← Back to Home

Privacy Policy

Last Updated: August 12, 2026

Introduction

Welcome to Omoggle, operated by Omoggle LLC. This Privacy Policy explains how we handle account, guest-session, gameplay, payment, analytics, moderation, Discord integration, and camera-check information for the Omoggle 1v1 Arena, Lab reports, leaderboard, private rooms, and related community features.

References to "Omoggle," "we," "us," or "our" in this Privacy Policy refer to Omoggle LLC and its authorized agents.

Biometric Data Processing

Omoggle uses MediaPipe WebAssembly for facial landmark tracking and facial analysis. Our approach is designed so the camera challenge and facial analysis run locally on your device rather than serving as a permanent identity record. These on-device statements describe our biometric and camera-verification processing. Separately, our safety systems may sample still video frames on the server for content moderation, as described under “Automated Content Classification” in Section 10:

  • Client-Side Processing: Facial scanning, landmark detection, and biometric analysis run locally on your device. Saved Lab reports are the limited exception described below. This client-side guarantee covers biometric/landmark analysis and the camera-verification gate; it does not cover the server-side safety frame sampling described under “Automated Content Classification” in Section 10.
  • Session Gate Only: The Omoggle camera challenge is used as a short-lived anti-abuse and access gate. It is not a government ID check or durable proof of identity.
  • No Server Storage of Faceprints: We do not store, sell, lease, trade, or otherwise profit from facial meshes, faceprints, or face templates.
  • Ephemeral Processing: Once a match or analysis session ends, the local biometric mapping is immediately discarded from your device's active memory.
  • What We Do Store: Only a boolean "verified" status plus a timestamp (not an image, mesh, or template) is persisted on our servers so that the 24-hour gate works. This record contains no biometric content.
  • Saved Lab Reports: When you save a Lab report, Omoggle may store one private final scan snapshot plus sparse normalized overlay points for that report so paid/Pro users can reopen feature overlays later. We do not store raw video, continuous camera feeds, dense landmark arrays, faceprints, or face templates.
  • Server-Side Identity Verification (when used): If we engage a third-party identity-verification provider (for example Stripe Identity or Persona) to confirm you are 18 or older, that provider may briefly process a government-issued ID image and a selfie on its own servers to perform the comparison. Omoggle stores only a verification reference identifier and the binary outcome plus timestamp; we do not retain the ID image, selfie, or any biometric template generated during that comparison. The provider operates as our service provider under a written contract that limits use of your information to performing the verification.

If you are a resident of Illinois, Texas, or Washington, please also see Section 7 ("Biometric Information Privacy Act") below for state-specific disclosures.

Live Video Feeds

The 1v1 Arena connects users globally using live video feeds. It is imperative that our users understand how this media is handled during gameplay:

  • Real-Time Routing: Camera feeds are routed in real-time via secure WebRTC/SFU connections (LiveKit), optimized for low latency. We do not continuously record, store, or replay the live audio/video stream. For safety enforcement, our server-side moderation system may automatically capture a small number of short, downscaled still frames of a participant’s video — for participants reported under our nudity or hate categories, and on a small random sample of matches — and retain them as moderation evidence accessible only to our moderation team, as described in Section 10 (“Trust & Safety, Reporting, and Law-Enforcement Cooperation”) and in the Data Retention table in Section 6. The continuous audio/video stream itself is not recorded.
  • Promotional and Editorial Use: By participating in live matches, you authorize Omoggle to capture and use match-related content, including clips, screenshots, gameplay visuals, audio, usernames, display names, profile images, rankings, and match results, for promotional, editorial, advertising, and platform-marketing purposes on Omoggle properties and Omoggle-operated social media channels, subject to applicable law.
  • Peer-to-Peer Foundation: The connections are optimized for low-latency live interaction and immediately terminate once an arena match concludes.

Where Omoggle elects to create or publish promotional assets from match content, we may retain those assets for as long as reasonably necessary for brand, marketing, archival, legal, or business record purposes, unless a shorter period is required by law.

