triggair
Legal

Privacy Policy

Last updated: 13 July 2026

This Privacy Policy explains how Triggair (“Triggair”, “we”, “us”) handles personal data in connection with the Triggair platform, SDK, MCP server, dashboard, APIs, and websites (together, the “Service”). It covers two groups of people: the developers who use Triggair to build games (“Developers”) and visitors to our websites; and the players of games that Developers build on Triggair (“players”). Please read it alongside our Terms of Service.

1. Our two roles

Triggair plays two different roles depending on whose data is involved:

  • We are a data controller for the personal data of Developers (account and billing data) and of visitors to our websites. This Policy describes how we handle that data.
  • We are a data processor for the personal data of players that we handle on a Developer’s behalf when they build a game on Triggair. In that relationship, the Developer is the controller and decides why and how player data is used; we process it on their instructions. If you are a player, the game you are using is responsible for its own privacy practices, and you should consult that game’s privacy notice and contact its developer to exercise your rights. Section 11 explains how we support those requests.

2. Privacy by design: anonymous-first, minimal data

Triggair is built to collect as little personal data as possible. Players are anonymous by default: a game creates a random, device-scoped identifier and exchanges it for a short-lived access token, without requiring a name, email address, or password. We do not ask players for real-world identity, and features such as our age-gating tool are designed to avoid storing sensitive data — for example, when an age screen collects a birth year, that year is mapped to an age bracket and then discarded, so no date of birth is stored.

3. Information we collect and process

a. Developer account data (we are controller). When you create a Developer account and use the dashboard, we process:

  • your name and email address, and the identifier from the sign-in provider you use (email magic-link or a supported OAuth provider);
  • the games, API keys, configuration, and settings you create;
  • support communications you send us; and
  • billing-related records described in Section 5.

b. Website and product usage data (we are controller). When you visit our websites or use the dashboard, we and our infrastructure providers process technical data such as IP address, browser and device information, pages or endpoints accessed, and timestamps, primarily in server logs used to operate, secure, and debug the Service.

c. Player data processed on a Developer’s behalf (we are processor). Depending on the features a Developer enables, the Service may store and process the following categories of player data on the Developer’s instructions:

  • Identifiers and technical data: a hashed device identifier, access tokens, and IP address and request metadata used transiently for authentication, security, rate-limiting, and approximate region selection;
  • Profile data: optional, player-chosen display name, handle, and avatar seed;
  • Gameplay data: cloud saves (game state the Developer defines), stats, leaderboard scores, achievements, quests and progression, and economy data such as currency balances, transaction ledgers, and inventory;
  • Social data: friend relationships, teams, and the context attached to share links;
  • User-generated content: content players create (such as levels), including titles, descriptions, tags, ratings, and the content payload itself;
  • Trust and safety data: moderation checks on names and text, reports, and records of bans, mutes, and appeals;
  • Age and compliance data: an age bracket (not a date of birth), the resulting feature-gating decisions, and, where a Developer uses parental consent, records of consent requests and outcomes;
  • Diagnostics: crash reports a game submits; and
  • Analytics events: product and gameplay events. Custom properties attached to analytics events are stripped of personal data by default and retained only where consent has been indicated.

4. How we use information

We use the data described above to:

  • provide, operate, maintain, and secure the Service and its features;
  • authenticate Developers and players and enforce plan quotas and rate limits;
  • detect, prevent, and respond to fraud, abuse, cheating, and security incidents;
  • process subscriptions and provide receipts and support;
  • communicate with Developers about the Service, including service and security notices;
  • understand and improve the Service through aggregated and de-identified analysis; and
  • comply with legal obligations and enforce our Terms.

We do not sell personal data, and we do not use player data to serve behavioral advertising.

