What we process, why we process it, and where you stay in control.
This notice explains personal-data processing connected with the website, app, accounts, gameplay, rankings and community submissions.
1. Controller and contact
The controller is SmirkDuel, an independent game project operated from Hungary. Privacy questions and rights requests may be sent to privacy@smirkduel.com. Operator address: Hungary.
2. Data we may process
Internal user ID, username, Google account identifier used for linking, authentication status and account settings.
Random web device ID, authentication tokens, IP address, user agent, timestamps, request IDs, logs and anti-abuse signals.
Room and match metadata, role, result, rating, wins, losses, win rate, leaderboard position and integrity checks.
Camera frames and facial-expression signals used for gameplay. They are not intended for biometric identification. Online video may be transmitted in real time to the opponent.
Uploaded image or video, title, description, category, age rating, rights confirmations, moderation status and reviewer notes.
Messages, reports, rights requests and evidence needed to resolve disputes, enforce rules or comply with law.
3. Purposes and legal bases
Where processing relies on legitimate interests, we balance those interests against your rights and reasonable expectations.
4. Camera and facial-expression processing
The game may analyse face landmarks, visibility and smile-related signals to run rounds and display warnings. The purpose is gameplay, not identifying who you are. Where technically applicable, analysis occurs on the device. In Online Battle, live video may be sent through a real-time peer connection to the opponent, while signaling services help establish and maintain the connection. SmirkDuel does not intend to store live camera streams unless a separate capture, reporting or sharing feature is clearly activated.
Automated gameplay outcomes do not produce legal or similarly significant effects.
5. Public data
Your username and selected game statistics may be publicly visible in the Arena leaderboard. Approved community content may be published in the app, website or official promotional channels together with a username or attribution where appropriate. Do not use a username or upload content that reveals information you do not want to make public.
6. Browser storage, cookies and external resources
- Session storage: the website stores the temporary submission token and username for the current browser session.
- Local storage: a random web device identifier supports secure Google-linked sign-in.
- Server cookies: authentication or security infrastructure may set strictly necessary cookies.
- Google Identity Services: Google may receive technical request data and use its own cookies or storage when the sign-in component loads or is used.
- Fonts, icons and delivery providers: external providers may receive IP address, browser and request information when resources are delivered.
This version of the landing page does not intentionally use advertising cookies or behavioural advertising analytics. If non-essential analytics or marketing technologies are introduced, this notice and any required consent controls must be updated before activation.
7. Recipients and processors
Data may be shared with staff or contractors who need access for operation, moderation, security or support; hosting, storage, networking and content-delivery providers; Google for identity services; app-store providers; professional advisers; and public authorities where legally required. Providers are given only the access reasonably needed for their role.
8. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers are protected by an adequacy decision, approved Standard Contractual Clauses or another lawful safeguard, together with supplementary measures where appropriate.
9. Retention
We keep personal data only for as long as necessary for the purpose collected. Retention depends on account status, token expiry, moderation and appeal needs, leaderboard integrity, security investigations, legal claims, statutory requirements and backup cycles. Data may be anonymised instead of deleted where individual identification is no longer needed. Legal holds or active disputes may require longer retention.
10. Security
We use measures appropriate to the nature of the service, including encrypted transport, access controls, token-based authentication, restricted administrative access, logging, moderation and backups. No online system can guarantee absolute security. Do not send passwords, full identity documents or authentication tokens by ordinary email unless we specifically request a secure verification method.
11. Children
Children deserve heightened protection. In Hungary, a child below 16 cannot independently give consent for consent-based online-service processing; valid parental or guardian authorisation may be required. Account-linked and upload features are not intended for unsupervised use by children below that age.
12. Your rights
Depending on the circumstances, you may have rights of information, access, correction, deletion, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority. Open the tab for the request process and limitations.
13. Changes
We may update this notice when the service, providers, data practices or law change. Material changes will be highlighted through the website or app. The version and effective date at the top identify the current notice.