General Data Collection

To operate Omoggle, calculate your Elo rating, and maintain the Global Leaderboard, we store minimal account-level information including:

  • Authentication descriptors provided during login (managed by Supabase).
  • Guest session identifiers for anonymous play before an account is claimed.
  • Your username and selected display preferences.
  • Match outcomes (win/loss/draw) and your current Elo rating.
  • A short-lived verification session record (session id + boolean outcome + expiry).
  • A random first-party security token stored in an HTTP-only cookie for up to 90 days, plus server-side keyed hashes of limited device/network signals, used only to detect coordinated account abuse and ban evasion. We do not use this token for advertising or tracking across other sites.
  • Payment metadata returned by Stripe (we never see card numbers).
  • Optional Discord link metadata if you connect your Discord account (Discord user id, username, avatar hash) used to sync community roles.
  • Analytics events from Google Analytics 4, Vercel Analytics, and Vercel Speed Insights — these services may receive online identifiers, IP address, user agent, page path, referrer, device/browser information, and event metadata such as button clicks. We do not permit these services to use your face images, biometric-adjacent data, Lab snapshots, or moderation evidence for advertising or model training. Where required, we honor Global Privacy Control (GPC) and privacy-choice signals before loading non-essential analytics.

This non-biometric data is securely stored in our databases to provide you with the persistent ranking and progression features of the Omoggle platform.

Guest Accounts and Claiming Your Rank

Omoggle lets you enter as a guest so you can try the Arena without first creating a permanent account. A guest profile may have a temporary display name, rank, Elo, match history, private room activity, verification status, device/session identifiers, and anti-abuse logs associated with it.

Guest access is intended to be temporary. If you claim your rank with Google or another supported sign-in method, we link the guest profile data that is reasonably available in your current browser session to the claimed account. If you clear browser storage, use a different device, or wait too long, guest profile data may become unavailable and may not be recoverable.

Guest accounts are still subject to this Privacy Policy, the Terms of Service, and our safety systems. We may limit, suspend, or delete guest sessions to prevent abuse, enforce age and safety requirements, or keep the Service reliable.

Data Retention

We keep each category of data only as long as needed for the purpose it was collected. Verification and Arena face imagery are not written to our servers. Saved Lab reports may store one private final scan snapshot for report overlays, as described above. When you submit a moderation report with an attached screenshot, that screenshot is stored in a private bucket and is treated as sensitive personal information available only to our moderation team for review of the specific incident.

