LiberPrompt Privacy Policy — INDUSTRY MILLENNIUM 2001

Effective Date: July 8, 2026
Last Updated: July 8, 2026

LiberPrompt ("LiberPrompt," "we," "us," or "our") respects your privacy. This Privacy Policy explains what we collect, how we use it, with whom we share it, and the choices you have when you use our websites, games, applications, and other online services that link to this Policy, including the online game INDUSTRY MILLENNIUM 2001 (the "Services").

By using the Services, you agree to this Privacy Policy and our Terms of Service.

1) Information We Collect

We collect Personal Information (information that identifies or can reasonably be linked to you) and Non-Personal Information (which does not identify you).

A. Information you provide to us

B. Information collected automatically

C. Information from partners

Tip: Please avoid including personal or sensitive information in your Orders, city names, chat messages, or other UGC. Orders are processed by third-party AI providers, and excerpts may appear in the in-game newspaper visible to other players.

2) How We Use Information

We use information to:

Where required (such as in the EU/UK), our legal bases include performance of a contract, legitimate interests (such as security and improvement), consent (where applicable), and legal obligations.

We do not sell your Personal Information, and we do not use it for third-party advertising.

3) How We Share Information

We share information only with service providers and partners that help us operate, secure, and improve the Services, such as:

These companies are contractually required to use Personal Information only to provide services to us (or are bound by their own applicable terms) and to protect it.

We may also share information:

In-game, your display name, city names, in-game actions, scores, rankings, and excerpts of your Orders (such as in in-game newspapers and logs) are visible to other players by design.

We do not sell Personal Information, and we do not "share" Personal Information for cross-context behavioral advertising as those terms are defined by applicable U.S. state laws. If our practices change, we will update this Policy and provide required notices and opt-outs before such changes take effect.

4) Cookies & Similar Technologies

We use browser local storage such as:

We do not use third-party advertising or analytics cookies. You can control local storage through your browser settings; some features (such as staying logged in) may not function without it. Where required by law (such as in the EU/UK), we will display a consent banner before setting any non-essential cookies or storage, if any are introduced in the future.

5) User-Generated Content (UGC) & Public Areas

UGC you submit (such as Orders, city names, and chat messages) may be visible to others in-game or on the Services — including through rankings, in-game newspapers, and logs, which are public by design. Do not include personal or sensitive information in UGC. We may moderate or remove UGC that violates our Terms or law. As explained in our Terms, you grant LiberPrompt a broad license to use UGC (including derived content such as newspaper articles) to operate and improve the Services and for other purposes described in the Terms.

6) AI Features

Gameplay in the Services is built on AI-powered evaluation: the free-text Orders you submit are transmitted to third-party AI inference providers (such as OpenRouter and the model providers accessible through it) to be scored, and excerpts of your Orders may appear in derived content such as the in-game newspaper. When you use these features:

Please avoid including personal or sensitive information in your Orders. AI evaluations are game mechanics only, produce no factual claims, and may be imperfect. We do not use AI for automated decisions that produce legal or similarly significant effects about you.

7) Evaluation Integrity & Plan Hashes

To detect scoring abuse (such as reuse or plagiarism of high-scoring Orders) while protecting your privacy:

8) Data Retention

We retain information for as long as reasonably necessary to provide the Services and fulfill the purposes described in this Policy, such as:

If you request account deletion (Section 15), we will delete or de-identify your Personal Information within 30 days, except where retention is required by law. Excerpts of your Orders and other content already incorporated into public in-game content (such as in-game newspaper articles, logs, and historical records) may persist in de-identified form, no longer associated with your identity. Backup copies may persist for a limited time. We may retain information as needed to comply with law, resolve disputes, and enforce agreements.

9) Security

We implement reasonable administrative, technical, and physical safeguards, such as: authentication delegated to Google (we do not store account passwords), per-account API keys stored encrypted, HTTPS/TLS for transport where configured, access controls, input validation, and rate limiting. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Because your account is accessed through your Google account, we recommend securing your Google account (for example, by enabling two-factor authentication).

In the event of a security incident affecting your Personal Information, we will notify affected users and the relevant authorities without undue delay, in accordance with applicable data-breach notification laws.

10) Your Choices & Rights

A. Communications

You can opt out of non-transactional emails via unsubscribe links or by contacting us. We may still send important service or transactional messages (such as billing confirmations and material policy changes).

B. Access, Correction, Deletion

You may access or update certain information in your account settings. You may request access to, correction of, or deletion of your account and associated data by contacting us (Section 15). We will honor requests as required by law and subject to verification and exceptions (such as security, fraud prevention, and legal obligations), and we will not discriminate against you for exercising your rights.

