Gaming
The file is built from how you play and what you spend, and policies reserve the right to record voice and text chat. Anti-cheat software reads details of your machine. How long any of it is kept is left to the company, with no fixed end.
The read at a glance
Accounts are often opened by children and kept for years afterwards.
A leak exposes your account, your chats, your spend, and often a child's data.
Account and purchase data persists for years; moderation records longer.
Play needs little; age-assurance and appeals may demand a face or ID check.
Industry profile reviewed 23 August 2026. Also machine-readable via the free API.
If it leaks
A gaming account is a resale target with a card attached, and years of voice and text chat sit behind it. Where a child plays, what leaks is those messages and the age check that proved how old they are.
What repeats in the policies
The game reads how you play, and can listen
Every policy we read builds a profile from how you play and what you spend, including guesses about your tastes that you never typed out. Voice and text chat with other players can be recorded and reviewed, and policies word that as their own choice, so you cannot tell whether any one match was kept.
A child's account runs on a parent's consent
Policies check age and ask for a parent's consent, then switch off chat, purchases or social features rather than turn the child away. The ages vary: supervised accounts from seven on one service, a consent gate at thirteen on another, social features held back until sixteen on a third. Children's-privacy rules say a child's data cannot be kept indefinitely, and US regulators have fined game makers hundreds of millions of dollars for collecting it without a parent's consent.
The account closes and the data stays
Every policy we read keeps your data for as long as the company judges necessary, with no fixed end. Deleting the account rarely ends that: several reserve open-ended holds for legal reasons, fraud or player safety. Some add that tax and commercial law can require your purchase records to be kept for up to ten years, whatever you do with the account.
What a company here typically holds
Worked out from the industry, not from any one company. What you actually handed over is yours to record.
What this can reveal about you
Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.
Who matters to you Possible
Who you play and talk with maps a social graph.
What lawfully stays after you leave
Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.
Safety and abuse records They set it as long as the ban holds
To enforce bans and stop blocked or abusive users coming back.
Online-safety and child-protection reports Law sets it 1 year for content, 5 for the report reference
A legal duty to preserve child-safety reports, which overrides an erasure request for that data.
Tax and accounting records Law sets it about 6 years
Tax and company law makes them keep billing and payment records.
Records tied to a live or potential dispute They set it the limitation period of the claim
They can keep records to defend a live or possible legal claim.
Who wants this data
The advertising ID on your phone and what you do in the game feed ad markets that match you across other apps. One ad network embedded in thousands of apps aimed at children was fined for tracking locations without knowledge or consent. A single ransomware attack on one publisher exposed the personal data of more than fifteen thousand people.
Sold or shared Likely
Spend and engagement data drives targeting and monetisation.
AI training Moderate
Behaviour and chat train matchmaking and moderation models.
Even anonymised, this can still be you
In-game chat carries a writing style that language models attribute at scale (Staab et al., ICLR 2024), and four transactions identify 90% of people (de Montjoye et al., 2015).
Name, date of birth, postcode Typical
Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).
Payment patterns Typical
Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).
How you write Typical
Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).
Face and voice Typical
A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.
Browsing fingerprint Typical
Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).
The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)
The wording that does the work
Clauses that recur across this industry, and what each one actually permits.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.
The move An objection tells them to use your data to run the service and nothing more.
“we do not sell your personal information”
Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.
The move Use the do-not-sell switch where there is one, and put an objection in writing as well.
“service providers, partners, and affiliates”
This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.
The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.
“aggregated or de-identified information”
Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.
The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.
The move Which reasons apply to you, and how long each runs, is a request of its own.
“you grant us a licence to use your content”
This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.
The move Their terms say whether the licence ends when the account does. Close the account and log the date here.
“we reserve the right to monitor and record voice and text chat”
Blanket recording of what you say and type to other players, worded as the company's own choice. You cannot tell whether any one session was kept.
The move What was recorded and what is still held is theirs to answer.
“a machine 'fingerprint' or 'hash' of your machine components”
Anti-cheat software reads machine-level details of your computer and can run in the background while you play. Some policies extend this to outside anti-cheat firms.
The move What the anti-cheat reads from your machine is theirs to answer.
“if a report is made, and action is taken, the communications would be retained for up to 2 years”
A short chat window becomes a multi-year hold once another player reports you or a sanction attaches. The trigger sits outside your control.
The move Whether a report has put your chat on a longer hold is theirs to answer.
Their own policy is the one that binds them. Pin it down with a request, and keep the reply.