PRODUCT GUIDE · RELEASE PREPARATION
Your data & recovery
Play as a guest, keep a private table, and choose which optional features you use. This guide explains how the current version works.
Public launch review is still pending. This product guide does not supply an approved operator privacy policy, contact route, age policy or support response time.
Your browser and private tables
An opaque HttpOnly guest cookie protects your place for up to one year. The server stores its hash with a separate identity reference. Table invitations let others view or ask to join; they do not prove who owns a seat.
Your browser remembers your chosen name, Bot conversation preference and up to six recent table links, labels and visit times in local storage. These records have no automatic time expiry. Clearing this site’s browser data removes them and its cookies; it does not delete server records and can lose guest access.
The server stores table names, participant names and membership, seats, clocks, current game state, reactions, recovery requests and completed game facts. Players see only the views allowed by their role. Other invited people may see table or player names. Keep invitations private.
Optional accounts and providers
Guest games do not require a sign-in provider. When configured, Google sign-in requests OpenID identity only; standalone Discord sign-in requests identify. The server stores the verified provider identity reference and its account binding, without importing contacts or filling account email from provider claims. Provider tokens are used during verification and are not stored in the database.
Email sign-in, when configured, sends your address and a one-use sign-in link through Resend. The server stores your email and a hashed, 15-minute proof plus the guest-table recovery snapshot. Account cookies last at most 30 days. No email is sent merely by opening a table.
The Discord Activity is a separate optional surface. Discord verifies identity and current instance membership; the server stores Discord identity, application/instance table bindings and hashed sessions lasting two hours. Its bearer credential stays in page memory. Its OAuth access token is returned to the SDK for authentication; no access or refresh token is stored in SQLite. Discord channel voice and messages are not ingested. Saving from Activity is optional and separately confirmed with a recently verified website account and configured Google or email recovery. Only your selected membership is saved; later Activity sessions require deliberate authorized table selection. Disconnecting ends mapped Activity sessions while independently recoverable saved tables remain. Five-minute save proofs are hashed and browser-bound on review; expired proofs and one-hour save-attempt records are removed by startup maintenance.
Optional AI
Built-in engine bots play without a model provider. If AI is configured and you turn Bot conversation On, the selected provider receives bounded public game facts, your explicit question and relevant delivered replies from that match. Human table chat is not used as AI input. Off hides conversation and cancels pending private replies; it cannot recall a request already sent.
A separately consented Codenames AI spymaster receives the board words and their secret roles as allowed for that bot. Bot conversation Off does not disable that selected game role. Active Codenames conversation can use only neutral preset sentences. Other ordinary bot moves remain engine-controlled.
In the private Human or AI? model mode, all seated humans consent to the match. The model receives only the curated target, without your human clue, vote, name or transcript. Preset practice uses shipped text and makes no model request. Draw & Guess drawings and guesses are not AI inputs. Bot Night uses recorded engine moves and deterministic highlights, with no model calls. Its separate optional Pip presentation is unavailable in production; trusted internal tests select owned visible facts only.
A separate local Pro/Sparks foundation records verified-account test or promotional grants and an explicit single-table sponsorship. Checkout is unavailable. It does not change the AI pilots above. The private grant review shows available, held and consumed allowance. A debit means a validated authorized artifact was ready for retrieval, not proof anyone listened. Replay is free; test grants establish no purchase.
Private product gifts and owned themes use verified standalone accounts and existing mutual friendships. Only owner-attested test/promotional products can be offered; recipients accept or decline privately. Pro days start on claim or after reserved existing segments; gift Sparks remain bound to their original source. A sender sees fulfillment only, never your balance, usage or exact Pro expiry. Permanent original themes need no Pro or Sparks. A disputed/revoked source changes future eligibility; active games keep their fixed presentation. No checkout or external gift email/push is available. Private terminal/claimed gift review identities prune after 90 days; opaque source, command and event dedupe/accounting remain within fail-closed capacity limits.
Private standalone Connect Four has a separate optional English Pip Night Host. Caption requests use restricted public rule and event facts with color aliases, excluding names, boards and transcripts. Free static rules and fallback remain available. Captions require each current player’s consent; voice recipients also choose independently. Caption-only requests never promise audio.
