Scope
This policy applies to the Neon Go Stop website, browser game, game services, player accounts, feedback system, and related support surfaces operated through gostop.io.
Neon Go Stop is currently an alpha product. The service does not currently include advertising, payment processing, real-money wagering, public chat, or third-party behavioral advertising trackers.
Information we handle
Guest and account identity
Guest play uses a randomly generated profile identifier stored on your device and a generated display name. If you protect a player with a passkey, we store account and profile identifiers, username and display name, avatar selection, account status, timestamps, a one-way recovery-key hash, and the public credential material required to verify the passkey. We do not receive the biometric data or device PIN used by your device to unlock a passkey.
Game and progression data
We store player profile settings, match history and results, statistics, XP, achievements, challenges, titles, cosmetics, inventory, multiplayer room state, and settlement records needed to preserve game progress and prevent duplicate rewards.
Feedback and support
When you submit feedback, we store the message, category, optional rating, player or profile identifier, display name, page or game surface, platform, app version, build identifier, environment, submission time, and later administrative status or notes.
Technical operations
Servers process network and request information needed to deliver and secure the service, including request identifiers, request method and normalized route, response status, timing, connection events, and security limit events. Caddy access logs remove client IP addresses, request headers, and request URIs before writing. Infrastructure providers may separately process network information under their security and privacy terms.
Browser performance and reliability telemetry uses bounded categories such as browser family, device class, network class, reduced-motion setting, startup outcome and timing, frame timing, memory range, game surface, quality mode, and the first fault category, phase, and fatality reported during a game page. Fault telemetry does not include exception messages, stack traces, filenames, page URLs, account names, feedback text, card choices, or free-form identifiers.
How we use information
- Provide guest play, passkey sign-in, recovery, account deletion, multiplayer, and saved progression.
- Operate matchmaking, restore interrupted rooms, settle rewards, and investigate gameplay defects.
- Respond to feedback, prioritize fixes, and understand whether the alpha is stable on supported devices.
- Detect abuse, enforce request limits, protect accounts, and diagnose outages.
- Meet legal obligations and establish or defend legal claims when necessary.
We do not sell personal information or use it for targeted advertising.
Device storage and cookies
The website uses local storage for a guest profile identifier and guest display name. It uses strictly necessary cookies for guest claiming, passkey ceremonies, authenticated sessions, and cross-site request forgery protection. These features are necessary to remember a player, complete secure sign-in, or protect account changes. There are currently no advertising cookies.
Passkeys may sync through an account or password manager chosen on your device. That syncing is controlled by your platform provider, not Neon Go Stop.
Retention
- Passkey ceremony records expire after 5 minutes.
- Guest claim records expire after 30 days.
- Account sessions last 30 days by default and may be configured between 1 and 90 days.
- Durable multiplayer room snapshots expire after 24 hours.
- Accounts, progression, inventory, and match records are retained while the account or service remains active, unless deletion is requested.
- Feedback and administrative notes are automatically deleted from active stores 365 days after submission. Account deletion removes feedback associated with that profile sooner.
- Privacy-minimized Caddy access logs rotate at least every 24 hours and are deleted after 30 days.
- Encrypted backend backups are automatically deleted after 35 days unless temporarily preserved under an approved incident or legal hold.
- Searchable application logs and high-resolution metrics are retained for 30 days, with daily error aggregates and downsampled metrics retained for up to 13 months. Infrastructure-provider security records may follow separate disclosed or contractually controlled periods.
Deletion removes active account identity, sign-in credentials, supported profile data, progression, related rooms, matches, inventory, and feedback associated with that profile. Profile data may remain in encrypted rotating backups for up to 35 days, or longer only while a documented incident or legal hold applies.
Your choices and rights
You can play as a guest without creating an account. Signed-in players can review profile information, change supported profile selections, sign out, and permanently delete their player account from the Player Identity panel.
Depending on where you live, you may have rights to ask for access, correction, deletion, restriction, portability, or objection. Use the support path below and include enough detail to locate the relevant player profile without sharing a recovery key or private passkey information.
Never include a recovery key, session token, device PIN, biometric information, or passkey export in a feedback message.
Audience and children
Neon Go Stop is intended for players age 13 and older and is not directed to children under 13. A player who is not old enough to consent under local law should use the service only with permission from a parent or legal guardian.
If we learn that information was collected from a child in a way that requires parental consent, we will delete it or take the steps required by applicable law. A parent or guardian can contact us through Support.
Security and international processing
We use measures including passkey verification, hashed session and recovery secrets, short-lived authentication ceremonies, secure cookies in production, CSRF protection, rate limits, access controls, and encrypted network transport. No system is perfectly secure, so players should keep devices and recovery keys protected.
The service and its providers may process information in the United States and other countries where infrastructure operates. Privacy protections may differ from those in your location.
Contact and changes
Use the in-game or website Feedback control for privacy requests, account help, or policy questions. Choose "Something else" and clearly label the message "Privacy request." Do not include secret credentials.
We may update this policy as the product and release footprint change. Material changes will be reflected by a new effective date and, when appropriate, an in-product notice.

