01The short version
- We keep what the game needs to run: your account, your room and animals, and what you post.
- No ads, no ad trackers, no tracking cookies, and we never sell your data.
- Everyone is counted anonymously (plain daily totals with no IDs). Detailed usage stats are off unless you turn them on.
- Nothing loads from YouTube unless you switch on a Wall TV and say yes.
- Download your data, or delete your account, any time from Settings › Privacy.
02Who we are
Lock and Lay is run by Duncan IT Services LLC ("we", "us"), with help from a small team of volunteer moderators. Duncan IT Services LLC is the controller of the personal data described here. This policy covers the game at lockandlay.com and mobile.lockandlay.com, and the Lock and Lay Discord server. Questions go to support@lockandlay.com.
03What we collect
When you make an account
- Account. Your breeder name and, if you sign in with a password, your sign-in name and a salted scrypt hash of the password (never the password itself). The sign-in name is separate from your breeder name and is used only for signing in. You can sign in with a password, Google and Discord on the same account, and add or remove them in Settings › Account. We also record that you confirmed you are 13 or older and agreed to the Terms (for Google and Discord sign-ups, by signing in from the sign-in screen, which says so), and which version of this policy you last saw.
- Recovery email (optional, password accounts). If you add one in Settings › Account, we keep the address, whether and when you confirmed it, and, while a link is out, a scrambled copy of the one-time link we emailed (a confirm link lasts 24 hours, a password reset link 30 minutes). We use it only to confirm it's yours, to send a password reset link when you ask for one from the sign-in screen, and to tell that address if it is replaced or removed: never for news, marketing or anything else, and it is never shown to anyone. Remove it any time in Settings.
- Sign-in with Google or Discord. We ask the provider for your basic profile and email. From that we keep only your account ID (which is how we recognise you), your name and your email address; the rest (such as your picture and language) we discard. Your breeder name starts as your first name (Google) or display name (Discord), and it is public; if you don't want that, sign up with a password and a made-up name instead. We keep the email address with your account, for each Google or Discord account you link, until you remove that sign-in or delete your account. We never see your Google or Discord password, contacts or servers.
When you play
- Gameplay. Your room and its layout and name, animals and their names, money and your cash flow (money in and out by kind, kept 14 days), trades, listings, offers, sales, breeder loans, expo entries, achievements, ribbons, level, daily goals and streak, your Morph Book, your breeding projects (their names, goal genes, founders and milestones), notifications (the latest 50), private notes you add to offers, trades and loans, time played, and when you were last active.
- Wanted ads. A wanted ad you post (the look you want, any sex, size or age you ask for, and the most you will pay) and the money held back for it until it is filled, cancelled or expires. If you leave the game for good, the ad is deleted along with your account. It is in your data download. House stores (the game's own shops) hold game stock only and store nothing about players.
- Hatch and social. Your posts, captions, comments, likes, follows, bio, invites to your room, and the invitations to browse your shop you add to room photos. If you mark a post as taking offers, an offer on it arrives as a direct message. If you delete a post, it's removed for everyone along with its likes and comments.
- Everyone chat and direct messages. What you send, who you've blocked, and any message you report. Everyone chat is public and is also kept in a staff-only moderation log for 30 days. Chat and messages go through a filter that removes links, email addresses and phone numbers, masks swearing and refuses slurs and threats; three refused messages within 15 minutes mute your chat and messages for 15 minutes. Messages aren't end-to-end encrypted: they're stored on our server so they're waiting when you sign in. We don't read them, except a message someone reports, which moderators see along with who sent it and who reported it. You can also report a Hatch post; moderators see the post, its caption and photo, and who reported it.
- Photos and profile picture. Pictures of your room you take with the in-game Camera and choose to keep, and your profile picture: either one of your animals (we keep only how it looks, never its hidden genes) or a square cut from one of your room photos. We keep your newest 40 photos, plus any you've posted or use as your picture. Photos are pictures of the game, so they shouldn't contain anything about you. A photo can be opened by anyone who has its link.
- Wall TV. If you add your own YouTube links, we keep the links and their titles with your account. They only play for you.