AI speech is unavailable in production; local tests inject synthetic tones. A future speech adapter receives only the vetted script and bounded voice settings. A reviewed caption + speech request holds its full price until validated audio is ready; speech failure releases or reverses the full action. Ordinary expiry or withdrawal after success preserves recorded spending. Personal audio starts muted and requires Prepare, then Play. Withdrawal clears available playback; bytes already delivered cannot be recalled.
The operator can select Anthropic, OpenAI, Google Gemini, OpenRouter, xAI or hosted NVIDIA NIM for each AI workload. OpenRouter is a gateway and may route the request to a downstream model provider. The selected service receives the request; this app does not establish that service’s retention, training, region or account-specific terms. Those choices require review before enabling a real pilot.
Private chat, party content and reports
Private chat and party formats require explicit pilot enablement and response preparation. Admitted participants see only their permitted channel. Chat and history pause before hidden-information rounds finish, including Codenames, Battleship, Fireworks, Draw & Guess and Human or AI?. Chat is plain text.
A report sends only the evidence you explicitly select to the private owner review queue: one visible chat message; the latest ten drawing strokes, with at most sixteen points per stroke; your selected guess; or one visible Human or AI? clue. Drawing reports exclude the prompt. Clue reports exclude the target, source labels and author identity from the evidence; report records still carry the reporter and, for human content, an internal target reference. Reports include a category and internal references for review.
Ordinary transcripts, drawings, guesses, clues and report evidence do not enter aggregate analytics, application error logs, owner CSV exports or third-party notice downloads. The server database and private backups do contain retained content. Disposition clears report evidence immediately; removing a chat message does not itself withdraw a submitted report. Known-identity blocks and mutes cannot identify a person who clears cookies and returns as a new guest.
What expires, and when cleanup runs
Credential or action expiry ends access or validity. It does not necessarily erase the underlying row. Cleanup depends on the operation below and a running server or operator maintenance; these are implemented bounds, not a promise that every copy disappears at an exact time.
| Data | Implemented limit and cleanup |
|---|---|
| Tables & history | New table creation removes tables dormant for a year. Up to 100 completed matches and 100 reaction events per table are retained. Continued table activity can keep that history longer. |
| Sign-in proofs | Email proofs expire in 15 minutes; OAuth states/review proofs in 10 minutes. Expired request rows are pruned one day after expiry when another relevant request starts. Account records have no automatic age-based deletion. |
| Friends & invitations | Friend codes/requests last seven days; challenges last 24 hours. Terminal receipts are pruned after 30 days on social access; attempt records after one day on writes. Friendships/blocks remain until removal or erasure. |
| Optional friend presence | Default Off and independent of other choices. Both current friends must opt in to see generic Here now from the focused Friends page. Server leases last at most 75 seconds; displayed results last at most 15 seconds from request start, for up to 90 seconds of stale observation. No last-seen, exact peer expiry or game/activity details. Off clears all account leases; sign-out/revocation clears that session. Fixed counters and latest digests replace heartbeat history; Off fences last 90 days with bounded startup/access cleanup. Deletion requests clear presence immediately. Ordinary/restored startup disables every old choice and requires fresh opt-in. Already observed indicators and private old snapshots/WAL/copies cannot be recalled. |
| Weekly private Fireworks challenge | Free optional three-human saved-account enrollment, once per account in each Monday-to-Monday UTC week. Consent is separate from normal readiness. A natural completed or engine-failed game earns a private participation marker; 15/15 is a separate perfect-show goal. Group roster/approval/session facts clear on cancellation, withdrawal or privacy changes; team score facts last seven days and content-free markers/fences up to 90 days. Withdrawing removes your marker permanently for that week and clears group facts; independently earned peers’ private markers may remain. Deletion requests immediately remove your marker. Every restart quarantines weekly reads and awards for private recovery review; suppression replay cannot enable them. Conservative recovery clearing removes badges and blocks new enrollment through the current UTC week. Already observed facts and private old backups cannot be recalled. |
| Chat & reports | Up to 200 messages per table, seven-day expiry; reports 30 days, evidence cleared on disposition. Access and operator chat cleanup prune them. Chat retry receipts last two days; attempts one day. |
| Party clues/drawings/guesses | Transient content clears on round change, cancellation or completion as applicable. Explicit reports are separate. Digest retry receipts last 24 hours, attempts one hour; matching startup/access cleanup applies. |
