Privacy Policy
JackedUp Gaming ("JackedUp Gaming", "we", "us") operates the website and services at jackedupgaming.com, including the gaming platform that hosts Realm of the Jacked (a first-person MMORPG) and several browser-based mini-games. This policy explains what we collect, why, and how to control it.
What we collect
- Account data: username, email address, password (hashed with SHA-256), and verification status.
- Payment data: handled by Stripe — we store a Stripe customer id and the last-4 digits of your saved card to label receipts. We never see or store full card numbers.
- Token ledger: every top-up, gameplay drain (1 token / hour played), and admin grant is logged with a timestamp.
- Game state: your one persistent character (name, level, XP, hero kit, items, kills/deaths), kept on the platform's Cloudflare D1 database.
- Session cookies: a single random opaque session id stored in a HttpOnly cookie — used only to identify your browser between requests. No third-party tracking cookies.
- Server logs: standard request logs (IP address, user-agent, path) retained 30 days for security + abuse mitigation.
- Avatar uploads: if you submit an avatar (image upload, or send to the avatar-watcher email address), we store the file
in our R2 bucket and link it to your account. You can delete uploads from
/account.
What we do NOT collect
- We do not run third-party analytics (no Google Analytics, no Facebook Pixel, no advertising trackers).
- We do not sell, rent, or share personal data with advertisers.
- We do not access your Gmail or Google account beyond what you explicitly authorize via OAuth — see "Google APIs" below.
Google APIs (the JackedUp Gaming OAuth app)
We integrate with Google APIs only for one specific feature: a per-user Gmail mailbox poll that imports avatar attachments sent to a designated address. The OAuth scopes used are limited to read-only Gmail message access; we do not read non-avatar messages, send mail on your behalf, or modify your Google account in any way. Your Google access token is stored encrypted as a Cloudflare Worker secret, scoped to your account only, and is revocable from your Google Account → Security → Third-party access.
Google's privacy policy applies to data Google holds about you. We are bound by Google's API Services User Data Policy including the Limited Use requirements: data obtained via Gmail OAuth is used only for the avatar import feature, never for ads, and never sold or shared.
How we use your data
- Run the games and platform — character persistence, token economy, item inventory.
- Process payments and credit token purchases (via Stripe).
- Send transactional email (account verification, receipt confirmations) via Resend.
- Enforce community rules and detect abuse / cheating.
Your controls
- Update or delete your account: contact Jacksonmilesmorris@gmail.com. Account deletion wipes the row from our Players table and unlinks your character + inventory; payment records are retained as required by law (typically 7 years).
- Revoke Google OAuth: Google Account → Third-party access → remove "JackedUp Gaming". Effective immediately on Google's end.
- Manage your saved card: log in, go to
/account, and remove the saved payment method.
Data retention
- Active accounts: data retained while the account is active.
- Inactive accounts (no login for 24 months): we may delete the row.
- Payment + ledger records: retained 7 years for tax/audit compliance.
- Server logs: 30 days.
Children
The platform is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe your child has created an account, contact us and we will delete it.
Changes to this policy
If we materially change how we handle your data, we will email registered users at least 14 days before the change takes effect and update the "Last updated" date at the top of this page.
Contact
Questions, complaints, GDPR / CCPA / data-deletion requests: Jacksonmilesmorris@gmail.com.