Privacy policy
Last updated: September 5, 2026
The short version
Gessa is a free browser game engine. We show no ads, set no advertising trackers, and never sell your personal data. This policy covers the website, the Studio, the API and MCP server, and the desktop app.
What we collect and why
On the website, our hosting provider keeps server logs (IP address, browser, pages requested) to serve and secure the site. The “describe a game” box sends what you typed to the Studio when you press the button.
In the Studio we process your account details, the projects and assets you create or upload, and your generation and usage activity, to run your account and provide the service. AI coding agents can self-provision an anonymous workspace with an API key; a claim link can later move that workspace to your account. If you email us, we keep your address and message to reply. If you buy something, our payment provider handles the payment and we never store full card numbers.
Cookies and analytics
Our analytics provider (PostHog, in the United States) receives pages viewed, referrer and campaign source, interaction events, a pseudonymous browser id kept in a first-party PostHog analytics cookie shared across gessa.ai subdomains, and session replays in which all text and inputs are masked. We use this to understand how Gessa is used and to improve it. After you sign in, it may be linked to your account. An invisible bot check (Cloudflare Turnstile) runs in the Studio, anonymous performance measurements go to our own servers, and your browser stores a language preference.
In regions whose law requires it, we ask before setting analytics cookies or recording sessions. That choice, and the region we detected, are kept in two small cookies, gessa_consent and gessa_region, that are not tied to your identity; you can change the choice at any time by clearing cookies. Everywhere, you can limit analytics with your browser’s Do Not Track setting, which we honor, or by blocking or clearing cookies.
Separately from analytics, the Studio keeps you signed in with host-only session cookies whose names begin with the __Host- prefix; the front door may set one non-secret gessa_login_hint cookie to show the right sign-in or open-studio button. These are necessary for the service and are not used for analytics.
Who we share with
We share data only with the service providers who run Gessa (hosting, analytics, bot protection, payments, and email), with the people you invite to a project, when the law requires it, and as part of a business transfer. We never sell it.
Where data is processed
Our providers may process your data in the United States and elsewhere, under appropriate safeguards.
How long we keep it
We keep personal data for as long as we need it for these purposes, or as the law requires, then delete or anonymize it.
Security
We use reasonable measures to protect your data. No method is perfect.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, port, or object to how we use your data, to withdraw consent, and to complain to your local privacy regulator. Email contact@gessa.ai to exercise them. We may ask you to verify your identity.
Children
Gessa is not for anyone under 13. We do not knowingly collect a child’s data, and we delete it if we learn we have. If you are under 18, you need a parent or guardian’s agreement to use Gessa.
Changes and contact
We may update this policy and post the new version here. For material changes we will give notice, for example by email or in the Studio. Questions: contact@gessa.ai.