Privacy Policy
Effective September 11, 2026 · MattyJacks LLC, New Hampshire, USA
This policy describes how MattyJacks LLC (“MattyJacks,” “we,” “us,” or “our”) handles information across the 4weird Games websites, games, accounts, Clans social features, bot platform, agent rentals, Vibe Coins economy, Teams/enterprise workspaces, VibeCodeWorker surfaces, exhibits, APIs, and related services (collectively, the “Service”). It applies whenever you visit or use the Service, on 4weird.com or any domain where the Service is served.
1. Who is responsible for your information
MattyJacks LLC, New Hampshire, USA, is the controller (or “business”) for information collected through the Service. Contact: matt@mattyjacks.com. Exercise your privacy rights yourself anytime at /my/rights/; special cases (including family requests for a deceased user, with proof of authority) are handled by email; see Section 11.
2. Information we collect
Account and identity. Email address, password-authentication records, display name, public handle, permanent human ID (bot users), and account timestamps.
Profiles and preferences. Display name, handle, account settings (friend requests, playtime visibility, marketing email, Kids Mode flag), accessibility controls, and creator submissions.
Games. Cloud-save content (game, slot 0-3, versioned data ≤1 MiB, including any permanent cheat-mode mark; slot 0 can never be marked), gameplay telemetry (kills, actions, active seconds, deaths), matchmaking/lobby/presence records, and leaderboard aggregates (handles + totals only).
Clans and user content. Clans, memberships, posts, comments, uploaded images (≤1 MB; PNG/JPEG/WebP/GIF; hash + storage path), and moderation reports (anonymous reports allowed; CSAM reports trigger immediate quarantine and evidence preservation for authority referral).
Bots. Bot usernames, human-ID links, and API-key hashes (key secrets are shown once and never stored).
Vibe Coins and transactions. Coin ledger and grant entries, daily-claim streaks, referral codes and referral links, signup-trial records (privacy-preserving IP hash), checkout sessions and order reconciliation by email, voluntary Support transfers (tips, subscriptions) and gift-based launch-Campaign backing. Campaign pages publicly show the campaign story, goal, raised totals, and backer counts; individual contribution amounts are visible only to you and the campaign creator. Card and payment details are processed by our checkout provider (Shopify and/or its payment processors); we do not store full payment-card numbers.
Agent rentals and Teams compute. Listings, bookings, escrow and metered-usage records, provider references, org/team/project/room memberships and roles, cloud provisions and usage, wallet ledgers, and audit entries.
Communications. Support and rights-request messages you send us, including verification and authority documents for special-case requests.
AI and voice/camera features. Text you send the Gaming Buddy (messages, transcripts, screen text), one downscaled image per message when you share your screen or attach a camera frame, and voice replies we generate for you. Screen snapshots and camera frames are processed for that turn only; never stored, never logged. Microphone audio for interruption detection never leaves your device (only transcripts are sent). Avatar, voice, camera, purchase, and cookie choices tied to your account or device.
Age checks (never collected). Date of birth entered in a game age gate is checked on your own device, in memory, for that check only. It is never sent to our servers, never written to any database, and never stored in your browser; there is nothing to export or delete because we never receive it. The Kids Mode flag is an ordinary account/device preference, not age data.
Family accounts. Full accounts store only a self-declared band — Teen (13-17) or Adult (18+) — never a birth date. Parent accounts (Adult 18+ only) hold their children's handles (username#1234), parent-attested age bands (Kid 0-12, Teen 13-17, Adult 18+), play controls (budgets, time limits, hours), wallet ledgers, and daily play totals; never passwords (scrypt hashes only, never exported) and never session tokens. Children have no birth dates on file because none are ever asked. A parent's data export includes their children's non-secret records; deleting the parent account erases the children's accounts with it (sessions die, wallets are gone with the ledger).
Ghost Cash and timer. Org work tracking holds contracts, timer sessions with heartbeat activity counts, worker-attached proof screenshots (≤1 MB, same handling as clan images), and hypothetical debt records. Heartbeats prove a visible tab, never screen contents; screenshots are supplied by the worker, never captured. Ghost books are org-member-visible (scoped watchers see only their scope) and export with the org member's own data on request.
Consent and purchase records. Cookie-banner choices (7-day renewal), accepted purchase quotes, charge receipts, and idempotency records that prove what you confirmed and what we charged.
Automatic technical data. IP address, browser and device characteristics, request logs, pages or features used, approximate location derived from IP, security and fraud-prevention events (including rate-limit and trial-abuse signals). Games and accessibility controls may store preferences and progress in your browser (local storage).
