Escape Director
LEGAL

Privacy Policy

Effective Date: August 25, 2026


1. Scope and Our Role

This Privacy Policy explains how Escape Director ("Escape Director," "we," "us," or "our") collects, uses, discloses, and retains personal information through our websites, applications, support channels, and related services (collectively, the "Service"). Escape Director is operated from Maryland, United States, and the Service is designed primarily for escape room businesses and their personnel. For account administration, billing, security, product analytics, and our own business operations, Escape Director determines why and how personal information is processed. When an escape room business uses the Service to store information about its personnel, players, or game sessions, that business generally controls the information and Escape Director processes it to provide the Service. If you are an employee, player, or other person whose information was entered by an Escape Director customer, you may wish to contact that business first. We will assist our customer as required by applicable law and our agreement with the customer.

2. Information We Collect

The information we collect depends on how you interact with the Service and which features you use. It may include: • Account and contact information: Name, email address, telephone number, authentication records, linked sign-in method, account identifiers, and communications preferences. Passwords are handled through our authentication system and stored as password verifiers rather than readable passwords. • Business and subscription information: Business details you provide, selected plan, trial and subscription status, billing cycle, renewal and cancellation dates, Stripe customer and subscription identifiers, and transaction records. Stripe collects and processes payment-card and billing details; Escape Director does not receive or store complete payment-card numbers. • Customer Content: Rooms, puzzles, clues, messages, media, Live View settings, dashboards, leaderboard settings, and other material you create or upload. • Personnel and game-session information: Game Master Profile names; team names; player counts; session dates, results, timing, clues and messages used, notes, corrections, and action history; and analytics derived from that information. Customers decide what names and notes to enter and are responsible for having an appropriate basis to provide them. • Device, log, and usage information: IP address, browser and device type, operating system, referring page, approximate location derived from IP address, pages and features used, timestamps, cookie or similar identifiers, performance data, and diagnostic events. When enabled, our analytics and error-monitoring tools may collect masked session replays. We configure those tools to mask text and inputs and block media, but technical metadata may still be collected. • Support and feedback information: Messages, attachments, feedback, support history, and information you submit through email or our feedback tools. • AI feature information: If you choose to use the AI Analytics Assistant, we process your question, the assistant's response, the current conversation and dashboard context, approved Room, Puzzle, and Game Master display names, and governed aggregate analytics needed to answer it. To support follow-up questions, Escape Director temporarily stores the conversation in our Railway-hosted PostgreSQL database. The feature is designed not to send raw Room Session records, session notes, email addresses, or database identifiers to the model provider. We collect information directly from you, automatically from your browser or device, from the business that gives you access to the Service, and from services you choose to connect, such as Google sign-in and Stripe. If you choose Google sign-in, Google provides the account information needed to authenticate you, such as your name, email address, profile image, email-verification status, and Google account identifier. Before a new Google account registration begins, we require you to agree to our Terms of Service and acknowledge this Privacy Policy.

3. How We Use Your Information

We use the information we collect for the following purposes: • Provide, operate, maintain, and support the Service, including authentication, room operation, offline preparation, session synchronization, analytics, leaderboards, and requested AI features. • Create and administer accounts, trials, subscriptions, transactions, and billing communications. • Send verification, password-reset, service, security, support, and other transactional communications. • Diagnose errors, monitor performance, understand feature use, and improve the reliability and usability of the Service. • Protect the Service, our customers, and others from fraud, abuse, security incidents, and unlawful activity. • Enforce our agreements, resolve disputes, establish or defend legal claims, and comply with legal obligations. We do not sell personal information. We also do not share personal information for cross-context behavioral advertising or provide Customer Content to third parties for their own marketing.

4. How We Disclose Information

We may disclose information in the following circumstances: • Service providers: Companies that help us host, store, secure, support, analyze, and operate the Service, subject to contractual or other appropriate restrictions. • Customer-directed and public features: People authorized by the customer may access Customer Content. If a customer publishes a leaderboard, the configured leaderboard information becomes available to anyone with access to its public link and may be copied or shared by others. • Legal and safety reasons: When we reasonably believe disclosure is necessary to comply with law or legal process; protect rights, safety, or security; investigate abuse; or enforce our agreements. • Business transactions: In connection with a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate protections. • With your direction or consent: When you ask us to disclose information or otherwise authorize it. Depending on the features used and our production configuration, service providers may include Railway for application hosting and PostgreSQL database hosting; Amazon Web Services for media storage; Stripe for billing and payment processing; Google for optional sign-in; Resend for transactional email; Featurebase for feedback and support; PostHog for product and website analytics, including masked session replay; Sentry for error, performance, and masked replay monitoring; and Vercel AI Gateway and selected model providers, including OpenAI, for the optional AI Analytics Assistant. The AI request configuration instructs OpenAI not to store the generated response. Gateway and model providers may retain limited operational records under their own terms, and Escape Director enables additional zero-data-retention routing only when it is supported and configured. These providers process different information depending on their function. Some, such as Stripe and Google, may also process information under their own terms and privacy policies.

