Frankencart — Privacy Policy

Version 0.1 (draft) · Last updated: 2026-07-20 · Effective: [DATE]

Draft — not yet reviewed by counsel. Fields marked […] need real values. The data-handling descriptions below were written against the actual code as of 2026-07-20 and are accurate to it; they must be re-checked whenever data handling changes, particularly when the ladder database lands.

1. The short version

2. Who is responsible

[LEGAL ENTITY NAME], contactable at [CONTACT EMAIL], is the controller of personal data described here. [If a GDPR representative or DPO is required, name them here.]

3. What we process, and why

3.1 Game files you load — not collected

When you choose a cartridge file, it is read into your browser's memory and passed to the emulator running in the same page. It is never uploaded. There is no API endpoint in the Service capable of receiving a game file, which is a deliberate architectural decision rather than a policy promise.

This applies equally to the Discord bot: the bot never receives game files.

3.2 Server access logs — collected

Our web server records, for each request: IP address, timestamp, requested URL, HTTP status, bytes sent, referring URL, and user-agent string (Apache combined format).

3.3 Discord identity — collected where you use Discord features

Where you use the Activity or bot commands, Discord provides us with your Discord user ID, username/display name, and the server and channel context in which you invoked it.

*As of this version the bot stores nothing per-user; commands are answered and nothing is written. This section must be revised when the ladder database is built.*

3.4 Competitive results — planned, not yet live

When ladders and head-to-head matches launch, we intend to store: your Discord user ID and display name, the game or recipe played, scores/times and match outcomes, and timestamps. Results may be displayed publicly with your Discord display name.

This section will be updated with specifics before that feature is released.

3.5 What stays on your own device

The emulator keeps working data in your browser's own storage — settings such as control bindings, and a cache of engine files so they need not be downloaded again. This is local to your device and strictly necessary to run the emulator you asked for. We do not receive it, and it is not personal data we hold. Clear it at any time through your browser's site-data controls.

We set no cookies of our own and use no cookie-based tracking.

4. What we do not do

5. Who else is involved

Party What they handle Their terms
Discord Runs the Activity and bot; processes your account data and Discord activity independently of us Discord Privacy Policy
[HOSTING PROVIDER] Serves the site; access logs sit on that infrastructure [link]
[DNS / TLS PROVIDER] Domain and certificates [link]

Discord additionally proxies all network traffic for Activities. Requests your browser makes while the Activity is open pass through Discord's infrastructure, and Discord may log them under its own policy. This is a property of the Activity platform, not something we add.

6. International transfers

Our infrastructure is located in [COUNTRY]. Discord operates internationally. If you are in the UK/EEA, transfers outside your region rely on [TRANSFER MECHANISM — e.g. Standard Contractual Clauses].

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data; to object to or restrict processing; and to withdraw consent where processing relies on it. UK/EEA residents may complain to their supervisory authority; California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.

To exercise any of these, contact [CONTACT EMAIL]. We will respond within the period the applicable law requires (generally one month).

Practical note: because game files are never collected, there is nothing for us to return or delete in respect of them. Requests will concern access logs and, in future, competitive results.

8. Children

The Service is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child under 13 has provided us data, contact us and we will delete it.

9. Security

We serve the site over HTTPS and restrict administrative access to the systems that hold logs. No system is perfectly secure, and we cannot guarantee absolute security.

10. Changes

We will update this policy as the Service changes — in particular when competitive features begin storing data. The version and date at the top will change, and material changes will be announced in the Frankencart Discord.

11. Contact

[CONTACT EMAIL] · [POSTAL ADDRESS, if required]