Data CategoryWhere It LivesRetention
MediaPipe face landmarks / mesh / template (in-browser)Your device (MediaPipe runs in-browser; the face mesh/template is never stored on our servers). A sparse landmark-coordinate subset is streamed to the match server during a live match for real-time scoring and anti-cheat, and is not retained.Discarded on match/session end (seconds)
Live 1v1 video / audioWebRTC/SFU transport (LiveKit)Continuous stream is not recorded or stored; A/V transport is dropped when the call ends. Exception: short still frames may be sampled automatically for safety — see the “Sampled safety frames (server-side moderation)” row below.
Saved Lab report snapshotPrivate Supabase Storage bucket scoped to your account/reportUntil report/account deletion; removed during account deletion cleanup
Guest session profileSupabase + browser storageUntil claimed, expired, deleted, or no longer needed for operations/safety
Verification status fieldsSupabase profile fields including verified_at, verified_until, and age_acknowledged_atRetained while your account exists; cleared on account deletion.
Moderation report evidence (screenshots)Private moderation-evidence storage bucket and report evidence table (admin-only access)Retained only as long as necessary to investigate abuse, appeals, legal claims, or safety incidents, then deleted or anonymized under a documented schedule. Evidence subject to a legal hold (for example, content reported to NCMEC under 18 U.S.C. §2258A) is preserved for at least one year as required by law and will not be deleted in response to an account-deletion request during that period.
Sampled safety frames (server-side moderation)Private moderation-evidence storage bucket (Supabase) and a moderation detections table (admin-only access)Short downscaled still frames captured automatically for safety review. Frames captured because a participant was reported for nudity or hate, or because a match fell into a small random safety sample, are transmitted to our classification subprocessors (see Section 12) for automated review. A separate set of liveness still frames is captured only for anti-cheat (detecting a frozen or static feed); these anti-cheat frames are stored in the same private bucket for admin review but are not transmitted to any classification subprocessor and are not used for automated content moderation or automated bans. All of these frames are retained only as long as necessary to investigate abuse, appeals, legal claims, or safety incidents — and to support any resulting sanction — after which they are deleted or anonymized under a documented schedule. Frames subject to a legal hold (for example, content reported to NCMEC under 18 U.S.C. §2258A) are preserved as described in the moderation-report-evidence row above.
CyberTipline submissions and chain-of-custody recordsPrivate storage with restricted admin accessPreserved for at least one year per 18 U.S.C. §2258A(h) as amended by the REPORT Act of 2024; longer if law enforcement requests preservation. Storage follows the most recent NIST Cybersecurity Framework guidance.
Identity-verification reference (when third-party verification is used)Provider-side (Stripe Identity / Persona / equivalent); Omoggle stores only a reference id and binary outcomeVerification reference retained while your account exists; provider follows its own retention policy. We do not retain the underlying ID image or selfie.
Account & usernameSupabaseUntil you delete your account
Elo, match history, leaderboardSupabaseUntil account deletion; then anonymized
Discord link (id, username, avatar hash)SupabaseUntil you disconnect Discord or delete your account
Payment metadataStripe + our DB (ids only)Retained while subscription active; up to 7 years after for tax/accounting obligations
Stripe webhook event logSupabaseRetained as part of our payment audit trail; periodically pruned once the events are no longer needed for reconciliation, dispute response, or tax/accounting purposes.
Analytics / rate-limit logsVercel / Redis30 days
First-party anti-abuse device tokenHTTP-only __Host-omoggle-device cookie; keyed signal hashes in SupabaseCookie expires after 90 days. Server-side correlation records are subject to the anti-abuse retention schedule and are deleted when no longer needed.

You may request earlier deletion at any time via the Account settings or by emailing [email protected].

Biometric Information Privacy Act (BIPA / CUBI / HB 1493)

If you reside in Illinois (BIPA, 740 ILCS 14), Texas (CUBI, Bus. & Com. Code §503.001), or Washington (HB 1493, RCW 19.375), the following applies to you:

  • What we process: ephemeral facial landmark coordinates generated in-browser by MediaPipe for the purposes of (a) confirming a live person is present, (b) powering real-time gameplay visuals, and (c) deriving saved Lab report metrics and sparse overlay points.
  • What we do not do: We do not create, collect, capture, purchase, receive through trade, sell, lease, trade, or otherwise profit from a biometric identifier or biometric information as those terms are defined under BIPA. We do not retain faceprints. Separately, our safety and anti-cheat systems may capture, store, and classify still video frames from a live match for content moderation and liveness/anti-cheat purposes (see Section 10 and Section 12); those frames are JPEG images reviewed only to detect prohibited content or confirm a live person is present, and are never used to generate, compare, search, or retain a faceprint, face template, face-geometry scan, or other biometric identifier.
  • Retention schedule: Verification and Arena landmark values are destroyed at the end of the session/match. Saved Lab report snapshots and sparse overlay points are retained only with the saved report and are deleted during account/report deletion.
  • Consent: By clicking through the camera check, you acknowledge you have read this policy and the Terms of Service and provide informed written consent (via electronic signature) to the processing and saved Lab report storage described here.

Your Rights (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:

  • Access the personal data we hold about you.
  • Request correction or deletion of inaccurate or unnecessary data.
  • Object to or restrict processing, including withdrawing consent at any time.
  • Receive your data in a portable, machine-readable format.
  • Lodge a complaint with your local supervisory authority.

Our legal bases for processing are (a) your consent (camera check, marketing emails), (b) performance of a contract (gameplay, leaderboard, subscriptions), and (c) legitimate interests (fraud prevention, rate limiting). Contact [email protected] to exercise any of these rights.

