Privacy

What Blockmaker handles, and why.

This notice explains the current early-access service in plain language. Blockmaker provides game developers with account, backend, and blockchain tools; each developer remains responsible for how their own game collects and uses player data.

Last updated:

Keep secrets out of support.

Never post a server key, wallet recovery phrase, private key, reward-wallet credential, API token, session token, or .env file in GitHub, AI chat, or a support request.

1. Who this notice covers

This notice covers the Blockmaker public website, secure admin, API, and official SDKs. “Blockmaker”, “we”, and “us” mean the Blockmaker project operating those services.

If you are a game developer, Blockmaker handles your account and service data. If you are a player, the developer of the game you use normally decides what player information the game sends to Blockmaker and why. Contact that developer first about game-specific data, account, item, or reward questions.

2. Information we handle

Developer accounts and games

  • Your account contact email, game names, public game IDs, allowed web origins, feature settings, collaborators, and account activity.
  • Your public Algorand wallet address and wallet-signed ownership proofs. The zero-ALGO setup proof is verified by Blockmaker and is not submitted to the blockchain.
  • Server-key metadata. A new server key is shown once; Blockmaker keeps a one-way hash for later verification rather than a readable copy of that key.
  • Optional game treasury or managed-wallet material when a developer deliberately enables those features. Sensitive signing material is protected server-side, but developers must keep their own independent recovery information and controls.

Players and game use

  • Game-scoped player identifiers, wallet addresses, and—only when a game enables it—email sign-in details.
  • Information the game chooses to store, such as cloud saves, settings, profiles, leaderboard entries, access-rule outcomes, reward records, and transaction references.
  • When a game enables beginner wallet-funding help, the authenticated Algorand game-wallet address, its public ALGO balance, the account type needed to choose the right instructions, and the game’s enabled/disabled setting. The guide does not collect card details, identity documents, private keys, or recovery words.
  • Authentication, anti-abuse, and operational records needed to run and protect the service.

Website, device, and network information

Servers and hosting providers may process IP addresses, request times, routes, response codes, browser or device information, and security logs. The public site does not currently run behavioural advertising. The admin and game integrations may use necessary browser storage or session tokens to keep users signed in and protect requests.

Public blockchain information

Wallet addresses, asset ownership, transactions, and contract activity on a public blockchain are public by design. Blockmaker may read that information from nodes or indexers and may submit a transaction when an authorised feature calls for it. Blockchain records can be copied by others and generally cannot be deleted by Blockmaker.

3. Why we use it

We use information to provide and secure accounts and game features, verify wallet ownership, keep games separated, authenticate users, process developer-configured game actions, diagnose failures, prevent abuse, support users, maintain backups, and meet legal obligations.

The account contact email is for service, support, operational, and security contact; it is not a substitute for wallet access and is not used to recover the owner wallet. We do not currently use it for marketing unless a person separately asks for that communication.

Where law requires a legal basis, processing may be necessary to provide the requested service, based on legitimate interests in operating and securing it, based on consent for an optional feature, or required by law. A game developer must establish the appropriate basis for the player data that their game asks Blockmaker to process.

4. Game isolation and public chains

One developer account can contain multiple games. Each game has a separate public ID, credentials, configuration, player-data scope, and optional treasury boundary. Collaborators receive access only to the games shared with them.

This is logical tenant isolation within shared Blockmaker infrastructure—not a promise that every game runs on separate physical hardware or that any online system has zero risk. Public AI guide URLs intentionally reveal game-specific integration instructions and public configuration, but not the private server key. Do not put confidential information into a game name, public guide field, or other setting described as public.

On-chain activity is outside that private boundary. Anyone may be able to associate a public wallet with assets and transactions.

5. Service providers and sharing

We use service providers to run Blockmaker. The current architecture includes Vercel for the public website, Railway for the application/API and database hosting, Resend when email delivery is enabled, and Nodely or fallback node/indexer providers for Algorand access. Cloudflare may provide domain services and, when configured, encrypted backup or object storage. Providers and configurations can change as the service develops.

Some games may choose optional third-party wallet, media, or blockchain services. Blockmaker’s current beginner wallet-funding guide opens fixed official Pera resources in a separate page. Opening a web link sends the normal browser, device, and network request directly to that destination under its privacy notice, but Blockmaker does not add the player’s wallet address or email address to that web link. If the player deliberately chooses Open in Pera, the game passes the authenticated public Algorand address to Pera through Pera’s documented local-app URL so Pera can show that address and its available actions. The guide never sends card details, identity documents, private keys, or recovery words. If a player independently chooses Pera Fund or another service, that service and its payment providers process the purchase, payment method, eligibility, and any identity verification under their own terms and privacy notices.

Optional services have their own eligibility rules, fees, regional limits, terms, and privacy practices. The game developer must tell players which services are enabled and provide any additional notice or consent the game and its audience require.

We may disclose limited information when needed to operate or secure the service, follow a valid legal request, protect users or the public, or handle a business reorganisation. We do not currently sell personal information or use Blockmaker data for behavioural advertising.

Providers may process data in countries other than yours. Developers using Blockmaker for regulated or location-restricted data must confirm that the service and any required transfer arrangements meet their obligations before launch.

6. Retention and deletion

We keep account, game, and player information while it is needed to provide the service. Some security, transaction, abuse-prevention, and audit records may be kept longer where reasonably needed or required by law. Encrypted backups rotate on their own schedule, so a deleted record may remain inaccessible in a backup until that backup expires.

An account owner can request account or game deletion through Support. We may ask for a fresh proof from the owner wallet before acting. Players should normally ask the relevant game developer first; Blockmaker can then work with that developer where appropriate.

Deletion means removing or anonymising information from systems we control where reasonably possible. It cannot erase public blockchain records, copies held by the game developer or other third parties, or records we must retain for security, dispute, or legal reasons. We will explain any material limitation rather than promise deletion that cannot be completed.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or export personal information, or object to certain uses. You may also have the right to complain to your local data-protection authority.

Use the process on the Support page. The current support tracker is public, so post only a minimal request and ask for private handling instructions—never include your email, wallet proof, game secrets, or player data in the issue. We may need to verify account or wallet control before responding to a request.

8. Security and credentials

Blockmaker uses tenant boundaries, scoped credentials, access checks, encryption for designated stored secrets, and operational safeguards. No online service can guarantee perfect security or uninterrupted availability.

Keep your wallet recovery phrase offline. Keep each game’s server key only in a private backend or secret manager; never ship it in a website or Unity build. Do not send any credential to support or an AI coding agent. If a credential may be exposed, rotate or revoke it first, then report the non-sensitive facts through Support.

9. Children

Blockmaker is a developer service and is not directed to children. A game developer must assess the age of its audience, avoid sending children’s data without an appropriate legal basis and safeguards, and provide any notices or parental controls the law requires.

10. Changes and contact

We may update this notice as Blockmaker’s features, providers, or legal obligations change. The date above shows the latest version. Material changes should be explained on this page or through the service where practical.

No support email or postal contact is currently published. Use Blockmaker Support for privacy questions and requests, following its instructions for keeping personal information and security details out of public issues.