Privacy Policy

Effective 10 September 2026

The short version

  • We collect what running the site and the games needs: your account details, your play history, and your Tickets ledger.
  • We do not sell your data, and we do not run cross-site ad tracking ourselves.
  • Game developers see how their game performs. They never see your email address.
  • Cookies here are ours, not third-party trackers, until ads switch on and Google sets its own.
  • Deleting your account and exporting your data are both self-serve, in Settings. Deletion takes 30 days, and you can cancel in that time.
  • You can turn off spectating and control what other players see of your profile.
  • Any questions: write to privacy@miniant.games.

Who we are, and what this covers

MiniAnt Games runs miniant.games, a portal of browser games, and the developer portal at publish.miniant.games where other people publish games onto it. The site is operated by Miniant Labs Limited, a company in Bangladesh, and that company is the one responsible for your data under this policy.

This policy covers everything that happens on miniant.games itself: signing in, playing, chatting, spectating, and buying things. A game you play through us can have its own developer, and that developer is a separate party from us for the data its game handles inside its own iframe. We say plainly, section by section, what we hand a game and what we never do.

What we collect, by situation

We collect different things depending on what you are doing on the site. Here is the whole list, organised by situation rather than by data type, because that is the order you actually encounter it in.

Just visiting

Loading any page sets our functional cookies (listed below) and sends basic technical information — your browser, the page you loaded, and whether anything broke — to our error monitoring and performance tools. We do not build a profile of visitors who never sign in or play.

Playing as a guest

You can play without an account. We mint a guest id, stored in a cookie on your device, so we can count your 3 free sessions per device per day. A guest has no wallet, no saved profile, and no data tied to a name or email — the guest id resets when its cookie is cleared or expires.

Creating an account

Signing in needs an email address (for a one-time six-digit code) or a Google or Discord account (Apple is not yet turned on for everyone). We create a profile: a unique username, and whatever you choose to add to it — a display name, an avatar image address, a short bio, and a free-text country with a toggle for whether other players see your flag. We do not ask for your date of birth or your real name; at sign-in you confirm that you are 13 or older.

We rate-limit sign-in codes to stop abuse: at most 3 codes per email and 10 per IP address in any 10 minutes. Your IP address is used for that check and then discarded once the window passes; it is not kept as part of your profile.

Playing

We record every session you play: which game, when it started and ended, the result, and any XP it earned. If a game saves your progress, we store that save on our servers at the point you enter a level, so you can pick up where you left off. We also record integrity signals — automated anti-cheat flags — as an append-only log; these are never edited after the fact, only added to.

Games themselves run inside an iframe served from our separate game-host origin. For each game we start, we hand that iframe your display name, avatar, country flag (only if your flag toggle is on), whether you are a guest, your locale, and the cosmetics and entitlements you own for that game. We never hand a game your email address.

When ad impressions happen inside a game, we record which game, what kind of ad slot, which provider served it, and the outcome (shown, skipped, failed) — never anything about the ad's own content.

Multiplayer, spectating and chat

In a multiplayer match, the other players see your name, avatar, flag, and cosmetics — the same things a game iframe sees. Being watched is optional: the spectator switch in your settings is on by default and you can turn it off at any time. Watching someone else's match costs 2 Tickets. A spectator sees the match itself and a spectator-only chat channel; spectators cannot message the players.

If you or another player reports a game or a chat message, the report can include the message text and the surrounding context so our staff can review it fairly. Staff actions taken on a report are logged for audit purposes.

Buying things

Purchases run through Stripe Checkout. We never see or store your card number — Stripe handles that and passes us only the confirmation that a purchase succeeded, its amount, and which product it was for.

Referrals

A referral link sets a cookie with the referral code, read once when you sign up and then cleared. To catch referral fraud, we hash the referring and joining IP addresses (a one-way transformation we cannot reverse back into the original address) and compare hashes rather than raw addresses.

Contacting us

If you email us — for support, a deletion request, or anything else — we keep that email thread to handle your request and to have a record that we handled it.

