← Back to Home

Privacy Policy

Last updated: October 24, 2025

Note: All characters, names, companies, and scenarios in Casefile are entirely fictional. Any resemblance to real persons, companies, or events is purely coincidental. See our Terms & Conditions for more information.

Introduction

Welcome to Casefile. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you about how we handle your personal data when you use our multiplayer mystery game.

Information We Collect

When you play Casefile, we collect minimal information necessary to provide the game experience:

  • Account Information: Email address and name when you create an account to play. Authentication is handled securely by trusted third-party providers.
  • Subscription Information: If you subscribe to Premium, payment information is securely processed by Stripe, our payment processor. We store subscription status and plan information to manage your access to premium features. No payment card data is stored on our servers.
  • Username: The display name you choose when joining a game room
  • Game Session Data: Room codes, game state, and gameplay interactions during your session
  • Connection Information: WebSocket connection IDs for real-time gameplay (automatically deleted when you disconnect)
  • Technical Data: IP address, browser type, and timestamps for security and debugging purposes
  • Analytics Data: Anonymous gameplay events (room creation, game completion, scores) to improve the game experience. No personally identifiable information is collected.

How We Use Your Information

We use your information to:

  • Authenticate and manage your account access
  • Process subscription payments and manage Premium access
  • Provide real-time multiplayer game functionality
  • Maintain game room connections and synchronize game state
  • Prevent abuse and ensure fair gameplay
  • Improve game performance and fix technical issues
  • Analyze gameplay patterns to enhance game design and user experience
  • Monitor game popularity and player engagement metrics
  • Comply with legal obligations

Data Storage and Security

Your data is stored securely using AWS services:

  • Authentication Data: Account credentials and profile information are securely managed by trusted authentication providers with industry-standard security practices including encryption at rest and in transit
  • Session Data: Game session information is stored temporarily and automatically deleted after 24 hours of inactivity
  • Encryption: All data transmitted between your browser and our servers is encrypted using HTTPS/WSS protocols

Cookies and Tracking

Casefile uses minimal cookies essential for game functionality. We use privacy-focused analytics to improve the game, but do not use advertising or marketing cookies. See our Cookie Policy for more details.

Third-Party Services

We use the following third-party services:

  • Authentication Services: For secure user authentication and account management. Our authentication provider handles email, password, and profile data with enterprise-grade security and compliance with GDPR, CCPA, and SOC 2 standards.
  • Payment Processing (Stripe): When you subscribe to Premium, your payment is securely processed by Stripe. Stripe is PCI Level 1 certified and fully PCI-DSS compliant. We never see or store your payment card details on our servers.
  • Cloud Infrastructure: For hosting, data storage, and real-time multiplayer functionality
  • Analytics Services: For privacy-focused usage analytics and performance monitoring. Our analytics provider is GDPR and CCPA compliant, does not use cookies, and collects only anonymous aggregated data about game events (e.g., rooms created, games completed, scores). No personally identifiable information is tracked.

These services have their own privacy policies. We carefully select partners who prioritize user privacy and security. For specific privacy policies, please refer to the respective service providers' documentation.

Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request deletion of your data
  • Object to processing of your personal data
  • Request restriction of processing your personal data
  • Data portability

Note: Since we do not require accounts and automatically delete session data, most personal data is already ephemeral.

Children's Privacy

Casefile is intended for general audiences. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new privacy policy on this page and updating the "Last updated" date.

Contact Us

If you have any questions about this privacy policy, please contact us at: martin@hughes.lol