Privacy Policy
This policy explains how we handle information across everything we run for game developers:
- This site,
developer.yes2games.com, including the “Get Started” form. - The Yes2Games dashboard,
dashboard.yes2games.com, where studios upload builds, run QA, and read reporting. - The hosted Yes2SDK MCP endpoint,
mcp.yes2games.com, which serves our SDK documentation to AI assistants.
We've kept it plain. If anything is unclear, email us and we'll explain.
Who we are
The data controller is Yes2Games (Y2G Pte. Ltd.), 160 Robinson Road, 068914 Singapore. When this policy says “we”, “us”, or “Yes2Games”, that is who we mean, and it applies to all three surfaces listed above. You can reach us any time at [email protected].
What we collect and why
Each surface collects different things, and none of them collects more than it needs. We don't track you across the web, we don't buy data about you, and we don't use any of this for advertising or profiling.
The “Get Started” form on this site
There are two ways to send us a pitch, and it is worth being clear about both.
Signing in with Google is optional. If you choose it, Google hands this page a signed identity token for your Google account. We pass that token to our dashboard at dashboard.yes2games.com, which verifies it with Google and returns a session token and your email address. That saves you typing your name and email, and it is the only sign-in anywhere on this site. If you would rather not, fill the form in by hand — no account is required to pitch.
Whichever route you take, we end up holding:
- Your name. So we know who we're talking to and can address you properly.
- Your email address. This is how we reply, and our only way to reach you.
- Your studio or team name. So we understand who is behind the games.
- Your game links, and where each one is live. So we can look at the games and evaluate the fit.
- Whether you have an HTML5 version ready. If not, whether you're looking for a porting partner and which engine the game uses. That tells us what help you might need.
- Anything else you choose to tell us in the notes field. It's optional, entirely up to you.
- Your consent and the time you gave it. We record that you agreed to this policy, and when, so we have a clear basis for contacting you.
The form also carries one hidden field you never see or fill in. It is a spam trap: automated bots fill in every field on a page, a person leaves this one empty, so a filled-in value tells us the submission was not typed by a human. It is sent only when you fill the form in by hand, and it holds nothing about you.
The purpose is narrow: to evaluate your pitch and respond to it.
The Yes2Games dashboard
The dashboard is the signed-in product. If you have an account there, we hold:
| What we hold | Why we hold it |
|---|---|
| Your account — name, email address, the sign-in identity you used, and which studio team you belong to | To sign you in and to decide what you are allowed to see |
| Game builds you upload, and the bundles we generate from them | To run QA on a build and package it for the platforms you target |
| QA and Inspector session results — the findings, logs, and event data captured while testing a build | So you can read the report for a build, and so we can help you when something fails |
| Reporting we receive from stores and platforms, including Android Vitals crash and performance data | To show you how your published games are performing and earning |
| Access tokens for the third-party platform accounts you connect | So the dashboard can publish builds and read reporting on your behalf, without you re-authorising every time |
| Your AI assistant conversations — the messages you send the integration assistant and the replies it gives | So a conversation survives a page reload, and so we can diagnose the assistant when it answers badly |
Two of those deserve to be said plainly rather than buried in a table.
We store access tokens that belong to your third-party platform accounts. That is what lets the dashboard upload a build or pull reporting for you. It also means a token you grant us sits on our servers until you ask us to remove it. We use each token only against the platform that issued it, and only for the actions the connection is for.
We store your AI assistant conversations, including the text of your messages. Treat the assistant as a place whose contents we can see. Don't paste secrets, credentials, or anything you would not want stored into it.
One more thing belongs here, because it affects your players rather than you. A bundle we build for Yandex can carry Yandex Metrica. If you set a Yandex Metrica counter ID on a game, the bundle we generate for the Yandex platform includes Yandex's Metrica tag, which collects analytics about the people who play that game. That is your analytics account and your relationship with your players; we insert the tag you asked for and nothing more, and no tag is inserted unless you set a counter ID.
Reviews we import from game platforms
Where a studio has connected a platform, the dashboard imports the reviews left on that studio's games. A review record holds the review text, the rating, and the reviewer name exactly as the platform publishes it. We keep it so a studio can read and reply to its reviews in one place, and we run it through a classifier that labels sentiment and flags reviews that need attention — that step sends the review text to our model provider. We collect nothing about a reviewer beyond what the platform already publishes, we don't join a review to any other record, and we don't use reviews to build a profile of anyone. If you left a review and want our copy removed, email us and we will delete it.
The hosted MCP endpoint
mcp.yes2games.com serves our SDK documentation, API reference, and platform-compliance rules to AI assistants over the Model Context Protocol. There is no account on it and nothing to sign in to. When your assistant calls a tool there:
- The request travels over HTTPS and carries whatever your assistant sent — normally a tool name and its arguments, such as a platform name, an SDK module name, or a path from your project.
- The endpoint is stateless. It holds no account, keeps no session, and writes nothing to a database. It answers from fixed documentation data and retains nothing about your request.
- Our web server keeps a standard access log line: the connecting IP address, the forwarded-for header, any HTTP auth user, timestamp, request method and path, response status and size, referrer, and user agent. The endpoint sits behind Cloudflare, so the connecting address is normally Cloudflare's and your own address is the one carried in the forwarded-for header. Request bodies are not logged, so the arguments your assistant sends — including anything quoted from your project — do not land in our logs.
- We do not use this traffic to train any model.
Who we share it with
We do not sell your data. We don't rent, trade, or hand it to third parties for their own use. Your pitch is read by the Yes2Games team who assess new games; your dashboard data is seen by the people on your team and by the Yes2Games staff who operate the service and support you.
We rely on service providers to run the service — hosting, storage, email delivery, Cloudflare as the network and CDN layer that every request to these surfaces passes through, and Anthropic as the model provider behind the AI assistant. They act on our instructions and only to the extent needed to run the service. Where you have connected a third-party game platform, we exchange data with that platform to do what you asked (upload a build, read its reporting); what that platform then does is covered by its own policy, not this one.
How long we keep it
- Pitches from the form on this site — we keep a pitch until we've reviewed and responded to it, then for a reasonable period in case the conversation continues. After that we delete it.
- Dashboard data — kept while your account is open, because it is the product: your builds, reports, and history are what you came for. Ask us to delete your account or any part of it and we will.
- Platform access tokens — kept while the connection is in place. Email us and we will delete the token for any platform you have linked.
- Web server access logs — the access-log line described above. It is written for every web surface we run, not the MCP endpoint alone, rotated daily and kept for up to 15 days, then deleted. Operational service logs, which contain no request content, are kept for up to 30 days. Cloudflare sits in front of these surfaces and keeps its own logs under its own retention, which we do not control.
Your choices
You can ask us to show you the information we hold about you, correct it, or delete it. Email [email protected] and we'll take care of it. If you're asking about a pitch, please write from the address you used to submit the form, or tell us enough for us to find your record.
The same address covers the rest: ask us to delete our copy of the access token for a platform you have linked, to delete an assistant conversation, or to close your account entirely, and we will do it.
Changes to this policy
If we change how any of these surfaces handles your information, we'll update this page and revise the effective date at the top.
Contact
Questions, requests, or concerns about your data? [email protected], or write to Yes2Games (Y2G Pte. Ltd.), 160 Robinson Road, 068914 Singapore.
The terms that apply when you use these surfaces are set out separately in our Terms of Service.