- Moderation. If staff ban your account or ask you to change your breeder name, we keep when, which staff member, the reason they gave you and how long it lasts, plus a short log of staff actions. If you lose your password and staff make you a one-time reset link, we keep only a scrambled copy of it until it is used or 30 minutes pass, and the log notes when and which staff member made it. It's deleted with your account.
- Bug reports you send. What you write, plus your breeder name, the game day, the screen you were on, your window size and your browser's identification string (which names your browser, operating system and, on some phones, the device model).
- Which ad brought you. If you arrive through a link from one of our ads (it ends in something like
?c=ig1), the game remembers that short code for up to a week and saves it with your account if you sign up, so we can tell which ads work. It names the ad, not you, and no cookies or third-party trackers are involved; staff can see which code an account came in with. - Your choices. Whether usage stats and game-news email are on (and when you chose), whether your room is open to visitors or paused, whether your net worth is hidden, and whether Everyone chat is hidden.
Automatically
- Anonymous counts, for everyone. See Analytics. Plain numbers with no ID attached.
- Usage stats, only if you turn them on. See Analytics.
- Security data. To stop password guessing, spam sign-ups and connection floods, the server keeps IP addresses in memory while you are connected and for up to an hour after. They aren't written to disk or logs, with one exception: when a connection trips an abuse limit (too many sign-in failures or new accounts, a message or request flood, too many connections, or heavy bandwidth use), the server log records the IP address with what happened and, if signed in, the player ID, so we can block repeat offenders. Normal play never logs your IP address. Sign-in sessions record when they started and were last used. We also note when you last sent a report, bug report or photo, to rate-limit them.
We don't ask for your real name, address, phone number, date of birth, location, contacts or photos. The only exception is the first name or display name Google or Discord gives us if you sign in with them (see above).
If you're an advertiser
Companies that sponsor Lock and Lay can have an advertiser account. We keep the company name, a contact email, the password (only as a scrambled hash we can't read back) and when the account last signed in. We make the account and send you a one-time link to choose your password. We keep the account while we work together; ask us at the address below to close and delete it.
04What other players can see
- Your breeder name, profile picture, level, prestige stars, ribbons and the animals that won them, how your current run compares with your last one (days, level, counts, and net worth unless you hide it), achievements, supporter badge (if you have one), bio, the game day you joined, your room's name and size, and your follower and following counts (and whether you follow them).
- Your stats on your profile and the boards: rank, animals, racks, hatched, clutches, sales, likes this week and room visitors, and your net worth unless you hide it in Settings. Your profile also shows your best animals and their genetics.
- Whether you're online now (the dot stays for about a minute and a half after you leave), and a "came in" or "left" line in Everyone chat when you arrive or go.
- Your Hatch posts (including room photos you post), comments and likes, and your lines in Everyone chat.
- Your open wanted ads: what you want, the most you will pay, and your breeder name as the poster, shown to other breeders who could fill them. Who fills an ad is shown to you, and the price they got is in your own cash flow.
- Your listings on the market (with the animals' genetics), your expo entries and results, whether you're in the rat co-op, and public news lines such as "X discovered a gene", "X bought Y from Z for $N", "X won Best in Show" or "X started over".
- Breeding projects: a project you complete shows as a badge on your profile and store card (its name, tier and the date), and reaching a project milestone posts a news line with the project's name. Projects you haven't completed, their goal genes and their animals stay private.
- Your room, but only if you open it or invite someone. Visitors see your animals as they look (unproven hets stay hidden there), and you see who is visiting.
- If you block someone, they can tell they're blocked when they try to message you.
Direct messages are only seen by you and the other breeder (and moderators, if one of you reports a message). Your email address is never shown to anyone.
Visible to anyone, without an account: the front page shows the top rooms (breeder name, animal and hatch counts, prestige, and net worth unless hidden), recent hatches with the breeder's name, who discovered each gene, and how many breeders are online. Our Discord game channels show the same public news lines.
05Why, and our legal basis
- To run the game you signed up for (performance of a contract): your account, saving progress, the shared market, Hatch, chat, messages, notifications, and fixing bugs you report.
