CHECKPOINTZERO
Log inSign up

Legal

Privacy Policy

Last updated: July 2, 2026

This Privacy Policy explains how Checkpoint Zero collects, uses, shares, stores, and protects information when you use our website, apps, community features, game and studio pages, Learn articles, news, blogs, playtest tools, direct messages, subscriptions, credits, payments, analytics, and related services.

We try to collect only what we need to run a useful, safe, and reliable platform. We do not sell your personal information and we do not use it for third-party ad targeting.

1. Information we collect

Information you provide

  • Account details such as email address, username, display name, avatar, bio, role, password credentials, OAuth account connection, and account settings
  • Profile and public identity details such as social links, website links, pronouns or role text if you add them, badges, subscription status indicators, and public activity
  • Content you create, including posts, reposts, comments, replies, reviews, ratings, bookmarks, tags, Learn articles, blog/news drafts, game pages, studio pages, dev logs, polls, images, GIFs, videos, links, and uploaded files
  • Studio and game management data such as team memberships, roles, invites, game metadata, media, platforms, store links, publishing status, settings, and moderation actions
  • Playtest data such as rounds, invitations, access requests, accept/reject decisions, tester responses, private feedback, notes, and related notifications
  • Direct messages and message attachments you send or receive
  • Billing and commerce information such as billing name, email, country, address, checkout status, credit purchases, tip records, subscription status, product IDs, invoices, refunds, and payment event metadata
  • Support, contact, newsletter, and admin communication details such as name, email, subject, message, subscription preferences, and support history

Information collected automatically

  • Device and log data such as IP address, browser type, operating system, referring URLs, page URLs, timestamps, request metadata, approximate location from network data, and security logs
  • Usage data such as page views, sessions, clicks, searches, follows, likes, reposts, comments, bookmarks, impressions, outbound link clicks, feature usage, upload status, and analytics events
  • Cookies, local storage, and similar technologies used for authentication, session refresh, security, preferences, consent choices, analytics, and product functionality
  • Error, performance, and diagnostic data used to debug failures, improve reliability, and prevent abuse

Information from third parties

  • OAuth profile details from providers such as Discord, Google, or GitHub if you choose to sign in with them, including identifiers, email address where provided, username, avatar, and profile metadata
  • Payment, tax, subscription, refund, dispute, and fraud-screening information from payment providers such as Dodo Payments
  • Media processing and delivery metadata from storage, image, GIF, and video infrastructure providers
  • Email delivery events such as sent, delivered, bounced, complained, opened, clicked, or unsubscribed where available from our email provider

2. How we use information

  • Create accounts, authenticate users, maintain sessions, recover accounts, and support OAuth sign-in
  • Operate core product features such as feeds, profiles, posts, comments, reviews, game pages, studio pages, Learn, blogs, news, rankings, achievements, bookmarks, messages, notifications, playtests, wallet, credits, and Pro subscriptions
  • Display public content and make it discoverable through search, feeds, tags, recommendations, public pages, previews, embeds, social cards, and SEO surfaces
  • Process checkouts, credits, tips, subscriptions, invoices, refunds, billing support, fraud checks, tax records, and entitlement access
  • Send transactional emails and in-app notifications such as confirmation links, password resets, receipts, billing notices, invites, playtest notices, messages, achievement notices, moderation notices, and support replies
  • Provide creator, studio, post, game, Learn, and Pro analytics
  • Moderate content, investigate reports, prevent spam, detect abuse, enforce our terms, protect users, and secure the platform
  • Debug, test, measure, and improve Checkpoint Zero
  • Comply with legal obligations and respond to lawful requests

3. Legal bases and legitimate interests

Where applicable law requires a legal basis, we process information because it is necessary to provide the service you requested, because you consented, because we need to comply with law, or because we have legitimate interests such as securing the platform, preventing abuse, improving features, supporting users, processing payments, and understanding product performance.

4. Public visibility

Public profiles, usernames, avatars, bios, social links, posts, comments, replies, reviews, ratings, game pages, studio pages, dev logs, Learn articles, blog/news pages, media, tags, counts, and public activity may be visible to anyone. Public pages may be indexed by search engines, shown in link previews, and reshared by other users.

If you delete public content, copies may still exist in backups, search engine caches, previews, screenshots, reposts, quotes, moderation records, analytics, or places where others have shared it.

