Smart NPCsAutonomous Game Agents
PlaygroundPricingDocsStudioSettingsGitHub
API Health
Log InStart Free

Privacy Policy

Effective 27 September 2026.

1. Who we are

Smart NPCs ("we") operates the hosted NPC API at smartnpcs.com and the Studio dashboard. Privacy questions and requests: open an issue at github.com/antonihabek/NPC. If you are a player in a game that uses Smart NPCs, your first contact is that game's developer — see section 3.

2. Data we collect from developers

  • Account: email address, password (stored only as a hash by our auth provider — we never see it), and optional name and studio name. Google sign-in shares the email and profile name your Google account provides.
  • Studio content: games, characters, prompts, settings, API keys (we store public keys; secret keys are hashed and shown once), usage meters, and eval scorecards.
  • Billing: plan, billing cycle, Stripe customer id, subscription state, and metered event counts. Card numbers go directly to Stripe through their payment form — they never touch our servers.
  • Support: whatever you include in GitHub issues. Include a turnId rather than player personal data when reporting failures.

3. Data we process from players

When a game calls our API, we receive the event text, the world state the game sends, the NPC's reaction, disposition and memory updates, moderation flags, and a random browser player id (stored in the player's own local storage as npc_player_id). Request metadata (IP address, headers) is used transiently for rate limiting, abuse control, and error logs.

The game developer is the controller of player data; Smart NPCs processes it only to provide the API. Developers must have their own lawful basis and their own in-game privacy notice. A data-processing agreement is available on request.

4. Subprocessors

VendorPurpose
SupabaseAuthentication and Postgres storage (accounts, profiles, game rows)
VercelHosting the site and API
CloudflareCDN and proxy in front of the site and API
StripePayments, subscriptions, metered billing
Fireworks, TogetherModel inference: prompts are processed to generate reactions
Google FontsFont delivery (receives IP address with the request)

Inference runs on US-based vendors, so prompts may be processed in the United States. These vendors publish data-processing terms; sign them in each vendor dashboard for your own compliance records where required.

5. No training on your content

We do not train models on developer or player content, and we do not authorize inference vendors to train on it. Per-game training opt-in exists as a flag and defaults to off. We use only aggregated, anonymized statistics (token counts, cache rates, error rates) to operate the service.

6. Retention

  • Verbatim player text: scrubbed from interaction rows after 30 days.
  • Aggregated telemetry rows: deleted after 12 months.
  • Account data: kept while your account exists. Deleting your account in Studio revokes your game keys, blocks spend, cancels subscriptions, and deletes your profile, mappings, and auth user; residual worker rows are purged within 30 days.
  • Billing records held by Stripe follow Stripe's retention schedule.

7. Cookies and local storage

  • Supabase auth cookies: strictly necessary sign-in session. No consent banner needed.
  • npc_player_id in local storage: functional random player id. No advertising use.
  • Stripe.js may set its own fraud-prevention cookies on checkout pages.

We run no advertising trackers and no cross-site analytics.

8. Your rights (EU, UK, California)

Under the GDPR, UK GDPR, and CCPA/CPRA you may request access, correction, deletion, portability, and restriction of your personal data, object to processing, and withdraw consent. Californians may also opt out of any sale or sharing of personal information — we do not sell or share it. Exercise rights in-product (Studio settings, delete account) or via the contact above; we respond within one month. EU/UK residents may complain to their national supervisory authority.

9. Children

The service is not for children under 13, or under 16 in the EU without parental consent. Developers are responsible for rating their games (E / T / M) and for complying with child-safety law in their markets.

10. Security

Traffic is TLS-encrypted; database access is row-level secured; service-role keys never leave our servers. No system is perfectly secure — report suspected issues via the contact above.

11. Changes

Material changes are posted here with a new effective date. Continued use after the effective date constitutes acceptance.

Smart NPCs

The hosted NPC brain for browser games. Real-time reactivity with persistent memory.

Domain: smartnpcs.com

Product

Interactive PlaygroundClient SDKArchitecturePricing

Developers

DocumentationClient SDK ReferenceTroubleshootingAPI Status

Hosted API

Serverless deploymentLive status endpointVendor-backed inference

Legal

Terms of ServicePrivacy PolicyAcceptable Use

© 2026 Smart NPCs (smartnpcs.com). All rights reserved.

API Health