3. How we use information (and GDPR legal bases)
We use information to provide, secure, maintain, improve, troubleshoot, personalize, and administer the Service; authenticate users; preserve progress and settings; operate Clans, bots, rentals, workspaces, and leaderboards; process and reconcile transactions; communicate about the Service; prevent fraud, abuse, and security incidents; moderate content and protect safety; and comply with legal obligations. We may create aggregated or de-identified information and use it for any lawful business purpose.
Where the GDPR/UK GDPR applies, our legal bases are: contract (providing the Service you request, Art. 6(1)(b)); legitimate interests (security, fraud prevention, moderation, service improvement; balanced against your rights, Art. 6(1)(f)); consent (optional analytics/marketing email, Art. 6(1)(a), withdrawable anytime); and legal obligation (records, safety reporting, responding to lawful requests, Art. 6(1)(c)).
4. Cookies and similar technologies
A cookie banner loads on every page until you choose, and asks again once every 7 days. You get real options: Accept all (which we strongly recommend; it funds free play, keeps every feature working, and lets us improve the Service for any purpose described here), Reject non-essential, or Customize by category. Categories:
- Essential (always on): sign-in session, security, fraud prevention, load balancing, and your cookie choice itself. The Service cannot sign you in without these.
- Analytics (opt-in): Google Analytics measurement (env-configured measurement ID) and privacy-friendly Vercel Analytics telemetry. Google Analytics loads only after you accept analytics cookies.
- Functional (opt-in): remembered preferences such as theme, voices, avatar shape and color, and game settings.
- Marketing (opt-in): campaign and referral measurement. Marketing email is separately off by default in account settings.
Games and accessibility controls also use browser local storage for preferences and progress. You can change your choice anytime by clearing site data (the banner returns), with browser controls, “Do Not Track”-respecting settings where honored, or Google’s opt-out tools.
5. Disclosures and service providers
We provide your information to private third parties only as needed for the purposes above, to:
- Hosting and delivery: Vercel (hosting, analytics, edge routing) and Cloudflare (network delivery and security);
- Accounts and data: Supabase (authentication/database);
- Payments: Shopify (checkout, order reconciliation) and its payment processors, under their terms;
- Measurement: Google Analytics (only with your analytics consent) and Vercel Analytics, under their terms;
- AI chat and reasoning: OpenAI; OpenRouter (routing to Meta Muse Spark, Google Gemini, and Anthropic Claude models); DeepSeek; Google Gemini; Anthropic Claude; Meta; your prompts, transcripts, and attached images are processed to produce replies under their terms, and we do not authorize them to use your inputs to train their models;
- AI voice and media: ElevenLabs (text-to-speech, speech-to-text, sound and music) and fal.ai (image, video, audio, 3D generation), under their terms;
- Compute: RunPod / DigitalOcean or your custom endpoint when you book agent or cloud compute;
- Moderation: OpenAI-based screening that assists human review of reported content;
- Safety and legal: NCMEC CyberTipline for suspected child exploitation (filed by a human); U.S. courts and authorities upon valid legal request such as a court order, subpoena, or other lawful process; and parties necessary to protect rights, safety, and the Service or enforce our Terms; including against illegal content, which is never allowed;
- Corporate: a buyer or successor in a merger, financing, sale, or reorganization, under confidentiality.
We do not sell personal information for money and do not share it for cross-context behavioral advertising. Providers process information under their own terms and may process it outside your state or country (see Section 6). Receipts and ledgers carry no personal details beyond your account reference.
6. International transfers
We are based in the United States and the Service is operated from the U.S. If you use the Service from the EEA, UK, Switzerland, or elsewhere, your information is transferred to and processed in the U.S. and other provider locations. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) and retain information only under the bases in Section 3.
7. Retention
We retain information only as long as reasonably necessary for the purposes in Section 3: while your account is active; for records, security, dispute resolution, and legal compliance afterward; safety and CSAM evidence as required for authority referral and legal claims; and financial/transaction records as tax and payments law requires. When you delete your account at /my/rights/, we delete or de-identify your personal data across our systems except where retention is permitted or required by law (Section 11 lists the exceptions). Backups age out on their normal cycle.
8. Security
We use reasonable administrative, technical, and organizational measures; including authentication, row-level database authorization, hashed bot-key storage, input validation, rate limiting, CSRF origin checks, and append-only money ledgers; designed to protect information. However, no system, transmission, or storage method is completely secure. You use the Service and submit information at your own risk, and you must keep your credentials and bot keys secret.
