Privacy Policy
Last updated: 28 July 2026
This policy explains how Aurora Byte Games handles personal data when you visit or use GameInDev. Aurora Byte Games, based in Sweden, is the controller for the service. Questions and privacy requests can be sent to support@gameindev.com.
1. Data we process
- Account data: username, display name, email address, password hash, account status, accepted terms and security timestamps.
- Workspace data: projects, plans, design documents, uploads, feedback, activity and other content you or your collaborators add.
- Support and account email: messages you send us and delivery details for verification, password reset and important service email.
- Security data: session identifiers, short-lived verification/reset tokens and privacy-preserving abuse-limit keys. Passwords, session IDs and account tokens are stored as one-way hashes.
- Basic public-site analytics: page and conversion events, broad device/viewport categories and referring domain. We do not store the raw IP address or full browser user-agent in marketing analytics.
- Optional AI data: messages and the limited project context needed for a Loke request, but only when someone chooses to use the assistant.
2. Why we process it
- Contract: to create and secure your account, provide workspaces, collaboration, exports, public pages you choose to publish and account support.
- Legitimate interests: to protect the service from abuse, diagnose reliability problems and understand coarse, cookie-free public-site usage so we can improve the beta. We limit the data used for these purposes and do not build cross-site profiles.
- Legal obligations: when processing is required by applicable accounting, security or legal requirements.
- Consent: if we later add non-essential cookies or another feature that legally requires consent, it will stay disabled until you choose to allow it.
3. Cookies and browser storage
GameInDev currently uses only first-party cookies that are necessary to keep you signed in and remember the active project. They are not used for advertising or cross-site tracking. Browser local storage is used only for interface preferences such as theme, colour scheme, onboarding state and whether the Loke panel is open. Public marketing analytics sets no analytics cookie and stores no identifier in local storage. Its daily visitor hash changes every day and cannot be used to follow a visitor across days. Because no optional cookie is currently used, there is no cookie-consent banner. We will add consent before enabling any non-essential cookie or third-party tracker.
4. Who receives data
We do not sell personal data and we do not use it for third-party advertising. Data may be handled by:
- our self-hosted infrastructure and backup storage in the EU (Finland);
- Brevo, when sending verification, password-reset and other essential account email;
- OpenAI or Anthropic, only when a user enables Loke and sends a request through the selected provider;
- professional advisers or authorities when disclosure is legally required.
Where a supplier processes data for us, we require suitable data-processing terms. If data is transferred outside the EU/EEA, we rely on an applicable transfer mechanism such as an adequacy decision or standard contractual clauses. A user's chosen AI provider may also apply its own terms to that user's API account.
5. Loke and public pages
Loke is optional. When used, the prompt, relevant conversation history and only the project context needed for the answer are sent to the selected AI provider. API keys are encrypted at rest and are excluded from account exports. AI output may be inaccurate and should be reviewed before use. Project and studio pages are private by default; only content an authorised member explicitly publishes is made public.
6. Retention
- Account and workspace data is kept while the account or relevant project remains active.
- Deleting an account removes its active account, project, upload and Loke data. Disaster-recovery copies expire as the rolling backup set is replaced; the normal schedule keeps the 14 most recent daily database and upload snapshots.
- Detailed public marketing events are kept for up to 90 days. Aggregated daily visitor rows are kept for up to 400 days.
- Verification and reset tokens expire after 24 hours and 30 minutes respectively; expired token records are removed within the following 30 days.
- Abuse-limit records expire automatically. Operational and security logs are retained only as long as reasonably needed for reliability, abuse prevention and incident investigation.
7. Your rights
Depending on the circumstances, you can request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. A machine-readable export is available in Settings → Profile → Download my data. You can delete your account from Settings → Profile → Delete account, or contact support@gameindev.com. We may need to verify your identity before completing a request. You can also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
8. Security and changes
We use access controls, signed-in server-side authorisation, hashed passwords and tokens, encrypted API keys, transport encryption in production and restricted backups. No online service can promise absolute security, so please report suspected account misuse promptly. If this policy changes materially, we will publish the new date and provide an in-app or email notice when appropriate.