Privacy Policy
Last updated: 22 July 2026
This policy explains exactly what data Classic Games Hub collects, why, where it lives and what your rights are. It's written to match what the platform actually does — no more, no less.
1. Who is responsible for your data
Classic Games Hub (“the Hub”, “we”) is operated from the United Kingdom by BlobbyOfficial, who acts as the data controller for the personal data described here. Contact: blobbyofficial@blobbyofficial.com. We handle personal data in line with UK data-protection law, including UK GDPR and the Data Protection Act 2018.
2. What we collect
Account data
- Email address and password (password stored only as a secure hash) if you sign up by email — used to sign you in and for account emails such as password resets. We do not send marketing emails.
- Discord identity if you sign in with Discord or link your account: your Discord user ID and username, and the avatar Discord provides. We never see your Discord password.
- Profile information you choose to add: username, display name, avatar, banner, bio, pronouns, status line, featured achievements and cosmetics. Your profile is visible to other users.
Gameplay & progression data
- Play sessions, scores, leaderboard entries, achievements, XP, levels, credits and your credits-transaction history, daily-reward streaks, challenge progress, shop purchases, inventory and equipped cosmetics.
Social data
- Friendships, follows, blocks, friend requests, group memberships, stories, message reactions and the messages you send (including links to GIFs you pick). Direct messages are only visible to their participants (plus, where strictly needed, moderation review of reported content); group messages to group members.
- Private notes and nicknames you set on other players (visible only to you).
- Reports you file about content or players.
- Presence data: a “last seen” timestamp updated while you use the site, and the presence/visibility preferences you configure.
Discord bot data (only if you use our Discord server)
- Your Discord user ID and display name, a count of counted chat messages, Discord XP and level, and timestamps of your last counted message. The bot reads only message metadata for XP — it does not store the content of your Discord messages.
- The Discord roles our bot assigns or removes for you, and moderation actions taken through the bot (warnings, timeouts, bans, and the reason given), which are recorded in our audit log.
- One-time link codes while an account link is in progress (they expire within 10 minutes and are then purged).
Technical data
- IP addresses and device/browser informationappear in the server logs of our hosting providers (Vercel, Supabase) as a normal part of serving requests and securing authentication. We don’t build profiles from them.
- Anonymous usage analytics via Vercel Analytics and Speed Insights (page views and performance). These are cookie-less and aggregate — visitors are not individually identified or tracked across sites.
3. Cookies
The Hub uses only essential cookies: the authentication cookies that keep you signed in (set by our Supabase-based auth). There are no advertising or cross-site tracking cookies. If you enable the optional rewarded-ads programme in Settings and an ads provider is active, we will update this policy first to describe exactly what it sets.
4. Why we process your data (legal bases)
- Performance of a contract — running your account, gameplay, economy and social features you signed up for.
- Legitimate interests — keeping the platform safe and fair (moderation, anti-cheat, audit logs, rate-limiting), understanding aggregate usage, and securing our infrastructure.
- Consent — optional features you actively turn on, such as linking your Discord account or enabling rewarded ads. You can withdraw consent by unlinking or turning the feature off.
5. Where your data lives and who processes it
- Supabase — our database and authentication provider; data is stored in an EU region (Ireland). Row Level Security restricts every record to the people entitled to see it.
- Vercel — hosts the website and processes requests (including IP addresses in transient logs) and anonymous analytics.
- Discord — if you use Discord sign-in, linking, or our server, Discord processes your data under its own privacy policy.
- Giphy — GIF searches in chat are proxied through our server, so Giphy receives the search term but not your identity or IP address.
Some providers may process data outside the UK/EEA; where they do, transfers rely on recognised safeguards such as the UK International Data Transfer Agreement or adequacy decisions. We never sell your data.
6. How long we keep data
- Account, gameplay, social and Discord-level data: for as long as your account exists.
- One-time Discord link codes: minutes (purged shortly after expiry).
- Stories: expire and stop being served 24 hours after posting.
- Audit logs (moderation and admin actions): kept while relevant for the safety of the platform.
- Hosting/server logs at Vercel and Supabase: short rolling windows controlled by those providers.
7. Your rights
Under UK GDPR you can ask us to:
- Access a copy of the personal data we hold about you;
- Correct inaccurate data (most profile data you can edit yourself in Settings);
- Delete your account and personal data;
- Restrict or object to particular processing;
- Port your data in a machine-readable format.
Email blobbyofficial@blobbyofficial.comfrom your account email and we’ll respond within one month. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
You can unlink Discord at any time in Settings → Connections. Unlinking removes the connection and synced roles; Discord XP earned in the server remains associated with your Discord ID (delete-able on request).
8. Security
- All traffic is encrypted in transit (HTTPS).
- Passwords are hashed; we can never read them.
- Every database table is protected by Row Level Security; privileged operations run in audited, server-side functions that clients cannot call directly.
- Admin actions are recorded in an audit log.
9. Children
The Hub is not for children under 13, and we don’t knowingly collect their data. If you believe a child under 13 has an account, contact us and we will remove it.
10. Changes to this policy
When the platform changes what it collects, this policy is updated first (the date at the top tells you the current version). Significant changes will be announced on the site or in Discord.
11. Contact
Privacy questions or requests: blobbyofficial@blobbyofficial.com. See also our Terms of Service.