LiberPrompt Privacy Policy — INDUSTRY MILLENNIUM 2001
Effective Date: July 8, 2026
Last Updated: July 8, 2026
LiberPrompt ("LiberPrompt," "we," "us," or "our") respects your privacy. This Privacy Policy explains what we collect, how we use it, with whom we share it, and the choices you have when you use our websites, games, applications, and other online services that link to this Policy, including the online game INDUSTRY MILLENNIUM 2001 (the "Services").
By using the Services, you agree to this Privacy Policy and our Terms of Service.
1) Information We Collect
We collect Personal Information (information that identifies or can reasonably be linked to you) and Non-Personal Information (which does not identify you).
A. Information you provide to us
- Account & profile details (such as your email address, display name, and basic profile information received from Google when you sign in). Sign-in to the Services is provided through Google: we do not collect or store account passwords, and authentication is handled by Google.
- User-generated content (UGC) (such as the free-text plans ("Orders") you submit, city and entity names, chat messages, and other gameplay content).
- Support requests (such as messages you send to our support email, including billing inquiries).
B. Information collected automatically
- Usage and device data (such as IP address, session timestamps, and logs needed to operate, secure, and rate-limit the Services).
- Gameplay telemetry (such as in-game actions, Orders submitted, scores, in-game currency balances, world/matchmaking events, settlement outcomes, and progression events).
- Local storage (such as your session token for authentication and preferences such as language and theme).
- Security signals (such as signals used for fraud, abuse, and scoring-manipulation detection, including cryptographic hashes of top-scoring Orders — see Section 7).
C. Information from partners
- Payments and subscriptions: checkout details (such as your name, billing address, and payment details) are collected and processed by Creem, which acts as merchant of record and seller of record for purchases, under its own terms and privacy policy. We receive limited billing metadata (such as transaction IDs, amounts paid, subscription status, and what was granted), not full card details.
- AI inference providers (such as processing metadata about the evaluation of your Orders, including usage and cost metrics metered under an API key provisioned for your account).
- Sign-in providers (such as Google, if you choose Google sign-in).
2) How We Use Information
We use information to:
- Provide and operate the Services (such as accounts, matchmaking into worlds, gameplay, AI evaluation of Orders, settlement, rankings, and in-game newspapers).
- Maintain safety and integrity (such as fraud and abuse prevention, scoring-manipulation detection, rate limiting, and incident response).
- Process payments and subscriptions (such as billing, granting Tokens, and account status).
- Support you (such as responding to requests and resolving billing errors).
- Improve the Services (such as analyzing gameplay and AI evaluation performance).
- Comply with law and enforce our Terms (such as content moderation and handling legal requests).
Where required (such as in the EU/UK), our legal bases include performance of a contract, legitimate interests (such as security and improvement), consent (where applicable), and legal obligations.
We do not sell your Personal Information, and we do not use it for third-party advertising.
3) How We Share Information
We share information only with service providers and partners that help us operate, secure, and improve the Services, such as:
- Cloud hosting and databases (such as Amazon Web Services (AWS) for hosting, databases, and storage).
- AI inference providers (such as OpenRouter and its underlying model providers, which process your Orders to produce evaluations, scores, and derived in-game content).
- Payments and subscriptions (Creem, which processes purchases as merchant of record — for checkout and billing data, Creem acts as an independent controller/seller under its own privacy policy).
- Sign-in providers (such as Google, if you choose Google sign-in).
These companies are contractually required to use Personal Information only to provide services to us (or are bound by their own applicable terms) and to protect it.
We may also share information:
- To comply with law or lawful requests (such as responding to subpoenas or court orders).
- To enforce our Terms and policies (such as investigating violations).
- To protect the rights, property, or safety of users, the public, or LiberPrompt.
- In a corporate transaction (such as a merger, acquisition, or sale of assets), where information may be transferred as part of the deal subject to this Policy.
In-game, your display name, city names, in-game actions, scores, rankings, and excerpts of your Orders (such as in in-game newspapers and logs) are visible to other players by design.
We do not sell Personal Information, and we do not "share" Personal Information for cross-context behavioral advertising as those terms are defined by applicable U.S. state laws. If our practices change, we will update this Policy and provide required notices and opt-outs before such changes take effect.
4) Cookies & Similar Technologies
We use browser local storage such as:
- Essential/session storage (such as your session token for login and account security).
- Preferences (such as to remember your language and theme settings).
