
Privacy Policy
Effective August 6, 2026
This policy explains what information Roundcade collects, why, how long we keep it, and what you can do about it. Roundcade is a browser-based multiplayer games service operated by Social Design Lab from the Philippines. For any privacy question or request, contact socialdesignlab.ph@gmail.com.
Who is responsible for your data
Social Design Lab is the personal information controller for Roundcade, and is responsible for the processing described here. We are based in the Philippines and process personal data under the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules. Where the EU or UK General Data Protection Regulation applies to you, we act as the data controller for the same processing.
Information you give us
Account. To register you provide an email address and a password. We store your email address and protect your password using a strong, non-reversible process. We never store your password itself and cannot recover it.
Date of birth. Roundcade is an 18+ service, so registration requires your date of birth. We check it against the minimum age and retain the date so we can evidence that the check was performed.
Profile. Optionally a username, display name, short bio, avatar selection, and favorite games. Other players who view your profile see exactly these five fields and nothing else. Your email address is never shown to another player.
Messages and content. Direct messages, lobby channel messages, in-room chat, and anything you submit while playing, such as answers, drawings, and game moves.
Photos you upload. Profile pictures and photo posts. We never keep the file you sent. It is decoded and re-encoded into a new image, which removes camera, device and location (GPS) data that phones commonly embed, and only that new image is stored. We also keep a one-way fingerprint of it, which is what lets us refuse an image that was previously removed. Photos and profile pictures appear immediately and are not reviewed beforehand.
Captions and posts. The caption on a post, who reacted to it, and comments. Captions are checked automatically against a list of terms associated with abuse, advertising and scams. This is a fixed word list, not artificial intelligence and not profiling: it does not build a picture of you, and a match only places the post in front of a person.
Follows and social activity. Who you follow and who follows you, and the posts you hide from your own feed. Following is one-way and separate from mutual friendship. Your follower and following lists have their own visibility settings in Privacy Settings.
Voice rooms. If you join a voice room we process your microphone audio in order to transmit it to the other people in that room, in real time. We do not record it and we do not store it. What we do keep is the surrounding record: which room you joined, when, whether you held a microphone seat, and moderation events such as being muted by a host or removed from a seat. Voice rooms are off unless the feature is switched on for your account.
VIP and purchases. Your VIP level and the entitlements attached to it, and, where you have made a payment, the order record and any payment proof you upload. Payment proofs are reviewed by a person and are never published anywhere.
GCash withdrawals. If you request a withdrawal, we store the GCash account name and mobile number you provide. Your first successfully submitted request links that GCash identity to your Roundcade account. You cannot edit it yourself. After verified support contact, an authorized operator may make a reasoned and audited correction. It is used to send and reconcile payouts, prevent the same destination being spread across accounts, and investigate payment fraud. It is visible only to you and to authorised payment operators handling a specific request.
Reports. If you report a player or a message, we store your written description and a snapshot of the reported content. Our system automatically strips fields that look like credentials, tokens, emails, phone numbers, or addresses from that snapshot.
Agreement records. When you accept these documents at registration we record which version you accepted, when, and a privacy-preserving network record as evidence of acceptance.
Information we collect automatically
Sessions. For each signed-in session we store the browser user-agent string, the times it was created and last used, and its expiry, so you can review your active devices and sign them out remotely.
Funded-match browser identifier. When you use Gem Match, the server gives the browser profile a random, script-hidden cookie and stores only a keyed one-way result on the funded offer. This helps stop two accounts in one browser profile from holding active offers at the same time. Clearing cookies, private browsing, and another device can produce a different identifier, so it is not treated as proof of identity or as a reason for a sanction by itself.
Network information. We record the IP address a session connects from, together with a privacy-preserving identifier derived from it, and use them for security, rate limiting, fraud prevention, and investigating abuse such as one person running several accounts. Stored addresses are encrypted, access to them is restricted and every access is recorded, and they are deleted on the schedule below. Most of our day-to-day checks use only the derived identifier, which cannot be turned back into an address. Infrastructure providers also process IP addresses and request information as necessary to route and protect web traffic.
