Pre-release status: the production game service is hosted by Render, but verified publisher identity, support-ticket retention and deletion procedures, final legal contact details, and governing-law terms remain incomplete. Those items will be completed before a public ChatGPT submission.
Summary
Turnplay Arena does not require an account and does not sell personal information, show ads, process payments, or use analytics or advertising trackers on this website. The game server processes the minimum data needed to run and resume a match, defend the service, and diagnose reliability.
Data processed by the game server
- Game session data: a random game ID, selected game, board size, player color, difficulty, moves, reset epoch, version, status, and last game-changing activity time. Imported Go setups also contain the transcribed stone coordinates, next turn, and any supplied capture totals.
- ChatGPT widget state: Current v2 writes persist only the active game ID and draft game, difficulty, and side selectors so the same rendered game card can request the game again after a reload. Current v2 writes never persist the board, legal moves, move history, message, reset epoch, or state version. The authoritative game state remains on the Turnplay Arena server. Earlier v1 builds could persist a full validated game snapshot; migration reads that legacy copy only to recover the game ID and safe draft selectors and never renders its cached board. OpenAI processes current pointer and selector state, and may retain an unmigrated legacy copy, as part of the user’s ChatGPT experience.
- Short-lived network abuse data: the direct request address, or an address resolved only through an explicitly trusted proxy, is converted immediately into a process-random HMAC value for a fixed-window rate-limit bucket. The app does not persist the raw address or the HMAC value to its game store or operational logs.
- Operational events: production-safe structured events may contain the route category, request method, status, bounded duration, MCP operation category, tool name, and outcome. They do not include request bodies, game IDs, moves, board history, tokens, authorization headers, or raw network addresses.
Why this data is used
Session data enforces game rules, confirms exactly-once changes, resumes the same board, and preserves settings across a reset. Short-lived network keys limit abusive traffic. Operational events identify availability, latency, and failed tool calls without recording board contents.
Go board images
When a player attaches a Go-board image in ChatGPT, ChatGPT interprets the image. The Turnplay Arena server receives the resulting coordinates, role choices, turn, difficulty, and optional capture counts—not the uploaded image itself. OpenAI’s handling of the attachment is governed by the user’s OpenAI service terms and privacy settings.
Storage and retention
- Server game records: the deployed inactivity window is 30 days after the latest game-changing action. An expired game becomes inaccessible at that boundary. While the process is running, cleanup is scheduled every 15 minutes; startup and later game mutations also prune expired records. Timer delays, a failed cleanup write, or an offline service can postpone physical removal until a later successful sweep, mutation, or startup.
- Migration backup: a one-time mode-0600
.v1.bakcopy may be created when a legacy game store is upgraded. The deployed backup-retention setting is seven days, after which a successful maintenance sweep or startup deletes it. - ChatGPT widget state: retention of current active-game pointers and draft selectors, and of any legacy v1 snapshot, is controlled by OpenAI’s ChatGPT product and the user’s account and chat controls. A legacy v1 snapshot may remain until a compatible card opens and successfully replaces it with v2 state, or the user clears it; the game server cannot independently erase either kind of widget-state copy.
- Rate-limit buckets: values become eligible for removal after the configured window, 60 seconds by default, and are removed by a later limited request or process restart.
- Operational logs: Render hosts the production game service in a Hobby workspace. Render documents a seven-day log-retention period for that plan. The app’s structured operational events intentionally omit request bodies, game IDs, moves, tokens, and network addresses.
- GitHub Pages request data: GitHub controls retention of ordinary website request and diagnostic data under its own privacy statement. The publisher has not added analytics or advertising scripts to this website.
- Standalone preview: Current v2 local storage contains only the active game ID and draft game, difficulty, and side selectors until they are replaced or the user clears site data. An older v1 save may still contain a full snapshot until a compatible preview opens and successfully migrates it. A failed or blocked local storage overwrite can leave the legacy standalone copy in place until the user clears site data. The current build never renders the cached legacy board; it requests authoritative state from the Turnplay Arena server.
- Support requests: Support requests may contain a submitted email address, request type, message, optional game ID, and associated delivery metadata. The project has not yet verified or adopted a bounded retention schedule for Formspree submissions or delivered inbox copies. Public launch is blocked until the owner confirms the applicable deletion controls, adopts a schedule, and publishes it.
Recipients and processors
Render hosts the production game service and processes game traffic, the persistent game store, and bounded operational logs on the publisher’s behalf. OpenAI processes ChatGPT messages, attachments, and widget state under its own terms. GitHub Pages hosts this public website and may process ordinary web-request and diagnostic data; the website itself runs no analytics. If a player submits the support form, Formspree receives the supplied email address, selected request type, message, constant product label, and ordinary request metadata to deliver the request. A game ID reaches Formspree only if the player includes it in the message; the app does not send game data to Formspree automatically.
Player controls
Players can reset or end a match, use ChatGPT’s account and chat controls for widget-state copies, clear the standalone preview through browser site-data controls, or let the 30-day game-access window expire. Reset and End Game are gameplay actions and are not full deletion requests. A game ID is a pseudonymous possession-style continuation token, not proof of an authenticated account. For a privacy or deletion request, use the support form and include only the game ID needed to locate the record—never a password, API key, payment detail, or unrelated private content. The verified publisher identity, request-verification procedure, response process, and support-retention schedule remain public-release gates.
Children and restricted data
The service is intended for people age 13 or older. Do not submit health records, financial-account details, government identifiers, precise location, passwords, private keys, or other sensitive information. The app does not need those categories to function.
Changes and contact
Material changes will update the effective date. Privacy questions can be sent through Support. The verified publisher identity and business contact will be inserted here before the app is submitted publicly.