In short
We collect what we need to run multiplayer for your games and to bill you, and nothing else. We don't sell your data or your players' data, we don't use it for advertising, and we don't use it to train AI models.
GameRelay is currently run by an individual developer based in California, not by a company. "GameRelay", "we" and "us" mean that person and, if the Service is later moved to a company, that company, which will keep to this policy.
This policy explains what GameRelay collects when you use gamerelay.io, the GameRelay SDK, APIs, MCP servers and relay servers (the "Service"), and what we do with it. It covers three groups of people: developers with a GameRelay account, players of games built on GameRelay, and visitors to our website.
Developers (your account)
- From GitHub, when you sign in with it: your GitHub user ID, username, name, avatar and public email address (if you've set one). We don't get access to your repositories.
- From Discord, when you sign in with it: your Discord user ID, username, display name, avatar and email address (only if Discord has verified it). We don't see your servers, messages or friends.
- From Google, when you sign in with it: your Google account ID, name, profile picture and email address (only if Google has verified it). We don't get access to your Gmail, Drive or anything else in your Google account.
- One account per sign-in: each provider you sign in with gives you its own GameRelay account. We never merge accounts because their email addresses match.
- What you create: workspaces, games (instances), settings, API keys (secret keys are stored hashed), webhooks and connected AI agents.
- Billing: if you subscribe, Stripe processes your payment. We store your Stripe customer and subscription IDs, your plan and its status. We never receive or store full card numbers.
- Support: anything you send us through the support form or by email, with your name and email address.
- How you found us: when you create an account, the domain of the site that linked you to us and any campaign tags in the link you arrived on (such as
reforutm_source), so we know which channels bring people in. It's recorded once, only for new accounts, and not at all if your browser sends Do Not Track or Global Privacy Control. - Usage: how your games use the Service (traffic, messages, players online), so we can show you analytics and apply plan limits.
Players (in games you build)
When someone plays a game built on GameRelay, we process data on behalf of that game's developer, who decides what their game sends. For player data, the developer is responsible for it (the "controller") and we process it for them (the "processor"). Players with questions should contact the game's developer first. This data can include:
- a random player ID (and, if the developer's backend provides one, their own ID for the player);
- the display name and avatar the game sets;
- messages, room state and chat the game relays, which pass through our servers in real time;
- saves and leaderboard scores the game stores;
- connection details such as IP address, used to deliver traffic, prevent abuse and rate-limit, and kept only briefly in server logs.
Player-to-player connections
An experimental feature lets players' browsers also send game messages straight to each other (WebRTC), for lower latency. Games use it unless their developer turns it off. Every message still goes through our servers as well. Messages sent between players are encrypted between their browsers, including when they pass through our relay, so we can't read those copies. What players share depends on the route:
- On the same network: players in the same room exchange local network addresses (usually hidden names the browser makes up) through our servers, so their devices can connect directly.
- On different networks: players connect through our relay, and don't see each other's IP address. The relay sees each player's IP address, like our other servers do.
- Directly over the internet, with party members only: only if the game's developer turns this on, both in the game and in the dashboard (where it's off by default), members of the same party exchange their public IP addresses so they can connect directly. A party is a group of players who chose to play together. The addresses aren't sent to players outside the party. An IP address can show a player's rough location and internet provider, so developers who turn this on must tell their players and, where the law requires it, ask for their consent first. It must not be turned on in games that children under 13 may play.
Website visitors
- Cookies: we only set cookies when you sign in:
gr_sessionkeeps you signed in, and a few short-lived ones (gr_oauth_state,gr_next,gr_src) carry the sign-in through your provider and expire within 10 minutes. We don't use advertising or tracking cookies, there are no third-party analytics on our site, and our fonts and scripts are served from our own servers, not third-party CDNs. - Page views: our own server counts visits to our public pages: which page, and the domain of the site that linked you there, added up per day. To count unique visitors without cookies we use a hash of your IP address and browser that changes every day, is kept only in memory and is never stored. Nothing is sent to third parties. If your browser sends Do Not Track or Global Privacy Control, we don't count your visit at all.
- Live ping: our homepage and dashboard measure your latency by opening a short connection to our own relay. It's counted like any other game connection and isn't linked to your identity.