- Legitimate interests: keeping the game secure and fair (rate limits, logging the IP address behind abuse, the chat filter, anti-cheat, moderating reports), anonymous daily counts, error reports to Sentry so we can fix what breaks, staff announcements, and posting public game news to our Discord. You can object to any of this; see Your rights.
- Consent: usage stats, game-news email, and loading YouTube for the Wall TV. Each is off until you turn it on, and you can turn it off any time in Settings › Privacy. Turning one off stops new collection straight away.
- Legal obligations: keeping payment and tax records if you buy a supporter membership or Gems, and answering lawful requests.
We don't make automated decisions about you that have legal or similarly significant effects, and we don't build advertising profiles. The chat filter decides whether a message is posted, and mutes chat for 15 minutes after three refused messages in a row; that's the only automatic action it takes.
06Cookies and browser storage
Lock and Lay sets no tracking or advertising cookies. The only cookie is a short-lived one while you sign in with Google or Discord (below). The game keeps a few small things in your browser's local storage (and one in session storage, which clears when you close the tab) so it works and remembers your settings. None of it is used for advertising or to follow you around the web, and none of it is read by anyone but us: our own pages read local storage, and our server reads the sign-in cookie only to finish your sign-in. Because these are needed for the service you asked for or only remember your own choices, we don't need to ask before storing them, but here is the full list:
| What | Stored as | Why | How long |
|---|---|---|---|
| Sign-in | lockandlay_session, lockandlay_name | Keeps you signed in and fills in your breeder name. | Until you sign out |
| Google or Discord sign-in | lockandlay_oauth_state (session storage only if local storage is blocked) | A random check number and when it was made, so the game only accepts a sign-in that this browser started. | Until the sign-in finishes; it stops counting after 10 minutes and is removed once it has expired |
| Google or Discord sign-in (cookie) | __Host-ll_oauth, a cookie only our server can read (not page scripts) | A random check number, set when you press Continue with Google or Discord, so our server only finishes a sign-in in the browser that started it, even if the browser loses the local storage above on the way back. It doesn't name you or your account. | 10 minutes |
| Settings | lockandlay_theme, _quality, _sound, _buzz, _camera, _cam, _scene, _tips, _notifs, _pauseask, _offerask, _tv_sound, _tv_volume, _tv_fade, _snakemodel | Your theme, graphics, sound, vibration, camera, notification, confirm-before and Wall TV sound choices. | Until you clear them |
| Where you left off | lockandlay_view_*, _collsort, _collfilters, _colldensity, _collfull, _marketfull, _breedtab, _breed_hidelisted, _season, _shopfilter, _shopsort, _shopview, _shopSeen, _hatchsort, _wantsort, _wantall, _designSnap, _designSelect, _tour_*, _coach_* | Remembers sorting, filters, views, the last shop restock you saw, and how far you got in the tour and tips. The tour and tip keys include your player ID so two accounts on one device each keep their own. | Until you clear them |
| Phone recovery | lockandlay_boot | On the phone site, the screen you opened and when, so a screen that crashed the browser doesn't reopen straight away. | About 10 seconds |
| Desktop on a phone | lockandlay_desktop (session storage) | That you chose the desktop version in this tab. | Until you close the tab |
| Hatch | lockandlay_hatchseen, lockandlay_hatchsaved | Which posts are new to you, and posts you saved. Saved posts stay on this device only. | Until you clear them |
| Announcements | lockandlay_ann_seen, lockandlay_ann_hidden | So an announcement you've closed doesn't come back. | Until you clear them |
| Wall TV | lockandlay_tv_ok | That you said yes to loading YouTube. | Until you turn it off |
| Advertiser dashboard | lockandlay_adv, lockandlay_adv_days | Only for advertisers: keeps you signed in to your dashboard, and the date range you picked. | 30 days, or until you sign out |
| Ad link | lockandlay_camp | The ad code from the link you arrived through, until you sign up. | A week (cleared on your next visit after that) |
| This notice | lockandlay_notice | That you've seen the storage notice on the front page. | Until you clear it |
| Staff analytics | ll_an_days, ll_an_theme | The date range and theme a staff member picked on the analytics page. Staff only. | Until cleared |
Fonts and every game file come from our own server, so loading the game doesn't contact any other company. The one exception is the Wall TV: once you turn it on, YouTube may store data in your browser under Google's own policy (see YouTube). Signing out removes the sign-in keys; the rest stay until you clear them. You can clear all of the above at any time in your browser's site settings; you'll just be signed out and your settings will reset.