5. Payments

Subscription payments are processed by our payment provider acting as the merchant of record. That provider collects and processes the payment information needed to complete your purchase (such as card or billing details) as an independent controller under its own privacy policy, and it handles tax collection and remittance. We receive limited billing records — such as your plan, billing country, transaction identifiers, and subscription status — but we do not receive or store your full payment card number.

6. Cookies and local storage

Our marketing website uses minimal local storage — for example, to remember your light or dark theme preference — and does not use third-party advertising or cross-site tracking cookies. The Triggair SDK, when integrated into a Developer’s game, uses the browser’s local storage on the player’s device to hold the anonymous device identifier, the current access token, and a durable outbox that lets writes survive a dropped connection; this is essential to the Service and is not used for advertising. We use a bot-protection challenge from our infrastructure provider to defend sign-up endpoints against automated abuse.

7. Sub-processors and disclosure

We share personal data with a small set of infrastructure providers that process it on our behalf, under contracts that require appropriate safeguards:

  • Cloud infrastructure & security provider — content delivery, network security, and bot protection;
  • Managed data-hosting provider — hosted database and file storage (European region by default);
  • Paddle — payment processing and merchant-of-record services for subscriptions; and
  • Email-delivery provider — transactional email, such as parental-consent and account notifications.

We may also disclose data where required by law or valid legal process, to protect the rights, safety, and security of Triggair, our Developers, players, or the public, or in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this Policy or notify you of any material change.

8. International data transfers

We aim to keep data in the European region by default. Where personal data is transferred to a country that does not provide an equivalent level of data protection, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, to protect it.

9. Data retention

We keep Developer account data for as long as your account is active and as needed to provide the Service, and we retain limited billing records for the period required by law. If a subscription lapses or is terminated, the associated game does not disappear immediately: it becomes read-only for 14 days, is then archived for a further 90 days, and is then permanently deleted. Player data is retained for as long as the Developer’s game uses it and in line with the Developer’s instructions and retention settings, and is deleted when a Developer or a valid player request requires it, or when the game reaches the end of the lifecycle above. Server logs and security data are kept for a limited period appropriate to their purpose.

10. Security

We use technical and organizational measures designed to protect personal data, including encryption of data in transit, database-level tenant isolation so one game cannot read another’s data, access controls limited to the trusted control plane, request rate limiting and abuse detection, and scanning to detect leaked secret keys. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect data using measures appropriate to the risk.

11. Your rights

Depending on your location, you may have rights over your personal data, including the rights to access, correct, delete, restrict or object to processing, and receive a portable copy, as well as the right to withdraw consent where processing is based on consent and to lodge a complaint with a data-protection supervisory authority.

  • Developers can exercise these rights over their account data by contacting us at support@triggair.com.
  • Players should contact the developer of the game they are using, who is the controller of that game’s data. We provide Developers with the tools to honor these requests, including the ability to export and to permanently delete a player’s data, and we assist Developers with requests directed to us.

We may need to verify your identity before acting on a request, and we will respond within the time required by applicable law.

12. Children’s privacy

The Triggair website and Developer dashboard are intended for developers, not children. Games built on Triggair, however, may be played by children, and we provide Developers with tooling to help them comply with children’s-privacy laws such as COPPA and the GDPR’s rules on children. This includes a neutral age screen, an age-bracket model that stores a bracket rather than a date of birth, per-feature gating that fails closed when age is unknown so sensitive features (such as loot boxes, open chat, and public user-generated content) are restricted, exclusion of minors from behavioral profiling, and a verifiable parental-consent flow. Developers are responsible for configuring and using these controls appropriately for their audience.

13. Automated processing and moderation

Some safety features apply automated processing — for example, checking a username or chat message against moderation rules and returning a decision to allow, mask, block, or route the content for review. These checks are designed to keep games safe and compliant. Where a Developer’s configuration results in a restriction on a player, the Service supports an appeal path so a human can review the decision.

14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.

15. Contact us

For privacy questions or to exercise your rights, contact us at support@triggair.com. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data-protection supervisory authority.