Privacy Policy
In this policy, "omegLOL," "we," "us," and "our" refer to Alexander Minch, the operator of omegLOL. "You" and "your" refer to a user of the Service. "Service" means the omegLOL website, applications, and related features. This policy explains what information we collect, what we deliberately do NOT collect, why we collect it, how long we keep it, who we work with, and the choices and rights you have. It should be read together with our Terms of Service.
1. The Short Version
- We do NOT receive, watch, record, or store your webcam video or audio. Live video/audio is sent directly between matched players (peer-to-peer), and the "laugh detection" runs entirely on your own device.
- We do NOT collect or store facial images, facial geometry, or other biometric identifiers. The only thing that leaves your device from the camera analysis is a numeric reaction/score signal.
- We collect the minimum needed to run accounts, gameplay (ratings, friends, leaderboards), and safety/moderation.
- We do not sell your personal information and do not use third-party advertising or cross-site tracking.
- You can request access to or deletion of your data (see Sections 10 and 11).
The rest of this policy explains the details.
2. Information We Collect
2.1Account information (registered users)
- Your email address, chosen screen name, and a securely hashed password; OR
- If you sign in with a third party (such as Google), the account identifier and email address that provider shares with us. We do not receive your third-party password.
- Authentication records needed to keep you signed in (session and linked-account records).
2.2Guest identifier (guests)
- A randomly generated token stored locally in your browser (in local storage) that maintains your guest session and progress. It is not tied to your real-world identity.
2.3Gameplay data
- Your friend code, rating (Elo), win/loss/draw records, match history (opponents, scores, and rating changes), friends list, and online/presence status. Presence ("who is online right now") is held temporarily in memory and is not a permanent record.
2.4Safety and moderation data
- Reports you submit or that involve you, including the report reason, any description you write, timestamps, the game and users involved, and a snapshot of the reporter's reliability ("trust") indicator at the time.
- Enforcement records, including suspensions/bans, their reason, and their duration.
- A reliability ("trust") score associated with your account or session, used to weigh reports and detect abuse.
- A salted, one-way hashed form of your IP address, used solely to detect abuse and ban evasion. We do not store the raw IP address for this purpose, and the hash cannot be reversed back into your IP address.
2.5Technical and operational data
- Cookies and local storage used for authentication and to run the Service (see Section 7).
- Basic server and security logs (such as timestamps, error records, and coarse request metadata) needed to operate, debug, and protect the Service. As a normal part of delivering any internet service, our infrastructure and security providers (see Section 8) process network-level information, including IP addresses, in transit.
2.6Communications
- If you contact us (for example, by email), we receive the information you choose to provide.
We do not currently collect payment information because the Service is free. If that changes, we will update this policy.
3. Information We Do Not Collect
3.1Webcam video and audio. Your live video and audio are transmitted directly between matched players (peer-to-peer). We do not receive, view, record, or store your video or audio streams.
3.2Facial images and biometric identifiers. The facial analysis that powers "laugh detection" runs locally, in your browser, on your device. We do not receive or store facial images, facial landmarks/geometry, faceprints, or any other biometric identifier. Only a numeric reaction/score signal derived on your device is transmitted to run the game.
3.3Payment or financial information (the Service is currently free).
3.4Precise geolocation. We do not collect GPS-level location. (Approximate region may be inferable from an IP address at the network level by infrastructure providers, as with any website.)
3.5We do not buy personal information from data brokers, and we do not sell or rent your personal information to anyone.
Important: while WE do not store your video/audio, remember that the other participants in your match can see and hear you live, and a third party could attempt to capture a stream through means outside our control. Only show what you are comfortable showing (see our Terms of Service).
4. How the Camera / "Laugh Detection" Works (On-Device)
When you play, your browser accesses your camera to (a) send your live video directly to your matched opponent(s) and (b) run a facial-expression model locally to estimate amusement (smiles/laughs). This analysis happens entirely on your own device. The model's output is reduced to a small numeric signal (for example, a reaction "tier" and a score value) that is used to keep score. That numeric signal — not your image or any facial data — is what is transmitted. We do not store the raw analysis, the facial landmarks, or the video frames.
