Privacy policy

Your gaming context should stay under your control.

Effective

1. Who this policy covers

This policy explains how GamerBFF handles information when you visit the site, access a profile, connect a supported service, import gaming activity, teach GamerBFF something, or ask for help. “GamerBFF,” “we,” and “the service” refer to this GamerBFF deployment and its operator.

Public self-registration remains closed during the small invitation-only alpha. Visitors can choose to join the wait-list, and the same privacy commitments apply before and after access is authorized.

2. Information we handle

Account and security information

We handle a profile identifier, display name, appearance preference, linked sign-in methods, verified email address when you add one, password hash for email sign-in, active sessions, and security state needed to protect account changes. We do not merge profiles because an email address, name, gamertag, or provider display name happens to match.

Alpha wait-list information

If you join the alpha wait-list, we store the email address you submit, when the request was made, and whether an invitation or registration was completed. The public page does not reveal queue size, position, or membership. A custom invitation can be created by the operator without consuming a standard alpha place.

Gaming information

Depending on what you choose to connect or add, this can include library relationships, public profile identifiers, play activity, playtime, achievements, platform or subscription availability, imports, preferences, progress, plans, notes, recommendations, and feedback. GamerBFF labels provider or import evidence separately from information you declare yourself.

Requests and operational information

We process the questions and updates you send, bounded context needed to answer them, meaningful in-app notification history and read state, security and abuse-prevention signals, and aggregate operational diagnostics. The active-session list keeps only a coarse browser and platform label. Hosting and security infrastructure may process ordinary request metadata, such as network addresses and request timing, to deliver and protect the service.

3. How we use information

We use this information to manage the alpha queue and invitations, authenticate you, maintain the gaming profile you asked for, import or synchronize selected sources, answer questions, make and explain recommendations, remember approved context, secure the service, diagnose failures, and improve reliability. We do not sell personal information or use it for third-party advertising.

4. Where information goes

GamerBFF uses service providers only for functions needed to operate the service. Which providers receive information depends on the features you choose and on how this deployment is configured.

  • Hosting and storage: site requests pass through configured hosting and security infrastructure, and account and gaming information is stored in the configured application database.
  • Sign-in providers: when you choose an external sign-in method, that provider receives the authentication request and returns identity evidence needed to link the sign-in to the correct GamerBFF profile.
  • Gaming sources: when you connect or refresh a supported source, that service receives the requested lookup and GamerBFF receives the selected profile or activity information.
  • Email delivery: when an alpha invitation or email authentication action is sent, the configured delivery provider receives the destination address and message needed to deliver it.
  • AI processing: configured AI providers receive the current message and relevant gaming context for eligible requests. When OpenAI-managed Companion is enabled, OpenAI maintains the conversation and tool loop in a stored Agents session. GamerBFF supplies bounded projections of current gaming records, validates application tools, and commits durable memory only through authenticated application checks. Raw connected-provider payloads and authentication credentials are not included in those projections. Other AI features may use separate bounded request packets.
  • Public research: research receives server-resolved public game titles and fixed research topics, platforms, and services. Private profile notes and the personal conversation are not public search queries. Research sources and limitations appear with the reply.

Those providers process information under their own terms and privacy notices. GamerBFF does not treat a public catalog entry as proof that you own a game or subscribe to a service; user-declared relationships and public catalog provenance remain distinct.

OpenAI-managed Companion

When you create a GamerBFF account, you agree to this Privacy Policy and the Terms of Use. OpenAI-managed Companion stores session messages, relevant gaming context, and tool results in an OpenAI Agents session; Agents sessions are not eligible for Zero Data Retention. OpenAI's Agents data controls describe provider storage. Automatic gaming memory is a separate opt-in: a confirmed receipt identifies a saved update, with review and undo controls. Corrections and undo update GamerBFF's authoritative records; a later reply starts with refreshed provider context when those records have changed.

Nintendo Store play activity

The experimental Nintendo connection is unofficial and is not affiliated with or endorsed by Nintendo. GamerBFF opens Nintendo’s account page for account-owner authorization; Nintendo receives that authorization and subsequent Nintendo Store play-history requests. GamerBFF never asks for, receives, or stores your Nintendo password or two-factor code.

GamerBFF stores a data-protection-encrypted Nintendo session credential, a non-reversible account fingerprint, consent and refresh state, and bounded normalized Nintendo Store title, application-identifier, playtime, and first-played evidence. It validates the Store’s platform, last-played, and recent-activity fields before normalizing play evidence. It obtains short-lived access tokens only in memory to make a request, and does not store them, raw Nintendo responses, or credentials in logs, browser responses, health output, diagnostics, or AI context.

Play activity is evidence of play, not proof of ownership, entitlement, purchase, installation, subscription, or current access. A bounded, return-triggered refresh may obtain a fresh short-lived Store token after at least a day; there is no timer-based polling or inactive-account scan.

Xbox Activity Sync

When you connect a gamertag and start Xbox Activity Sync, GamerBFF sends that gamertag to OpenXBL to resolve the matching Xbox user identifier, then requests provider-reported title history. For a bounded recent set it also requests the Xbox MinutesPlayed statistic by Title ID and service configuration ID. OpenXBL and its upstream Xbox services receive these lookup requests. OpenXBL states that it retains API request logs for usage, billing, and debugging; it and upstream services process information under their own terms and privacy notices.

