a privacy right. Some rights vary by location and may be subject to lawful exceptions.
10. Security
We use safeguards appropriate to a public beta, including encrypted HTTPS transport, authenticated sessions, row-level and object-level authorization, restricted administrative paths, server-side state transitions, limited client privileges, audit records, rate limits, feature kill switches, and separation of secrets from the mobile client.
No system is perfectly secure. Keep your credentials private, use device security, and contact support@gameconnectsocial.com if you suspect unauthorized access. Do not send passwords, access tokens, or other secrets to support.
11. Children and minors
GCS is not directed to children under 13, and users under 13 may not create an account. Users under the age of majority where they live should use GCS only with a parent or legal guardian's permission. If you believe a child under 13 provided personal information, contact support@gameconnectsocial.com so we can investigate and delete it.
GCS does not knowingly use children's information for targeted advertising.
12. International users
GCS is operated from the United States. Information may be processed in the United States and other locations where our service providers operate. Those locations may have privacy laws different from those where you live. We use provider and contractual safeguards appropriate to the service and will honor applicable privacy rights.
13. Policy changes
We may update this policy as the beta, providers, or legal requirements change. The current version and effective date will appear at https://gameconnectsocial.com/privacy. We will provide reasonable notice of material changes and request consent when required.
14. Contact
Privacy questions, data requests, and deletion questions may be sent to:
Malyk Parker
Operator, Game Connect Social
support@gameconnectsocial.com