Attorney review required — not legally approved

Privacy Policy

Version 2026.10.09.v1 · Effective October 9, 2026

Operated by V Games Lab LLC, 161 Ocean Avenue, Point Pleasant Beach, NJ 08742, United States.

Important — Attorney Review Required

This Privacy Policy is a DRAFT prepared for attorney review. It is NOT legally approved, is NOT legal advice, and must not be treated as a final, production-ready privacy notice.

V Games Lab LLC intends to have this policy reviewed by qualified counsel before any public production launch. Disclosures that remain unresolved are called out expressly below.

Until an approved version is published, do not rely on this draft as the complete privacy notice for a live commercial service.

1. Introduction

This Privacy Policy explains how V Games Lab LLC ("PuzzleForge," "we," "us," or "our") handles information in connection with PuzzleForge.

It is intended to describe actual practices reflected in our current product and infrastructure. Where a practice is not yet implemented or not finally decided, we say so.

2. Who We Are

Operator: V Games Lab LLC, 161 Ocean Avenue, Point Pleasant Beach, NJ 08742, United States.

A dedicated privacy or legal contact email is pending attorney review and has not yet been designated in this draft. Until published, use the physical mailing address above for privacy-related correspondence.

3. Account Information

If you create a permanent account, we process account-related information such as email address, authentication identifiers, and profile data associated with your user record.

Plan and entitlement state (for example Free, Creator, or Publisher) may be stored so the Service can enforce product capabilities.

4. Authentication Data

Authentication is provided by Supabase Auth. Supported sign-in methods in the current product include email/password accounts and anonymous guest sessions.

Password credentials are handled by Supabase Auth according to its systems; PuzzleForge application code is not designed to store plaintext passwords.

We may store session-related identifiers necessary to keep you signed in and to associate requests with your user.

5. Guest Session Identifiers

PuzzleForge supports anonymous guest usage. Guest users receive a Supabase Auth anonymous identity that can own content, Points, and acceptance records in the same way a permanent user identity does within our systems.

If you later upgrade a guest account to a permanent email/password account, ownership and related records are intended to remain associated with that same user identity where the upgrade path is supported.

6. Uploaded and User-Provided Content

We process content you provide to create and manage puzzles and books, including themes, word lists, clues, questions, prompts, titles, descriptions, publishing settings, and uploaded cover images.

Saved creative work may include puzzle drafts, Activity Books and their item references, generation runs, and cover artwork metadata (including your artwork description) with image bytes stored in a private storage bucket named cover-artwork.

7. AI Prompts and Model Inputs

When you use AI-assisted features, we process the prompts and related inputs you submit, along with system instructions needed to operate the feature.

Those inputs may be sent to OpenAI to generate structured content, images, or moderation results. See "OpenAI Processing" and "Content Safety" below.

8. Generated Puzzle and Artwork Files

Generated puzzle definitions, Activity Book compositions, AI text outputs, and cover artwork derivatives may be stored so you can reload, edit, export, and continue work later.

Export jobs may produce PDF, HTML, or text artifacts. Downloadable job artifacts are stored in a private Supabase Storage bucket named job-artifacts.

9. Saved Activity Books and Related Records

Activity Books reference your puzzle drafts and may include publishing settings, cover settings, generation run state, and readiness or export history metadata.

We have not published a fixed retention period for saved puzzles and books. Unless and until we publish a specific retention schedule, saved creative work may remain until you delete it (where deletion tools exist) or until we change our retention practices with notice where required.

10. Points Balances and Transaction Records

PuzzleForge Points are tracked in an append-only ledger of point transactions. Balance is derived from those transactions rather than a separately mutable balance field.

We store transaction amounts, reasons/metadata needed for billing integrity, and related identifiers such as feature or purchase references.

OpenAI token counts and estimated provider costs may be recorded separately as internal telemetry in AI usage events. That telemetry is not the same as your customer-facing Points balance and is not exposed as a public write API.

11. Stripe Payment Processing

Paid subscriptions and Point Pack purchases may be processed by Stripe in test or live mode depending on environment configuration.

Stripe processes payment details according to its own privacy policy. We synchronize subscription and purchase state from verified Stripe events into our billing tables and entitlement systems.

As implemented today, Stripe refunds do not automatically claw back PuzzleForge Points. Cash-refund handling for purchased Points is not implemented as an automatic product feature in this version.

12. OpenAI Processing

We use OpenAI for AI content generation, cover image generation, and content moderation/safety checks.

Prompts, selected content, and related context needed for a request may be transmitted to OpenAI to provide the feature you requested.

We do not claim in this draft that OpenAI never trains on your data, never retains data, or never shares data beyond what is stated in OpenAI's own terms and policies. Those practices are governed by OpenAI and our contractual/configuration choices with OpenAI, which counsel should review.

13. Supabase Storage and Authentication

We use Supabase for authentication, PostgreSQL database storage, and object storage.