GamerBFF stores the resolved Xbox user identifier only on that exact user-scoped Xbox connection so later syncs can use the stable identity without repeating the gamertag lookup. It also stores connection-scoped title identity, last-played, device or platform evidence, and known playtime. Replacing or disconnecting that connection, or deleting the account, removes the stored Xbox user identifier with the connection. The deployment's OpenXBL API key stays server-side and is not stored with a user or returned to the browser. Raw OpenXBL responses, API keys, Xbox user identifiers, rate-limit headers, and title-level provider payloads are excluded from browser responses, application logs, health output, diagnostics, and AI context.

Xbox history and device fields are activity evidence only. They do not prove ownership, entitlement, purchase, installation, Game Pass access, current ability to play, a complete library, or the exact device used for a session. In particular, provider-reported Win32 activity can reflect external PC activity. Missing playtime remains unknown rather than becoming zero.

5. Cookies and browser storage

GamerBFF uses essential cookies for authenticated sessions, sign-in safety, and request-forgery protection. Short-lived browser storage can resume bounded in-progress operations. The browser also caches your selected appearance so the page can paint consistently while the profile preference loads; the profile value remains authoritative. GamerBFF does not use third-party advertising cookies.

6. Retention, disconnection, and deletion

Personal profile data is kept while your account is active or as needed to provide a feature you chose. In-app notification history expires after 90 days and is removed with the account. Account controls let you remove individual memories, disconnect supported gaming sources, reset source-specific imports, delete gaming-profile data, or permanently delete the entire account.

Raw guided-import and bulk-extraction payloads are not retained as separate Gaming Profile source transcripts. The browser may retain a bounded visible conversation history in the current tab. The server keeps a separate bounded conversation state for continuity: up to eight recent user turns plus small typed references, facts, constraints, and question targets. Older relevant details are condensed, inactive context stops being used after 30 days, and deleting gaming-profile data or the account removes this state. Derived profile records remain separately available to review, correct, export, and delete through the existing Gaming Profile and account controls.

Managed Companion keeps an account-scoped transcript and durable recovery state, limited to 100 conversations and 100 turns per conversation. Starting a new chat retains old chats. Delete chat removes its app transcript and queues deletion of its associated OpenAI sessions; pending deletion remains visible until API removal is confirmed. Deleting gaming data or the account also queues provider-session deletion. Remote cleanup resumes after restarts. OpenAI's physical cleanup may continue after API removal, and provider billing or security records can have separate retention. Opaque cleanup references and de-identified task usage/liability records are retained separately; unknown costs are not treated as zero. Deleting a conversation does not undo Gaming Profile memories saved from it.

A request that remains only on the alpha wait-list is retained for no more than 365 days unless it is invited sooner. Invitation access is retained while needed to honor the invitation and enforce the alpha capacity. You can ask Support to remove a wait-list request before account creation. Complete account deletion also removes the account’s matching alpha invitation record.

Disconnecting a gaming source is separate from removing a sign-in method and separate from deleting your account. A supported source disconnect stops that connection from supplying new information and removes the connection-scoped information identified by the confirmation shown before the action. Shared game-catalog facts are not personal connection data and can remain after a disconnect.

Disconnecting Nintendo stops future refreshes and removes the encrypted session credential, Nintendo account fingerprint, consent and refresh state, imported activity and audit rows, and Nintendo-derived Library projections. An identifier-free generation tombstone can remain to prevent work already in flight from recreating deleted data; shared catalog facts and context you told GamerBFF can remain.

Disconnecting Xbox Activity Sync cancels queued connection work and removes that connection's resolved Xbox user identifier, accepted Xbox activity, and Library projections. Shared catalog identities and global identifier-free provider admission state can remain.

Complete account deletion removes the profile and user-scoped identity, session, notification, gaming, connection, memory, recommendation, evaluation, and legacy budget records. Managed task accounting is retained without account attribution, and opaque provider deletion references remain until cleanup is confirmed. It can preserve shared game-catalog facts, global service configuration, aggregate operational health, and a short-lived non-public security tombstone used to stop delayed callbacks from recreating a deleted identity. The tombstone contains bounded security fingerprints rather than provider account values and expires automatically.

7. Your choices

  • Choose which sign-in methods and gaming sources to connect.
  • Review and remove remembered information and supported imported connections.
  • Correct gaming context by telling GamerBFF what changed.
  • Export supported gaming-profile information.
  • Delete gaming data separately or permanently delete the account.
  • Ask Support to remove an alpha wait-list request that has not become an account.

These controls are available from Account after sign-in. If you cannot use an account control, see the current availability notice on the Support page.

8. Security

GamerBFF uses secure cookies, anti-forgery protection, fresh verification for sensitive account changes, one-use expiring email actions, bounded inputs, and separation between profiles. No service can promise absolute security. Use a unique password and remove sessions or connections you no longer recognize.

9. Children’s privacy

GamerBFF is not directed to children under 13, and public self-registration is not currently available. Do not submit a child’s email address to the alpha wait-list or provide GamerBFF with a child’s personal information. Additional age or parental-consent requirements can apply where you live.

10. Changes to this policy

We may update this policy as the service changes. The effective date above will change when the policy is revised. Material changes should be explained before they take effect when practical.

11. Contact and privacy requests

For account-access help, privacy requests, security reports, or reproducible technical problems, use the official contact listed on the Support page.

Do not send passwords, sign-in links, session tokens, private provider payloads, or full exports. If you already have access, use the self-service Account controls for supported export, disconnection, and deletion actions when practical.