Privacy Policy
Last updated 3 March 2026
Sablecrest, Inc. ("Sablecrest", "we") provides content delivery infrastructure to game studios. This policy explains what we collect, why, and what you can ask us to do about it. It covers this website and the Sablecrest service.
1. Who we are
Sablecrest, Inc. is a Delaware corporation with its principal place of business in Los Angeles, California, United States. For privacy questions, contact privacy@sablecrest.dev.
2. Two different relationships
We handle data in two distinct roles, and it matters which one applies:
- As a controller — for people who contact us, evaluate the product, or administer a studio account. That's the data you give us directly.
- As a processor — for data that passes through the service on behalf of a studio. The studio decides what its game sends us; we act on their instructions.
3. What we collect
| Data | Why |
|---|---|
| Name, email, studio, and anything you type into our contact form | To reply to you and to decide whether to onboard your studio. |
| Account details for studio administrators | To operate the service, issue API keys, and bill where applicable. |
| Service logs — IP address, timestamp, request path, response status, bytes transferred, user agent | To deliver content, keep the service up, investigate abuse, and diagnose faults. |
We do not run advertising, we do not sell or share personal information, and we do not build cross-site profiles. This site sets no cookies and loads no third-party scripts or fonts.
4. Player data
Our SDK is designed to need as little as possible about a player. The service resolves content against an app identifier, a build number, and whatever cohort attributes the studio chooses to send. We do not ask for names, email addresses, or device advertising identifiers, and we would rather studios did not send them. If a studio does send personal data, they are the controller and their own privacy policy governs it.
5. Retention
- Service logs — 30 days, then deleted.
- Contact enquiries — up to 24 months, so we remember prior conversations.
- Account records — for the life of the account, plus any period we are required to keep billing records.
6. Subprocessors
We keep this list short on purpose.
| Provider | Purpose |
|---|---|
| Our hosting provider (United States) | Runs the delivery endpoint and stores bundles. |
| Our email provider | Delivers and receives correspondence. |
We'll tell affected studios before adding a subprocessor that handles their data.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict how we use it, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them — and since we don't sell or share personal information, there is nothing to opt out of. If you're in the EEA or UK, you may also lodge a complaint with your supervisory authority.
Email privacy@sablecrest.dev and we'll respond within 30 days. If a studio is the controller, we'll pass your request to them and help them answer it.
8. International transfers
We operate in the United States, so data you send us is processed there. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum.
9. Security
Traffic is encrypted in transit. Access to production is limited to the people who need it and is authenticated with hardware keys. We're a small team and we don't claim certifications we don't hold — if you need specifics for a vendor review, ask and we'll answer honestly. To report a vulnerability, see our security.txt.
10. Changes
If we change this policy materially we'll update the date above and, for anything that affects a live integration, tell studio administrators directly.