Boiling Frog Games

Last Updated: July 13, 2026

Privacy Policy

We are a small game studio, not a data broker, and we intend to stay that way. This policy explains what little we collect, why, and the control you have over it. We have written it to meet strong privacy laws by default, before we are ever large enough to be legally required to, because that is simply how we want to run the place.

Who is responsible for your data

The Service is operated by Boiling Frog Games LLC, an Oregon limited liability company ("we", "us", "our"). For the purposes of data protection law, Boiling Frog Games LLC is the Data Controller, and Peter Stolmar is the person responsible for the protection of personal data.

You can reach us about anything in this policy at privacy@boilingfroggames.com, or through our contact form.

Our privacy-first principles

What we collect

Account data

Your email address, which is required to create an account and to manage a subscription. Optionally, a display name if you choose to provide one. If you set a password, we store only a salted, one-way hash of it, never the password itself. If you sign in with Google instead, we receive the name and email address that account shares with us, nothing else. We record when your account was created, and if you opt into our mailing list, the date you did so. If our neutral age screen applies to your signup, we store only the timestamp that it passed, never your birth date or age.

Transactional email

We use Resend as an email delivery provider for essential messages such as password-reset instructions, billing notices, and direct replies where appropriate. To deliver those messages, Resend processes the recipient email address, message content, and ordinary delivery metadata on our behalf. We do not use Resend for advertising profiles, and we do not enable open or link tracking for these transactional messages. See Resend's privacy policy and Data Processing Addendum.

Wallet and Frogsense

Playing games earns Frogsense cosmetic currency and cosmetic items, tracked against your account (or, for guests, your session). Frogsense is never sold or bought with real money; it is earn-only and has no cash value. For guests and Basic accounts, earned Frogsense and cosmetics are held for a limited time and expire if not claimed. Members keep earned Frogsense and cosmetics in their account while the wallet feature is available. We also track a small amount of earn-rate bookkeeping (such as which day you last earned, and whether the month's member bonus was already granted) purely to enforce fair daily and monthly limits, not to profile you. We store this wallet data to run the feature itself.

Payment data

Payments are processed by Stripe acting as our payment processor. Stripe collects and processes your card details directly. We do not see or store full card numbers. We retain only the limited billing records we need (Stripe's own customer and subscription identifiers, your renewal date, and whether a subscription is set to cancel at period end) to provide the service, handle refunds, and meet our tax and accounting obligations. If you redeem a gift or complimentary code, we store how long that access lasts. See Stripe's privacy terms at stripe.com/privacy.

When you start checkout, Stripe's own code loads directly in your browser and sets cookies and uses similar signals (like your IP address) to help detect and prevent fraud. That happens under Stripe's privacy terms linked above, not ours — we don't receive or store that data ourselves.

Usage and monitoring data

To troubleshoot problems and keep the Service running, we rely on our own server logs — the ordinary records our servers make of requests they receive, such as which pages and games are accessed and general diagnostic data. We use this for ordinary operational purposes: performance optimization, catching bugs, and general maintenance. We do not currently run a separate analytics product; if we add one, it will be first-party and self-hosted, and we will update this policy first. Either way, we do not use this data to build advertising profiles, and we do not share it with advertisers or data brokers.

Technical data

To keep you signed in, we set a single session cookie that identifies your session, not you personally, and that only our own servers read. We may log IP addresses for diagnostics, security, and to prevent abuse, such as in server or hosting infrastructure logs. Today, our application code does not write your IP address into any log or record we query day to day, though it is visible in passing to our hosting infrastructure, the same as it is for any website. If that changes as the platform grows, we intend to keep any IP logging narrow and masked wherever practical. If your browser sends a Global Privacy Control (GPC) signal, we record that preference against your account so it is honored going forward, even on a later visit where the signal isn't resent.

Camera-based controls (specific games)

One of our games, Joustified 3D, offers an optional webcam head-lean control: if you choose to enable it, the face tracking runs entirely on your own device in your browser — no camera image, video, or face data ever leaves your device or is sent to us or anyone else.

Support and contact data

If you email us or use the contact form, we receive what you send us, so we can help you. If we're troubleshooting an issue together, we may ask you to share diagnostic information, such as a HAR file, screenshot, or session details; we only ever look at what you actively choose to send us, and only to work on that issue.