C. Global Privacy Control (GPC)

Where required by law (such as California/Colorado), we honor the Global Privacy Control signal as an opt-out of sale/sharing where applicable. (As stated above, we do not sell or share Personal Information for cross-context behavioral advertising.) Some browsers also offer a separate "Do Not Track" (DNT) setting; because no uniform industry standard for responding to DNT signals has been adopted, we do not respond to DNT signals at this time.

D. U.S. State Privacy Rights (such as CA, CO, CT, VA, UT)

Depending on your state of residence, you may have rights such as:

To exercise rights, contact us (Section 15). We will verify your identity and respond within the timeframes required by applicable law (typically 45 days for U.S. state law requests and one month for GDPR requests, with extensions where permitted). If we deny your request, you may appeal by replying to our decision email with "Appeal" in the subject; we will respond to your appeal within the timeframe required by applicable law and inform you of our final decision, including how to contact your state Attorney General or supervisory authority if you remain unsatisfied.

E. EU/EEA/UK Rights

If you are in the EU/EEA/UK, you may have rights such as: access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent where processing is based on consent. You may lodge a complaint with your local supervisory authority.

11) International Data Transfers

We and our providers (such as AWS, OpenRouter and its model providers, Creem, and Google) may process information in the United States, the European Union, and other countries that may have data-protection laws different from your country. Where required, we use appropriate safeguards for cross-border transfers, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Agreement, as applicable. You may request a copy of the relevant safeguards by contacting us (Section 15).

12) Children's Privacy

The Services are not directed to children under 13, and we do not knowingly collect Personal Information from children under 13. Account registration requires an affirmative confirmation that the user is at least 13 years old (or, if higher, the age of digital consent in the user's jurisdiction), and we do not offer a parental-consent registration path: users below the applicable age may not use the Services even with parental permission. We do not proactively monitor chat messages or other user content for age disclosures; however, if we obtain actual knowledge that an account holder is below the applicable age — for example, through a user report, a support inquiry, or a statement brought to our attention — we will suspend or terminate the account and delete the associated Personal Information. We do not sell or "share" (as defined under applicable state privacy laws) the Personal Information of users we know to be under 16 years of age, and purchases are restricted to users 18 years of age or older as described in our Terms of Service. If you believe a child below the applicable age has provided us Personal Information, contact us (Section 15).

13) Anti-Scraping & Security Notice

For your protection and ours, we prohibit — and may detect and prevent — scraping, data mining, automated harvesting, reverse engineering, automated submission of Orders, or circumvention of access controls, scoring mechanisms, or rate limits. Unauthorized access to or extraction of game data, UGC, or databases may violate our Terms and applicable laws.

14) Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will post the updated Policy, adjust the "Effective Date," and announce the changes in the Services or by email before they take effect, and where required, obtain consent. Your continued use after the effective date signifies acceptance of the updated Policy.

15) Contact Us (Controller)

LiberPrompt
Email: [email protected]

We are the controller for your Personal Information in connection with the Services (except where certain vendors act as separate controllers or sellers of record — in particular, Creem is the merchant of record and an independent controller for checkout and billing data it collects). To exercise privacy rights or to request account deletion, contact us and include enough information for us to verify your identity.

16) State Category Disclosures (Summary)

The table below summarizes categories of Personal Information we may collect, typical sources, purposes, and disclosures under U.S. state privacy laws (such as the CPRA). This is a summary; sections above provide additional context.

CategoryExamplesSourcesPurposesDisclosed to
Identifiersemail, IP, display name, account IDYou; deviceoperate; secure; supportservice providers (such as hosting)
Customer Recordssubscription status, transaction IDsYou; Creembilling; account; fraud preventionCreem (merchant of record)
Commercial Infopurchases, Token grants, plan tierYou; Creembilling; accountingCreem (merchant of record)
Internet/Network Activitylogs, timestamps, rate-limit dataDeviceoperate; debug; securityservice providers (such as hosting)
Geolocation (coarse)region inferred from IPDevicelocalization; abuse preventionservice providers
UGCOrders, city names, chat, scoresYouoperate game; AI evaluation; moderationother players/public (by design); AI providers (OpenRouter); hosting
AI Interaction DataOrders, evaluation outputs, usage/cost metrics, plan hashesYou; AI systemsgameplay features; integrity; supportservice providers (such as AI hosts)
Sensitive Datanot required; please avoid submittingYouN/AN/A

We do not sell Personal Information and do not "share" it for cross-context behavioral advertising as defined by applicable U.S. state laws.