// Security
Player Privacy
Last updated June 19, 2026
How Players Access a Playtest#
Players join through the Userplay player application. They receive a unique, signed playtest link — typically delivered by the studio through its own channels (email, Discord, an in-game prompt, etc.). The web flow asks the player to sign in before joining, which lets them manage their own sessions and profile in the player portal.
The signed link grants access only to the specific playtest’s recording and consent flow. It cannot be used to access any other part of the studio’s workspace.
Consent Before Recording#
When a player opens the playtest URL, Userplay shows them a consent screen before any recording begins. The screen clearly describes:
- What will be captured (screen, and microphone and system audio if enabled).
- Which studio is running the playtest.
- How long recordings will be retained.
The player must explicitly accept before the recorder starts. If they decline, no data is captured and no upload occurs.
What Players Can Control#
Players have meaningful control throughout the session:
- Before recording starts — they choose which screen, window, or browser tab to share using the browser’s built-in picker, and can decline microphone capture if the playtest requests it.
- During recording — they can stop the session at any time. Data captured up to that point is only uploaded if the player explicitly confirms.
- After the session — players can ask the studio (the data controller) to delete their recording. Studios can delete recordings per recording or in bulk. Players can also contact privacy@userplay.io for requests that require more targeted action.
What Players See and Don’t See#
Players see only the consent screen and the playtest itself. They cannot see:
- Other players’ sessions or recordings.
- The studio’s workspace, other playtests, or any recordings.
- Any data about other participants in the same study.
Microphone Defaults#
Microphone capture is optional by default, and Userplay does not capture webcam video. A studio must explicitly enable the microphone per playtest. Even when enabled by the studio, the player’s browser presents its own permission dialog — the player retains control at the browser level.
Data Minimization#
Userplay is designed to capture what is needed for the playtest and nothing more. The screen recorder is the only live capture path. Optional telemetry agents operate only after gameplay ends — they never capture data during active play, and they never capture credentials, cookies, or browsing history outside the playtest context.