Private buckets used by the product include job-artifacts (export and job files) and cover-artwork (cover image bytes). Access is intended to be restricted by server-side controls and storage policies; clients should not receive service-role credentials.

14. Hosting

PuzzleForge is intended to be hosted on Render for application and worker services, with Supabase providing managed database, auth, and storage services.

Hosting and infrastructure providers may process operational data such as IP addresses, request metadata, and logs as part of delivering the Service.

15. Logs and Diagnostics

We and our providers may process logs and diagnostics to operate, secure, and troubleshoot the Service. Logs may include timestamps, request paths, error messages, job identifiers, and similar technical data.

We do not publish a single fixed retention period for all logs in this draft. Log retention may vary by system and provider.

16. Cookies and Session Technologies

We use cookies and similar technologies as needed for authentication sessions, security, and basic application operation.

A comprehensive cookie classification and consent-banner regime has not been finalized in this draft and is subject to attorney review for production launch, especially for jurisdictions with cookie consent requirements.

17. Retention and Deletion

Job artifacts: downloadable export artifacts in the private job-artifacts bucket are generally retained for approximately 7 days under current product design.

Job history: terminal job history is generally retained for approximately 90 days under current product design.

Saved puzzles, Activity Books, cover artwork records, Points ledger history, legal acceptance records, and related creative/account data: we have not published a fixed retention period for saved puzzles and books, and similar long-lived account data may persist until deletion processes are completed or retention policies are later published.

In-app account deletion and automated data-subject request (DSAR) workflows are not yet implemented. Deletion and access requests must currently be submitted via contact using our physical mailing address (and any later-published privacy email). Handling timelines, verification steps, and residual backup retention for such requests remain unresolved and require operational and legal review.

18. Security Measures

We apply administrative and technical measures appropriate to a modular web application, including authenticated API access, server-side enforcement for sensitive operations, private storage buckets for certain artifacts, and separation of secret credentials from browser code.

We do NOT claim encryption-at-rest guarantees, perfect security, or that unauthorized access can never occur. No method of transmission or storage is completely secure.

19. User Privacy Requests

Depending on where you live, you may have rights to request access, correction, deletion, or other actions regarding personal information.

Because in-app account deletion and DSAR tooling are not yet shipped, please send requests by mail to V Games Lab LLC, 161 Ocean Avenue, Point Pleasant Beach, NJ 08742, United States. A dedicated privacy email is pending attorney review.

We may need to verify your identity before acting on a request. Some records (for example, immutable billing or acceptance audit records) may be retained where we have a legitimate need or legal obligation. Exact response procedures remain subject to legal review.

20. Third-Party Service Providers

Key processors and service providers currently used or intended include: Supabase (auth, database, storage), OpenAI (AI generation and moderation), Stripe (payments), and Render (hosting).

These providers process data according to their own terms and privacy policies and our instructions/configuration. We do not claim that data is never shared with providers necessary to operate the Service.

21. International Processing

We are based in the United States. Information may be processed in the United States and in other countries where our providers operate.

Cross-border transfer mechanisms and regional privacy addenda (for example GDPR/CCPA operational details) are subject to attorney review and are not fully specified in this draft.

22. Children's Privacy

PuzzleForge is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Broader eligibility age rules (including whether users 13–17 may use the Service, and any parental-consent requirements) are TBD pending legal review. If you believe a child under 13 has provided personal information, contact us using the address in this policy so we can take appropriate steps.

23. Content Safety Moderation

We use server-side content-safety moderation for AI prompts/outputs and certain exportable publishing copy. Moderation may involve sending content to OpenAI moderation systems and applying internal policy checks.

Moderation is not perfect. Content may occasionally be blocked incorrectly or may occasionally pass despite being inappropriate. Moderation logs or related signals may be processed to operate and improve safety features.

24. Changes to This Privacy Policy

We may update this Privacy Policy as our practices or legal requirements change. Material updates will be published as a new version with an updated effective date.

Historical published versions are intended to remain available for reference where our legal versioning system is in place.

25. Contact Information

Privacy contact (draft): V Games Lab LLC, 161 Ocean Avenue, Point Pleasant Beach, NJ 08742, United States.

Dedicated legal/privacy email: pending attorney review — not yet designated in this document.

26. Effective Date and Document Version

This Privacy Policy is version 2026.10.09.v1, with a stated effective date of October 9, 2026.

This draft remains subject to attorney review and may change before production launch.

27. Unresolved Disclosures Pending Review

The following items remain unresolved or incomplete and require owner input and/or attorney review before production launch:

Dedicated privacy/legal contact email; final eligibility age and children's privacy program details; cookie consent banner and cookie categorization; formal GDPR/CCPA request workflows and response SLAs; in-app account deletion; published retention schedule for saved puzzles/books and related long-lived data; encryption-at-rest representations (none claimed here); OpenAI training/retention contractual posture; international transfer mechanisms; and any state or country-specific privacy notices beyond this general draft.