Optional feedback and playtest data

Sometimes, if you have opted in to something like our playtest list (or another list you have chosen to join, and possibly in future our members or occasional guests), we may invite you to share voluntary feedback or diagnostic information that helps us fix and improve a game. This can include things you decide to send us, such as a screenshot, a short screen recording, debug logs, or basic session details. This is always entirely optional and opt-in. We only ever receive what you actively choose to send, we tell you plainly what we are asking for and why, and we will never force a survey on you, interrupt your play, or grey out or pop anything over the screen to collect it. You control exactly what, if anything, you share, and you can leave any such list at any time. If you send a screen recording or screenshot, please share only what is relevant, since we cannot control what else might appear on your screen.

Why we use it, and our legal bases

Where data protection law requires a legal basis (for example, under the GDPR and UK GDPR), we rely on the following:

Who we share it with

We do not sell or rent your personal information. We share it only with the limited service providers that help us run the Service, and only as needed for them to do so. These currently include our payment processor (Stripe), transactional email provider (Resend), and hosting infrastructure. We may also disclose information where required by law, to protect our rights or the safety of others, or in connection with a business transfer. We do not share data with advertisers, ad networks, or data brokers. Cloudflare Turnstile protects our forms from bots and processes your IP address and browser signals solely for that purpose, with no advertising use.

How long we keep it

We keep account data for as long as your account is active, and for a reasonable period afterward to handle billing, tax, and legal needs, after which we delete or anonymize it. Support correspondence is kept only as long as useful to resolve your issue and our records. You can ask us to delete your data at any time (see Your rights).

How we protect it

We host on our own secured infrastructure, encrypt data in transit, and restrict access to the few people who need it. No system is ever perfectly secure, but we take protecting your data seriously and design well past what a studio our size would strictly need. If a data breach affecting your personal information ever occurs, we will notify affected users and any regulators as required by applicable law.

International data transfers

We are based in the United States and process data there. If you access the Service from another country and provide us information, you understand it will be transferred to and processed in the United States. If and when we formally offer the Service in the EU/EEA or UK, we will put appropriate transfer safeguards (such as Standard Contractual Clauses) in place and update this policy accordingly.

Your Privacy Choices

If you have an account on the platform, you can download everything we hold about you, or permanently delete your account, directly from your account page; no support ticket needed. Wherever you are, you can also contact us at privacy@boilingfroggames.com to access, correct, export, or delete your personal data, and we will respond. Depending on where you live, you also have specific rights:

This is an informational privacy choices page, not a cookie banner. We do not use advertising or cross-site tracking cookies, and we do not sell or share personal information as those terms are used in California privacy law. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a privacy preference and record it for your account when you are signed in.

United States, including California (CCPA/CPRA)

You have the right to know what personal information we collect and how we use it, to access and delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell or share your personal information as those terms are defined under California law, and we do not use sensitive personal information for purposes that would trigger a right to limit. We honor Global Privacy Control (GPC) opt-out signals. You may use an authorized agent to make a request.

EU, EEA, and UK (GDPR / UK GDPR)

You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, the right to withdraw consent where processing is based on consent, and the right to lodge a complaint with your local supervisory authority.

Canada (PIPEDA) and Quebec (Law 25)

You may access your personal information and challenge its accuracy, and we handle personal information in line with PIPEDA's principles. For Quebec residents, the person responsible for the protection of personal information is Peter Stolmar, reachable at privacy@boilingfroggames.com.

Children

The Service is intended for a general audience and is not directed to children under 13 (or the equivalent minimum age in your region). We do not knowingly collect personal information from children under that age. If you believe a child has provided us personal information, contact privacy@boilingfroggames.com and we will delete it promptly. Any game we offer that is specifically intended for children will be clearly identified and handled in line with applicable children's privacy law.

Cookies and tracking

We use only the cookies needed to keep you signed in and to operate the Service, plus the server-log monitoring described above. We do not use advertising or cross-site tracking cookies. We honor Global Privacy Control (GPC) signals.

Changes to this policy

We may update this policy from time to time. We will post the new version here with a revised "Last Updated" date, and for material changes we will take reasonable steps to let account holders know. Continued use of the Service after changes take effect means you accept the updated policy.

Contact

Data Controller: Boiling Frog Games LLC (Oregon, USA). Responsible person: Peter Stolmar. Email: privacy@boilingfroggames.com, or use the contact form.

To report claimed copyright infringement, email copyright@boilingfroggames.com — see the copyright infringement reports section of our Terms of Service for what to include.

This policy is governed by the laws of the State of Oregon, USA, except where local data protection law grants you rights that apply regardless.