Gameplay. Rooms you join, matches you play, who you played with, and the timing and outcome of your moves, so that games work, can be reconnected to, and can be audited for cheating.
Diagnostics. Server error and security logs. These can contain internal account identifiers but are not designed to contain your email address or IP address.
Why we are allowed to process it
Under the GDPR, where it applies, we rely on: performance of a contract for your account, your profile, matchmaking, gameplay and messaging; legitimate interests for security, abuse prevention, moderation, rate limiting, service reliability and aggregate analytics; legal obligation for records we must keep, including proof of age and of your acceptance of these terms; and consent where we specifically ask for it. Under the Philippine Data Privacy Act we rely on the corresponding lawful criteria in sections 12 and 13, principally the necessity of the processing for our contract with you and for our legitimate interests.
Where we rely on legitimate interests, you have the right to object. See Your rights below.
How we use it
- to create and run your account, and to sign you in and keep you signed in;
- to run games, place you in rooms, reconnect you, and record results;
- to deliver friend requests, invites, notifications, and direct messages;
- to send service email such as address verification and password resets;
- to keep the service safe: blocking, muting, reporting, moderation, rate limiting, and detecting cheating or automated abuse;
- to verify that account holders meet our minimum age;
- to diagnose faults and measure aggregate performance and usage; and
- to comply with law and to establish, exercise, or defend legal claims.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles. We do not make any decision about you by purely automated means that produces a legal or similarly significant effect.
What other people can see
Other players can see your username, display name, bio, avatar, and favorite games, subject to your privacy settings; your online status, subject to your privacy settings; your chat and messages in the rooms and conversations you take part in; and your activity in a game you are playing together.
Direct messages are visible to you and to the person you sent them to. Blocking or unfriending someone stops new messages, but it does not delete or hide the messages already delivered to them. Treat anything you send as something the recipient keeps. There is more detail below, under Your private messages.
When you mute someone, they are not told. When you block someone, blocking applies in both directions.
Photo posts and Explore. A post is visible according to the audience you chose when you created it: everyone, your followers, your friends, or only you. Posts set to everyone can be recommended to people who do not follow you, including on Explore, and each recommendation carries a short line explaining why it appeared. That explanation is built only from things like shared games and mutual connections. It never uses your spending, your payment records, your private messages, or your device. You can hide any recommended post from your own feed without the author being told.
Voice rooms. Everyone in a room can hear whoever holds a microphone seat and can see who is present. A host can mute you or move you off the microphone, and those actions appear in the room as a short activity note. A host can never switch your microphone on remotely: only you can do that, from your own device.
Your picture. A profile picture is visible wherever you appear on Roundcade, and it appears as soon as you upload it. If you remove it, or if it is taken down after a report, it stops being served everywhere.
Your private messages
Your direct messages are private. They are for you and the person you are talking to, and we treat them that way. This section explains exactly who can read them, the one narrow situation where a member of our team can, how long we keep them, and what we will never do with them. We have written it in plain language on purpose, because a promise you cannot understand is not a promise worth making.
Nobody on our team reads your messages
Our staff cannot browse your conversations. There is no screen anywhere in our systems that lets an employee open your inbox, search your messages, look through a list of your chats for something interesting, or export them. That is not a policy we ask our team to follow. It is a limit built into the software itself, so that following it is not a matter of anyone's good behaviour.
This applies to everyone who works on Roundcade, including our moderators and our support team. A moderator handling a report about you cannot open your messages. Support helping you with your account cannot see them either. Being on our team gives nobody a window into your private conversations.
The one exception, and the rules around it
There is a single exception, and we would rather describe it honestly than claim it does not exist. When someone is in danger, or a serious safety or fraud problem is being investigated, one owner-level account can open one specific conversation as part of that investigation. This exists because refusing to ever look would mean being unable to act on the most serious reports we receive: grooming, threats, coordinated scams, and similar harms where the evidence is in the conversation itself.
Every one of the following is required before a single message can be opened, and the system enforces all of them:
- A real, open case or report. Access is always attached to a specific investigation that already exists. There is no way to open a conversation without one, and no way to look at a conversation belonging to someone the case is not about.