Do Not Track and Global Privacy Control. We don't sell or share personal data for advertising, and detailed usage stats are off unless you turn them on, so there's nothing further for these signals to switch off.
07Analytics
All analytics run on our own server. We use no third-party analytics service, no tracking pixels, and no cookies for it.
Anonymous counts, for everyone
Daily totals such as how many players were active and at what hour, sign-ups, sales and money flows in the game, which kind of device, operating system and browser people play on, which website a visit to our front page came from (just the site's name, like "instagram.com"), how long connections last, and how often the game hits an error (the error message and where in our code, nothing about you). These are plain numbers with no ID attached, so they don't identify anyone, and we keep them.
Usage stats, only if you turn them on
Which screens you open, the in-game actions you take, your device type, screen size, language, the site that sent you, how long you play, and errors in your browser. They're stored under a random ID made from a secret key, never with your name, email or IP address, and deleted after 90 days. You're asked once when you start playing, and you can change your answer any time in Settings › Privacy.
Play time
For everyone, the game counts the minutes you actually play: the game is open in a visible tab and you've done something in the last five minutes. Your total is kept with your account like your other game stats (it's in your data download), and the daily totals above include it as plain numbers.
Sponsor links
Links to a sponsor's website go through lockandlay.com/go/… so we can tell the sponsor how many people followed them. Each click is added to a plain daily count for that link: no cookie, no IP address and nothing else that could identify you is kept. Once you reach the sponsor's site, its own privacy policy applies.
Who can see it
Only the operator and one designated staff member can open the analytics dashboard. It shows totals and trends; a live list of who is online right now (desktop or phone, active or idle, since when, and whose room they're in); and a staff-only list of accounts with their game stats (breeder name, level, animals, money, net worth even if hidden, play time, posts, follows, trades, visits, when they joined and were last seen, how they sign in, the ad code they came in with, whether usage stats are on, and whether their room is paused or open). It also shows the sales ledger (who sold what to whom, for how much), the most valuable animals and their owners, bug reports, the Everyone chat log (30 days) and the messages, posts and breeders players have reported. It never shows emails, passwords, IP addresses, direct messages that nobody reported, or the pseudonymous usage-stats IDs.
Advertisers who sponsor the game can sign in to a dashboard that shows the site's daily totals (players per day, week and month, sessions, hours played, sign-ups and front-page visits) and how many times their own links were followed. It never shows anything about a single player.
08Who we share it with
- Amazon Web Services hosts the game server in the United States. AWS processes data only on our instructions. AWS's email service (Amazon SES) also delivers the account emails: the link to confirm a recovery email, password reset links, and a notice to the old address when a recovery email is replaced or removed. For those, AWS handles your email address and the message.
- Google or Discord, only if you choose to sign in with them. They act under their own privacy policies.
- Discord, for our community server. Bug reports you send from the game are posted to the #bug-reports forum, which members of our Discord server can read: what you wrote, your breeder name, the game day, the screen, your window size and your browser's identification string. Reported messages, posts and breeders (with the reported text or photo link, or the breeder's name, bio and picture link, plus who it is about and who reported it) go only to a staff-only channel. Public game news lines (including new breeders joining, big sales and discoveries) are posted to game channels. Staff can post announcements into the game from a staff channel; the game stores the staff member's Discord display name with the announcement, and sends nothing about players to Discord. If you join the server, Discord's own privacy policy covers your account there.
