PeteZah Legal
Privacy Policy
Last Updated / Effective Date: July 24, 2026 Document Version: 2026-07-24 This Privacy Policy explains what information PeteZah / Arc Glass Browser and related services (the "Service," "we," "us") collect, how we use it, and the choices you have. It should be read with our Terms of Service and DMCA / Copyright Policy. 1. Scope This Policy covers data processed when you visit our sites, pass verification, create an account, use proxy/relay features, claim links, play catalog games/apps, view ads, or interact with community features. It does not control third-party websites you visit through the proxy — those sites have their own policies. 2. Categories of Information We Collect 2.1 Account and profile data (if you register): email address; password (stored as a one-way hash, e.g. bcrypt — we do not store plaintext passwords); optional username, bio, avatar/banner, school, age, or similar profile fields you choose to provide; email verification status; optional two-factor authentication secrets/metadata for features that require them (e.g. Get Links); role flags (e.g. admin) for authorized operators. 2.2 Security, session, and anti-abuse data: IP addresses (and derived geolocation/ASN where available); user-agent and basic device/browser signals; timestamps of access, sign-in, sign-up, and sensitive actions; session identifiers and cookies (including authentication sessions and verification/legal-acceptance cookies); CAPTCHA / proof-of-work challenge metadata; rate-limit counters; ban and reputation signals; rough connection or presence signals used for live-site / capacity features; referral or landing path where relevant to abuse review. 2.3 Service usage (operational): feature usage necessary to operate the product (e.g. settings sync payloads you choose to save; link-claim events and cooldowns; feedback/comments you submit; admin audit actions). We aim NOT to build a commercial advertising profile of your private browsing destinations, but technical logs needed for reliability and abuse prevention may incidentally include request metadata. 2.4 Proxy / technical transmission: while proxying, systems necessarily process URLs, headers, and content bytes in transit to fulfill your request. We do not sell your browsing history. Retention of detailed proxy destination logs, if any, is limited to what we reasonably need for security, debugging, capacity, and legal compliance, then discarded or aggregated. 2.5 Advertising technology: Ad Partners (such as Adsterra, AppLixir when enabled, Google advertising tags, and others) may set cookies, use pixels, or collect device/IP/user-agent data under THEIR policies to serve and measure ads. Their processing is governed primarily by those partners. See Section 7 of the Terms regarding aggressive or malicious ad creatives. 2.6 Analytics: we may use first-party or third-party analytics (including tag managers / measurement IDs present on some pages) to understand aggregate traffic and reliability. 2.7 Communications: emails you send us; verification or transactional emails we send you. 3. How We Use Information We use information to: provide and maintain the Service; authenticate users; verify email where required for certain features; enforce Terms; detect bots, fraud, credential stuffing, DDoS, scraping, and other abuse; apply bans and cooldowns; improve performance and UX; communicate service notices; comply with law and valid legal process; and protect users, operators, and the public. 4. Anti-Abuse Philosophy (What "Generous but Firm" Means) We try to keep friction low for legitimate users. At the same time we operate meaningful anti-abuse controls, which may include verification gates, signed cookies, rate limits, IP reputation, challenge/response, session binding, automated blocks, manual staff review, and cooperation with infrastructure providers. Those controls may process the security data listed above. Circumventing them is prohibited. 5. Legal Bases (Where Applicable) Where GDPR/UK GDPR or similar frameworks apply, we rely on one or more of: performance of a contract (providing the Service you request); legitimate interests (security, anti-abuse, service improvement, limited analytics); consent (where we ask for it, including legal-document acceptance and certain optional features); and legal obligation. 6. Sharing and Disclosure We do not sell your personal information as "sale" is commonly understood for raw email lists. We may share data with: infrastructure and email providers acting on our instructions; Ad Partners and analytics vendors as needed to display/measure ads and traffic; professional advisors; and authorities or complainants when required by law or necessary to protect rights, safety, or the Service (including responding to valid DMCA or security reports). Business transfers (e.g. change of operators) may include user data as an asset under continued confidentiality commitments where feasible. 7. Cookies and Similar Technologies We use essential cookies/tokens for sessions, security gates, and recording that you accepted current legal documents. Disabling them may prevent access. Advertising and analytics cookies may be set by partners. Browser controls and industry opt-outs may limit some non-essential cookies; essential security cookies generally cannot be disabled if you wish to use the Service. 8. Retention We retain account data while your account remains active and for a reasonable period afterward for security, dispute, and legal purposes. Security logs are kept for rolling windows appropriate to abuse investigation. You may request account deletion subject to residual backup/log copies and legal holds. 9. Security We use hashing for passwords, HTTPS where configured, httpOnly cookies for sensitive tokens, rate limiting, and related controls. No method of transmission or storage is perfectly secure. You are responsible for device security and for not interacting with malicious advertisements. 10. International Transfers Servers and vendors may be located in multiple countries. By using the Service you understand information may be processed outside your home country, with safeguards where required by law. 11. Your Choices and Rights Depending on your location, you may have rights to access, correct, delete, export, or restrict certain personal data, or to object to certain processing. Contact contact@petezahgames.com. We may verify your identity before fulfilling requests. You may close your account where the product supports it. You may withdraw consent for optional features; essential processing for security may continue if you keep using the Service. California / similar U.S. state laws: we do not knowingly "sell" or "share" personal information for cross-context behavioral advertising as a primary business model, but Ad Partners may engage in advertising measurement. Use platform/ad settings and browser controls where available. You may designate an authorized agent as permitted by law. 12. Children We do not knowingly collect personal information from children under 13 (or the applicable higher age). If you believe we have, contact us and we will take appropriate steps to delete it. 13. Do Not Track There is no uniform DNT standard we can promise to honor across Ad Partners. Our own essential security tooling will continue to function. 14. Third-Party Links and Proxied Sites We are not responsible for privacy practices of third-party sites, apps, ad landing pages, or destinations you open through the Service. 15. Changes We may update this Policy by posting a new version and version identifier. Continued use after the effective date means you accept the updated Policy. Re-acceptance may be required at the verification gate when the legal version changes. 16. Contact Privacy questions: contact@petezahgames.com Community: https://discord.petezahgames.com