- A written reason, recorded at the time. Whoever opens the conversation must type why. That reason is stored permanently against every message they see.
- A fresh security code. Re-confirmation with an authenticator app, within minutes, every time.
- A permanent, unchangeable record. Each individual message opened is recorded with who opened it, when, and under which investigation. These records cannot be edited or deleted by anyone, including the person who created them and including the owner.
- No bulk access. One conversation at a time, with a strict limit on how much can be shown. There is no search across accounts and no way to export in bulk.
We keep these controls because they protect you from us. Anyone who looked at a conversation without a genuine reason would leave a permanent trail with their name on it, which is reviewed. Access without a good reason is a serious matter and is treated as one.
What we never do with your messages
- We do not read them to target advertising, and we do not show advertising in them.
- We do not sell them, rent them, or share them with advertisers or data brokers.
- We do not scan them to build a profile of your interests or personality.
- We do not use them to train artificial intelligence. Roundcade uses no AI services at all.
- We do not hand them to anyone outside the company except where the law genuinely requires it, or to protect someone from serious harm.
How long we keep them
We keep direct messages for about six months, and then our systems delete them automatically. You do not have to ask, and nobody has to remember to do it. This is a deliberate choice: holding on to years of private conversation would be more information than we need to run a game platform, and information we do not hold cannot be lost, misused, or demanded from us.
There is one situation where a conversation is kept longer. If it is part of an active safety investigation or we are legally required to preserve it, it is held until that finishes. Once the hold is lifted, the normal six-month deletion applies again.
Two consequences are worth being clear about. Older conversations will disappear from your own history over time, which is normal and not a fault. And deleting your account does not remove the messages you already sent to other people, because those are part of their conversation too. They will age out on the same six-month schedule.
Reporting a message
If someone sends you something that breaks our rules, report it. When you report a message, that specific message is included with your report so our moderators can act on it. This is the one way a conversation reaches our team, and it happens because you chose to send it, not because anyone went looking.
Who we share it with
We use carefully selected service providers to operate Roundcade. Depending on the service they provide, they may process only the information necessary for cloud hosting and data storage, network delivery and security, transactional email, or website analytics and performance monitoring.
These providers act on our instructions and are required to protect the information they process. We do not give them permission to use it for their own advertising or to sell it. You may contact us for more information about the current providers used for a particular processing activity.
We may also disclose information where we are legally required to, or where it is necessary to investigate suspected abuse, protect the rights and safety of our users or the public, or establish or defend legal claims. If Roundcade is ever transferred to another operator, personal data would transfer with it, and we would tell you first.
Where your data is processed
Roundcade is operated from the Philippines, and some service providers process data in other countries. Where a cross-border transfer requires additional protection, we rely on contractual or equivalent safeguards available under applicable law. You can contact us for information relevant to your location.
Analytics
We use cookieless website analytics and performance measurements to understand aggregate visits and how reliably pages load. These may process page paths, referrers, approximate location, device and browser information, timestamps, and performance measurements. We use the results to improve reliability and usability, not to profile you or advertise to you.
How long we keep it
These are the actual retention periods built into the service:
- Account, profile, and date of birth - while your account exists, then as described under Deleting your account.
- Direct messages - about six months, then deleted automatically. A conversation held for an active safety investigation or a legal requirement is kept until that finishes, then follows the same schedule. Deleting your account does not remove messages you already sent to other people; those age out on the same six-month schedule. See Your private messages above.
- Lobby channel messages - the most recent 200 messages, or 24 hours, whichever is shorter.
- In-room chat - the last 60 messages, held only in server memory, and lost when the room closes or the server restarts.
- Online status - live status expires within 30 seconds of disconnecting; a last-seen timestamp is kept for 30 days.
- Sessions - expire after 30 days of inactivity, and in all cases after 90 days.
- Funded-match browser identifier - the cookie expires within one year. Its keyed one-way result is kept only on the corresponding Gem Match offer and follows that offer's retention rather than becoming a separate browsing history.