5. Why We Collect Information (Purposes)
We use the information described above to:
- Provide and operate the Service, including matchmaking, live rounds, ratings, leaderboards, friends, and lobbies.
- Create and secure accounts and keep you signed in.
- Maintain safety and integrity: process reports, run moderation (including automated moderation), enforce our Terms, and prevent, detect, and respond to abuse, cheating, and ban evasion.
- Protect the Service, our users, and the public, and maintain security.
- Communicate with you about the Service and respond to your requests.
- Comply with legal obligations and enforce our agreements.
Legal bases (for users in the EU/UK, where GDPR applies). We rely on: performance of a contract (to provide the Service you request); our legitimate interests (to keep the Service safe, secure, functioning, and free from abuse); your consent (where required, such as certain optional features); and compliance with legal obligations. Where we rely on legitimate interests, we balance those interests against your rights.
6. How We Share Information
We do not sell your personal information. We share information only as follows:
- With service providers and infrastructure that operate the Service on our behalf (see Section 8), under terms that limit their use of the data.
- With other players, only to the extent necessary to play: your screen name, rating/rank, and friend code are visible in gameplay contexts, and your live stream is sent to your matched opponent(s).
- For legal and safety reasons: to comply with law, legal process, or valid government requests; to enforce our Terms; and to protect the rights, safety, and security of our users, the public, or us. This includes reporting child sexual exploitation to the National Center for Missing & Exploited Children (NCMEC) and/or law enforcement as required or permitted by law.
- In a business transfer: if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
7. Cookies and Session Handling
7.1Authentication session cookie. For registered users, we set a session cookie when you sign in. It is intended to be HTTP-only (not readable by page scripts), Secure (sent only over HTTPS), and set with a SameSite attribute to reduce cross-site risk. This cookie is strictly necessary to keep you logged in.
7.2Guest local storage. For guests, we store a random identifier in your browser's local storage (not a cookie) to maintain your session and progress. You can clear it at any time through your browser (see Section 11).
7.3Infrastructure/security cookies. Our security and infrastructure provider (see Section 8) may set cookies that are strictly necessary to protect the Service (for example, bot-management or security-challenge cookies).
7.4No advertising or cross-site tracking. We do not use third-party advertising cookies or cross-site tracking. [If web analytics are added in the future, we will update this policy and, where required, request consent.]
7.5Controlling cookies. Most browsers let you block or delete cookies and clear local storage. Blocking strictly necessary cookies may prevent sign-in or break parts of the Service.
8. Third-Party Services and Technologies
We rely on the following. Where a provider is a separate company that processes data, its own privacy policy also applies.
Third parties that process data:
- Google Sign-In (OAuth) — for optional "Sign in with Google." When you use it, Google authenticates you and shares your account identifier and email with us. Your use of Google is governed by Google's Privacy Policy. [https://policies.google.com/privacy]
- Cloudflare — for domain/DNS, and for hosting/content delivery, proxying, and security (including DDoS and bot protection). Cloudflare processes network traffic, including IP addresses, to route and secure requests. [https://www.cloudflare.com/privacypolicy/]
- [DATABASE / APPLICATION HOSTING PROVIDER] — where our application and database run, if different from Cloudflare. [ADD PROVIDER + PRIVACY POLICY LINK]
- STUN/TURN (WebRTC connectivity) — to establish peer-to-peer connections, the Service uses STUN and, when network conditions require, TURN relay servers. If a TURN relay is used, your encrypted media may pass through it in transit; it is not stored by us. [ADD TURN PROVIDER IF SELF-HOSTED OR THIRD-PARTY]
- [EMAIL PROVIDER] — if/when we send transactional emails (such as password reset). [ADD PROVIDER + LINK, OR REMOVE IF NOT USED]
Technologies we run on our own systems (not separate data recipients):
- better-auth — an open-source authentication library integrated into our own backend. It handles account creation, password hashing, and session management on our infrastructure; it is a component we operate, not a third party we send your data to.