Your Rights (CCPA / CPRA — California)

California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to limit the use of sensitive personal information, and to opt out of the "sale" or "sharing" of personal information as those terms are defined under the CCPA/CPRA. We do not use or disclose sensitive personal information (including biometric data) for purposes other than those permitted by §7027(m) of the CCPA regulations. Our collection and use of sampled video frames is limited to detecting and preventing unlawful or harmful conduct, classifying content for nudity, gore, or hate, and enforcing our Terms (including automated camera or account sanctions) — a permitted business purpose for sensitive personal information that does not trigger the right to limit. We do not use these frames for advertising, cross-context behavioral advertising, profiling, or model training. You will not receive discriminatory treatment for exercising any CCPA right.

Your California Privacy Choices

California residents may exercise their privacy rights through the Your California Privacy Choices link in our footer, by visiting /privacy/choices, or by emailing [email protected]. We recognize Global Privacy Control (GPC) signals as valid requests to opt out of the sale or sharing of personal information. When we receive a GPC signal, we suppress analytics or advertising-relevant tags that are not strictly necessary, record the opt-out for the browser session, and persist it to your account when you are logged in. You may also use the Do Not Sell or Share My Personal Information and Limit the Use of My Sensitive Personal Information controls to opt out of sharing and limit non-essential uses of sensitive personal information.

How to Submit a Verifiable Request

To submit a request to know, delete, correct, port, or limit, email [email protected] from the email address on your Omoggle account, or use the in-product Account > Delete Account flow for deletion. We verify requests by matching the requesting email to the authenticated account on file. We respond within 45 days as permitted by California Civil Code §1798.130(a)(2). You may designate an authorized agent to submit a request on your behalf; we may require the agent to provide proof of authorization and may require you to verify your identity directly.

Categories of Personal Information We Collect, Disclose, and Retain

In the preceding 12 months we have collected the categories described in Section 4 above (identifiers, account credentials managed by Supabase, internet/network activity, geolocation inferred from IP, commercial information related to subscriptions, and limited sensitive personal information consisting of short-lived in-browser facial landmark coordinates, saved Lab snapshot images, and still video frames sampled by our automated safety-classification system). We disclose these categories to the service providers listed in Section 12 (International Transfers and Subprocessors) — including the content-moderation providers (OpenAI and Amazon Web Services / Rekognition) that classify sampled safety frames — under written contracts that limit their use of the information to providing services to Omoggle. We do not sell personal information for monetary consideration. We do share certain online identifiers and activity — such as cookie identifiers, IP address, and browsing activity on Omoggle — with Google for personalized advertising through Google AdSense, which is a "share" for cross-context behavioral advertising as defined under the CCPA/CPRA. We do not share your biometric or camera-check data, saved Lab snapshots, or moderation evidence for advertising. You may opt out of this sharing using the Global Privacy Control signal or the "Do Not Sell or Share My Personal Information" control described above, or through the ad-cookie opt-outs in Section 13 (Advertising and Cookies).

Trust & Safety, Reporting, and Law-Enforcement Cooperation

In-Product Reporting

Users can report another player from the live match interface. Reports may include a screenshot of the reported user's video feed plus a category and description. Report evidence is stored in a private bucket accessible only to the moderation team and is treated as sensitive personal information under the CCPA/CPRA.

Automated Content Classification

To enforce our rules at scale, Omoggle operates an automated, server-side moderation system. It samples short still frames of a participant's live video in limited circumstances — when a participant is reported for nudity or hateful content, on a small random sample of matches (on the order of 0.01%), and, for anti-cheat liveness checks, when a feed appears to be a static image. Sampled frames are stored as moderation evidence (see Section 6) and sent to our content-classification subprocessors (see Section 12) for scoring. Public chat text is screened the same way.

When multiple classifiers agree at high confidence, the system may apply an automated sanction without prior human review: sexually explicit content may result in a temporary account suspension; graphically violent content is handled under the same standard; and detected hateful symbols may result in a camera-broadcast restriction. These categories use the moderation reasons nudity, gore, and racism/hate; nudity and racism/hate are also available as user-report reasons. A rate limit suppresses automated sanctions during unusual spikes and routes those cases to human review instead. Anti-cheat liveness snapshots are used only to detect non-live (static-image) feeds and do not trigger content classification or automated content bans. The conduct these systems enforce is described in our Terms of Service, including Section 7 (Use of Match Content), which grants Omoggle the limited license to process your live match feed for the safety purposes described here. If an automated system or our moderation team applies an enforcement action to your account, you may request review through the appeal process described on the account-restriction page at /banned.