Why we use it, and the legal basis for each

Most of what we do with your data is to run the account and the games you asked to use — running a site necessarily means processing the data that makes it work. Where a legal basis has a name, we use it here once and explain it in plain terms.

  • Running your account and games — sign-in, saves, sessions, the wallet — because you asked us to and we cannot provide the service without it (performance of a contract).
  • Keeping the platform fair and safe — rate limits, anti-cheat flags, fraud checks, report review — because we and every honest player have a legitimate interest in a leaderboard and a wallet that mean something. This is what "legitimate interest" means in practice: a reason that is not a contract requirement, but is fair to both of us and does not override your own rights.
  • Fixing what breaks — error monitoring and performance timings — the same legitimate interest in keeping the site working.
  • Showing ads, once they are live — personalised ads run on your consent where the law requires it (see Advertising below); non-personalised ads and the ad slots themselves run on our legitimate interest in keeping the site free to play.
  • Legal obligations — payment records, responding to a lawful request — because the law requires it of us regardless of what we would otherwise choose.

Cookies and browser storage

Every cookie we set ourselves is listed here. They are all first-party, meaning they belong to miniant.games and no other site can read them.

  • mag-web-auth — keeps you signed in. httpOnly (invisible to page scripts). Lasts up to 400 days, refreshed each time you use the site. When the session is too large for one cookie it is split into numbered parts with the same name.
  • mag_guest — identifies a guest session so we can count free plays. httpOnly. Created when a guest starts a game; expires with the guest session.
  • mag_ref — holds a referral code from a link you followed. Read once at sign-up, then cleared immediately.
  • mag_rail_hidden — remembers whether you collapsed the sidebar. A preference, nothing more.

Games run inside their own iframe and may use their own browser storage (for example, to remember a volume setting) inside that iframe's own origin. That storage belongs to the game, not to us; we don't read it and this policy doesn't cover what a specific game chooses to store there — its developer is responsible for that.

Once ads run on MiniAnt, Google sets its own advertising cookies and identifiers in the ad slots, subject to the consent choice described in the next section.

Advertising on MiniAnt

The ad layer is built and switches on once our AdSense account is approved and live; until then, nothing in this section is running yet. When ads run on MiniAnt, here is how they will work.

Ads appear as interstitials between games and as rewarded ads you choose to watch for a benefit (see the Tickets section of our Terms). You never see an ad in your first session on the site. If you have MiniAnt Plus, interstitial ads are removed for you; rewarded ads you opt into still play, since you are asking for the reward.

Google is the ad network (AdSense / H5 Games Ads). If you are in the EEA, the UK, or Switzerland, we will ask for your consent before any personalised ad is shown, through a consent banner, and ads will run in non-personalised form until you answer. You can change that choice at any time under Settings → Legal & data, whether or not you ever saw the banner. Outside those regions, ads may be personalised by default, subject to Google's own settings for your account and browser.

Who we share it with

We do not sell your data, to anyone, ever. We do not run our own cross-site ad tracking. What we do share:

  • The vendors who run the site for us — Supabase (our database and sign-in system), Vercel (hosting), Cloudflare (the game host, the multiplayer relay, and file storage), Stripe (payments), Resend (the emails we send you), Upstash (rate limiting), Sentry (error reports), and, once live, Google AdSense / H5 Games Ads. Each only sees what it needs to do its job for us.
  • Game developers — a developer gets aggregated statistics for their own game and ad-impression counts, and is paid a share of ad revenue tied to their game. They never receive your email address, and a developer is a separate party from us for what happens inside their game's own iframe.
  • Other players — your name, avatar, flag, and cosmetics are visible to players and spectators in a match you are part of, as described above.
  • Legal requests — we disclose data if we are legally required to, and no further than that requirement.