| Shared cards | Drafts expire after 48 hours; published cards 30 days after publication. Access/operator sharing cleanup clears payloads; opaque replay receipts remain up to 30 further days. |
| Returns & Bot Night | Terminal deadline jobs and expired notice receipts: 30-day cleanup by the running worker. Bot Night drafts expire 30 days after creation, scheduled events 30 days after final start, at most 37 days from curation. |
| Experimental Bot Night presentation | Unavailable in production. Original consent closes on completion, Off, session or authority changes, and every restart. Transient text/audience clears by the next frame or five seconds, with a running worker. First terminal receipts keep content-free detail for 90 days; unknown synthetic reserves and conservative accounting keys have no automatic age purge. Restore gates and later privacy decisions remain independent. |
| AI & aggregate records | AI jobs expire for execution after 20 seconds; expiry/Off is not payload deletion. Stored requests/messages can remain with the table; bot reply cleanup keeps its newest 100 messages per match. Usage/budget records have no fixed age purge. Pilot events older than 90 days are pruned on new table creation. |
| Pack & operator records | Pack access lasts 30 days from issue. Receipt dedupe tombstones remain after erasure; pack audit keeps its newest 10,000 entries. Session hashes, identity references, deletion receipts and other authority/audit records may persist without a fixed age purge. |
| Pro & Sparks grants | Pro passes last 30 days from their scheduled start; explicit sponsorship nights at most 24 hours. General test/promotional allowances have a disclosed 1–365-day expiry; the fixed gift fixture supplies 100 source-bound Sparks with no expiry. Pending meter jobs expire in 120 seconds or earlier, leases in 30 seconds; startup releases stale holds. Content-free source/command/debit dedupe receipts have no fixed age purge and are capacity-bounded; the audit retains its newest 10,000 entries. Account erasure removes ownership/session/audience/artifact references and retains anonymous accounting. |
| Gifts & owned themes | Unclaimed offers expire after 30 days. Terminal or claimed review identities are scrubbed after 90 days in bounded startup/access batches. Permanent theme ownership remains while its source is valid. Anonymous source, command and event dedupe/accounting has no age purge; capacity limits fail closed for operator review. Deleting a sender after claim leaves the recipient’s independent benefits. Recipient erasure removes its own benefits and references. Later revocations, blocks and deletion must be replayed into restored private backups before traffic. |
| Night Host captions & speech | Private payloads expire within 24 hours, with earlier withdrawal or access changes. Speech is capped by duration, bytes and clip count; production speech is unavailable. Running startup maintenance erases expired SQLite payloads in bounded batches. Opaque job/accounting receipts remain capacity-bounded. Private backups and old database journals need separate expiry and replay of later privacy decisions before restored traffic; delivered bytes cannot be recalled. |
The operator must separately decide and verify host logs, backup expiry, provider handling and any records without an automatic purge. Application error logs use sanitized markers or a request reference rather than content. Hosting/proxy logs can still record IP addresses, URLs and headers according to their configuration; OAuth callback queries and credentials need redaction at the host.
Recovery, revocation and deletion
Keep the original guest browser. A private table’s host can approve a bounded seat-reclaim request, revoking the old seat credential; knowing a name or invite does not restore a lost host identity. Optional verified accounts save admitted website tables and support cross-device recovery. Linking requires proof and explicit confirmation; accounts are not merged by matching names or emails.
From My tables / account, sign out, revoke other account devices or review sign-in methods. Removing a method retains another configured recovery method and signs out other account devices. An unlinked identity used again creates a separate account. Provider consent can also be revoked in the provider’s own settings. Logout and browser clearing do not erase server history.
An account deletion request records a pending request; it does not automatically delete the account. A private operator must process it after a backup. Completion revokes account credentials, removes account email/provider bindings, memberships and affected private/social/report/share data, and redacts player names in retained completed results. Unclaimed guest identities stay separate. Shared mechanical facts and opaque references remain; this is not removal of every record.
Deletion can end an ongoing game under its loss rules, transfer hosting to a remaining admitted member, or remove a hosted table with nobody else admitted. Sharing withdrawals and the party formats’ own content-erasure controls are separate. There is no general guest-history deletion button or published operator response promise in this preparation release.
Backups can retain earlier personal content. Before restoring service, the operator must reapply later deletion, withdrawal, block and revocation decisions and run cleanup. An old backup cannot infer those later decisions. Copies already held by other people or providers are outside these local controls.