Playbook Privacy Policy
Last updated: 15 September 2026
Publication note: Version 1.1 consolidates Playbook's current privacy, moderation-review, legal-contact, and website-form practices. Playbook has not appointed an EU/EEA or UK statutory privacy representative at this time. Verified representative details will be added if and when an appointment is legally required and completed.
1. About This Privacy Policy
Playbook is a platform for publishing, preserving, collecting, and discovering human-made creative and cultural work.
This Privacy Policy explains how Playbook collects, uses, stores, shares, protects, and deletes personal information when you use the Playbook mobile applications, websites, services, and related systems.
Playbook is currently operated by:
Jubryl Al-Jabane
Asad Al-Jabane
acting as individuals.
Where applicable privacy law treats the operators as controllers of personal information, they are responsible for the processing described in this Privacy Policy.
Privacy contact:
hello@playbook.cam
Telephone:
+973 3444 0587
Playbook also maintains a public Legal & Regulatory Contact page for legal, regulatory, privacy, safety, intellectual-property, and moderation matters.
2. Children’s Privacy & Age Requirements
Playbook is intended for people aged 16 and older.
You may not create or use a Playbook account if you are under 16.
Our platform is directed toward creative individuals and users, and is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data to Playbook, please contact us and we will take appropriate steps to delete it.
Some laws may continue to treat users aged 16 or 17 as children for particular privacy or online-safety purposes. Where such laws apply, Playbook will apply the relevant protections and obligations.
If we reasonably determine that an account belongs to a person under the minimum age, we may restrict or delete the account and associated information as permitted or required by law.
If you believe a person under 16 is using Playbook, contact hello@playbook.cam.
3. Information You Provide to Playbook
3.1 Account information
When you create or manage a Playbook account, we may process information including:
- your email address;
- authentication credentials and authentication-related records;
- your display name;
- your account identifier;
- account creation and update timestamps;
- account status and related security information.
Passwords are handled through our authentication provider and are not stored by Playbook as readable plain-text passwords.
3.2 Profile information
You may choose to provide profile information such as:
- display name;
- username or handle;
- biography;
- profile image;
- general location you choose to publish;
- website address;
- Instagram handle;
- other profile information made available through Playbook.
Some profile information may be visible publicly depending on the feature and your account state.
3.3 Contributions and archive information
When you submit work to Playbook, we may process:
- uploaded images;
- contribution title;
- category;
- creator or maker name;
- year;
- country or origin information;
- Story text;
- Cultural Shift text;
- revisions to that material;
- submission status;
- publishing status;
- moderation status;
- rights confirmations;
- Human-Made Standard confirmations when that system is enabled;
- related timestamps and technical identifiers.
Published contribution information may become publicly visible through Playbook.
3.4 Rights and policy confirmations
Playbook may record whether and when you confirm matters including:
- rights to publish submitted material;
- acceptance of the Terms of Use;
- acceptance of the Community Standards;
- acceptance of the Human-Made Content Standard;
- acknowledgement of the Privacy Policy;
- the exact policy version involved;
- the date and time of acceptance;
- the context in which acceptance occurred.
3.5 Reports, moderation, and safety information
If you report content, submit an illegal-content notice, request review of a moderation decision, or otherwise contact Playbook about safety, moderation, abuse, or legality, we may process:
- your name or organization where provided;
- your email address where provided;
- your account identifier where applicable;
- the content or account involved;
- the exact content location or identifier;
- report or decision type;
- the territory or legal basis you identify;
- your explanation and supporting information;
- report timestamps;
- moderation status;
- moderation scores or reason codes where applicable;
- review decisions;
- enforcement records;
- administrative notes or evidence reasonably necessary to review the matter.
The public Illegal Content Notice and Moderation Decision Review forms are designed to be available without requiring a Playbook account.
3.6 Communications and website forms
If you email Playbook or use a Playbook website form, we may process:
- your name;
- email address;
- subject;
- message;
- attachments or supporting information you choose to provide;
- information reasonably necessary to respond;
- correspondence history;
- timestamps and technical delivery information.
Do not send unrelated sensitive personal information through public forms.
Google Sign-In and Google User Data
Playbook offers Google Sign-In as an optional method for creating or accessing a Playbook account.
