Joker uses a limited amount of Discord, gameplay, and optional voice-chat data to identify players, run multiplayer rooms, and keep each match synchronized. Joker does not sell personal information, serve targeted advertising, or use third-party advertising analytics.
1. Scope and operator
This Privacy Policy explains how Steve Mulholland ("Joker," "we," "us," or "our") processes information when you launch or play the Joker Discord Activity, visit the hosted Joker website, and use its related multiplayer services (collectively, the "Service").
Discord separately processes information under its own privacy policy. This Policy covers Joker's processing and does not replace Discord's terms or privacy notices.
2. Information we process
Discord account and Activity information
When you authorize and use Joker, the Service may receive or process your Discord user ID, username, global display name, Activity instance ID, and identifiers for the guild and voice or text channel in which the Activity is running. Joker may also access the list of users participating in the same Activity instance. Joker requests Discord's identify OAuth scope to identify the current player.
To determine whether a player may host Discord multiplayer, Joker asks Discord whether that player's account has an active entitlement for the durable Lifetime Access SKU. For users selected to receive complimentary access, Joker instead compares the authenticated Discord user ID to a private server-side allowlist. Joker processes the SKU, user, entitlement status, and related entitlement timing or revocation fields returned by Discord. Discord processes checkout and payment information; Joker does not receive complete payment-card details.
Direct website guest identity
When you use multiplayer directly from the hosted website rather than through Discord, Joker creates a random guest identifier and stores it in your browser. The identifier lets a reload reconnect as the same player and does not contain your name, email address, or Discord account information. You may replace the generated display name in the lobby.
Lobby and gameplay information
We process the name you choose for the lobby, seat assignment, ready and connection status, game actions, card passes, slap order, private hand contents, scores, letters, round state, and bot settings needed to operate an authoritative shared match. Other players receive the state needed to play, such as your display name, seat, readiness, actions, score, and card count. Your exact hand is sent only to your connected client.
Authentication information
Joker sends a short-lived Discord authorization code to its Cloudflare-hosted server, which exchanges that code for an access token using the application's confidential client secret. The access token is returned to the Activity so it can authenticate with Discord. The server uses a protected bot token to check entitlement status and issues a short-lived signed session bound to the Discord user and Activity instance. Joker does not intentionally persist OAuth authorization codes, access tokens, bot tokens, or signed Activity sessions in its multiplayer room storage.
Local preferences
Sound, music, bot-speed preferences, and the direct website guest identifier may be stored locally by the Godot web game or wrapper in storage controlled by your browser or Discord client. These values generally remain until you clear the application's local data.
Microphone access
On the direct website, you may choose to join voice chat and grant Joker access to your microphone by tapping the voice control and approving your browser's permission prompt. While you remain in voice chat, microphone audio is transmitted using encrypted WebRTC connections to the other voice participants in the same public lobby. When a direct connection cannot be established, a configured Cloudflare TURN service may relay the encrypted media. Joker does not intentionally record or persist microphone audio.
Joker's multiplayer Worker relays temporary WebRTC connection descriptions and network candidates between current voice participants so their browsers can establish media connections. These signaling messages are not intentionally stored in room storage. Network candidates may disclose connection-related IP address information to WebRTC peers and relay infrastructure as required to establish the connection.
Technical and service-provider data
Discord, Netlify, Cloudflare, and their infrastructure may automatically process technical information such as IP address, device and browser characteristics, request timestamps, routing data, and security or diagnostic logs when they deliver the Service. We may access limited diagnostic information when needed to investigate an outage, abuse report, or security problem.
3. How we use information
We use the information described above to:
- identify players and connect them to the correct Discord Activity instance or singleton public website lobby;
- verify Lifetime Access, activate a sponsored Discord room, and admit up to three guests without requiring those guests to purchase access;
- create lobbies, synchronize matches, operate bots, and enforce game rules;
- display player names, readiness, game actions, results, and reconnect status;
- connect players who voluntarily join browser voice chat and relay temporary connection-negotiation messages;
- maintain the security, reliability, and integrity of the Service;
- diagnose errors, prevent abuse, and respond to support or privacy requests; and
- comply with applicable legal obligations.
Where applicable law requires a legal basis, processing is based on providing the Service you request, our legitimate interests in operating and securing the Service, your consent where requested, and compliance with law.
4. How information is disclosed
- Other players: multiplayer participants receive the shared lobby and game information necessary to play. Exact private hands are not intentionally disclosed to opponents. Players who join browser voice chat transmit microphone audio and WebRTC connection information to the other voice participants.
- Service providers: Discord provides the Activity platform, identity flow, entitlement records, and checkout; Netlify hosts the static Activity files; and Cloudflare hosts the OAuth exchange, entitlement verification, signed-session service, WebSocket service, temporary room state, and optional TURN media relay.
- Legal and safety reasons: information may be disclosed when reasonably necessary to comply with law, protect users, investigate fraud or abuse, or defend legal rights.
- Business changes: information may be transferred as part of a merger, acquisition, financing, reorganization, or transfer of the Service, subject to appropriate protections.
Joker does not sell personal information or share it for cross-context behavioral advertising. Joker does not use personal information to deliver targeted advertising.
5. Retention
Active multiplayer room and match state is stored in a Cloudflare Durable Object. The direct website's singleton public room is cleared when its final browser connection closes. A Discord Activity room is scheduled for deletion after approximately six hours without a connection; reconnecting during that period may reactivate it.
OAuth authorization codes, Discord access tokens, detailed entitlement responses, and signed Activity sessions are not intentionally stored in room state. A room-level flag recording that a licensed player activated the room remains with that room until its cleanup; it does not contain payment details. Discord user IDs selected for complimentary access remain in encrypted server configuration until removed. WebRTC signaling messages and microphone audio are not intentionally recorded or persisted by Joker. Short-lived TURN credentials expire automatically. Local preferences remain on your device until cleared. Hosting and security logs may be retained by service providers under their own operational and legal retention practices. We may retain information longer when reasonably necessary for security, dispute resolution, or compliance with law.
6. Security
We use reasonable administrative and technical safeguards appropriate to this Service, including HTTPS and secure WebSocket transport, server-side storage of Discord credentials, signed sessions that bind Discord identity to an Activity instance, server-side entitlement verification, and separation of each player's private hand in multiplayer responses. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
7. Your choices and privacy rights
You may stop processing by leaving or closing the Activity. Browser voice chat is optional; you may mute, leave voice, revoke microphone permission, or close the page at any time. You can change the display name used in a lobby and can clear locally stored preferences through your browser or Discord client settings. Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection regarding your personal information, and to appeal or complain to a privacy regulator.
To make a request concerning information controlled by Joker, contact us using the address below. We may need to verify your request. Requests concerning Discord's own account records or platform processing should be directed to Discord.
8. Children
Joker is not directed to children under 13 or anyone below the minimum age required to use Discord in their country. We do not knowingly collect personal information from a child who is not permitted to use the Service. If you believe this has occurred, please contact us so we can investigate and delete the information where appropriate.
9. International processing
The Service and its providers may process information in countries other than your own. Those countries may have different data-protection laws. Where required, applicable safeguards are provided by the relevant service provider or as otherwise required by law.
10. Changes to this Policy
We may update this Privacy Policy as the Service changes. The revised version will be posted at this URL with a new "last updated" date. Material changes may also be communicated through the Service or Discord when appropriate.
11. Contact
Steve Mulholland
Email: flatlus.games@protonmail.com