We do not use third-party advertising or analytics cookies. You can control local storage through your browser settings; some features (such as staying logged in) may not function without it. Where required by law (such as in the EU/UK), we will display a consent banner before setting any non-essential cookies or storage, if any are introduced in the future.
5) User-Generated Content (UGC) & Public Areas
UGC you submit (such as Orders, city names, and chat messages) may be visible to others in-game or on the Services — including through rankings, in-game newspapers, and logs, which are public by design. Do not include personal or sensitive information in UGC. We may moderate or remove UGC that violates our Terms or law. As explained in our Terms, you grant LiberPrompt a broad license to use UGC (including derived content such as newspaper articles) to operate and improve the Services and for other purposes described in the Terms.
6) AI Features
Gameplay in the Services is built on AI-powered evaluation: the free-text Orders you submit are transmitted to third-party AI inference providers (such as OpenRouter and the model providers accessible through it) to be scored, and excerpts of your Orders may appear in derived content such as the in-game newspaper. When you use these features:
- Your inputs (Orders) and the generated outputs (evaluations, scores, articles) may be processed by AI inference providers to produce content and to measure usage.
- Per-account AI usage may be metered under an API key provisioned for your account; such keys are stored encrypted (see Section 9).
- Providers and models may change over time.
- We use contractual and technical measures (such as encryption in transit and access controls) to protect this data and limit its use to providing services to LiberPrompt.
Please avoid including personal or sensitive information in your Orders. AI evaluations are game mechanics only, produce no factual claims, and may be imperfect. We do not use AI for automated decisions that produce legal or similarly significant effects about you.
7) Evaluation Integrity & Plan Hashes
To detect scoring abuse (such as reuse or plagiarism of high-scoring Orders) while protecting your privacy:
- What is stored: cryptographic hashes of top-scoring Orders — not the text of the Orders themselves — retained for up to 100 days.
- Purpose: detecting reused, plagiarized, or manipulative submissions; enforcing fair play; and protecting the integrity of the evaluation system.
- Access: limited to authorized personnel for integrity, abuse-prevention, and support purposes.
- Retention: perfect-plan hashes expire automatically after 100 days.
8) Data Retention
We retain information for as long as reasonably necessary to provide the Services and fulfill the purposes described in this Policy, such as:
- Accounts & profile: retained while your account exists and until you request deletion (subject to legal obligations).
- Gameplay logs & in-game history: pruned on rolling windows (such as Order history and in-game newspapers keeping recent entries only).
- Plan hashes: retained for up to 100 days (see Section 7).
- AI usage metering: retained as needed for billing, quota enforcement, and abuse prevention.
- Payments: certain records retained as required by tax and accounting law.
If you request account deletion (Section 15), we will delete or de-identify your Personal Information within 30 days, except where retention is required by law. Excerpts of your Orders and other content already incorporated into public in-game content (such as in-game newspaper articles, logs, and historical records) may persist in de-identified form, no longer associated with your identity. Backup copies may persist for a limited time. We may retain information as needed to comply with law, resolve disputes, and enforce agreements.
9) Security
We implement reasonable administrative, technical, and physical safeguards, such as: authentication delegated to Google (we do not store account passwords), per-account API keys stored encrypted, HTTPS/TLS for transport where configured, access controls, input validation, and rate limiting. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Because your account is accessed through your Google account, we recommend securing your Google account (for example, by enabling two-factor authentication).
In the event of a security incident affecting your Personal Information, we will notify affected users and the relevant authorities without undue delay, in accordance with applicable data-breach notification laws.
10) Your Choices & Rights
A. Communications
You can opt out of non-transactional emails via unsubscribe links or by contacting us. We may still send important service or transactional messages (such as billing confirmations and material policy changes).
B. Access, Correction, Deletion
You may access or update certain information in your account settings. You may request access to, correction of, or deletion of your account and associated data by contacting us (Section 15). We will honor requests as required by law and subject to verification and exceptions (such as security, fraud prevention, and legal obligations), and we will not discriminate against you for exercising your rights.
C. Global Privacy Control (GPC)
Where required by law (such as California/Colorado), we honor the Global Privacy Control signal as an opt-out of sale/sharing where applicable. (As stated above, we do not sell or share Personal Information for cross-context behavioral advertising.) Some browsers also offer a separate "Do Not Track" (DNT) setting; because no uniform industry standard for responding to DNT signals has been adopted, we do not respond to DNT signals at this time.
