Your data, explained clearly.
This policy describes the information Larpit uses to operate profiles, social features, live challenges, safety systems, and Larpit+ subscriptions.
Larpit is currently available only for private development testing. These pages describe the intended beta controls and will be reviewed for each launch country before public availability.
These operational drafts do not replace country-specific legal review.
1. Who this policy covers
This policy applies to the Larpit mobile app, larpit.net, and related services. Larpit is a pre-release service operated under the Larpit brand. The final operator identity, postal address, and launch-region representative details will be published before an external beta.
Private camera-match testing is currently limited to invited adults. Larpit does not knowingly permit children under 13, and it does not yet permit minors to submit live-match evidence for AI processing.
2. Information we collect
- Account and profile: email, authentication provider identifiers, display name, username, avatar, cover image, bio, and verification state.
- Social activity: posts, photos, comments, likes, reposts, saves, follows, views, reports, blocks, and notification state.
- Competition: match participation, prompts, connection events, ready state, result, score receipt, LP, season history, disconnects, and appeals.
- Live media: real-time camera and microphone are transmitted to the matched participant. Audio is not recorded or sent to the visual judge.
- Temporary evidence: selected still frames captured during a challenge for integrity, safety review, and visual judging. Full match video is not recorded for judging.
- Device and security: app version, device/platform signals, App Check attestation, IP-derived security signals, crash information, request identifiers, and abuse-prevention events.
- Purchases: Apple transaction and entitlement identifiers for Larpit+. Larpit does not receive your full payment-card number.
- Support: messages, reports, evidence you choose to send, and actions taken on a case.
3. How we use information
We use information to authenticate users; deliver profiles, feeds, live rooms, rankings, subscriptions, and notifications; calculate competition results; investigate reports; prevent fraud and unsafe conduct; provide support; measure reliability; and meet legal obligations.
Larpit’s intended visual judge may assess observable prompt completion, sequence, composition, and presentation coherence. It must not score or infer attractiveness, body or face, age, race, ethnicity, nationality, sex, gender, health, disability, religion, sexuality, personality, emotion, intelligence, authenticity, wealth, status, popularity, brand value, or ownership.
4. Processors and international transfers
The services used now, or planned for the controlled beta, include Firebase and Google Cloud for authentication, databases, storage, server functions, security, and delivery; LiveKit for real-time audio/video transport; OpenAI for limited image safety screening and policy-bounded visual judging; Apple and Google for sign-in; Apple for in-app purchases; and Cloudflare for domain, edge security, and public web delivery. Only enabled features send data to their relevant provider. These providers may process data in countries other than yours under their applicable terms and safeguards.
When OpenAI judging is enabled, Larpit intends to send selected still frames only, configure Responses requests with storage disabled, and keep audio, usernames, profiles, follower counts, and prior rank out of the request. Depending on the approved OpenAI data-control tier, limited abuse-monitoring data may still be retained by OpenAI for up to 30 days. Larpit will not opt API content into provider training without separate notice and consent.
5. Retention and deletion
- When evidence-based judging is enabled, ordinary match evidence is scheduled for deletion 48 hours after settlement.
- A timely report or appeal can place only the relevant evidence on a restricted hold, normally for no more than seven days. A documented legal or urgent safety hold may last longer.
- Audio and full match video are not recorded for judging.
- Result receipts, hashes, model/rubric versions, and LP ledgers may remain through the season plus 30 days without retaining the images.
- Posts and profile content remain until deleted by you or your account is deleted, subject to narrow legal and safety exceptions.
- After account deletion, Larpit may retain a minimal non-public deletion lock and one-way hashed completion record so old sessions cannot recreate the account and the deletion job can be audited without retaining your email or username.
- Safety reports made by other people and shared completed-match records may be retained in minimized, pseudonymous form for abuse prevention, disputes, legal obligations, and the other participant's history. They no longer resolve to a public Larpit profile.
- Security logs are retained only as long as reasonably needed for abuse prevention, incident response, and legal obligations.
6. Your choices and rights
You can edit profile information, control camera and microphone access, delete posts, block or report users, manage notifications, and request access, correction, export, objection, restriction, or deletion where applicable. Before App Store release, the app will provide recent-sign-in protected data export and account deletion. Deletion covers the account, profile, authored posts and owned media, private social data, and active sessions, subject to the minimized shared safety, competition, audit, and legal records described above.
Deleting a Larpit account does not automatically cancel an Apple subscription. You can manage subscriptions in your Apple ID settings.
7. Security and contact
The intended beta controls include authenticated access, least-privilege service identities, encrypted transport, private evidence storage, bounded upload grants, integrity checks, and audited deletion jobs. No online system is perfectly secure. Public security and privacy email routing is not active yet; invited testers must use the contact channel provided with their invitation. Current contact status is published in the Support center.