- YouTube (Google), only if you turn on a Wall TV in a room. The first time, the game asks before anything loads. After you say yes, clicking a TV loads a video from YouTube's privacy-enhanced player (youtube-nocookie.com). Google then receives your IP address, browser details and the page it's embedded on, and may store data in your browser, under Google's privacy policy. We don't send Google your name, account or anything about your game. When you add your own link, our server asks YouTube for the video's title and sends nothing about you. If you never turn a TV on, nothing is loaded from YouTube. You can switch this off any time in Settings › Privacy ("Wall TV can load YouTube"), which also turns off a TV that's playing.
- Sentry (Functional Software, Inc., United States), for error monitoring. When the game hits an error, on our server or in your browser, a report goes to Sentry so we can find and fix it: the error message and where in our code it happened, the game version, the game day, your browser and operating system, and the page's address with anything after a
?or#removed. If it happened during something you did, the report also says which kind of action it was (such as buying a rack) and carries a random ID made from your account with a secret key, so we can tell one player hitting an error ten times from ten players hitting it once; Sentry can't turn that ID back into your account, and it isn't the same ID as your usage stats. Before a report leaves, we remove IP addresses, emails, names, sign-in keys, cookies, and chat and message text. Reports from your browser go to our server first, which checks them again and passes them on, so your browser never contacts Sentry. Sentry keeps reports for up to 90 days. - GitHub, where we track bugs and ideas, in a private repository only our team can see. Every post in our Discord #bug-reports and #suggestions forums is copied there automatically: its title, what you wrote, any images, your Discord display name (not your Discord account ID) and a link to the post, plus anything you add to your post later. Bug reports you send from inside the game are copied there automatically too: what you wrote, your breeder name, whether you were on a phone or a computer, the game day, the screen, your window size and a short device line such as “iPhone · iOS 18.7 · Safari 26.6”. Your browser's full identification string is never copied to GitHub.
- Stripe (Stripe, Inc., United States), our payment processor, only if you buy a supporter membership or Gems (see below).
- If the law requires it, we may disclose data to authorities. If the game is ever handed over to someone else, your data would go with it under this policy, and we'd tell you first.
We never sell or rent personal data, and we don't share it for advertising.
09Supporter membership and Gems
You can support the game with an optional supporter membership ($5 a month, a rosette by your name and supporter decor), and you can buy Gems, a cosmetic currency. Both are paid through Stripe:
- You give your card details to Stripe, in Stripe's own checkout, not to us; we never see or store card numbers. Stripe collects your billing address and email for the payment and the receipt, under Stripe's privacy policy.
- For the membership we keep: that your account is a supporter, when it started and when it renews or ends, the amount, and Stripe's references for your customer record and subscription.
- We keep payment records for as long as tax and accounting law requires (usually up to 7 years), even if you delete your account. Everything else about the membership is deleted with your account.
- Other players see only the badge, never payment details.
- If you gift a membership to another breeder, we keep who gave it, who received it, how long and when, and everyone in the game is told who gifted it. The payment record is kept like any other.
- If you redeem a free supporter pass, we keep which code you used and when, so each account can use one. Our staff can see that your account redeemed it. This is deleted with your account.
Gems
Gems buy cosmetic items only: never cash, animals, speed or odds. For Gems we keep, in a separate ledger on our server: your balance, every change to it (packs bought, the weekly supporter Gems, what you spent them on, refunds, chargebacks and staff adjustments, each with the date), the items you unlocked and which you have on, your 30-day spending limit, and for each pack you buy, the pack, the amount, and Stripe's references for the checkout and the payment. Your breeder name, email and card are never in the ledger.
- Where you are: Gems are only sold in some countries for now. When you sign in, the game looks up which country your IP address is in, on our own server with a local database (nothing is sent anywhere), to grey out packs where they aren't sold yet. The country is used for that check only and never saved. The billing country on the Stripe checkout, and the country your card was issued in (which Stripe tells us for the payment; we don't keep it), decide in the end: a payment from a country where Gems aren't sold is refunded automatically and noted in your ledger. To stop stolen cards being tried out, the server also counts in memory how many Gem checkouts each IP address opens in an hour; that count is never saved.
- Refunds and chargebacks take back the Gems they paid for, and if those Gems were already spent, the newest items bought with them.
