United States / effective September 9, 2026
Privacy Policy
Operator and contact
offworldapp@gmail.com
New Jersey, United States
What this preview collects
You can browse and enter worlds without an account. Qualifying human and AI-controlled visits contribute to public play totals. Sign-in, uploads, comments, reactions and follows are disabled in this preview. We do not use advertising, sell personal information or share it for targeted advertising.
Delivering the site and worlds involves technical request information, such as your IP address, requested address and browser information, processed by our hosting and network providers. We use service diagnostics to maintain availability, investigate failures and protect the service. Application diagnostic logs in AWS CloudWatch are retained for 30 days.
Browser preferences
If you choose a light or dark appearance, a first-party theme cookie remembers that choice for up to one year. When you enter a world, a first-party __Host-visitor cookie lasts up to one day and helps avoid counting repeat visits. It is sent securely to this site and cannot be read by page scripts. You can clear these cookies in your browser. We do not create account-session cookies in this preview. Fonts are served with the site, and worlds run in a sandbox on a separate domain without access to the site's cookies or storage.
For play counting and abuse review, we store daily salted hashes of the visitor identifier and IP address rather than the original values. Scheduled cleanup removes these play records and daily hashing secrets after roughly two days; short-lived request counters expire separately. Aggregate play totals remain public. Shared networks and automated browsers are not, by themselves, reasons to exclude a play. Technical request information may still be processed by AWS for service delivery and protection as described above.
Optional usage analytics
When enabled, we use PostHog to understand traffic sources, which pages and guides are useful, and whether worlds load and keep visitors engaged. The footer shows an Analytics control when this collection is available. Analytics records page paths without query strings, public world identifiers, loading times, broad failure categories, browser and device information, referring sites and campaign labels. It records whether a search or filter was used and how many results appeared, without the search text.
We also measure clicks on site links and buttons, including the type and position of the control and its destination within the site. We remove click text, arbitrary element attributes, URL queries and creator handles. Page performance measurements describe rendering speed, layout stability and responsiveness; they exclude detailed page-element and network-request information. We do not record sessions, form entries, keystrokes, clipboard contents or activity inside sandboxed worlds. We do not send account emails, credentials, prompts or world contents.
PostHog receives technical connection information, including your IP address, and can derive approximate location from it. Our project is configured to discard the raw client IP address after deriving location and traffic classifications. We use its United States service. An anonymous analytics identifier stored in a site cookie helps recognize return visits; it expires after up to 90 days. We use PostHog's free plan, which retains analytics data for one year. We do not link this identifier to an account or infer age, gender or interests. Analytics includes qualifying human and automated browser activity; traffic classifications do not reliably distinguish the two.
You can turn usage analytics off using the footer control. We also honor Global Privacy Control and Do Not Track browser signals. Your choice is stored in a separate site cookie for up to one year. Turning analytics off removes the analytics identifier and stops new collection from that browser; it does not erase events already received. Browsing and playing continue to work.
When analytics is enabled, a newly counted play can also produce an analytics event from our server, including plays initiated through the API by an AI agent. These events contain the public world identifier, time and whether the play was anonymous, without the visitor's identifier or IP address. API clients can opt out with the DNT: 1 or Sec-GPC: 1 header. Turning analytics off does not disable the separate public play-counting and abuse controls described above. Forwarding diagnostics are kept for seven days; failed deliveries can remain in an AWS queue for up to fourteen days.
Providers and correspondence
AWS hosts the application and world assets. Cloudflare provides domain registration and DNS. PostHog processes usage analytics when enabled. Our application infrastructure is based in the United States; content delivery and network services may process requests in other locations.
If you email us, your email address and message are received through Gmail and used to answer your request. We keep correspondence as needed to handle the request and related issues. Avoid sending sensitive information. You can ask us to delete correspondence, subject to any information we need to retain to meet legal obligations or address a dispute.
Age restrictions and privacy requests
Portamora is intended for adults in the United States aged 18 and older. We do not knowingly collect personal information from children under 13. Please contact us if you believe a person under 18 has provided personal information so we can investigate and remove it.
Email offworldapp@gmail.com with privacy questions or requests to access, correct or delete information you have provided. We may need information to verify that a request is yours.
Changes
Updates will appear here with a new effective date. We will update this policy before enabling accounts or creator uploads. See our terms of use for more about this preview.