5. Private and limited-audience content

Direct messages, playtest applications, private feedback, team invites, billing details, and certain settings are intended for limited audiences. We do not make this content public by default, but it may be accessible to intended recipients, authorized team members, admins, service providers, or others where needed for safety, support, legal compliance, or platform operation.

6. How we share information

We share information only as needed to operate, secure, and improve Checkpoint Zero, process payments, comply with law, or protect rights and safety. This may include sharing with:

  • Supabase for authentication, database, backend services, session handling, and related infrastructure
  • Vercel for hosting, deployment, logs, edge delivery, and web analytics
  • Cloudflare R2 and Cloudflare Stream for uploaded files, images, GIFs, videos, processing status, storage, and delivery
  • Dodo Payments for checkouts, credits, subscriptions, billing events, refunds, taxes, fraud prevention, and payment support
  • Resend or similar email providers for confirmation links, password resets, receipts, contact form delivery, newsletters, and notifications
  • Sentry or similar monitoring tools for error reporting, performance monitoring, and reliability
  • OAuth providers such as Discord, Google, or GitHub when you choose to sign in or connect an account
  • Analytics providers such as Vercel Analytics, only according to your consent choices where consent is required
  • Law enforcement, regulators, courts, rights holders, safety organizations, payment networks, or other parties when required by valid legal process or when we believe disclosure is needed to protect users, rights, security, or platform integrity

7. Payments, credits, tips, and subscriptions

Payment card or bank details are handled by our payment provider. We do not intentionally store full card numbers on Checkpoint Zero servers. We store payment-related records needed to provide credits, tips, subscriptions, Pro access, receipts, billing history, customer support, accounting, fraud prevention, tax compliance, and dispute handling.

8. Cookies and local storage

We use cookies and local storage for login, session refresh, security, preferences, theme, consent choices, analytics, and product functionality. Necessary cookies and storage are required for core features. Optional analytics are used only according to your consent choices where consent is required. Blocking necessary cookies may prevent login or break parts of the platform.

9. Analytics and tracking

We collect product analytics to understand which pages and features are used, improve onboarding, measure creator and studio activity, debug issues, detect abuse, and support Pro analytics. We may track outbound link clicks through a warning page so users understand they are leaving Checkpoint Zero and so creators can see useful aggregate signals.

We do not sell personal information and do not use your data for third-party advertising targeting.

10. Data retention

We keep information for as long as needed to provide Checkpoint Zero, comply with law, resolve disputes, enforce terms, support users, prevent abuse, maintain backups, and keep financial or security records. Retention periods vary by data type.

  • Account and profile data is generally kept while your account is active.
  • Public content remains until deleted, moderated, or otherwise removed.
  • Messages, playtest records, support messages, and notifications may be retained for product, safety, and support purposes.
  • Payment, tax, invoice, refund, fraud, and audit records may be retained longer where required by law or legitimate business needs.
  • Backups and logs may retain data for a limited period after deletion before being overwritten.

11. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.

You can update some profile and account information in settings, unsubscribe from marketing emails using the unsubscribe option, and change cookie or analytics choices where available. To request privacy help, contact us through our contact page or email contact@checkpointzero.net.

12. Account deletion

You may request account deletion where available. Deletion may remove or anonymize account data, but some information may remain where necessary for legal, tax, payment, fraud-prevention, security, moderation, backup, or dispute-resolution purposes. Public content that other users interacted with may not disappear immediately from all surfaces.

13. Security

We use technical and organizational safeguards designed to protect personal information, including authentication, access controls, RLS-backed database rules, provider security features, and monitoring. No online service is completely secure. You should use strong passwords, protect OAuth accounts, and contact us if you suspect unauthorized access.

14. International processing

You may use Checkpoint Zero from different countries, and our service providers may process information in countries other than where you live. Where required, we rely on appropriate safeguards for cross-border transfers.

15. Children's privacy

Checkpoint Zero is not directed to children under 13, and users must be at least 13 years old. If we learn that a child under 13 has created an account or provided personal information, we will take steps to delete it. If you believe a child under 13 has provided information to us, contact us.

16. Do Not Track and privacy signals

Some browsers send "Do Not Track" or similar signals. There is not a single industry standard for responding to these signals. We honor the privacy and analytics choices made through our available consent controls where applicable.

17. Changes to this policy

We may update this policy as Checkpoint Zero changes. If changes are material, we will provide notice through the platform, by email, or by another reasonable method. The updated policy applies once posted unless stated otherwise.

18. Contact

Questions about this policy or your privacy rights? Contact us at contact@checkpointzero.net or through our contact page.