Short version: B4D uses your basic Discord identity and live game state to authenticate you and run multiplayer. We do not sell personal information, run targeted advertising, or intentionally store match traffic in a B4D database.
1. Scope
This policy covers B4D's Discord Activity, public web client, multiplayer room service, and the server endpoint used to complete Discord authentication. Discord, Supabase, and Vercel also process information under their own policies.
2. Information we process
Discord identity and Activity context
When you launch B4D in Discord, the Activity asks for the Discord identify permission. We process your Discord user ID, username or display name, avatar, the Activity instance and channel identifiers, and the list of connected Activity participants. We also process a one-time OAuth authorization code and the resulting access token long enough to authenticate the Activity and confirm that you belong to the current Activity instance. B4D does not request your email address or your Discord message history.
Live multiplayer and game state
To operate a run, B4D processes the run code, team, ready state, selected campaign and infected class, connection status and timestamps, connection-quality and latency reports used for host selection, and live gameplay data such as movement, health, actions, combat events, objectives, and match state.
The current prototype broadcasts this information on a Supabase Realtime topic derived from the run code. It does not require each browser client to authenticate to a private Supabase channel. Other clients that obtain or guess a current run code may be able to receive or attempt to send traffic on that topic. The Activity validates and filters game messages, but that is not equivalent to a private, server-authorized room.
Run codes, URLs, invites, and clipboard
When you create or join a run, B4D may place its code in the page URL and browser history. If you choose Copy Code or invite players, the code or an invite link can be copied to your clipboard or passed to Discord's invite flow. Treat a current run code as a shared access secret: give it only to intended players and do not post it publicly. Browsers, Discord, and your device may retain URL, history, invite, or clipboard information under their own controls.
Browser storage
B4D stores volume, look sensitivity, crosshair scale, and the source game's music-mute preference in local browser storage. Session storage can hold a selected survivor model and, outside Discord, a randomly generated guest identifier and guest name. During an active multiplayer run, a frozen Survivor client can also retain one short-lived recovery checkpoint containing the run code, campaign, frozen role assignments, and the latest live world and player state. That checkpoint is used only to let the same Survivor browser tab safely resume world authority after an accidental reload; an Infected client cannot use it to become host. This data remains in your browser until B4D clears it, you clear site data, or the relevant session ends. The settings and recovery checkpoint are not used for advertising.
Service and network metadata
Discord, Vercel, Supabase, and ordinary internet infrastructure may automatically process IP address, browser/device type, request time, connection diagnostics, and similar log or security metadata when they deliver the Activity or multiplayer service. Their handling and retention are governed by their policies and service configurations.
B4D does not intentionally collect Discord messages, voice or video content, contacts, camera or microphone input, precise geolocation, payment information, or advertising identifiers.
3. How we use information
- Authenticate you with Discord and verify membership in the current Activity instance.
- Create and join multiplayer rooms, synchronize players, and run campaign or versus matches.
- Show player identity, roster, connection, team, class, and match status to room participants.
- Remember your on-device game settings.
- Protect the Activity, diagnose failures, enforce room capacity, and prevent misuse.
- Meet legal obligations and enforce the Terms of Service.
Where local law requires a legal basis, these uses support providing the service you request, our legitimate interests in operating and securing B4D, compliance with law, and consent where required.
5. Retention
The Discord authorization code is used once. The access token is returned to the Activity for its Discord session; the token response is marked not to be cached, and B4D does not intentionally write it to a B4D database.
Multiplayer presence and broadcasts are designed for the live run and are not intentionally written to a B4D match database. Disconnect cleanup is best-effort, and Realtime presence normally expires after a player disconnects; B4D does not promise immediate deletion from provider systems. Local preferences remain until you clear site data, while session preferences and a fallback guest identity remain for the browser session. A Survivor recovery checkpoint is refreshed during an eligible live run, expires after 15 minutes without a refresh, and is cleared when the run ends or you intentionally leave it. A run code may remain in browser history or on the clipboard until you clear or replace it. Infrastructure providers may retain limited logs and metadata under their own policies, security needs, and service settings.
B4D currently has no separate player-account or match-history database.
6. Your choices and requests
- Close or disconnect the Activity to stop participating in the live room.
- Clear B4D site data in your browser to remove saved preferences, fallback guest data, and any retained Survivor recovery checkpoint. Clear browser history or replace clipboard contents if you do not want a copied run code to remain there.
- Leave the run and create a new code if the current code was shared beyond the intended squad.
- Use Discord's User Settings → Authorized Apps controls to review or revoke the B4D authorization.
- Use Discord's own privacy controls for information held by Discord.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or an objection concerning personal information we control. To make a request, use the contact method below and include your Discord user ID, the approximate date of use, and enough context to locate any applicable records. We may need to verify your identity. Because B4D currently has no separate account or match-history database, most B4D-controlled data is either live room traffic or browser storage you can clear directly.
7. Children
B4D is not directed to children under 13 or anyone below the minimum age required to use Discord in their country. Do not use the Activity if you do not meet that age. If we learn that we control personal information from someone who is not eligible to use the Activity, we will take appropriate steps to delete it.
8. Security and international processing
We use reasonable technical measures designed to protect B4D, including server-side OAuth secret handling, Activity-instance validation, restricted browser permissions, and no-store token responses. No internet service can guarantee absolute security.
Discord, Supabase, Vercel, and their service providers may process information in countries other than yours. Where applicable, those providers describe their international transfer safeguards in their policies.
9. Changes to this policy
We may update this policy as B4D changes. We will post the revised policy here and change the "last updated" date. If a change materially affects how we use information, we will provide additional notice when reasonably required.
10. Contact
For a privacy question or request, contact the Blox 4 Dead developer or the server administrator who made the Activity available through that Discord server or channel. Start the message with "B4D privacy request" and include your Discord user ID and approximate use date. This build does not yet publish a dedicated support email or contact form; do not include credentials, OAuth codes, tokens, or other secrets in a request.