Product policy

Privacy notice

This notice describes the current adult, private-room research release. It is deliberately specific about what is implemented and what remains gated.

Version 2026-09-05 · effective 20 August 2026

Who is responsible

Deadpan (playdeadpan.com) is responsible for product data. Privacy questions and rights requests can be sent to [email protected]. Deadpan is still completing its entity and launch-jurisdiction review and does not claim a fictional company or registered office.

Adult, friend-first service

Deadpan is currently for adults aged 18 or older. We request birthday and gender from Google when you choose Google sign-in. If Google does not share those fields, you must enter them directly and confirm the age calculated from your birthday before camera or matchmaking starts. This is an age gate, not government-ID age assurance.

Camera, smile detection and live media

Your browser processes camera frames locally to detect a smile. Deadpan does not intentionally receive or store ordinary camera frames, face landmarks, or a face template for that detection. The server receives gameplay events such as readiness, smile confidence, score and match state.

For fair play, each player's browser also checks the other player's incoming video for smiles, in the same local way, and reports only "smile seen" events and their confidence. The moment you are caught is shown to you as a small local snapshot; it stays in your browser and is never uploaded. If you tell us whether a hit was fair, we store that answer with the match.

Live camera and microphone, if you separately enable it, travel over encrypted WebRTC to the invited participant. Connections may be relayed through Deadpan's coturn service. Ordinary live media is not intentionally recorded. Another participant can still use device or external recording tools, so play only with someone you trust and do not show private material in the background.

Information we use

  • Account email, password hash, verification, private birthday, gender, profile, selected country, game statistics and policy acceptance.
  • Session identifiers, refresh-token hashes, IP address, user agent and security timestamps.
  • Temporary room/invite state, match/player state, HP, scores, connection events, reactions and optional chat.
  • Reports, blocks, friendships and enforcement records.
  • Clip files, metadata, moderation results and play scoring only where the gated upload feature is used.
  • Minimal anonymous queue and friend-invite funnel events. These exclude identity, IP, room/match/invite identifiers, free text, clips, device/camera detail and media-derived data.
  • Coarse WebRTC health measurements such as direct/relay connection type, browser family, mobile/desktop class, network generation, quality level, round-trip time, packet loss, jitter and outgoing bitrate. These are stored only as aggregate operations snapshots without account, IP, room, candidate address or media identifiers.

Why and how long

We use information to provide and secure the service, connect invited participants, recover matches, enforce safety rules, respond to requests and understand whether the invite flow works. Depending on the law and purpose, the working bases are performance of the service contract, legitimate interests in security/safety and legal obligations. Qualified review remains pending for the chosen launch countries.

  • Anonymous queue/friend funnel events and operations history: 30 days.
  • Expired or revoked authenticated sessions: normally 7 days after they are no longer active.
  • Proposed raw match retention: 90 days; proposed raw event/chat retention: 30 days, extended where tied to an open report or legal hold.
  • Reports: open case plus a proposed 12 months, longer only for appeal, legal hold or statutory duty.
  • Temporary private room/invite state: 10 minutes or first successful join.

The match/report/clip schedules are the adopted targets but automated deletion is not yet enabled. They must be relation-tested and legally reviewed before production deletion begins. We will update this notice when enforcement is live.

Providers and transfers

The service is hosted with Hetzner Online GmbH in Falkenstein, Germany. A self-hosted coturn relay and configured STUN service process network metadata needed for WebRTC. Google processes identity, birthday and gender data only when you choose Google sign-in and approve the requested access; Deadpan falls back to direct profile entry when those optional fields are unavailable. Discord processes identity data only if you choose Discord sign-in. Cloudflare R2 may hold gated clip objects when configured. Provider contracts, exact production configuration and international-transfer requirements are under review before promoted launch.

Your controls and rights

You can deny camera, leave, mute microphone, revoke active login sessions and clear browser site data. Depending on applicable law, you may request access, correction, deletion, restriction, objection or a portable copy and complain to your regulator.

Email [email protected] with subject “Deadpan privacy request”. We verify requests proportionately, normally through the account email and a fresh authenticated session rather than requesting government ID by default. Anonymous funnel events cannot be linked back to you and will not be re-identified.

Storage on your browser

Strictly functional browser storage remembers settings, short-lived reconnect state and local UI choices. Deadpan does not currently use advertising cookies or session replay on camera/game routes. If non-essential tracking is added, it must receive a separate review and consent treatment before activation.

Changes and contact

Material changes to processing, recording, sharing, age access or user licences receive a new dated policy version and, where required, renewed acceptance. Contact [email protected] for questions, complaints or requests.