CSAM Detection and NCMEC Reporting

Omoggle is an “electronic communication service” under U.S. federal law. If we obtain actual knowledge of apparent child sexual abuse material (CSAM), child sexual exploitation, child sex trafficking, or enticement of a minor, we are required by 18 U.S.C. §2258A (as amended by the REPORT Act of 2024) to report to the National Center for Missing & Exploited Children (NCMEC) CyberTipline as soon as reasonably possible. We may voluntarily use NCMEC-provided hash lists and industry hash-matching tools (such as PhotoDNA and Thorn Safer) to identify known CSAM at upload paths before any human review. Reports submitted to NCMEC, and the underlying evidence, are preserved for at least one year (or longer if requested by law enforcement) and are not subject to user deletion requests during the preservation period.

Nonconsensual Intimate Imagery — TAKE IT DOWN Act Intake

Under the federal TAKE IT DOWN Act (Pub. L. 119-, May 19 2025), Omoggle provides a clearly disclosed process for victims to request removal of nonconsensual intimate imagery (NCII), including AI-generated deepfakes intended to cause harm. To submit a takedown request, visit /takedown or email [email protected]. Valid requests receive an action within 48 hours of receipt.

Law-Enforcement Requests

We respond to lawful government requests for user information consistent with applicable law. We require valid legal process appropriate to the type of information sought (for example, a subpoena for basic subscriber information, a court order for non-content records, and a warrant for content). Where permitted by law, we will notify affected users before disclosure. Emergency disclosure requests are handled on a case-by-case basis under 18 U.S.C. §2702(b)(8) standards. Send formal legal process to the legal contact in Section 16.

Security and Breach Notification

Omoggle maintains administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity, including encryption in transit, scoped database access controls, rate limiting and signature verification on payment webhooks, and isolated private storage buckets with admin-only access controls for biometric-adjacent and moderation-evidence media (saved Lab snapshots, report screenshots, and sampled safety frames are held under this same access-controlled, admin-only regime). No system is perfectly secure, and we do not guarantee that unauthorized access will never occur.

If we determine that an unauthorized acquisition of unencrypted personal information has occurred, we will provide notice to affected individuals and to the California Attorney General as required by California Civil Code §1798.82, in the form and within the timing required by law. To report a suspected security incident or vulnerability, contact [email protected].

International Transfers and Subprocessors

Omoggle operates globally. Non-biometric data (account info, match metadata, payment metadata, and analytics events) may be processed on servers located outside your country, including the United States. In addition, where our safety systems capture still video frames — including on a small random share of live matches and on matches that are the subject of a nudity or hate report — those frames are transmitted to our content-classification subprocessors (OpenAI and AWS Rekognition) for automated review, which may result in automated enforcement action. Each such subprocessor is engaged under a written agreement that restricts its use of this content to providing the moderation service to Omoggle. Where EU/UK data is transferred, we rely on Standard Contractual Clauses with the subprocessors below.

  • Supabase — authentication, database, storage, and Edge Functions.
  • Stripe — payment processing and subscription billing.
  • Vercel — application hosting, Vercel Analytics, and Vercel Speed Insights.
  • Google — Google Analytics 4 (web measurement) and Google sign-in (authentication).
  • Google AdSense — third-party advertising. Google and its advertising partners may set and read cookies to serve and measure ads, as described in Section 13 (Advertising and Cookies).
  • LiveKit — real-time WebRTC/SFU transport for the live 1v1 Arena.
  • Discord — optional account linking for community role sync.
  • Redis (Upstash) — rate-limit counters and active-user signals.
  • OpenAI — automated content-safety classification of public chat text and of still video frames sampled for safety review (image moderation). Frames and text are processed transiently to return a safety score, are not used by us to train models, and are subject to the limits in Section 4.
  • Amazon Web Services (AWS Rekognition) — automated image content-safety classification of sampled still video frames (detection of hateful symbols and a confirming check on sexual/violent content). Frames are processed transiently to return moderation labels; see Section 4.
  • Email delivery — transactional email is sent via the provider integrated with our authentication stack. We will update this list if we add or replace an email provider.