- IP addresses - the encrypted address is deleted after 90 days, matching the longest a session can live. The derived identifier is kept with the session record, and it cannot be turned back into an address.
- Email verification links - 7 days. Password reset links - 1 hour.
- Guest identities - 30 days. Guest play is disabled on the live service.
- Reports and moderation records - kept while they are needed for safety and for our records, including after the reported account is deleted.
- Photo posts and their images - about a year, then the image file is deleted while a record that it existed and what was decided about it remains. A removed picture keeps its one-way fingerprint so the same image cannot be uploaded again.
- Profile pictures - kept while the account exists, because the current one is in use and an older one may be the evidence in a report about it.
- Anything under a hold - an image tied to an open report, an open moderation case, or a legal preservation request is not deleted on the schedule above. It is kept until that finishes, and then deletes normally. This is deliberate: deleting evidence on a timer is how the picture an investigation was about disappears before anyone acts.
- Voice room audio - never recorded and never stored. The record of joining a room and any moderation events follow the moderation-record line above.
- Payment proofs and transaction records - about five years, because a payment dispute can arrive long afterwards and the proof is the record.
- GCash binding and correction history - kept with the account, including its retained financial record after account deletion, because the durable destination link prevents one payout identity being reused across Roundcade accounts and records authorized corrections.
- Proof of age and of your acceptance of these documents - kept for as long as we may need to evidence them.
Deleting your account
You can request deletion at any time from your account settings. Deletion is scheduled for 30 days, during which your account keeps working and you can cancel. After that window we permanently delete your profile, your date of birth, and your login credentials, revoke all your sessions, and reserve your username for a further 30 days so nobody can immediately impersonate you.
We want to be exact about what deletion does not do. We keep a minimal, inert account record so that data belonging to other people stays intact, and the following are not erased straight away: direct messages you sent, which remain part of the other person's conversation until they age out on the usual six-month schedule; your friend and block relationships; notifications; records of matches you played and who you played with; reports involving you and their descriptions; and the record of your age check and your acceptance of these documents. We keep these for the integrity of other users' data, for safety, and for our legal records. If you want us to go further than this, write to socialdesignlab.ph@gmail.com and we will consider your request on its facts.
Your rights
Subject to law, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You can also withdraw any consent you have given, without affecting processing already carried out.
Some of this is built in: you can edit your profile, change your privacy settings, review and revoke your active sessions, block or mute other players, and request account deletion, all from within Roundcade. We do not yet offer a self-service data export, so send export and access requests to socialdesignlab.ph@gmail.com and we will handle them manually. We may need to verify your identity first, and we will respond within the time the applicable law allows.
If you are in the Philippines and you are not satisfied with our response, you may complain to the National Privacy Commission (privacy.gov.ph). If you are in the EEA or the UK, you may complain to your national data protection authority.
Security
We use technical and organisational safeguards appropriate to the service, including protected password storage, encrypted network connections, session and request protections, access controls, rate limits, monitoring, and additional controls for staff access. We review these safeguards as Roundcade changes.
Two-factor authentication is not yet available for player accounts. Please use a strong, unique password and keep control of the email address connected to your account.
Direct messages are encrypted in transit, and at rest to the extent our database provider encrypts stored data, but they are not end-to-end encrypted, and they are not separately encrypted by Roundcade. We can read them where necessary to investigate a report or comply with law. Do not use Roundcade to send sensitive personal information.
No service can promise perfect security. If a breach occurs that is likely to put you at risk, we will notify you and the relevant authority as the law requires, which under the Philippine Data Privacy Act means notifying the National Privacy Commission within 72 hours of knowledge of the breach.
Children
Roundcade is only for people aged 18 and over. We do not knowingly collect personal information from anyone under 18, and we ask for a date of birth at registration in order to enforce this. If you believe someone under 18 has an account, contact socialdesignlab.ph@gmail.com and we will review it and remove the account and its data.
Changes
We may update this policy as the service changes. We will post the revised version here with a new effective date. If a change materially affects your rights, we will give you notice in the service and, where the law requires it, ask you to accept the new version before continuing.