Privacy Notice
This notice explains what the Playport login experiment collects, why it is needed, and the choices available to you.
Effective and last updated: August 15, 2026
What this service is
Playport Labs is the name used for this independent login experiment. It compares account access methods. It does not currently provide games, chat, user posts, social networking, advertising, or purchases.
Data we collect
During adult signup, a birthday is sent once to confirm that the person is at least 18; the birthday is not stored. We store only the resulting adult age band, along with the username used as the initial display name, verified email, salted password hash, passkeys you add, account role, sessions, security events, policy acceptance, and deletion state. Parent accounts may create managed teen profiles with a display name, username, salted password hash, family settings, and a record of the parent’s authorization. We never receive the fingerprint, face scan, or device PIN used to unlock a passkey.
Why we use it
We use this data to create and secure accounts, deliver login and recovery codes, compare login options, prevent misuse, respond to safety and privacy requests, diagnose failures, and meet legal obligations. We do not sell personal information or use it for targeted advertising.
Companion sign-in
Playport Companion uses your existing secure account session to approve another device. A handoff stores a random one-time code, a broad browser-and-device label, status, and timestamps. The code expires after five minutes and the handoff record is removed after 24 hours. We do not request or store precise location for Companion approval, and the installed app does not cache account data or approval state for offline use.
Service providers
Cloudflare processes application traffic and stores the account database. OpenAI Sites hosts and deploys this experiment. Resend delivers account email and reports delivery events such as bounces and complaints. These providers process data to operate the service.
Retention and deletion
Account deletion locks access immediately and permanently removes account data after a 30-day restoration window. Security events are kept for 90 days. Resend delivery-event records are kept for 90 days; hashed suppression entries remain while needed to prevent repeated delivery to an address that bounced or complained. Resolved safety reports are deleted after one year. Unresolved reports remain while needed to investigate and respond.
Children and teens
Personal and parent accounts are for adults age 18 or older. The public beta does not allow profiles for children under 13. A parent may create a managed profile only for a teen age 13–17 and must confirm authority to do so. If we learn that an under-13 child submitted personal data, we will disable the profile and delete the data. Use the Safety & reports page to tell us.
Your choices and rights
You can review basic account information, remove passkeys, recover access, and schedule deletion from the account hub. Depending on where you live, you may also have rights to know, access, correct, delete, restrict, or object to processing. Submit a privacy or account-access report; we may need to verify that you control the account before acting.
Security and changes
We use encrypted transport, secure session cookies, salted password hashing, passkeys, rate limits, and minimal operational logs. No internet service can promise absolute security. Material policy changes will receive a new version and require renewed acceptance where appropriate.