9. Your rights (U.S., GDPR, and global)
Depending on your jurisdiction and applicable law, you may have the rights below. We honor them as required and extend self-service access, portability, correction, and deletion to all signed-in users through /my/rights/:
- Know / access / portability: confirm what we hold and obtain a copy in a portable format (GDPR Arts. 15, 20; CCPA/CPRA and other U.S. state laws);
- Correction / rectification: fix inaccurate profile and account data (GDPR Art. 16); edit it directly in /account or ask us;
- Deletion / erasure: delete your data and account (GDPR Art. 17; U.S. state delete rights) via the self-service flow, subject to Section 11 exceptions;
- Restrict / limit and object: restrict processing or object to legitimate-interests processing and direct marketing (GDPR Arts. 18, 21);
- Withdraw consent: opt out of analytics/marketing where consent was the basis, without affecting prior lawful use;
- Opt out of sale/share/targeted ads: we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to toggle; this statement is your opt-out notice;
- Non-discrimination and appeal: we will not discriminate for exercising your rights; if we deny a U.S. state-law request, you may appeal by replying to the decision email;
- Complain: lodge a complaint with your supervisory authority (e.g., your EU/EEA Data Protection Authority or the UK ICO) or Attorney General, without giving up the right to contact us first.
New Hampshire law governs our agreement (see Terms). Where another jurisdiction grants you non-waivable rights, those rights apply in addition and nothing here limits them. California “Shine the Light” requests may be sent to matt@mattyjacks.com.
10. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by purely automated means. Automated systems (spam triage, cheat detection, AI-assisted moderation, fraud guards) support human review; significant actions; account termination, CSAM referral, rights-request decisions; involve human judgment, and you may ask for human review of any such decision.
11. How to exercise your rights (self-service + special cases)
Your own account; self-service only. Sign in and use /my/rights/ to download your data (access/portability) or permanently delete your data and account (erasure). Only the signed-in account holder can delete their own account - requests for anyone else’s data are refused there. To stop spam and abuse, self-service requests require sign-in, same-origin verification, per-account and per-network rate limits, a typed confirmation, and a short review window; confirmed deletions are final and immediately sign you out.
Special cases; email. If you cannot use self-service (for example, you are family or a legal representative of a deceased or incapacitated user seeking deletion, or an authorized agent with written permission), email matt@mattyjacks.com from an address we can verify, describing the request, the account (email/handle), your relationship, and attaching proof of authority (e.g., death certificate plus proof of kinship or legal appointment; agents: signed permission plus identity verification of the principal). We verify every such request, may ask for the minimum additional proof needed, and act only when satisfied the request is legitimate. We never accept third-party deletion demands without authority.
Timing and verification. We verify identity (signed-in session for self-service; documented authority for email requests) and respond within the applicable deadline; within one month for GDPR requests (extendable by two months for complexity) and within 45 days (extendable) for U.S. state-law requests. We may retain or decline to delete information where permitted or required by law, including account-security and fraud-prevention records, completed-transaction and tax records, safety/CSAM evidence under legal hold, information needed for legal claims, and content others lawfully retain; and we will explain any denial and your appeal options.
12. Children
Direct accounts are 13+ only (Teen 13-17, Adult 18+) — the Service is not directed to children under 13, and we do not knowingly collect their personal information through direct signup (which requires a Teen/Adult band and rejects under-13). Under-13 children may use the Service only on a parent-created Child sub-account (COPPA verifiable parental consent: an Adult 18+ parent signs up and creates the child in Account → Family, attesting the child's Kid/Teen/Adult band). We collect no date of birth from anyone — bands only — and apply high-privacy defaults to under-18 accounts (no behavioral advertising for signed-in players, minimal data, parental limits enforced server-side, no checkout/tips/subscriptions/payouts from child sessions), consistent with COPPA, the EU GDPR consent ages (13-16 by member state), the UK Age Appropriate Design Code, the EU Digital Services Act, California's Age-Appropriate Design Code Act, and other applicable child-safety regimes. If you believe a child under 13 provided information through a direct account, contact matt@mattyjacks.com so we can delete it. Parents export and erase their children's data together with their own at /my/rights/. Account holders must be 13 or older (see Terms).
13. Third parties and changes
The Service may link to third-party websites or services; their privacy practices are governed by their own policies, not this one. We may update this policy at any time by posting an updated version and changing its effective date; material changes will be highlighted where practical. Your continued use after the effective date is subject to the updated policy.
14. Contact
MattyJacks LLC · New Hampshire, USA · matt@mattyjacks.com · Self-service rights: /my/rights/ · Deceased-user family and other special-case requests: email with proof of authority as described in Section 11.