DEADFALL Privacy Policy
Effective and last updated: August 27, 2026
This policy explains how ScopeSift LLC (“ScopeSift,” “we,” “us,” or “our”) handles information when you use the browser game.
Information handled
- Existing account data: Account creation and sign-in are currently disabled. If you used an earlier account-enabled build, Supabase may retain your email address, user ID, authentication records, and account timestamps. The DEADFALL game server did not receive or store your password.
- Saved profile: earned credits, owned and equipped cosmetic skins, best score, best wave, total kills, run count, and last update time.
- Multiplayer data: the display name you choose, room membership, gameplay state, and chat sent to the room. A public room listing shows its host’s chosen display name, room code, player count, and wave. Do not use your real name or share personal information in a display name or chat.
- Presence and technical data: a random browser identifier used to avoid counting one visitor twice, plus IP address, user agent, request times, and security logs that hosting providers may process.
- Aggregate play count: each gameplay start creates a random run identifier and timestamp so a network retry cannot count the same play twice. The run identifier is not connected to a browser identifier, account, display name, room, or gameplay results. The game publicly displays only the combined number of plays.
- Data stored only in your browser: guest progress, control bindings, loadout, multiplayer visibility preference, display name, the random presence identifier, policy acknowledgement, and—when signed in—a refresh token.
How information is used
Information is used only to preserve guest progress, run solo and multiplayer gameplay, show the public room list, live player count, and aggregate play count, maintain any existing account records, prevent abuse, diagnose failures, and protect the service. DEADFALL does not use behavioral advertising or sell personal data.
Service providers
Supabase provides authentication and profile storage. Railway or another deployment host may deliver game files, run multiplayer rooms, and process technical logs. These providers process information to supply and secure their services. Information may also be disclosed when reasonably necessary to comply with law, protect users, investigate abuse, or defend legal rights.
Who can see what
Other players can see only the multiplayer display name, chat, and gameplay information you choose to send to their room. They are not given your email address or saved profile. Database row-level security restricts each signed-in player to their own profile. Changing a URL or API query does not grant access to another player’s row.
Retention and deletion
- Account and profile data is kept while the account remains active or as reasonably needed to operate, secure, and comply with legal obligations.
- Multiplayer rooms, gameplay state, and chat are held in server memory and are not intended as permanent records. Infrastructure security logs may be retained under provider policies.
- Anonymous run identifiers, their start times, and the aggregate play count are retained to keep the historical total accurate. They cannot be used by DEADFALL to identify a player.
- Browser-only data remains until you clear site data. Signing out removes the stored refresh token but does not automatically erase guest progress.
- You may request access to or deletion of your account by contacting ScopeSift through the same account or communication channel that provided the game link. ScopeSift can verify the request and delete the Supabase Auth user and linked profile.
Security
DEADFALL uses HTTPS in production, restricted database policies, limited public file routes, input validation, security headers, message limits, and provider authentication controls. No online service can promise absolute security. Use a unique password and do not put personal or sensitive information in multiplayer names or chat.
Children
DEADFALL is a general-audience game and is not directed to children under 13. Anyone under 13 must not submit a display name, chat, or other personal information. If ScopeSift learns that an existing account belongs to a child under 13 without legally sufficient parental permission, the account and associated profile will be deleted.
Your choices and rights
You may use a non-identifying display name, keep a room private, clear browser site data, or request access to or deletion of an existing account. Depending on where you live, additional access, correction, deletion, portability, objection, or appeal rights may apply. DEADFALL does not sell personal data or use it for targeted advertising.
Changes and contact
Material changes will receive a new effective date and may require renewed acknowledgement. Privacy questions and requests should be sent to ScopeSift through the same account or communication channel that provided the DEADFALL link.