D. U.S. State Privacy Rights (such as CA, CO, CT, VA, UT)
Depending on your state of residence, you may have rights such as:
- Access your Personal Information.
- Correct inaccuracies.
- Delete Personal Information.
- Obtain a portable copy of Personal Information.
- Opt out of targeted advertising, sale, or profiling (where applicable).
To exercise rights, contact us (Section 15). We will verify your identity and respond within the timeframes required by applicable law (typically 45 days for U.S. state law requests and one month for GDPR requests, with extensions where permitted). If we deny your request, you may appeal by replying to our decision email with "Appeal" in the subject; we will respond to your appeal within the timeframe required by applicable law and inform you of our final decision, including how to contact your state Attorney General or supervisory authority if you remain unsatisfied.
E. EU/EEA/UK Rights
If you are in the EU/EEA/UK, you may have rights such as: access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent where processing is based on consent. You may lodge a complaint with your local supervisory authority.
11) International Data Transfers
We and our providers (such as AWS, OpenRouter and its model providers, Creem, and Google) may process information in the United States, the European Union, and other countries that may have data-protection laws different from your country. Where required, we use appropriate safeguards for cross-border transfers, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Agreement, as applicable. You may request a copy of the relevant safeguards by contacting us (Section 15).
12) Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect Personal Information from children under 13. Account registration requires an affirmative confirmation that the user is at least 13 years old (or, if higher, the age of digital consent in the user's jurisdiction), and we do not offer a parental-consent registration path: users below the applicable age may not use the Services even with parental permission. We do not proactively monitor chat messages or other user content for age disclosures; however, if we obtain actual knowledge that an account holder is below the applicable age — for example, through a user report, a support inquiry, or a statement brought to our attention — we will suspend or terminate the account and delete the associated Personal Information. We do not sell or "share" (as defined under applicable state privacy laws) the Personal Information of users we know to be under 16 years of age, and purchases are restricted to users 18 years of age or older as described in our Terms of Service. If you believe a child below the applicable age has provided us Personal Information, contact us (Section 15).
13) Anti-Scraping & Security Notice
For your protection and ours, we prohibit — and may detect and prevent — scraping, data mining, automated harvesting, reverse engineering, automated submission of Orders, or circumvention of access controls, scoring mechanisms, or rate limits. Unauthorized access to or extraction of game data, UGC, or databases may violate our Terms and applicable laws.
14) Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will post the updated Policy, adjust the "Effective Date," and announce the changes in the Services or by email before they take effect, and where required, obtain consent. Your continued use after the effective date signifies acceptance of the updated Policy.
15) Contact Us (Controller)
LiberPrompt
Email: [email protected]
We are the controller for your Personal Information in connection with the Services (except where certain vendors act as separate controllers or sellers of record — in particular, Creem is the merchant of record and an independent controller for checkout and billing data it collects). To exercise privacy rights or to request account deletion, contact us and include enough information for us to verify your identity.
16) State Category Disclosures (Summary)
The table below summarizes categories of Personal Information we may collect, typical sources, purposes, and disclosures under U.S. state privacy laws (such as the CPRA). This is a summary; sections above provide additional context.
| Category | Examples | Sources | Purposes | Disclosed to |
|---|---|---|---|---|
| Identifiers | email, IP, display name, account ID | You; device | operate; secure; support | service providers (such as hosting) |
| Customer Records | subscription status, transaction IDs | You; Creem | billing; account; fraud prevention | Creem (merchant of record) |
| Commercial Info | purchases, Token grants, plan tier | You; Creem | billing; accounting | Creem (merchant of record) |
| Internet/Network Activity | logs, timestamps, rate-limit data | Device | operate; debug; security | service providers (such as hosting) |
| Geolocation (coarse) | region inferred from IP | Device | localization; abuse prevention | service providers |
| UGC | Orders, city names, chat, scores | You | operate game; AI evaluation; moderation | other players/public (by design); AI providers (OpenRouter); hosting |
| AI Interaction Data | Orders, evaluation outputs, usage/cost metrics, plan hashes | You; AI systems | gameplay features; integrity; support | service providers (such as AI hosts) |
| Sensitive Data | not required; please avoid submitting | You | N/A | N/A |
We do not sell Personal Information and do not "share" it for cross-context behavioral advertising as defined by applicable U.S. state laws.