LNVPlay Privacy Policy
Last updated: September 7, 2026
Document version 2026-09-07
This Privacy Policy describes how LNVPlay (“LNVPlay,” “we,” or “us”) handles information when you visit lnvplay.com and play Late Night Rumble Arena. It is written to match how the service actually works. It is not a claim of legal compliance with any particular statute.
1. Data minimization
LNVPlay is a temporary livestream companion. Players do not create accounts. We ask for a room code and an agreement to the current Terms, not for a real name, email, phone number, age, date of birth, school, address, photos, videos, or social-media login.
2. How LNVPlay works
A host creates a temporary room. A five-digit room code appears on the Late Night Vision livestream. You visit LNVPlay, enter the code, agree to the Terms and acknowledge this Privacy Policy, receive a server-generated display name, and play. When the host closes the room, the code stops working, gameplay sessions end, and the public site returns to a dormant join page. A later room may reuse a previously used code.
3. Temporary player information
While you play, LNVPlay processes:
- The room code you enter
- A server-generated player identifier
- A server-generated display name
- The operator/character you select
- Scores and live game state
- A temporary player session
- Limited operational diagnostics (connection and lobby status)
That gameplay information is held in memory for the room. Display names, player identifiers, and scores may be visible to other players in the same room, the authenticated display screen, and the administrator. They are removed when you leave, are removed, or the room closes. We do not keep a permanent player profile or score history.
4. Information we do not ask for
LNVPlay does not ask players for a real name, email address, phone number, age, date of birth, school, physical address, photos, videos, files, YouTube identity, social-media identity, precise location, MAC address, or a browser fingerprint. There is no player chat, direct message, public profile, friend list, or player directory.
5. Cookies
LNVPlay sets first-party cookies that are HttpOnly, SameSite=Strict,
path-scoped to /, host-only, and Secure in production:
-
lnv_player_session— authenticates your gameplay session and WebSocket. Its maximum age is the remaining room lifetime. The server revokes the session when you leave, are kicked or banned, the room closes, or the session expires. A leftover cookie may remain in the browser until that maximum age, but a revoked session is not valid. -
lnv_security_id— a random security identifier used for moderation, one active session per browser, and join rate limits. Maximum age is 30 days. It can remain after a room closes. The server stores a hash, not the raw value, when it needs the identifier. This is not an advertising identifier, but it can distinguish the same browser across visits for up to 30 days. -
lnv_display_session— used only for an authenticated display/projector connection, not ordinary play. -
lnv_admin_session— used only for the host dashboard. Default idle timeout is about 30 minutes and default absolute lifetime is about 8 hours.
Our network provider, Cloudflare, may also set its own security cookies. Those cookies, if present, are created by Cloudflare, not by the LNVPlay application.
6. Browser preferences
The browser may store local preferences that are not sent to
LNVPlay:
lnvplay.muted,
lnvplay.sfxVolume,
lnvplay.musicVolume,
lnvplay.reducedEffects, and
lnvplay.joystickSize.
They have no automatic expiration. You can remove them with Reset
local preferences on the
Accessibility page or by clearing
site data.
7. IP addresses and network security
Cloudflare processes your network address as the public edge for LNVPlay. The LNVPlay application does not store raw player IP addresses in its database and does not write raw IP addresses to its application logger. It derives a daily rotating hash from the client network address for rate limiting and related security controls. Player bans use the security identifier, not an IP address.
8. Cloudflare and YouTube
Cloudflare is used for DNS, HTTPS, tunnel ingress, and network protection. Request metadata that reaches Cloudflare is handled under Cloudflare’s terms and settings. Retention of Cloudflare logs or analytics, if any, is configured in the Cloudflare dashboard and is separate from LNVPlay application logs.
The site may include an outbound link to the Late Night Vision YouTube channel. LNVPlay does not embed YouTube, call YouTube APIs, or connect a YouTube account. If you follow that link, YouTube receives the request under YouTube’s own policies.
9. Children and teenagers
LNVPlay does not ask for age or date of birth and has no age-verification or parental-consent collection. The product is designed as a family-friendly livestream companion without social posting or player-to-player messaging. This is a data-minimization choice, not a certification of compliance with any children’s-privacy law.
10. Advertising and sale of information
LNVPlay does not use behavioral advertising, advertising pixels, or cross-site advertising trackers in the application. LNVPlay does not sell player information.
11. Moderation and security records
- A kick ends the current session. It is recorded in the admin audit log, not as a standing ban.
- A room ban is tied to the security-identifier hash for that room and is deleted when the room closes.
- A temporary ban can last 15 minutes, 1 hour, 24 hours, or 7 days and is removed about 24 hours after it expires or is revoked.
- Permanent bans are not a live player feature.
- Clearing the security cookie or using another browser can evade a cookie-based ban. LNVPlay does not fingerprint devices to prevent that.
12. Retention
- Gameplay state, scores, display names, player identifiers, and player sessions: removed on leave, removal, or room close.
- Terms/Privacy acceptance for a join: kept only with that temporary in-memory session and deleted when the session ends. LNVPlay does not keep a permanent acceptance ledger.
- Closed room administrative records: about 30 days.
- Used room-code hashes: kept as operational tombstones and deleted after about 30 days. They do not identify a player. Closed codes may later be reused.
- Admin audit events: about 90 days.
- Admin sessions: until idle/absolute expiry or logout, then removed about 24 hours later.
- Security identifier cookie: up to 30 days in the browser.
- Application and host logs: allowlisted operational events. Exact host retention depends on the production logging configuration and is separate from the 90-day admin audit.
- Cloudflare data: per Cloudflare’s configuration.
- Local preferences: until you clear them.
Room close deletes temporary gameplay data. It does not delete every security or administrative record.
13. Your requests
Privacy questions can be sent through the Contact page. Because LNVPlay does not keep permanent player accounts or real-world identity records, we may be unable to locate a particular temporary session. We do not require government identification for ordinary privacy questions.
14. Security practices
LNVPlay uses HttpOnly cookies, same-origin checks, hashed secrets, allowlisted application logs, and a restrictive content-security policy. No security measure is perfect.
15. Sharing
We use Cloudflare as the public network provider. We do not share player information with advertising networks. We may disclose information if required by law or to protect the service and other people.
16. Changes
If this Privacy Policy changes, the document version changes. The next time you join a room you must acknowledge the current version. Players already in a room are not interrupted mid-match.
17. Contact
Use lnvplay.com/contact. The currently published inbox is [email protected]. We do not publish a mailing address on this site.