Morgames

Privacy Policy

How Morgames handles your data.

This policy summarizes what Morgames stores, why it is used, how security features work, and what choices are available from the dashboard and cookie preferences.

Last updated

August 13, 2026

Written for the current Morgames dashboard, builder, forms, auth, publishing, analytics, and support flows.

1. Information we collect

Account data includes username, email, password hash, plan, profile details, avatar, verification status, security settings, phone fields when provided, and timestamps.

Project data includes project names, descriptions, app names, templates, builder state, canvas settings, target platform/device, publication status, share codes, publication update notes, and timestamps.

Security data includes session token hashes, device identifiers, browser, device, platform, user agent, IP address, site origin, online status, blocked device state, passkeys, two-factor status, backup codes, QR login sessions, verification codes, and password reset records.

Interaction data includes notifications, friendships and friend request state, connected account provider identifiers, provider profile data, scopes, support/form submissions, data export requests, and cookie preferences.

2. How we use information

We use data to operate Morgames, authenticate users, secure accounts, manage sessions and device approval, save projects, publish games, provide support, process forms, handle notifications and friendships, and maintain connected account login flows.

We use analytics and performance tools to understand reliability, performance, and product usage when allowed by cookie consent settings or when the data is strictly necessary for service operation.

3. Cookies and local storage

Morgames uses essential cookies for authentication, account security, session management, and cookie consent. The main authenticated session is stored as a secure session cookie.

Optional cookie categories include preferences, analytics, and marketing. Optional categories are disabled unless accepted in the cookie consent panel.

The app may store interface settings, project list cache, connected account display cache, and similar preferences in browser localStorage to keep the interface fast and consistent.

Theme brightness is adjusted locally from the device time of day. Morgames uses this only in the browser to choose color tones and does not need to send the local time to the server for this visual behavior.

4. Service providers

Morgames can use Supabase/Postgres for database storage, Vercel for hosting and performance/analytics tooling, Cloudflare R2/CDN for asset delivery, OAuth providers for connected accounts, and cookie consent tooling for privacy choices.

These providers process data only as needed to deliver infrastructure, authentication, storage, analytics, security, or support functionality.

5. Public content

Draft and prototype projects are private to the account owner unless a sharing workflow is used.

Published games and the public information needed to display them may become publicly accessible. Analytics data is shown to the project owner in the dashboard.

6. Support center and forms

Support, contact, beta test, and request forms collect the details needed to respond to the request, such as name, email, username, subject, message, form type, source origin, metadata, status, and timestamps.

If you are logged in, Morgames can use your authenticated account information instead of asking you to re-enter account identifiers.

7. Security

Morgames uses hashed passwords, session token hashes, passkeys, two-factor authentication, backup codes, device approval, device blocking, account sessions, verification codes, and reset tokens to protect accounts.

No system is perfectly secure. You should use strong credentials, keep passkeys and backup codes private, review active sessions, and revoke sessions or block devices you do not recognize.

8. Data export and deletion

The privacy settings include a data export workflow that can provide profile, settings, project, session, passkey, and notification data. Exports are temporary and expire after a limited period.

Account deletion removes the account and linked data that is configured to cascade from the user record, such as projects, sessions, notifications, passkeys, friendships, connected accounts, and related security records where applicable.

9. Retention

Morgames keeps data for as long as needed to provide the service, protect accounts, comply with legal obligations, resolve disputes, prevent abuse, or maintain reliable backups.

Temporary records such as verification codes, reset tokens, QR login sessions, device access requests, and data exports have expiration timestamps and are intended to be short-lived.

10. Your choices

You can update settings, cookie preferences, connected accounts, active sessions, device approvals, passkeys, two-factor authentication, profile details, and data exports from the dashboard where available.

For privacy questions or requests, use the Morgames support center or contact forms.