This section specifically explains how Playbook accesses, uses, processes, stores, protects, shares, retains, and deletes information associated with Google Sign-In.
Google user data Playbook may receive
When you choose Google Sign-In, Google may make basic Google account information available to Playbook through the authentication process.
Depending on the information available through your Google account and the permissions used for authentication, this may include:
- your email address;
- your name;
- your Google profile image or profile-image URL, where available;
- your unique Google account identifier;
- basic Google identity metadata; and
- authentication and session-related information necessary to securely authenticate you.
Playbook uses Google Sign-In for basic identity and authentication purposes.
Playbook does not request access through Google Sign-In to:
- the contents of your Gmail messages;
- your Google Drive files;
- your Google Contacts;
- your Google Calendar;
- your Google Photos;
- your YouTube account content;
- your Google Docs, Sheets, or other Google Workspace content; or
- other unrelated Google services or private Google account content.
Your Google account password is not provided to Playbook and is not stored by Playbook.
How Playbook uses Google user data
Information received through Google Sign-In is used only as reasonably necessary to provide and protect Playbook's user-facing authentication and account functionality.
This may include using the information to:
- authenticate you;
- create your Playbook account;
- identify the correct Playbook account when you sign in;
- associate your Google identity with your Playbook account;
- initialize basic account information made available through the authentication process;
- maintain your authenticated Playbook session;
- allow you to access your existing account through Google Sign-In;
- support authentication-related account management;
- protect your account against unauthorized access;
- detect or investigate fraud, abuse, or security incidents; and
- troubleshoot authentication or account-access problems.
Some basic identity information supplied during account creation, such as a name or email address, may become part of the account information Playbook maintains as described elsewhere in this Privacy Policy.
Playbook does not use Google user data received through Google Sign-In for:
- targeted advertising;
- personalized advertising;
- behavioural or interest-based advertising;
- advertising retargeting;
- selling or renting user information;
- data brokerage;
- information resale;
- determining creditworthiness;
- lending decisions;
- unrelated marketing; or
- purposes unrelated to providing, maintaining, securing, or supporting Playbook's user-facing account functionality.
Playbook does not use Google user data received through Google Sign-In to create, train, or improve generalized or non-personalized artificial-intelligence or machine-learning models.
Authentication provider and processing
Google processes the Google authentication request.
Playbook uses Supabase Auth as its authentication provider. Supabase processes the Google OAuth authentication response on Playbook's behalf and connects the authenticated Google identity to the applicable Playbook authentication identity.
As reasonably necessary to provide authentication and account infrastructure, Supabase may process information such as:
- the linked Google identity;
- the Google account identifier;
- the email address supplied through authentication;
- basic identity or profile metadata supplied through authentication;
- authentication records;
- account identifiers;
- session information; and
- security or technical metadata associated with authentication.
After authentication succeeds, Supabase issues the authentication session used by Playbook.
Playbook may securely persist the Supabase authentication session on the user's device so that the user can remain signed in between uses of the Playbook application.
Playbook does not receive or store the user's Google password.
Storage of Google user data
Google-linked identity and authentication information used by Playbook is maintained through Playbook's Supabase authentication and backend infrastructure.
Server-side authentication information may be stored through Supabase for as long as reasonably necessary to:
- maintain the active Playbook account;
- authenticate the user;
- maintain account security;
- operate account-management functionality;
- investigate security or abuse incidents;
- comply with legitimate technical requirements; and
- satisfy applicable legal obligations where required.
Google user data is not maintained for unrelated advertising, data-brokerage, or resale purposes.
Additional information about Playbook's general storage and retention practices appears in Section 16, Data Retention.
Sharing, transfer, and disclosure of Google user data
Playbook does not sell, rent, or trade Google user data.
Playbook does not transfer or disclose Google user data to:
- advertising networks;
- advertising platforms;
- data brokers;
- information resellers;
- credit-reporting businesses;
- lenders; or
- unrelated third parties for their own marketing or commercial purposes.
Google user data may be processed by Supabase, Playbook's authentication and backend service provider, only to the extent reasonably necessary to provide Playbook with authentication, account infrastructure, session management, security, database, logging, and related technical services.