- Your whole ledger is in your data download. Deleting your account deletes your balance, your items and every ledger entry except the records of real payments (packs, the supporter Gems that come with a paid membership, refunds and chargebacks), which we keep for tax and accounting under a scrambled code instead of your account. That code can't be turned back into your account by us, but the kept records still carry Stripe's payment references, so they are pseudonymous, not anonymous.
- Other players see the cosmetics you wear, never your balance or what you paid.
10International transfers
The server is in the United States. If you play from the EEA, UK or Switzerland, your data is transferred there. We rely on our providers' safeguards for these transfers: Standard Contractual Clauses, and the EU-US Data Privacy Framework where the provider takes part.
11How long we keep it
| Data | Kept |
|---|---|
| Account and gameplay | Until you delete your account. We may also delete accounts that haven't been used for 24 months. |
| Your email (Google and Discord sign-ins) | With your account, for each Google or Discord account linked to it, until you remove that sign-in or delete your account. We don't send game news by email yet; if we start, it will only go to players who turned it on. |
| Recovery email | Until you remove it or delete your account. A confirm link expires after 24 hours and a password reset link after 30 minutes, or as soon as it is used. |
| Hatch posts and comments | Until you delete them or your account. The feed keeps the most recent 1,500 posts, plus any you pin to your profile (up to 5). |
| Room photos | Your newest 40, plus any you've posted or use as your profile picture. Deleting a photo post deletes its photo. All of them go when you delete your account. |
| Everyone chat | Shown in the room for ten minutes. Kept in a staff-only moderation log for 30 days, then deleted. |
| Direct messages | The latest 200 in each conversation, until you or the other breeder deletes their account (then the whole conversation goes). |
| Message and post reports | The most recent 300 in the game for moderation, with a copy in a staff-only Discord channel. Reports about a player are kept after that player deletes their account, for moderation, with their name replaced by an anonymous tag. |
| Bug reports | The most recent 300 on the server. Posts in the Discord bug forum are removed within 12 months of the issue being resolved. |
| Discord and in-game reports copied to GitHub | Kept with the issue while we work on it; ask us and we'll remove your name from it. |
| Usage stats (opt-in) | 90 days, then deleted automatically. |
| Anonymous daily counts | Kept, as they contain no personal data. |
| Supporter and Gems payment records | As long as tax law requires, usually up to 7 years, even after you delete your account (under a scrambled code, as above). |
| Gems balance, items and spending | Until you delete your account. |
| Server backups | Up to 30 days. |
| Error reports (Sentry) | Up to 90 days at Sentry, then deleted. |
| Server logs | Error and service logs, including the IP address of a connection that tripped an abuse limit: up to 30 days. |
| Security data | IP addresses in memory while you are connected and for up to an hour after; the IP address behind an abuse event, in the server log for up to 30 days. Sign-in sessions until you sign out or after 30 days unused (each account keeps at most five). |
12Your rights
Wherever you live, you can:
- Get a copy of your data (access and portability): Settings › Privacy › Download my data gives you your account and game data as a JSON file, with links to your photos. It also has what other players' records hold about you: the likes you gave, offers you made on their listings, your followers, your expo results, discoveries, animals you hatched that others now own, news lines naming you, and reports made about you (without who made them). A few things aren't in it: your pseudonymous usage stats (if you turned them on) and your Google or Discord account ID. Email us and we'll send those too.
- Delete your account (erasure): Settings › Privacy › Delete my account removes it along with your animals, posts, comments, likes, messages, chat log lines, photos, follows, notifications, sign-in and usage stats. Your account ID is removed from everything we keep, and where our own records name you as part of someone else's game (their sale and purchase records, trade history and log lines, "hatched by" on animals you sold, expo results, discoveries and news lines) you're called "a former breeder" instead. What other players wrote themselves (their captions, comments, chat, bios, and names they gave their animals or stores) stays as they wrote it, even if it mentions you. Lines written before this change didn't record who they named, so they keep the name until they roll off (the news feed after 40 lines, each breeder's log after 80). Reports other players made about you are kept for moderation under an anonymous tag instead of your name. Your breeder name is held for 60 days so nobody can take it straight away; for that we keep only a scrambled code made from it with a secret key, not the name. Posts already made to Discord aren't changed; email us and we'll remove them. Backups roll off within 30 days.
