1. Scope and operator
Thunder Buddies Studios operates the Service and is responsible for the account and audit data described here. This notice covers the hosted application, account system, owner dashboard, and same-origin server proxies. Third-party feeds, linked sites, map providers, and AI/voice providers have separate notices and act under their own terms.
The Service is for adults and is not directed to anyone under 18. We do not knowingly permit children to create accounts.
2. Information collected
Account and security records
We collect email address; a salted password digest rather than the plaintext password; approval, denial, and security-lock status; lock reason; account timestamps; the accepted legal version and acceptance time; session-token digests and expiration; and owner actions affecting access.
Activity and console records
We record an account ID when signed in, a pseudonymous browser identifier, event type, time, and limited metadata for page views, submitted location searches, filter changes, scanner interest, selected controls, authentication results, legal acceptance, owner policy changes, and security actions. Passwords, provider secrets, API keys, tokens, microphone audio, and voice recordings are rejected from this application audit log.
Network, device, and hosting records
Our hosting, proxy, security, and infrastructure providers may process IP address, request time, route, user agent, device/browser characteristics, referrer, error details, and similar network logs. We do not currently use third-party behavioral advertising or sell personal information.
Location, voice, AI, and external data
Search text, selected locations, map coordinates, filters, and commands may reveal interests or location intent. Browser speech recognition may process spoken commands according to the browser vendor’s behavior. If optional OpenAI Realtime is enabled, microphone audio, transcripts, conversation context, tool results, and session metadata are sent to the configured provider. TTSForFree receives short response text used to generate spoken confirmations. Internet-radio or public-safety playback requests may reach source providers.
Identity verification
We do not currently collect government ID through the application. If risk-sensitive access later requires it, we may request a government-issued photo ID and process the name, image, date of birth, issuing jurisdiction, expiration, document identifiers, authenticity signals, and verification result. A separate just-in-time notice will identify the secure channel, vendor, purpose, retention, and required/optional fields. Do not submit ID until that notice is presented.
3. Why information is used
- Authenticate operators, administer approvals, maintain sessions, and provide requested features.
- Detect misuse, investigate incidents, enforce policies, lock accounts, protect providers, and keep an auditable security record.
- Diagnose failures, measure actual product operation, improve search and interface behavior, control costs, and maintain data-layer availability.
- Meet contractual, licensing, safety, tax, regulatory, preservation, and valid legal-process obligations; protect vital interests in a genuine emergency.
Depending on location and purpose, processing may rely on performance of a contract, legitimate interests in operating and securing the Service, consent for genuinely optional processing, legal obligation, or protection of vital interests. Acceptance of service terms is not presented as consent for every privacy purpose.
5. Retention and deletion
Application activity events are automatically removed after 180 days during schema maintenance. Expired sessions are removed and active sessions expire after 30 days unless revoked sooner. Account approval, lock, security, and legal-acceptance records remain while the account is active and as reasonably needed for security, dispute, legal, and compliance purposes.
Provider and infrastructure logs have their own retention periods. A future ID-verification flow must use a separately disclosed, minimized retention schedule; no ID document should be retained by default merely because verification occurred. Backups and legally preserved records may persist for a limited additional period.
6. Choices and privacy rights
Depending on your jurisdiction, you may have rights to know, access, correct, delete, restrict, object, receive a portable copy, withdraw consent, limit sensitive-data use, opt out of sale/sharing, and appeal or complain to a regulator. The current Service does not sell data or use it for cross-context behavioral advertising.
Use the operator support channel published with the Service or the repository’s issue/contact channel to request assistance, but never post identity documents, credentials, private data, or security details in a public issue. We may verify identity before fulfilling a request and may retain records where an exception or legal obligation applies.
Browser settings can limit cookies, but the HttpOnly session cookie is necessary for authentication. Disabling it prevents account use.
7. Security, changes, and contact readiness
Controls include salted password hashing, HttpOnly SameSite cookies, server-side key proxies, same-origin checks, rate limits, owner approval, account locks, session revocation, metadata filtering, and restricted owner access. No system is perfectly secure; report suspected vulnerabilities through the private security process described in the repository’s Security Policy.
We will show the version and require renewed acceptance for material changes. Before production launch, Thunder Buddies Studios must publish a monitored privacy-contact method and legal mailing address here; a source-code repository alone may not satisfy applicable notice rules.