- Browser storage: the SDK keeps a player's session in the browser's session storage so a reload rejoins the same room.
How we use data
- to run the Service: relaying messages, matching players into rooms, storing saves and scores, delivering webhooks;
- to show you logs and analytics for your games and apply your plan's limits;
- to bill you and send receipts, through Stripe;
- to keep the Service secure and reliable: preventing abuse, fraud and overload, and debugging problems;
- to reply to you and send essential account notices, such as changes to these policies, prices or your plan.
What we never do
- We don't sell personal data, yours or your players', or "share" it for cross-context advertising.
- We don't use your content or your players' data to train AI or machine-learning models, and we don't let our providers do so.
- We don't read your games' messages or chat, except when you ask us to help debug something, or when we need to investigate abuse or meet a legal obligation.
- We don't send marketing email unless you opt in.
How long we keep it
| Data | Kept for |
|---|---|
| Account (GitHub, Discord or Google profile, workspace, settings, keys) | Until you delete your account |
| Billing records (Stripe customer, subscription status) | As long as tax and accounting law requires |
| Player saves and leaderboard scores | Until you, your game, or account deletion removes them |
| Room snapshots (for reconnecting) | While the room is open, then cleared |
| IP addresses our player-to-player relay sees | While the connection is open (the relay doesn’t write them to its logs) |
| Game event logs (joins, leaves, kicks) | 7 days |
| Raw analytics events | 30 days (hourly totals are kept for your plan’s analytics period) |
| Website page view counts | Daily totals per page, with no personal data |
| Webhook delivery records | 7 days |
| Support messages | As long as needed to help you, then deleted |
| Sign-in sessions | 30 days, or until you sign out |
| Database backups | 14 days |
Service providers
We use a few companies to run the Service. They only get the data they need to do their job for us:
| Provider | What for | Where |
|---|---|---|
| DigitalOcean | Hosting: the relay servers and database | United States |
| Stripe | Payments and invoices (we never see full card numbers) | United States |
| GitHub | Sign-in (we receive your public profile, including your public email if you have one) | United States |
| Discord | Sign-in (we receive your username, display name, avatar and verified email), and our private team channel, which gets support messages and short notices such as a new account’s username | United States |
| Sign-in (we receive your name, profile picture and verified email) | United States | |
| Namecheap | Domain registration | United States |
| Google (Gmail) | Our support inbox: email you send us, and our replies to support-form messages | United States |
We may also disclose data when the law requires it, to protect people from harm, or as part of a merger or sale of the business (in which case this policy, or one at least as protective, will continue to apply).
Security
Traffic to gamerelay.io and the relay is encrypted with TLS, and player-to-player messages are encrypted between the players' browsers. Secret API keys are stored hashed, and access to our servers is restricted to key-based SSH. No system is perfectly secure, though. Please report vulnerabilities to dlabs.colin@gmail.com with "Security" in the subject.
Your rights and choices
You can download your data or delete your account yourself, any time, from Account and data in the dashboard (/app/account). Deleting your account removes your games and their data right away and cancels any paid plan. You can also ask us to access, correct, export or delete your personal data by emailing dlabs.colin@gmail.com. Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California), you may have further rights, including objecting to or restricting some processing and complaining to your local data-protection authority. We'll respond within 30 days, and we won't treat you differently for using these rights. You can remove saves and scores through your game, or delete a whole game from the dashboard.
Children
GameRelay accounts are for people aged 13 and over. Games built on GameRelay may be played by children. Their developers are responsible for following children's privacy laws such as COPPA, including getting parental consent where it's required, and not turning on direct connections between players (see Player-to-player connections) in games that children under 13 may play. We don't knowingly collect personal information directly from children under 13. If you believe we have, contact us and we'll delete it.
Where data lives
The Service runs in the United States (our game server is in Kansas City, and our player-to-player relay is in San Francisco). If you or your players are elsewhere, data is transferred to and processed in the US, with the safeguards the law requires.
Changes
We may update this policy as the Service changes; the date at the top shows the latest version. For material changes, we'll give notice by email or in the dashboard before they take effect.
Contact
Privacy questions or requests: dlabs.colin@gmail.com or the support page (choose "Privacy").