Morgames

Privacy Policy

How Morgames handles your data.

This policy summarizes what Morgames stores, why it is used, how security features work, and what choices are available from the dashboard and cookie preferences.

Last updated

September 11, 2026

Written for the current Morgames dashboard, builder, forms, auth, publishing, analytics, and support flows.

1. Information we collect

Account data includes username, email, password hash, plan, profile details, selected avatar and banner, verification status, security settings, phone fields when provided, and timestamps.

Project data includes project names, descriptions, app names, templates, builder state, canvas settings, target platform/device, publication status, share codes, publication update notes, and timestamps.

Security data includes session token hashes, device identifiers, browser, device, platform, user agent, IP address, site origin, online status, blocked device state, passkeys, two-factor status, backup codes, QR login sessions, verification codes, and password reset records.

Interaction data includes notifications, friendships and friend request state, connected account provider identifiers, provider profile data, scopes, support/form submissions, data export requests, and cookie preferences.

Game-player data includes provider account identifiers, display names, avatars, game session records, per-project activity and saved game data. A provider-verified email is associated with a specific project only when that project's sign-in flow requests it and the player explicitly agrees to the displayed purpose.

Monetization data includes Stripe connected-account identifiers and status, payout eligibility and currency, advertising provider and reconciliation event identifiers, project attribution, gross and allocated revenue amounts, availability dates, withdrawal amounts and statuses, Stripe transfer identifiers, failure codes, and related timestamps or metadata.

Game analytics data includes a pseudonymous visitor identifier, project and session identifiers, approximate device category, broad referral source, country code when supplied by infrastructure, page-view counts, active visible-play time, and session timestamps. Morgames does not store the visitor's raw IP address in the game analytics session record.

2. How we use information

We use data to operate Morgames, authenticate users, secure accounts, manage sessions and device approval, save projects, publish games, provide support, process forms, handle notifications and friendships, and maintain connected account login flows.

When a player consents to project-scoped email sharing, we use provider verification to reduce false addresses and make the address available only in that project's authenticated runtime and authorized creator workflows.

We use analytics and performance tools to understand reliability, performance, and product usage when allowed by cookie consent settings or when the data is strictly necessary for service operation.

We use monetization data to validate advertising reports, calculate the creator and platform shares, apply holding periods and adjustments, display balances, prevent duplicate or fraudulent credits, enable withdrawals, reconcile transfers, and meet accounting, tax, security, and legal obligations.

3. Cookies and local storage

Morgames uses essential cookies for authentication, account security, session management, and cookie consent. The main authenticated session is stored as a secure session cookie.

Optional cookie categories include preferences, analytics, and marketing. Optional categories are disabled unless accepted in the cookie consent panel.

The app may store interface settings, project list cache, connected account display cache, and similar preferences in browser localStorage to keep the interface fast and consistent.

Public previews and published games use a first-party HttpOnly visitor cookie plus browser session storage to distinguish pseudonymous visitors and sessions, prevent duplicate counting, and calculate aggregate game analytics for the project creator.

Theme brightness is adjusted locally from the device time of day. Morgames uses this only in the browser to choose color tones and does not need to send the local time to the server for this visual behavior.

4. Service providers

Morgames uses Supabase/Postgres for accounts, project definitions, security records and pseudonymous gameplay analytics; Turso for persistent game-player variable values; Vercel for hosting and performance tooling; Cloudflare R2/CDN for asset delivery; OAuth providers for connected accounts; advertising providers for ad delivery and reconciliation; Stripe for billing, creator verification and payouts; and cookie consent tooling for privacy choices.

These providers process data only as needed to deliver infrastructure, authentication, storage, analytics, security, or support functionality.

Stripe's hosted onboarding and Express Dashboard collect and manage identity, tax, bank-account, IBAN, and eligible debit-card details according to Stripe's own terms and privacy notice. Morgames stores the connected-account and transfer identifiers needed to operate payouts, but does not intentionally collect or store full bank-account or card numbers in its own database.

5. Monetization and financial records

Connecting Stripe is optional unless you want to receive creator payouts. Stripe can require identity, business, tax, contact, and payout-account information and can send verification messages directly to the creator.

Morgames receives account capability and verification status from Stripe so the dashboard can determine whether onboarding is complete and payouts are enabled. Creators can use Stripe-hosted onboarding and the Stripe Express Dashboard to provide or update payout details.

Advertising and payout records can be retained longer than ordinary profile data when needed for reconciliation, fraud prevention, disputes, accounting, tax, payment-provider requirements, or other legal obligations.

For a detailed operational explanation of Premium billing, Stripe Checkout, creator funds, payouts, and account closure, see the Billing and Payouts Policy.

6. Public content

Draft and prototype projects are private to the account owner unless a sharing workflow is used.

Published games and the public information needed to display them may become publicly accessible. Analytics data is shown to the project owner in the dashboard.

Project analytics are aggregated from actual public-preview and published-game sessions. They can include approximate device, source and country breakdowns; small or missing datasets can produce incomplete summaries.

7. Support center and forms

Support, contact, beta test, and request forms collect the details needed to respond to the request, such as name, email, username, subject, message, form type, source origin, metadata, status, and timestamps.

If you are logged in, Morgames can use your authenticated account information instead of asking you to re-enter account identifiers.

8. Security

Morgames uses hashed passwords, session token hashes, passkeys, two-factor authentication, backup codes, device approval, device blocking, account sessions, verification codes, and reset tokens to protect accounts.

To prevent email abuse, Morgames applies automated bot checks, request limits, short-lived one-time codes, and pseudonymous security counters derived from account, recipient, IP, and device identifiers. Security delivery events may be retained for abuse detection and operational monitoring.

No system is perfectly secure. You should use strong credentials, keep passkeys and backup codes private, review active sessions, and revoke sessions or block devices you do not recognize.

9. Data export and deletion

The privacy settings include a data export workflow that can provide profile, settings, project, session, passkey, and notification data. Exports are temporary and expire after a limited period.

Account deletion removes or de-identifies linked data where applicable. Some monetization, transaction, payout, tax, fraud-prevention, dispute, security, and backup records can be retained when required by law or reasonably necessary for the stated purposes. A Stripe connected account and data controlled by Stripe can also remain subject to Stripe's separate retention and account-closure procedures.

10. Retention

Morgames keeps data for as long as needed to provide the service, protect accounts, comply with legal obligations, resolve disputes, prevent abuse, or maintain reliable backups.

Temporary records such as verification codes, reset tokens, QR login sessions, device access requests, and data exports have expiration timestamps and are intended to be short-lived.

11. Your choices

You can update settings, cookie preferences, connected accounts, active sessions, device approvals, passkeys, two-factor authentication, profile details, payout information through Stripe, and data exports from the dashboard where available.

For privacy questions or requests, use the Morgames support center or contact forms.