Service providers supporting Playbook's infrastructure may process information only to the extent reasonably necessary to provide their contracted technical services, subject to their applicable terms, security practices, and data-processing obligations.
Playbook may also disclose information where reasonably necessary to:
- comply with applicable law;
- respond to valid legal process;
- protect Playbook's legal rights;
- protect the safety or security of users;
- investigate fraud, abuse, or unauthorized access;
- enforce applicable terms or policies; or
- respond to a credible security incident.
Except for necessary service-provider processing, security purposes, user-directed functionality, or legally required disclosures, Playbook does not disclose Google user data for purposes unrelated to providing and protecting the Playbook service.
Protection and security of Google user data
Playbook applies technical and organizational safeguards designed to protect Google user data and other account information against unauthorized access, use, modification, loss, or disclosure.
Depending on the relevant system, these safeguards include:
- HTTPS/TLS-encrypted network transport;
- authenticated access controls;
- authorization checks;
- Supabase Auth authentication and session controls;
- Row Level Security where applicable;
- server-side authorization controls;
- restricted administrative operations;
- separation of public and protected data where applicable;
- controlled access to backend systems; and
- security, abuse-prevention, and account-management controls.
Google passwords are never provided to or stored by Playbook.
Authentication records maintained through Supabase are subject to Supabase's managed infrastructure protections as well as Playbook's application-level authorization controls.
No internet-based system can guarantee absolute security.
Additional information about Playbook's security practices appears in Section 15, Data Security.
Retention of Google user data
Google-linked authentication information and related account metadata are generally retained while the corresponding Playbook account remains active and while the information remains reasonably necessary to:
- authenticate the user;
- maintain the Playbook account;
- provide account functionality;
- maintain account and service security;
- investigate fraud, abuse, or security incidents;
- resolve technical problems; or
- comply with applicable legal requirements.
Authentication, security, technical, or deletion-audit records may be retained for a limited additional period where reasonably necessary for security, fraud prevention, troubleshooting, dispute resolution, legal compliance, or technical integrity.
Playbook does not retain Google user data indefinitely merely because that information was originally received through Google Sign-In.
Additional information, including Playbook's general retention principles, appears in Section 16, Data Retention.
Deletion of Google-linked account data
Users may permanently delete their Playbook account using Playbook's account-deletion controls.
When Playbook's permanent account-deletion process is successfully completed, Playbook is designed to remove the active Playbook authentication identity and associated active account information, including the applicable Google-linked authentication association.
Where applicable, limited records may remain only where reasonably necessary for:
- security;
- fraud prevention;
- deletion auditing;
- legal compliance;
- dispute resolution;
- technical integrity;
- backup lifecycle requirements; or
- another legitimate purpose described in Section 16, Data Retention.
Users who cannot access the Playbook application may request account-deletion assistance through Playbook's published support or account-deletion channels.
Additional information appears in Section 17, Account Deletion.
Revoking Google authorization
Users may also manage or revoke Playbook's authorization through their Google Account settings.
Revoking Google authorization may prevent future authentication or authorization through that Google connection.
Revoking Google authorization does not, by itself, necessarily delete the user's separate Playbook account or information already maintained as part of that Playbook account.
To permanently delete the Playbook account and its active account information, users should use Playbook's account-deletion process.
Google API Services User Data Policy
Playbook's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the applicable Limited Use requirements.
Playbook limits its access to and use of Google user data to the information reasonably necessary to provide, maintain, secure, and support the user-facing Google Sign-In and Playbook account functionality described in this Privacy Policy.
Playbook will not materially expand its use of Google user data beyond the purposes disclosed here without updating the applicable disclosures and obtaining additional authorization or consent where required.
4. Information Generated Through Your Use of Playbook
4.1 Product and recommendation telemetry
Playbook records limited authenticated product activity to operate and improve the Service and its recommendation systems.
This may include events such as:
- screens viewed;
- works displayed to you;
- works opened;
- time spent viewing a work;
- works saved or unsaved;
- works shared;
- creator profiles opened;
- creators followed or unfollowed;
- categories selected;
- positions of items displayed in a feed;
- a randomly generated Playbook session identifier;
- timestamps associated with those events.
This telemetry may be associated with your authenticated Playbook account.
