Privacy Policy
Last Updated: February 27, 2026
We care about privacy and classroom trust. This policy explains what data we collect, why we collect it, how we use it, and what choices you have. If anything is unclear, contact us and we will explain it in plain English.
1. What We Collect
- Account data: name, email, authentication identifiers, and optional avatar/profile details.
- Content you create: games, prompts, instructions, uploads, edits, and library items.
- Uploads: documents/images you attach for AI generation, plus game assets you choose to store.
- Community visibility data: whether content is public or private, plus public author display fields.
- Contact messages: name, email, and message text sent through the Contact form.
- Technical data: basic logs, request metadata, and error diagnostics from the app and hosting stack.
- Browser-local data (guest mode): games may be stored in your browser localStorage.
- Voice input (optional): if you use dictation, microphone audio is processed by browser speech recognition and/or local Whisper Web transcription, depending on availability.
2. How We Use Data
- To provide core features (account login, generation, editing, saving, sharing).
- To generate AI-assisted content based on your prompts and uploaded source material.
- To support community libraries and visibility settings.
- To operate, secure, troubleshoot, and improve reliability and safety of the service.
- To respond to support/contact requests and enforce legal terms.
3. Legal Bases (Where Applicable)
Depending on your location, we process data under one or more of these legal bases:
- Performance of a contract (providing the service you asked for).
- Legitimate interests (security, quality, abuse prevention, product operation).
- Consent (for optional actions like voice features where required).
- Legal obligations (compliance, dispute handling, lawful requests).
4. AI Providers and Gemini Data Handling
When you use AI features, prompts, uploaded source files, and related context are sent to Google Gemini API (either through our server endpoint or direct client-side integration where configured).
Based on Google Gemini API documentation and terms currently published (including Google AI Studio terms effective December 18, 2025):
- For Google "Paid Services," Google states prompts/responses are not used to improve Google products.
- For Google "Unpaid Services," Google states prompts/responses may be used to improve its products and machine-learning technologies.
- Google may retain logs for abuse and safety monitoring under its own policies.
Because provider plans and configuration can vary over time, do not submit highly sensitive personal data in prompts or uploads unless you are legally authorized and comfortable with provider-side processing terms.
5. Where Data Is Stored
- Supabase is used for authentication, database storage, and file storage.
- AI generation requests are processed through Google Gemini API.
- Stock image search uses Pixabay via our API route/proxy.
- Hosting/infrastructure providers may process request logs needed to run the site.
6. How Long We Keep Data
- Account and saved content are kept while your account remains active, unless deleted earlier.
- Guest localStorage content remains on your device until you delete it or clear browser data.
- Public community content may remain visible until removed by you or moderation action.
- Contact messages are retained as reasonably necessary for support and legal recordkeeping.
- Operational logs may be retained for security, abuse prevention, and diagnostics.
7. Data Sharing
We do not sell your personal data. We share data only when needed:
- With processors/service providers that run platform features (for example, Supabase, Google, Pixabay, hosting providers).
- With other users only for content you intentionally mark as public/community.
- When required by law, court order, or to protect rights, safety, and service integrity.
- As part of a merger, acquisition, or business transfer (with notice where required).
8. Cookies and Similar Technologies
- We use essential browser storage and auth/session mechanisms to keep the app working.
- Guest-mode saved items use browser localStorage.
- At the time of this policy update, we do not run third-party ad tracking networks in the app.
9. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object/restrict certain processing.
- You can update profile information from the Profile page.
- You can delete saved content from your library.
- You can contact us via the Contact page for privacy requests.
- You may have the right to complain to your local data protection authority.
10. Student Data and School Use
If you use the service in a school context, you are responsible for ensuring you have a valid legal basis for any personal data you submit, including appropriate notices/consents where required by law or school policy.
11. International Transfers
Your data may be processed in countries outside your own. Where required, we rely on lawful transfer mechanisms and contractual safeguards provided by our service providers.
12. Security
We use reasonable technical and organizational measures to protect data. No online service is perfectly secure, so we cannot guarantee absolute security. Please use strong passwords and avoid sharing account access.
13. Children
The service is intended for adult educators and is not directed to users under 18. If you believe someone under 18 has submitted personal information through direct account use, please contact us so we can review and remove it where appropriate.
14. Changes to This Policy
We may update this Privacy Policy as the service evolves or laws change. Updated versions will be posted here with a revised "Last Updated" date.
15. Contact
For privacy questions or data requests, please contact us through the Contact page on the site.
Friendly note: this document is for transparency and legal clarity; it is not legal advice to you.