Privacy Policy
Last updated: March 22, 2026
This Privacy Policy explains how Eon ("Platform", "Service", "we", "us", "our") collects, uses, and protects your information when you use game.olyeon.com and related services.
1. Information We Collect
| Data | When | Purpose |
| Email address | Account registration | Authentication, password reset, account notifications |
| Username | Account setup | Public identity on the Platform |
| Password (hashed) | Email registration | Authentication (stored as bcrypt hash, never in plain text) |
| OAuth identifiers | Social login | Link your Discord, Google, Twitter/X, or MetaMask account |
| Wallet address | MetaMask login | Authentication via Ethereum signature |
| IP address | Every request | Rate limiting, security, abuse prevention |
| User Content | When you create/publish | Hosting and displaying your games and scenes |
| Analytics events | During use | Session duration, feature usage, performance metrics |
| Chat messages | In-game chat | Delivering messages to other players, moderation |
| Voice data | Voice chat (LiveKit) | Real-time voice communication (not recorded or stored by us) |
| Profile info | Optional | Bio, avatar, banner — displayed on your public profile |
2. How We Use Your Information
We use the information we collect to:
- Provide and operate the Platform (authentication, hosting your content, multiplayer).
- Display your published games on the discover page for other users to find and play.
- Communicate with you about your account (password resets, security alerts).
- Improve the Service through aggregated, anonymous analytics.
- Enforce our Terms of Service and protect against abuse.
- Moderate content and user behavior for community safety.
3. Information Sharing
We do not sell your personal data.
We may share information only in the following circumstances:
- Public content: Your username, profile, and published games are visible to other users by design.
- Third-party authentication: When you log in via Discord, Google, Twitter/X, or MetaMask, those providers receive information as described in their own privacy policies.
- Voice chat: Voice communication is handled by LiveKit. Audio streams are transmitted in real-time and are not recorded or stored by us. LiveKit's privacy policy governs their handling of data.
- Legal obligations: We may disclose information if required by law, court order, or to protect the safety and rights of our users or the public.
4. Data Storage & Security
Your data is stored on our servers. We use the following security measures:
- Passwords are hashed with bcrypt before storage.
- Authentication uses signed JWT tokens transmitted over HTTPS.
- Database backups are performed daily with 30-day retention.
- All traffic is encrypted via TLS/SSL.
- Rate limiting is applied to authentication endpoints to prevent brute-force attacks.
While we take reasonable measures to protect your data, no system is 100% secure. You use the Service at your own risk.
5. Cookies & Local Storage
We use browser local storage to:
- Store your authentication token (JWT) so you stay logged in.
- Save editor autosave data (IndexedDB) locally on your device.
- Store your preferences and settings.
We do not use third-party tracking cookies or advertising cookies.
6. Your Rights
You have the right to:
- Access your personal data — contact us to request a copy.
- Correct inaccurate information in your profile or account settings.
- Delete your account and associated data — contact us or use the account deletion feature.
- Unpublish your content at any time through the editor.
- Withdraw consent for optional data processing by adjusting your settings or contacting us.
If you are located in the EU/EEA, you may also have rights under the GDPR, including the right to data portability and the right to lodge a complaint with a supervisory authority.
7. Children's Privacy
Eon is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete that information promptly. If you believe a child under 13 has provided us with personal data, please contact us.
8. Data Retention
- Account data: Retained for as long as your account is active. Deleted upon account deletion request.
- Published content: Retained while published. Removed when you unpublish or delete it.
- Analytics data: Retained in aggregated, anonymized form. Individual session data is retained for up to 12 months.
- Chat messages: Retained for moderation purposes for up to 90 days.
9. Third-Party Services
We integrate with the following third-party services. Their use is governed by their own privacy policies:
- Discord — OAuth authentication, community features
- Google — OAuth authentication
- Twitter/X — OAuth authentication
- MetaMask / Ethereum — Wallet-based authentication
- LiveKit — Real-time voice communication
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the Platform or via email. Your continued use of Eon after changes are posted constitutes acceptance of the updated policy.
11. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: support@olyeon.com