PRIVACY POLICY
Last updated: January 1, 2025. We take your privacy seriously.
1. Introduction
Welcome to Devception ("we," "our," or "us"). Devception is a multiplayer social deduction coding game accessible at devception.com. We are operated by the Devception team, a group of student developers. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our game. Please read this policy carefully. If you disagree with its terms, please discontinue use of the site immediately.
We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last updated" date of this policy. You are encouraged to periodically review this policy to stay informed of updates.
2. Information We Collect
We may collect information about you in a variety of ways. The information we collect includes:
- Google Account Information: When you sign in via Google OAuth (powered by NextAuth.js), we receive your name, email address, profile picture URL, and Google account identifier. We do NOT access your Google Drive, Gmail, Docs, Calendar, or any other Google services beyond basic profile data.
- Game Data: Match history, wins and losses, tasks completed, roles assigned, room codes generated, and in-game actions. Role assignments are anonymized after 90 days and match details after 12 months.
- Usage Data: Pages you visit, time spent on pages, links clicked, browser type, operating system, referring URLs, and IP address. This is collected automatically through server logs and Google Analytics.
- Cookies and Tracking Technologies: Session cookies, preference cookies, analytics cookies (Google Analytics), and advertising cookies (Google AdSense). See Section 5 for details.
3. How We Use Your Information
Having accurate information about you permits us to provide you with a smooth, efficient, and customised experience. Specifically, we may use information collected about you to:
- Authenticate you and maintain your session via Google OAuth
- Display your name and profile picture in game lobbies and results screens
- Track your match history and performance statistics
- Pair you with appropriate players through our matchmaking system
- Serve personalised advertisements through Google AdSense
- Analyse usage trends to improve our game and website
- Prevent fraudulent activity, cheating, and abuse of our platform
- Comply with legal obligations
- Respond to your inquiries and support requests
4. Google AdSense and Third-Party Advertising
We use Google AdSense to display advertisements on Devception. Google AdSense is a third-party advertising service provided by Google LLC. Google uses cookies, web beacons, and similar tracking technologies to serve ads based on your prior visits to our website or other websites on the internet.
Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to our site and/or other sites on the internet. You may opt out of personalised advertising by visiting Google's Ads Settings at google.com/settings/ads, or by visiting optout.aboutads.info. Note that opting out does not mean you will no longer see advertisements — you will still see non-personalised ads.
Google AdSense may collect data such as cookie identifiers, IP addresses, and browsing behaviour. This data is governed by Google's Privacy Policy.
5. Cookies
We use cookies and similar tracking technologies to access or store information. Specific information about how we use cookies and your choices regarding cookies is set out in our Cookie Policy. In summary:
- Essential Cookies: Required for the website to function. These include your authentication session cookie (next-auth.session-token) and CSRF protection token. You cannot opt out of essential cookies.
- Analytics Cookies: Google Analytics cookies (_ga, _gid) help us understand how visitors interact with the site. These can be disabled in your browser settings.
- Advertising Cookies: Google AdSense cookies serve personalised advertisements. You can opt out via Google's Ads Settings.
6. Data Sharing and Disclosure
We do not sell, trade, rent, or otherwise transfer your personal information to third parties for their marketing purposes. We may share your information in the following limited circumstances:
- Google LLC: For authentication (Google OAuth via NextAuth) and advertising (Google AdSense). Governed by Google's Privacy Policy.
- Vercel Inc.: Our hosting provider. Vercel processes HTTP requests and may log IP addresses and request metadata. Governed by Vercel's Privacy Policy.
- MongoDB Atlas (MongoDB, Inc.): Our database hosting provider stores your account and game data. Governed by MongoDB's Privacy Policy.
- Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests from public authorities.
7. Data Retention
We retain your personal information for as long as your account is active, plus an additional 30-day grace period following account deletion to allow for error correction. Specific retention periods:
- Account profile data (name, email, profile picture): Retained while account is active + 30 days after deletion
- Match history and game statistics: Retained for 12 months, then anonymized
- Role assignments: Anonymized after 90 days
- Server access logs: Retained for 30 days
8. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Right to Access: Request a copy of the personal information we hold about you
- Right to Correction: Request correction of inaccurate personal information
- Right to Deletion: Request deletion of your personal information and account
- Right to Object: Object to our processing of your personal information for certain purposes
- Right to Data Portability: Request a machine-readable copy of your data
To exercise any of these rights, please contact us at guptadiwanshu2007@gmail.com. We will respond to all legitimate requests within 30 days.
9. Children's Privacy
Devception is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately at guptadiwanshu2007@gmail.com and we will take steps to delete that information.
10. Security
We use administrative, technical, and physical security measures to help protect your personal information. Authentication is handled by Google OAuth through NextAuth.js, an industry-standard protocol. All data in transit is encrypted using HTTPS/TLS. Database access is restricted to authenticated server instances only. While we have taken reasonable steps to secure the personal information you provide, please be aware that no security measures are perfect or impenetrable.
11. Changes to This Policy
We may update this Privacy Policy from time to time in order to reflect changes to our practices or for other operational, legal, or regulatory reasons. The updated version will be indicated by an updated "Last updated" date and the updated version will be effective as soon as it is accessible. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your information.
12. Contact Us
If you have questions or comments about this Privacy Policy, please contact us at:
- Email: guptadiwanshu2007@gmail.com
- Website: devception.com/contact