Platform policy

Privacy notice

Effective 9 August 2026

What the portal stores

For creator accounts, the portal stores the username, email address, password hash, profile information, account status, acceptance records, sign-in and security timestamps, and the games and metadata you publish. It also keeps moderation and audit records needed to operate the service safely.

Technical information

The service processes IP addresses, request times, browser information, security events, and short-lived session cookies for sign-in, abuse prevention, troubleshooting, and reliability. Passwords are stored only as one-way hashes. Verification and reset tokens are stored in hashed form.

Hosting and service providers

The initial application and database are hosted in Singapore using Spaceship infrastructure. Cloudflare may process web traffic for DNS, security, caching, and delivery. Email providers process account-verification and password-reset messages. These providers handle data only as needed to deliver their services.

Third-party game dependencies

Published games may load explicitly declared HTTPS scripts, stylesheets, images, fonts, or media from third-party providers. Those providers receive their own resource requests and may process network information such as IP address and browser details under their own policies. Tracking and personal-data collection inside games are prohibited, but static validation cannot prove that arbitrary third-party code is tracking-free. Draft previews block third-party resources; their trusted owner bootstrap is exchanged before uploaded code loads for a short-lived signed asset capability and a separate host-only HttpOnly preview cookie.

Students and children

Creator accounts are for educators, not students. Games must not ask learners to enter names, email addresses, photographs, voice recordings, precise locations, account credentials, or other identifying information. Teachers should report any game that does so.

Retention and choices

Account, game, audit, and moderation records are retained while needed to operate, secure, and document the platform. Creators may unpublish their games and request account assistance through the contact channel on the main ClassBoard Games website. Some security, rights, or backup records may be retained where reasonably required.

Cookies

The creator portal uses a secure session cookie and anti-forgery token. Sandboxed game code cannot read that cookie. The recommended dedicated player hostname is also configured without portal credentials, adding a separate origin boundary. Advertising cookies are not required for the initial release.

External creation links

Opening an external creation, including an embedded view, connects your browser to the original provider. That provider may receive network and browser information and apply its own cookies, sign-in requirements and privacy policies. ClassBoard does not fetch or copy the remote creation when its URL is submitted. The external link and creator-selected page colours are stored as part of the listing and public profile.