Playbook's application-level telemetry is intentionally designed not to collect:
- precise GPS location;
- your address book or contacts;
- advertising identifiers for advertising purposes;
- device fingerprinting data;
- raw search-query text.
4.2 Saves, follows, and blocks
When you use community features, Playbook may process relationships and actions including:
- works you save;
- creators you follow or unfollow;
- accounts you block or unblock;
- timestamps associated with those actions.
These signals may affect what Playbook displays or recommends to you.
4.3 Technical and security information
When your device communicates with Playbook's infrastructure, technical systems may automatically process information such as:
- IP address;
- request time;
- request path;
- network and edge metadata;
- approximate country or region inferred by infrastructure providers;
- user-agent or application-environment information;
- authentication events;
- error information;
- request and response metadata;
- security and abuse-prevention signals.
Playbook may use this information for security, authentication, debugging, service reliability, fraud or abuse prevention, and technical operation.
Playbook does not use this infrastructure information to create advertising profiles.
5. Photo Library Access
Playbook may request permission to access your device's photo library when you choose images for a contribution or profile feature.
Photo access is used to allow you to select images for features you intentionally use.
Playbook does not need access to your entire photo collection for advertising or unrelated profiling.
Your operating system controls the permissions available to Playbook, and you can change those permissions through your device settings.
Images you actually choose to upload will be processed as described in this Privacy Policy.
6. How We Use Personal Information
Playbook may process personal information to:
Provide the Service
Including to:
- create and authenticate accounts;
- maintain profiles;
- receive contributions;
- store uploaded material;
- publish approved content;
- display profiles and archive pages;
- provide saving, following, blocking, sharing, and reporting features;
- process revisions;
- provide account settings and account deletion.
Moderate and protect the Service
Including to:
- evaluate submitted images and text;
- identify content that may violate Playbook rules;
- identify potentially synthetic or AI-generated material;
- identify content that may require human review;
- process user reports and illegal-content notices;
- investigate abuse;
- make moderation and enforcement decisions;
- provide reasons or notices where appropriate;
- review appeals or requests for reconsideration.
Personalize discovery
Including to:
- rank or recommend published works;
- estimate category or creator affinity;
- reduce repetitive recommendations;
- diversify recommendations;
- improve Home and Explore experiences.
Maintain security and reliability
Including to:
- authenticate requests;
- prevent unauthorized access;
- detect abuse;
- investigate errors;
- protect accounts;
- diagnose technical problems;
- maintain system integrity;
- enforce rate limits and other protective controls.
Communicate with you
Including to:
- respond to support requests;
- handle privacy inquiries;
- process legal, copyright, or intellectual-property complaints;
- communicate about safety or moderation;
- send receipts or follow-up messages concerning notices or review requests;
- provide important account or policy notices.
Meet legal obligations and protect legal rights
Including where reasonably necessary to:
- respond to lawful legal requests;
- protect legal rights;
- comply with applicable law;
- investigate fraud or unlawful activity;
- establish, exercise, or defend legal claims.
7. Legal Bases Where Applicable
Where data-protection law requires Playbook to identify a legal basis for processing, the applicable basis may depend on the activity.
Performance of a contract
We may process information necessary to provide the Playbook Service you request, including account authentication, publishing, profiles, saves, follows, blocks, account management, and related core functionality.
Legitimate interests
Where permitted by law, we may process information when reasonably necessary for legitimate interests such as:
- protecting Playbook and its users;
- preventing abuse or fraud;
- securing accounts and infrastructure;
- moderating the Service;
- improving reliability;
- understanding product performance;
- improving recommendations;
- handling rights and legal complaints;
- defending legal rights.
Where required, we consider whether those interests are overridden by your rights and interests.
Consent
We may rely on consent where applicable law requires it.
Where processing is based on consent, you may withdraw that consent as permitted by law. Withdrawal does not make earlier lawful processing unlawful.
Legal obligation
We may process information where necessary to comply with legal requirements that apply to Playbook.
Legal claims and vital interests
In limited circumstances, information may be processed where necessary to establish, exercise, or defend legal claims or to protect someone's vital interests.
8. Automated Systems
Playbook uses automated systems in parts of the Service.