We will update this list as our providers change.
9. Data Retention
We keep personal information only as long as needed for the purposes in this policy, then delete or anonymize it. Typical periods:
- Account information: kept while your account is active; deleted or anonymized after you delete your account or request deletion, except where we must retain limited records for legal or safety reasons.
- Guest identifier and guest gameplay data: the local identifier remains in your browser until you clear it; associated server-side guest records are retained while in use and pruned after 12 MONTHS of inactivity.
- Gameplay records (ratings, match history, friends): retained while your account is active to power your history and leaderboards; removed or anonymized on account deletion.
- Safety and moderation records (reports, bans, trust signals, salted IP hash): retained longer than other data to preserve the integrity of moderation and to prevent ban evasion — for 24 MONTHS, or longer where required for legal, safety, or security reasons. Some minimal enforcement records may be retained even after account deletion to enforce bans and protect the Service.
- Operational and security logs: retained for a short period, typically 30-90 DAYS, unless needed longer for security investigations.
10. Your Rights and Choices
Depending on where you live, you may have rights over your personal information. These may include the right to: access the information we hold about you; correct inaccurate information; delete your information; restrict or object to certain processing; port your information; and withdraw consent where processing is based on consent. Users in the EU/UK (GDPR) and California (CCPA/CPRA) have specific versions of these rights.
- We do not sell or "share" personal information for cross-context behavioral advertising, so there is no sale/share to opt out of.
- We will not discriminate against you for exercising your rights.
- To protect your account, we may need to verify your identity before acting on a request. For guests, we may be unable to verify ownership of an anonymous identifier and therefore may be unable to fulfill certain requests.
To exercise any right, contact us at [email protected]. EU/UK users may also lodge a complaint with their local data protection authority. If we have designated a data controller or representative, it is Alexander Minch.
11. How to Request Deletion
11.1Registered accounts. To delete your account and associated personal information, use the in-app account-deletion option (if available) or email us at [email protected] from the address associated with your account. We will delete or anonymize your personal information, except for limited records we are permitted or required to keep for legal, security, or safety reasons (for example, active ban records and the minimal data needed to enforce them).
11.2Guests. Clearing your browser's local storage (and cookies) removes the guest identifier from your device. Because guest data is not tied to a verified identity, we may be unable to locate or verify server-side guest records; where we can, you may contact us at [email protected] for assistance.
11.3Timing. We aim to respond to verified deletion requests within the period required by applicable law generally within 30 days, subject to extensions permitted by law.
12. Security
We take reasonable measures designed to protect your information, including:
- Encryption in transit (HTTPS/TLS) for traffic to the Service, and encrypted peer-to-peer media (WebRTC uses DTLS-SRTP by design) between players.
- Securely hashing passwords using industry-standard algorithms; we never store passwords in plain text.
- HTTP-only, Secure session cookies for authentication.
- Storing IP addresses used for abuse detection only as a salted, one-way hash.
- Keeping video and audio off our servers entirely (peer-to-peer, on-device analysis), which minimizes the most sensitive data we could hold.
- Infrastructure protections such as DDoS mitigation and bot/security controls provided by our infrastructure provider, plus access controls and data minimization.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and authorities as required by law.
13. Children
The Service is for adults 18 and older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete it and terminate the associated access. If you believe a minor is using the Service or has provided us information, contact us at [email protected].
14. International Users and Data Transfers
We operate the Service from the United States, Canada, European Union, and globally distributed regions operated by our hosting, CDN, and authentication providers. If you access the Service from another country, your information may be transferred to, stored, and processed in countries with different data-protection laws than yours. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for international transfers.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date and post the updated policy. If changes are material, we will take additional steps to notify you where required by law. Your continued use of the Service after an update takes effect means you accept the revised policy.
16. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or your information, contact:
Alexander Minch
[email protected]
Data controller: Alexander Minch, an individual based in Indiana, United States. No EU or UK representative is designated, as the Service does not target users in those regions.