5. Cookies, Analytics, and Local Device Storage

We use cookies and similar technologies for authentication, security, preferences, billing-flow continuity, analytics, and Service operation. PostHog may use cookies or local storage to associate product events with a browser or identified account. Sentry may collect diagnostic and replay information when configured. Escape Director also uses browser storage for functional purposes. This may include local storage for preferences and short-lived cross-window coordination, IndexedDB and Cache Storage for prepared Rooms and media, Offline Access Grants, Game Master Profile snapshots, and Pending Session Records that allow a Room Station to continue operating or synchronize after a connection interruption. This information remains on the device until it is synchronized, replaced, cleared through available controls, removed during application cleanup, or deleted through browser settings. Anyone who controls the device may be able to clear it, and customers are responsible for securing devices used as Room Stations. You can limit cookies and clear local browser data using your browser controls. Blocking required storage may prevent authentication, offline operation, or other Service features from working correctly.

6. Data Retention

We retain personal information for the period reasonably necessary for the purposes described in this Policy. The period varies according to the type of information, the customer's instructions and account status, operational and security needs, backup cycles, and legal requirements. Account information and Customer Content are generally retained while an account remains open and for a reasonable period afterward to support account closure, restoration, dispute resolution, and deletion from active systems and backups. Customers may delete certain Rooms, media, sessions, and other records using available Service controls. Billing and transaction records may be kept for tax, accounting, fraud-prevention, and legal-compliance periods. Security logs, diagnostic records, support communications, and records of agreement acceptance may be retained as reasonably necessary to protect the Service and establish or defend legal claims. AI Analytics conversations, including questions and answers, are short-lived application state. They are deleted when an End Chat request completes successfully or are scheduled to expire 30 minutes after the most recent activity and are normally removed shortly afterward. Separate AI usage records may be retained for subscription enforcement, cost accounting, security, and dispute resolution. Those usage records contain operational metadata such as the account identifier, billing period, provider and model, token counts, cost, latency, status, and generation identifier; they do not contain the question or answer text. Cancellation of a subscription stops future renewal but does not, by itself, necessarily delete the account or all associated information. To request account deletion, contact us as described below. We may retain information when required by law, necessary to protect the Service or others, or maintained in deidentified or aggregated form that cannot reasonably be linked to an individual.

7. Data Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These include encrypted network transmission, access controls, account authentication, secret-management practices, ownership checks, and controls intended to limit the information sent to analytics and AI providers. No system is completely secure, however, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Customers are responsible for using strong credentials, limiting access to authorized personnel, securing Room Station devices, and notifying us promptly of suspected unauthorized account access.

8. Your Choices and Privacy Rights

You may review and update certain account information through the Service and manage subscription billing through the available billing portal. Customers can delete certain Customer Content using available controls. You may also contact us to request access to, correction of, deletion of, or a portable copy of personal information that Escape Director controls. Depending on where you live and subject to legal exceptions, you may have additional rights, such as the right to confirm processing, obtain information about disclosures, opt out of certain processing, limit the use of sensitive information, or appeal a decision about your request. Escape Director does not currently sell personal information or use it for cross-context behavioral advertising. Submit a request to support@escapedirector.com. We may need to verify your identity and authority before completing it. If Escape Director holds information only on behalf of an escape room business, we may refer the request to that customer or work with it to respond. We will not discriminate against you for exercising a privacy right provided by applicable law.

9. Public Leaderboards

A customer may choose to publish a leaderboard through a publicly accessible link. Depending on the customer's settings, the leaderboard may display a team name, Room name, result, rank, completion time or time remaining, assistance information, and session date. The customer is responsible for choosing appropriate display information and obtaining any permission required from players. Customers should not publish a person's full name or other identifying information as a team name without appropriate authorization. Unpublishing a leaderboard prevents future access through the Service but cannot retrieve copies previously made by others.

10. Children's Privacy

The Service is offered to businesses and is not directed to children. A person accepting our Terms or creating a Customer account must be at least 18. We do not knowingly collect personal information directly from children under 13. A customer may authorize younger personnel to use the Service where lawful or may enter a team name or other game-session information relating to players who are minors; the customer is responsible for appropriate supervision, limiting that information, and having the authority required to provide and publish it. If you believe a child provided personal information directly to Escape Director without appropriate authorization, contact us so we can investigate and take appropriate action.

11. United States Operations and International Users

Escape Director is operated from the United States, and information may be stored and processed in the United States and other locations where our service providers operate. If you access the Service from outside the United States, your information may be transferred to a country with different data-protection rules. Customers are responsible for determining whether the Service is appropriate for the information they choose to process and for complying with laws that apply to their collection and use of that information. Additional contractual terms may be required before a customer uses the Service in a jurisdiction that imposes specific controller-processor or international-transfer requirements.

12. Changes to This Policy

We may update this Privacy Policy as the Service and applicable requirements change. We will revise the Effective Date and provide additional notice of material changes when appropriate, such as by email or within the Service. If applicable law requires consent for a new use of personal information, we will request it.

13. Contact Us

If you have questions, concerns, or privacy requests, contact Escape Director at support@escapedirector.com. Escape Director is operated from Maryland, United States.