Recommendation systems
Playbook may automatically rank and recommend published content using signals such as interactions with works, viewing duration, saves, follows, categories, recency, diversity, repetition, and other relevance or quality signals.
These systems affect what content is displayed to you. They are not intended to make decisions that produce legal effects concerning you.
Moderation systems
Playbook may use automated content-classification systems to evaluate submitted images or text.
A moderation system may:
- clear material automatically;
- reject material;
- route material to human review;
- provide moderation scores or reason codes.
Automated systems can produce false positives and false negatives.
Where appropriate, Playbook may use human review to assess or reconsider moderation decisions. More information is available in the Moderation & Enforcement guide.
9. Human-Made Content Moderation
Human-made creative work is a central rule of Playbook.
Images submitted to Playbook may be analyzed for signals associated with AI-generated imagery, deepfakes, unsafe or prohibited visual material, and other moderation categories.
Playbook may use those signals to approve content, reject content, or route content to human review.
A technical probability or automated signal does not necessarily prove that content was intentionally generated using prohibited technology.
The exact rules governing acceptable tools and workflows are described separately in the Human-Made Content Standard.
10. Service Providers
Playbook relies on service providers to operate the Service.
These providers process information for Playbook or provide infrastructure necessary for Playbook's operation.
10.1 Supabase
Playbook currently uses Supabase for backend infrastructure including authentication, database services, file storage, server-side functions, API infrastructure, security, and technical logs.
Information stored in Playbook's backend may therefore be processed by Supabase and its relevant infrastructure or subprocessors.
10.2 Sightengine
Playbook currently uses Sightengine for automated content moderation.
Depending on the feature, material sent to Sightengine may include contribution images, profile images, revised contribution text, titles, creator or maker names, Story text, and Cultural Shift text.
Sightengine processes that material to return content-safety and classification results used by Playbook's moderation systems.
10.3 Resend
Playbook's public website currently uses Resend to transmit email generated by contact, legal, illegal-content, and moderation-review forms and, where applicable, to send acknowledgement or receipt messages.
Information sent through those forms may therefore be processed by Resend and its relevant infrastructure or subprocessors for email delivery and related technical operation.
10.4 Future service providers
Playbook may use additional processors where reasonably necessary to operate the Service.
Before materially new data processing is introduced, we will update our disclosures where required.
We do not authorize service providers to use Playbook user information for purposes unrelated to providing their contracted services to Playbook except where independently required by law.
11. When We May Disclose Information
Playbook may disclose information in the following situations.
Service providers
We may provide information to vendors and processors necessary to operate Playbook, as described above.
At your direction
Information may be disclosed when you intentionally use a feature that makes information public or sends it to another person or service.
Legal and safety reasons
We may disclose information if reasonably necessary to:
- comply with applicable law;
- respond to valid legal process;
- protect users;
- investigate fraud or abuse;
- protect Playbook's rights or systems;
- address credible threats to safety.
Organizational transition
If the Playbook Service is later transferred to a company, partnership, successor operator, buyer, or other legal entity, information may be transferred as part of that transition where permitted by law.
Any successor responsible for the data would be required to handle it consistently with applicable privacy obligations.
12. Advertising, Sale, and Cross-Service Tracking
Playbook does not currently operate an advertising business.
Playbook does not currently sell personal information to advertisers.
Playbook does not currently share personal information for cross-context or cross-service behavioural advertising, and does not currently use personal information for cross-service targeted advertising.
Playbook's recommendation telemetry is used for the operation and improvement of Playbook itself, including content discovery and product analytics.
If this changes materially, this Privacy Policy and any legally required choices or notices would need to be updated before that processing is introduced.
13. Public Information
Playbook is an archive and social discovery service.
Information you intentionally publish may be visible to other people.
Depending on the feature, public information may include display name, handle, profile image, biography, profile links, general profile location, published contributions, contribution images, titles, category, creator or maker attribution, year, country or origin, Story, Cultural Shift, and follower or following information where the product makes it visible.
Do not publish information that you do not want publicly associated with your Playbook profile or contribution.
A public copy may also remain outside Playbook if another person independently records, screenshots, downloads where technically possible, quotes, or otherwise preserves information before it is deleted from Playbook.
14. International Processing and Transfers
Playbook is intended to operate internationally.