Each subprocessor is engaged under a written agreement that restricts their use of personal information to providing services to Omoggle.

Advertising and Cookies

Omoggle displays third-party advertising provided by Google AdSense. To serve and measure these ads, Google and its advertising partners use cookies and similar technologies stored on your device.

  • Third-party vendors, including Google, use cookies to serve ads based on your prior visits to Omoggle and other websites.
  • Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to Omoggle and/or other sites on the Internet.
  • You may opt out of personalized advertising by visiting Google Ads Settings. You may also opt out of a third-party vendor's use of cookies for personalized advertising by visiting www.aboutads.info/choices.

As described in Section 9, we recognize Global Privacy Control (GPC) signals and our California privacy controls as requests to opt out of the sale or sharing of personal information, which we apply to advertising-relevant tags that are not strictly necessary. We do not use the camera-check, facial-landmark, Lab snapshot, or moderation-evidence data described elsewhere in this policy for advertising.

Children and Likely-Minor-Audience Posture

Omoggle is an 18+ service. The Arena involves live 1v1 video and is not designed for, marketed to, or directed at children under 18. Account creation, the camera challenge, and entry to the Arena require an explicit 18+ acknowledgment. We do not knowingly collect personal information from anyone under 18, and we do not knowingly process or sell the personal information of consumers under 16 years of age. If we learn that we have collected data from someone under 18, we will delete it promptly.

We have considered the California Age-Appropriate Design Code (AADC) and structured the Service to discourage minor access: the 18+ self-attestation, the live-camera entry gate, and our prohibition on knowingly collecting personal information from anyone under 18. Because Omoggle is an adults-only service, we do not knowingly direct personalized advertising to minors; the third-party advertising described in Section 13 (Advertising and Cookies) is intended only for our verified-adult audience. We continue to monitor whether the Service is likely to be accessed by children and will adjust controls if our analysis changes.

Parents or guardians who believe their child has submitted information to Omoggle should contact [email protected] and we will delete the affected account and associated information.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced via the app or by email. The "Last Updated" date at the top of this page reflects the most recent revision.

Prohibited Uses — Intellectual Property

Omoggle LLC expressly prohibits the use of the Service — including its platform, API endpoints, match infrastructure, video feeds, avatar system, leaderboard data, Lab report engine, MediaPipe integration, and any associated content or output — for purposes that infringe upon the intellectual property rights of any third party. Without limiting the foregoing, the following are strictly prohibited:

  • Unauthorized Reproduction: Scraping, copying, mirroring, or reproducing Omoggle's proprietary content, scoring algorithms, facial-analysis pipeline outputs, leaderboard data, or match replay data without express written permission from Omoggle LLC.
  • Commercial Exploitation: Using any output, data, or content generated by the Service to train competing AI or machine-learning models, to build derivative products, or for any commercial purpose not explicitly authorized in writing by Omoggle LLC.
  • Brand Impersonation: Using the Omoggle name, logos, trade dress, or any confusingly similar mark in a manner that is likely to cause confusion as to the source, sponsorship, affiliation, or endorsement of any product or service.
  • Third-Party IP Violations: Using the Service to upload, transmit, display, or distribute any content that infringes upon the copyright, trademark, trade secret, patent, or other intellectual property rights of any third party.

Enterprise, business, or automated access to the Service for any of the above purposes is prohibited without a separate written agreement with Omoggle LLC. Violations may result in immediate account termination, IP-level blocking, and/or legal action.

Contact Us

Questions, concerns, or requests regarding this Privacy Policy or our data handling practices can be sent to [email protected]. We respond to verifiable requests within 30 days (or 45 days for CCPA requests, as permitted by statute).

© 2026 Omoggle LLC. All rights reserved. Terms of Service · Player Rules · Your California Privacy Choices · Parental Controls · Report NCII
Privacy Policy | Omoggle