PRIVACY POLICY
Use only what the session and research workflow need.
Effective 20 August 2026 · This policy covers the Playtest Live website, first-party session rooms, community PUGs and managed research.
1. Scope and approach
Playtest Live is an Australian sole-trader business operating under ABN 95 235 115 495. We minimise collection, keep the website as the system of record and do not sell personal information. Community play and managed paid studies remain separate.
2. Information we may collect
Account and profile information can include name, email, display name, role, availability, game experience, selected profile facts, optional Steam identity and browser or rig telemetry you explicitly choose to submit. We store a provider identifier and display label for a connected Steam account, but not Steam access or refresh tokens.
Private session records can include role, place type, team assignment, readiness, check-in, completion, consent version and timestamp, evidence provenance, support messages, private safety reports, participant awards and payment-state records. Public PUG discovery excludes room credentials, participant contact details, private reports, exact private telemetry and hidden or demonstration sessions.
When you use a browser room, the media service processes a room-scoped pseudonymous identity and the audio, video, screen or data tracks you choose to send. The application records room lifecycle and access events, not the media content. Recording is off by default.
3. Why we use it
We use information to authenticate accounts, coordinate rosters and readiness, issue time-limited room access, deliver browser voice and video, resolve reports and support requests, maintain security, create provenance-labelled participation history, operate studies and produce evidence-linked decision records. Profile discovery and browser telemetry each require their own visible choice.
4. Optional website behaviour analytics
On a small allow-list of public marketing and guide pages, you may choose to share anonymous page views, clicks, scrolling and a replay of the page layout with PostHog. We use this only to find confusing navigation, broken interactions and content people skip. The analytics library is not loaded before you allow it.
Account, sign-in, signup, support, brief, payment, community, PUG, private-build, dashboard and session-room routes are never eligible for behaviour recording. Forms are blocked, input values are masked, network bodies and headers are not captured, query strings are removed and we do not send an account ID, email or display name. A browser Global Privacy Control or Do Not Track signal keeps analytics off.
You can change the choice at any time with the Privacy choices control. Turning it off stops recording and disables PostHog persistence in that browser. For private owner monitoring, we may mirror an event label and the allow-listed public page path to a restricted internal activity channel. Separately, a form submission may send a private operational notice containing only its safe action route; it contains no page URL, account or device identity, IP address, query string, input value, button text, selector, form data or replay content. PostHog Cloud's EU service processes opted-in analytics outside Australia under its service terms; recordings follow the retention configured for our PostHog project and may be deleted earlier when no longer needed.
5. Disclosure and overseas processing
We disclose information only as needed to operate the service: to Steam when you choose its identity flow; to infrastructure, hosting, email, security and payment service providers where configured; when you direct us to; or where required by law. Providers may process information outside Australia. We do not sell personal information or disclose it for another party's independent marketing.
The realtime media node receives pseudonymous room identities rather than Playtest Live user IDs. Browser media is end-to-end encrypted for room participants. Operational metadata needed to route and secure the call is still processed by the media infrastructure.
6. Storage, retention and security
We use access controls, encryption in transit, browser media encryption and restricted operational access. Login sessions are expiring and revocable. Passwords, recovery codes, authenticator secrets and raw session credentials are not written to activity records.
Room credentials expire quickly and are bound to one room and role. Derived room names, participant pseudonyms and browser encryption keys are not displayed in operator history. Room lifecycle events are retained as a recorded history; chat and media content are not added to it.
Community participation records have a 24-month retention term after completion unless deletion is requested earlier. The retention process removes expired access material, anonymises participant and organiser identity, removes identifying evidence references and deletes resolved report content while retaining non-identifying audit facts. Open safety, dispute, payment and documented legal-hold records may be retained longer where required.
7. Your choices, access and complaints
You may use email and password, choose whether to connect Steam, withdraw browser telemetry consent, delete captured telemetry values and separately withdraw studio-discovery consent for community evidence. You can decline opportunities, leave eligible PUGs and control microphone, camera and screen sharing in every room.
A signed-in participant or research-team owner can use the privacy centre to download a no-store copy of account-linked product data or submit a tracked correction or deletion request. A deletion request immediately withdraws optional player matching and current evidence eligibility while safety, dispute, payment and immutable-record obligations are reviewed.
For another access, correction or deletion request, or a privacy complaint, use private support. We will verify identity and respond through the authenticated support thread or a safe contact channel. Never send account credentials or sensitive personal information in a support message.
8. Updates
We will post changes here with a new effective date. Where required, material changes will be notified through a reasonable available channel before taking effect.
This policy is published for transparency and does not replace the privacy, payment, employment, insurance and commercial review required for a paid launch.
Playtest Live