Privacy policy
Privacy Policy
This policy describes the production historical-player service.
The Owner accepted the residual risk of displaying attributed player names and historical facts. This is an independent project, not an opinion from external counsel or an endorsement by the NBA, any team, or any player.
Build A Hooper is operated by PENG CHAI, an individual operator based in Oregon, United States. The service is provided at buildahooper.dev. For support, privacy or deletion requests, intellectual-property complaints, or security reports, email support@buildahooper.dev.
Information handled by the service
- Guest session: a random guest-session credential, CSRF credential, session expiry, and server-side session state.
- Game and run: mode, position, version references, round choices, refresh state, fictional scenario choices, calculated output, and operational timestamps.
- Published result and challenge: random public identifiers, an allowlisted result, immutable versioned board reference, challenge state, timestamps, and a keyed digest used to verify a deletion credential. The tested application does not persist or replay the raw credential after initial delivery.
- Request and security: information ordinarily processed to deliver and protect requests, potentially including IP address, user agent, timestamps, route information, and security events. The production Cloudflare inventory is not yet verified.
- Communications: email and information voluntarily sent to support@buildahooper.dev. There is no in-product contact form.
The candidate does not request the guest user’s account profile, name, birth date, social handle, payment information, gameplay free text, uploads, or open user-generated content. Historical player names and approved biographical fields are content sourced from pinned public records; they are not collected from the guest user. This policy must be revised before any new collection feature is enabled.
Purposes
Information is handled to provide the guest game flow, keep server-authoritative state, calculate fictional output, create public links at the user’s request, process valid deletion requests, prevent abuse, protect and diagnose the service, and answer support or rights requests.
Public result and challenge links
Anyone who obtains a published link can view its allowlisted content. The link is not private. Search-engine noindex instructions are not access control. Do not associate secrets or personal information with a shared link.
Cookies and browser storage
The implementation uses the strictly necessary bah_guest cookie, a bah_one_time_deletion_notice sessionStorage marker, runtime memory for a CSRF credential and temporary UI state, and server-side state. See Cookie and Storage Policy.
Providers, analytics, and advertising
The service runs on Cloudflare Workers, Workers Assets, and D1. Cloudflare may process requests, application state, operational logs, caches, and backups under its service terms. Payments and advertising are disabled.
Google Analytics and Plausible are configured for optional visit and usage measurement, and Microsoft Clarity is configured for optional interaction diagnostics, heatmaps, and session replay. Build A Hooper does not load these providers’ external scripts or send analytics requests until the user expressly accepts optional analytics. A user can decline or later disable optional analytics. See the Cookie and Storage Policy for the preference record and provider-specific storage boundary.
Retention and deletion
Private guest sessions and runs have a 24-hour application expiry in tested local code. No approved claim states how long published objects, provider logs, caches, backups, tombstones, or support email are retained.
A valid deletion request makes the active result and linked challenge unavailable in tested local code. It does not promise immediate deletion from every log, cache, backup, email system, provider system, or third-party copy.
Security
The tested local implementation uses narrow measures including random identifiers, HttpOnly guest cookies, same-origin and CSRF checks, server-side validation and recomputation, keyed deletion-credential verification, and no-store API responses. No system is completely secure; these controls are not a promise that the service is secure, anonymous, private, or completely safe.
Rights, corrections, and children
Depending on location and applicable law, a user or data subject may have rights concerning personal information. Contact support@buildahooper.dev for a privacy, identity, source correction, or rights request. An affected historical player record may be suspended while a request is reviewed. Build A Hooper is a general-audience service, is not directed to children under 13, and is not designed to knowingly collect their personal information.
Changes and contact
Material changes should receive notice appropriate to their effect. Contact support@buildahooper.dev for questions, support, privacy or deletion requests, IP complaints, or security reports.