MasquePlay

Privacy Policy

Last updated: September 2, 2026

We know privacy policies are usually awful to read. We've tried to write this one like a normal human being would.


1. Who We Are

MasquePlay is operated by MasquePlay. When this policy says "we," "us," or "our," it means MasquePlay. We are based in Vancouver, British Columbia, Canada.

For privacy questions or requests, email [email protected].

2. What We Collect

Things you give us directly

Things the app creates as you use it

Things we collect automatically

3. What We Don't Collect

We don't collect:

4. How We Use Your Data

Data Why we use it
Email Account login, service notifications
Beta application email and answers Assessing eligibility and testing fit, organizing iOS and future device cohorts, and contacting selected applicants
Referral source Understanding which invitations or outreach brought applicants to the beta
Display name Shown to your partner in the app
Password hash To verify your identity when you log in
Date of birth Age verification (18+ check)
Persona selections Personalising your daily pool
Chat messages Storing your conversation history
AI usage and rewrite history Providing AI features, usage limits, data export, and debugging
Match records Stats shown on your profile
Reports Reviewing content issues, safety concerns, and abuse reports
Subscription status Managing plan features and usage limits
Notification preferences Sending push notifications you've opted into
Timezone Resetting your pool at midnight in your timezone
Usage and product analytics Measuring onboarding, feature reliability, aggregate engagement, and service cost

We do not use your data for advertising, and we do not sell your data to anyone.

5. Where Your Data Is Stored

MasquePlay runs entirely on Cloudflare's infrastructure, including:

Cloudflare operates globally. Your data may be processed in data centres outside your country. Cloudflare maintains security and compliance programs for its infrastructure.

6. How We Protect Your Data

We use HTTPS, hashed passwords, access controls, and service-provider security features to protect personal data. Access to admin tools is restricted. No online service can promise perfect security, but we design MasquePlay to avoid collecting more sensitive data than we need.

7. Who We Share Your Data With

We share data with no one for marketing purposes.

We use the following third-party services to operate the app:

Service What it's used for
Cloudflare Hosting, database, and CDN
Cloudflare Turnstile Preventing automated abuse of the private beta application form
Third-party AI providers Generating persona content and optional AI features. Depending on the feature, text sent to the provider may include your draft or recent chat context, but not account fields like email or date of birth. See AI Disclosure.
Email provider Sending verification, password reset, and service emails
Payment providers (when enabled) Processing web or in-app purchases, renewals, cancellations, and refunds. No payment provider is used during the free private beta.

Authorized MasquePlay staff may access account or content data only when reasonably needed to operate or debug the app, respond to support requests, investigate reports or abuse, protect security, enforce our terms, or comply with the law.

8. Push Notifications

If you enable push notifications, we store a device token to deliver them. You can revoke permission at any time in the app's notification settings or in your device settings.

Push notifications are meant to be vague. We try not to include sensitive roleplay details in notification text.

9. Cookies and Local Storage

We use browser local storage to keep you logged in between sessions. Some auth flows may also use essential cookies. The private beta application uses a short-lived, essential HttpOnly cookie to continue from the email form to the questionnaire without putting your email or application identifier in the URL. We don't use tracking or advertising cookies.

10. How Long We Keep Your Data

Most personal data is retained for the life of your account and deleted when you delete your account. Some limited records may be kept longer if needed for safety, security, legal compliance, or abuse prevention.

Data Retention
Account data (email, name, date of birth) For the life of your account
Incomplete beta applications Up to 30 days after the last activity
Completed beta applications For the relevant beta program and a reasonable follow-up period, then deleted when no longer needed for testing recruitment
Ineligible beta applications Kept only as long as reasonably needed to administer the current recruitment round; an application indicating either participant is under 18 is deleted immediately
Optional partner invite details Until the invite is used, changed, deleted, or your account is deleted
Chat messages For the life of your account
Match and persona history For the life of your account
Swipe history and preferences For the life of your account
AI usage, rewrite history, and additional photo interactions For the life of your account
Subscription status For the life of your account
Reports and support requests For as long as needed to respond, enforce our terms, protect safety, or meet legal obligations
Session tokens Until they expire, you sign out, or you delete your account
Push notification tokens Until you disable notifications or delete your account
Product analytics tied to your account For the life of your account; on deletion, useful event records may remain only after identifying and free-text fields are removed
Rate-limit trip records Up to 180 days; records attributable by email have their email and IP fields cleared when that account is deleted, while shared or IP-only security records follow the normal security retention period
Cloudflare Workers application logs Up to 7 days under Cloudflare's current plan-dependent retention limits

When you delete your account, personal records attributable to you are removed from our active application databases. This includes account and authentication records, notification registrations, private beta application contact and continuation data, and affected shared roleplay state. Useful product analytics may remain in their existing tables only after user, couple, invite, chat, message, attempt, email, IP, and free-text fields that could identify or reconnect them to you are cleared. We mark those records as anonymised so they are not treated as active account data.

Cloudflare Workers application logs may persist after deletion until their normal retention window expires (currently no more than 7 days). Third-party AI providers may keep API inputs and outputs for a limited time for abuse monitoring, security, or legal reasons under their own API terms.

11. Your Rights and Account Deletion

You have the right to access, correct, delete, and export your personal data. You can export your data and delete your account from inside the app. Exports include your data without exposing your partner's private answers or operational credentials such as session tokens and push endpoints. You can also email us at [email protected] and we'll respond within 30 days.

Because MasquePlay is built for couples, deleting one account may pause the couple pairing and remove or affect shared roleplay history tied to that account. Your partner's own account data remains theirs.

If you submitted a beta application but do not have an account, email us from the application address to request access, correction, or deletion.

12. Children's Privacy

MasquePlay is strictly for users aged 18 and over. We do not knowingly collect data from anyone under 18. If we discover we have done so, we will delete it immediately.

13. Changes to This Policy

If we make material changes, we'll update the "Last updated" date and provide any notice required by applicable law. The current app does not have an automatic in-app re-consent flow. If a change requires renewed consent, we will add that flow before relying on the new consent.

14. Contact

MasquePlay — Vancouver, BC, Canada Email: [email protected]