Where your data lives

Our database and the site itself run in Mumbai, India (Supabase and Vercel's ap-south region), so your data lives outside Bangladesh and, most likely, outside your own country too. Cloudflare serves games and the multiplayer relay from whichever of its data centres is nearest you, and Stripe, Sentry and Resend process their part in the United States. Where a transfer like that needs a legal safeguard, we rely on our vendors' standard contractual clauses, the mechanism the law provides for exactly this.

How long we keep it

  • Your account and Tickets ledger: for as long as the account exists. We keep ledger history because it is what keeps leaderboards and refunds honest.
  • After you ask us to delete your account: ledger rows are kept, with your identity removed from them, for up to 12 months to handle fraud and refund disputes, then deleted.
  • Rate-limit records: a few minutes, just long enough to enforce the limit.
  • Guest counters and the guest cookie: reset daily, and expire with the cookie.
  • Referral IP hashes: 90 days.
  • Error reports in Sentry: Sentry's own default retention, 90 days.
  • Payment records in Stripe: for as long as Stripe's own legal obligations require.

Your rights, and how to use them

You can ask us to access, correct, delete, or export your data, or to object to a particular use of it, at any time by emailing privacy@miniant.games. We confirm it is really you by asking you to write from the email address on the account. Where we rely on your consent (personalised ads), you can withdraw it at any time using the consent control described above, and that withdrawal does not affect anything already done under it.

Account deletion and data export are now self-serve, under Settings → Legal & data. Export hands you a JSON file of your data straight away. Deletion deactivates your account immediately and schedules it for permanent erasure 30 days later; you can cancel at any point in those 30 days by signing back in, and after that it cannot be undone. You can still email privacy@miniant.games if you would rather a person handled it. Before you ask, know that deleting your account forfeits your Tickets balance, MiniAnt Plus, cosmetics, and pass progress, and none of it is refunded.

Deletion erases your profile, saved game progress, friends and follows, and notifications, and replaces your player name everywhere it appears so that no one can tell who you were. Two things survive it. We keep your purchase and Ticket records — what was bought, when, and for how much — because tax and accounting law requires us to hold financial records for a number of years, and because those entries are one half of a double-entry ledger that would stop balancing if we removed them. We also keep the bare record that you accepted these terms, and when, because that record is the evidence for the agreement itself. Neither is kept for marketing, profiling, or any other use; we rely on our legal obligation to retain them, not on your consent. Everything in them is detached from your name once the erasure runs.

If you are in the EEA, the UK, or Switzerland

The rights above are the ones your data protection law already gives you (access, rectification, erasure, portability, objection, and withdrawal of consent), and you also have the right to complain to your local data protection authority. We would rather hear from you first and put things right.

If you are in a US state with a privacy law

The same rights apply, under whichever state law covers you. We do not sell personal information and there is nothing to opt out of on that front; the access, correction, deletion, and appeal rights your state law gives you work the same way as described above.

Everywhere else

We extend the same access, correction, deletion, and export rights to every player, regardless of where you live, because it is the right way to run this.

Children

MiniAnt is a general-audience site for players aged 13 and over. If you are under 18, a parent or guardian needs to agree to our Terms on your behalf before you use the site. We do not knowingly collect data from anyone under 13; if we learn that we have, we delete it. If you believe a child under 13 has an account, please email privacy@miniant.games and we will look into it right away.

Security

Connections to the site are encrypted, sign-in cookies are invisible to page scripts, identifiers are hashed wherever the raw value is not needed, and each vendor and staff role can reach only what its job requires. No system is perfectly secure and we will not pretend otherwise; if we ever learn of a breach that affects you, we will tell you.

Changes to this document

When we make a material change to this policy, we will update the effective date above and add an entry here. Small clarifications that do not change what we actually do may not get their own entry.

  • 10 September 2026 — Account deletion and data export became self-serve, and this policy now describes the 30-day window and what survives deletion. Ad-personalisation consent moved into Settings.
  • 7 September 2026 — First full version, replacing the placeholder.

Contact

For privacy questions, or to exercise any of the rights above, email privacy@miniant.games. For anything else, our support team is at support@miniant.games. You can also read our Terms of Service.