Privacy
Privacy policy
Last updated 12 August 2026. This is a pre-release test build; if this policy changes we'll say so here and on the sign-in page.
Short version: if you play without signing in, we record nothing at all. If you do sign in, we record what you did in the game so we can tell whether the game works. We don't sell it, share it, advertise against it, or use it for anything except making this game better.
Who we are
Above Black is a project of Gigabit Arcade. To delete your data you don't have to ask us: sign in and use the buttons on your account page to delete your account or delete everything. For anything else on this page, tell us through the form at Adjacent Interactive.
There's no dedicated privacy mailbox yet, which is why deletion is a button rather than a request.
What we collect
| What | Why | Where it comes from |
|---|---|---|
| Your name, email address and profile picture | To sign you in and to attach your save to you | Google, when you choose to sign in |
| The name you type for your character | The characters say it out loud — that is the point of asking | You, in the game |
| Gameplay events: which door you opened first, which accounts you heard, the conversation choices you made, which rooms you entered, and how long it took | The one question this build exists to answer | The game, as you play |
| Anything you type into Tell us something in the pause menu, and, sent with it, which room you were in, how long you had been playing and which build | It is the only way to tell us anything from inside the game — there is no address on this site. The room and the time are attached so a sentence about something going wrong arrives with the place and the moment it went wrong, instead of us having to ask | You, in the game, when you choose to send one |
| Session facts: build version, platform, input device, window size, start and end time | To tell a phone bug from a desktop bug | Your browser |
| Your save: which room you are in and your story flags | So you can come back | The game |
| Feedback you choose to give | Because we asked | You, if you answer |
| Your key and controller bindings, and whether you chose the light or the dark theme | So the controls you set on a laptop are the controls you get on a phone | You, in the game's settings |
| A cast pitch, if you send one: who you're proposing, where their public record is, why, how to reach them, and whether that person is you | It is the form on Join us asking who should be in the game — and most pitches are about somebody else, so we hold a way to ask them | You, if you use that form |
| An art submission, if you send one: the image, any note you attach, the name you want to be credited under, and which version of the contributor agreement you accepted | To review it, and to credit you correctly if it goes in | You, if you submit art |
What we deliberately don't collect
- No advertising or analytics trackers. No Google Analytics, no pixels, no fingerprinting. There are no third-party scripts on this site at all.
- No cookies except the one your sign-in session needs to exist.
- No free-text capture except the boxes you deliberately type into and send: your character name, feedback, Tell us something in the pause menu, the cast pitch form on Join us, and the note attached to an art submission.
- No location beyond what an IP address implies to our hosting provider in the normal course of serving you a page.
- No payment details, ever. Nothing here costs money.
Who can see it
Your rows are readable by you and by the project's maintainers. The database enforces this at the row level, not in the app: a signed-in player can only ever fetch rows whose player id equals their own, unless the database itself records them as a maintainer.
There is one deliberate exception, and it only fires if you submit art and we accept it. The name you chose to be credited under — or, if you left that box blank, the name on your account — and the link you gave with it, are published on the credits page, where anyone can read them, signed in or not. Nothing else goes with them — no email, no user id, no file path, no note, and nothing you submitted that we didn't accept. We don't share data with anyone else, and we have nothing to sell.
Two processors handle data on our behalf: Supabase (database and sign-in) and Netlify (hosting). Google is your identity provider if you sign in with it.
How long we keep it
For as long as this test runs, plus a short tail while we read the results. When the test build is retired we delete the event data. You delete your save and your account yourself, from your account page, and it happens immediately.
Your choices
- See it. Your account page shows your own sessions.
- Delete your account, keep the playtest data. The first button on your account page. Your login, name and picture are destroyed and your save is deleted. The gameplay records stay, attached to a random identifier and a name out of a hat, with nothing left connecting them to you. We keep them because they are the whole reason this build exists, and once your login is gone we have no way to work out they were yours.
- Delete everything. The second button, beside it. It happens the moment you confirm. Deleting your account cascades — the sessions, events, save and feedback go with it.
- Export it. There's no button for this one yet: tell us through the form at Adjacent Interactive, and we'll send you your rows as JSON.
- Play signed out. Nothing at all is recorded — there is no row to delete, because none is ever written.
Children
This build is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has signed in, tell us through the form at Adjacent Interactive and we'll remove the account.
Security
Sign-in is handled by Google and Supabase; we never see or store a password. Traffic is HTTPS only. The browser key this site ships is a public, deliberately-limited key — every table it can reach is protected by row-level rules, and no key capable of reading other people's rows exists in anything we send to your browser.