Privacy Policy
Last updated: July 24, 2026
1. Who is responsible
Far Away Fun operates this private two-player game. The person responsible for protecting personal information is the Far Away Fun Privacy Officer. Contact the officer through our secure privacy request form. No home address is published or required from players.
2. Information we collect
- A name or nickname, optional sex selection, and current setting chosen for prompt safety.
- Room code, private player token, readiness, votes, prompt history, and game status.
- Messages and replies players intentionally send inside their room.
- Short-lived technical security data needed to prevent abuse and unauthorized administrator access.
- De-identified daily totals such as rooms created, games started, completed prompts, and approximate session duration.
- If you submit a privacy request: your contact email, request type, and the information you provide.
We do not require legal names, phone numbers, home addresses, payment details, advertising identifiers, or user accounts. We do not use third-party advertising or behavioural analytics.
3. Why we use it
Room information is used only to create the shared game, tailor prompts, keep the two-player session synchronized, enforce boundaries, prevent unauthorized access, and respond to privacy requests. Sensitive or intimate messages are used only to show them to the two people in that room.
4. Consent and choices
Each player must be 18 or older and personally accept this policy and the Terms before creating or joining a room. Either player may skip, pause, leave, or delete the room without penalty. You may withdraw consent, request access or correction, or complain through the privacy request form. Withdrawing consent may make it impossible to continue the active room.
5. Retention and deletion
Active-room records—including nicknames, selections, messages, replies, tokens, events, and prompt history—expire 24 hours after room creation. Access is blocked after expiry and expired records are permanently removed during the automated hourly cleanup cycle. A player can also delete the entire room immediately from inside the game. De-identified daily statistics contain no room code, token, name, message, or IP address and may be kept for service measurement.
Privacy requests are kept only as long as reasonably needed to verify, complete, and document the request, normally no longer than 24 months unless law requires longer retention.
6. Sharing and processing outside Québec
We do not sell personal information. Hosting, database, and file-storage providers process information only to operate and secure the service. Their systems may process or store information outside Québec or Canada, including in the United States. We limit the information collected and use access controls, encryption in transit, private room tokens, and short retention to reduce this risk.
7. Local storage and cookies
The game uses device-local browser storage for age/consent status and the private rejoin token. It does not currently use advertising cookies, cross-site tracking, or third-party analytics. Clearing browser storage removes the device’s rejoin information but does not immediately delete the room from the server.
8. Security and incidents
We use restricted administrator access, rate limiting, content validation, security headers, expiring rooms, and limited data collection. No online service can promise absolute security. If a confidentiality incident creates a risk of serious injury, affected people and the Commission d’accès à l’information will be notified as required by Québec law.
9. Your rights
Subject to applicable law, you may ask what information we hold about you, request access or correction, withdraw consent, request deletion, or submit a complaint. Use the privacy request form. We may ask for limited information to verify that you control the relevant room or request.
10. Changes
Material changes will be dated and presented before new consent is collected. The version accepted by a player is recorded with the active room.