Our service providers and infrastructure may process information in countries other than the country where you live. Those countries may have privacy laws that differ from the laws in your jurisdiction.
Where applicable law requires safeguards for international transfers, Playbook will rely on legally recognized mechanisms, provider arrangements, contractual safeguards, adequacy decisions, or other valid transfer mechanisms appropriate to the circumstances.
Playbook will not claim that a particular transfer mechanism applies unless the relevant operational and contractual requirements have actually been satisfied.
15. Data Security
Playbook uses technical and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Measures currently used in the architecture include controls such as:
- authenticated access;
- authorization rules;
- row-level database security;
- private storage for material awaiting moderation;
- server-side access controls;
- restricted administrative operations;
- controlled publishing paths;
- moderation and enforcement records;
- encrypted network transport through HTTPS-enabled services;
- account deletion controls.
No online service can guarantee absolute security.
You should protect your password and device and notify us if you believe your Playbook account has been compromised.
16. Data Retention
Playbook keeps personal information only for as long as reasonably necessary for the purpose for which it is processed, subject to legal, safety, security, and technical requirements.
Active account information
Account, profile, contribution, community, and recommendation information may generally remain while your Playbook account remains active and the information is needed to provide the Service.
Deleted account information
When Playbook's account-deletion process is completed, the system is designed to remove the user's active account identity and associated account data, including applicable authentication identity, profile, profile images, contributions, contribution images, revisions, revision images, saves, follows, blocks, account telemetry, and related account storage.
Limited retained safety and legal records
Certain limited moderation, report, enforcement, fraud-prevention, security, rights-complaint, regulatory, or legal records may be retained after an account or contribution is deleted where reasonably necessary for protecting users, documenting prior enforcement, preventing repeated abuse, resolving disputes, complying with law, or establishing, exercising, or defending legal claims.
Where feasible and appropriate, those records may be detached from deleted public content or account identifiers.
Infrastructure and security logs
Infrastructure providers may retain authentication, API, storage, function, error, and security logs according to Playbook's project configuration, provider retention settings, legal requirements, and legitimate security or operational needs.
Playbook V1 retention schedule
Unless a longer period is reasonably necessary for an active legal, safety, fraud-prevention, security, or dispute-resolution purpose, Playbook currently applies the following retention periods and criteria:
- Active account, profile, and published contribution information: generally retained while the relevant account or content remains active and the information is necessary to provide the Service.
- Rejected, abandoned, or quarantine submission and revision files: generally deleted within 30 days after the relevant moderation or rejection process is complete, unless the material is reasonably needed for an active review, appeal, safety investigation, or legal matter.
- Raw product and recommendation telemetry: generally retained for up to 90 days, after which it should be deleted or irreversibly aggregated where reasonably practical.
- Support correspondence and ordinary website enquiries: generally retained for up to 12 months after the matter is resolved, unless a longer period is reasonably necessary.
- Account-deletion audit records: generally retained for up to 12 months after deletion is completed where reasonably necessary to document the deletion process, security handling, or compliance.
- Moderation, report, illegal-content notice, and enforcement evidence: generally retained for up to 24 months after the relevant case is closed, unless a longer period is reasonably necessary for repeat-abuse prevention, safety, legal compliance, appeals, or dispute resolution.
- Policy acceptance records: generally retained while the associated account exists, subject to deletion and any independently applicable legal-retention requirement.
- Human-Made submission attestations: generally retained while the associated contribution and account exist, subject to deletion and any independently applicable legal-retention requirement.
- Copyright, intellectual-property, regulatory, litigation, or other active legal-dispute records: retained for as long as reasonably necessary for the relevant matter and any applicable legal limitation, defense, compliance, or preservation period.
- Infrastructure and security logs: retained according to Playbook's provider configuration, security needs, technical limitations, and applicable provider retention settings.
Playbook will periodically review retained information and delete or anonymize information that is no longer reasonably necessary, subject to applicable law and technical limitations.
17. Account Deletion
You can permanently delete your Playbook account through the account settings provided in the Playbook application.
Account deletion is designed to remove the account and associated active user data rather than merely deactivate or freeze it.
Deletion is permanent.
Limited records may remain only for the reasons described in the Data Retention section above.
Playbook also maintains a public Account Deletion resource.