- Delete individual posts from Hatch at any time (a photo post takes its photo with it), and change or remove your profile picture.
- Correct your data: change your bio in the game, or email us for anything else.
- Withdraw consent for usage stats, email or YouTube in Settings › Privacy.
- Object or ask us to restrict processing, for example to keep your name out of Discord news posts. Email us.
We answer requests within one month, and we may ask you to confirm the request comes from the account holder. In the EEA or UK you can also complain to your data protection authority.
US state privacy rights, including California: we don't sell personal information or share it for cross-context behavioural advertising. We don't use sensitive personal information to infer anything about you. We won't treat you differently for exercising your rights.
13Children
Lock and Lay is not meant for children under 13, and we don't knowingly keep data about them. In the EEA and UK, players under 16 (or your country's age of digital consent) shouldn't turn on usage stats without a parent's permission, and anyone under 18 needs a parent or guardian to buy a supporter membership or Gems. If you think a child under 13 has an account, email us and we'll delete it.
14Security
Passwords are stored as salted scrypt hashes. All traffic uses HTTPS. Only the operator can access the server. Sign-in attempts and sign-ups are rate limited, and messages from Discord to the game are cryptographically signed and checked. If a data breach puts you at risk, we'll tell you and the relevant authorities as the law requires. This is a small project, so please don't reuse an important password here.
15Changes
If we change this policy in a way that matters, the game shows you a notice the next time you open it. The version and date at the top always show the current policy.
Version 18 (October 7, 2026): a password account now has a sign-in name of its own, separate from your public breeder name and used only for signing in, and one account can sign in with a password, Google and Discord, each added or removed in Settings › Account; we keep the email of each Google or Discord account you link until you remove it. Version 17 (October 7, 2026): wanted ads (a Wanted tab on the Market where you post the animal you want and the most you will pay, with the money held while the ad is open) and the game's own house stores; both are described above, and your wanted ads are in your data download and deleted with your account. Version 16 (October 7, 2026): password accounts can add an optional recovery email, used only to confirm it and to email a password reset link when you ask; Amazon SES delivers those emails. Version 15 (October 6, 2026): bug reports sent from inside the game are copied automatically to our private GitHub issue tracker, with your breeder name and a short device line, never your browser's full identification string. Version 14 (October 6, 2026): Lock and Lay now sets one short-lived sign-in cookie, only while you sign in with Google or Discord; still no tracking or advertising cookies. Version 13 (October 5, 2026): posts in our Discord #bug-reports and #suggestions forums are copied automatically to our private GitHub issue tracker, with your Discord display name; how long those copies are kept. Version 12 (October 3, 2026): Gems, the cosmetic currency, and what its ledger keeps; Stripe named as the payment processor; the IP country check for where Gems are sold, which is never saved. Version 10 (September 30, 2026): Lock and Lay is run by Duncan IT Services LLC, the controller of your data; questions go to support@lockandlay.com. Version 9 (September 29, 2026): error reports go to Sentry, through our own server, with nothing that names you. Version 8 (September 29, 2026): the IP address behind abuse (floods, repeated failed sign-ins) is logged for 30 days; what other players and visitors can see, spelled out; reported messages and posts go only to a staff channel, and bug reports to our Discord bug forum; Google and Discord sign-ins; what the data download and account deletion cover; the full list of browser storage; server logs. Version 7 (September 28, 2026): the ad code from an ad link can be saved with a new account. Version 6: Everyone chat is kept 30 days in a staff moderation log. Version 5: play time, and a clearer description of what staff can see on the analytics dashboard. Version 4: room photos from the in-game Camera and profile pictures. Version 3: a full list of what's kept in your browser, analytics explained in one place, deleting Hatch posts, staff announcements, the supporter membership, and a clearer "what other players can see". Version 2: the Wall TV and YouTube.
16Contact
Privacy questions and requests: support@lockandlay.com.