If you cannot access the application and need assistance concerning account deletion, contact hello@playbook.cam.
18. Correcting Your Information
Playbook may provide in-app controls for updating profile information and certain contribution information.
Where a published contribution requires revision, Playbook may review changes through moderation before making them publicly visible.
If you cannot correct personal information through available product controls, contact hello@playbook.cam.
19. Your Privacy Rights
Depending on where you live, applicable law may give you rights concerning your personal information.
These may include rights to:
- obtain information about processing;
- request access to personal information;
- correct inaccurate information;
- request deletion;
- restrict certain processing;
- object to certain processing;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent;
- make a complaint to an applicable data-protection authority.
These rights are not absolute and may be subject to legal conditions or exceptions.
To make a privacy request, contact hello@playbook.cam using the subject Privacy Request.
We may need to verify that a request concerns your account before disclosing or changing account information. Playbook will not intentionally require more personal information than reasonably necessary to verify and process the request.
20. European, UK, and Similar Privacy Rights
Where the GDPR, UK GDPR, or similar legislation applies, Playbook will process personal data according to applicable data-protection requirements.
Where applicable, you may have rights including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a competent supervisory authority.
Information regarding the applicable controller is provided at the beginning of this Privacy Policy.
EU/EEA representative
Playbook has not appointed an EU/EEA representative at this time.
If applicable law requires Playbook to appoint one, the representative's verified identity and contact details will be published in this Privacy Policy and/or the Legal & Regulatory Contact page after the appointment is completed.
UK representative
Playbook has not appointed a UK data-protection representative at this time.
If applicable law requires Playbook to appoint one, the representative's verified identity and contact details will be published after the appointment is completed.
Playbook will not publish placeholder representative information or claim that a representative has been appointed before that operational step has actually occurred.
Nothing in this section limits mandatory rights available under applicable law.
21. Copyright, Intellectual-Property, and Legal Complaints
If you submit a copyright, intellectual-property, illegal-content, regulatory, or other legal complaint, Playbook may process information necessary to investigate and resolve the matter.
This may include your identity, contact information, description of the protected work or legal right, location of relevant Playbook content, evidence supporting the complaint, statements concerning your authority, applicable territory or legal basis, and correspondence concerning the complaint.
Where appropriate and legally permitted, information concerning a complaint may be shared with the affected user so that the matter can be evaluated fairly.
Relevant routes are available through the Legal & Regulatory Contact page.
22. Moderation Appeals and Decision Reviews
If you ask Playbook to reconsider a moderation or enforcement decision, we may retain and process information necessary to evaluate the request.
This may include:
- the affected content or account;
- decision type and reference information;
- moderation scores;
- moderation reasons;
- previous decisions;
- your explanation;
- supporting information;
- administrative review information;
- timestamps;
- related safety history.
This information is used to evaluate the decision, maintain platform integrity, communicate the result where appropriate, and document enforcement where reasonably necessary.
The public review route is available at Moderation Decision Review.
23. Policy Acceptance Records
Playbook may retain records showing that you accepted or acknowledged a policy.
Those records may include your account identifier, policy name, policy version, acceptance type, acceptance context, and server-recorded acceptance time.
This helps Playbook determine which version of its rules and policies applied to a user or submission.
Policy acceptance records associated with your account are designed to be removed when your account is permanently deleted unless retention is independently required by law.
24. Changes to This Privacy Policy
Playbook may update this Privacy Policy as the Service, applicable law, providers, or processing practices change.
Published versions will include a version number and effective date.
Where a change materially affects how personal information is processed, Playbook will provide notice or obtain acknowledgement or consent where required by law.
Historical policy versions may be maintained for accountability and recordkeeping.
25. Contact Playbook
For privacy questions, requests, complaints, or concerns:
hello@playbook.cam
Subject: Privacy Request
Playbook
Operated by:
Jubryl Al-Jabane
Asad Al-Jabane
Telephone: +973 3444 0587
For legal, regulatory, safety, illegal-content, and moderation-review pathways, see Legal & Regulatory Contact.
Representative information, if appointed or legally required, will be published in Section 20 and/or the Legal & Regulatory Contact page.
End of Playbook Privacy Policy — Version 1.1

