Privacy Policy

MOSASOM LLC: Privacy Policy

Last Updated: May 18, 2026

1. Introduction, Data Controller, and Operational Scope

MOSASOM LLC (“we,” “us,” or “our”), a Missouri-based Limited Liability Company, is the data controller for information collected through our software, gaming applications, and educational services. As an independent systems developer and a licensed entity in the state of Missouri, we maintain an information security program designed to protect user data and ensure strict operational isolation between our distinct business divisions.

By using our Services, you confirm you understand English well enough to comprehend this policy. Our operations are divided into two parallel functional tracks, each subject to specific data minimization protocols:

  • Track A (Interactive Software & Storefront Products): Applies to all global commercial releases on Steam, the Epic Games Store, and other digital distribution platforms.
  • Track B (Live Academic Laboratory Services): Applies to all educational programming, computational science labs, and interactive mentoring services delivered via third-party educational marketplaces (e.g., Outschool) or direct institutional enrollment.

2. Data We Collect and Sources

We collect limited personal data strictly necessary to deliver product functionality, verify platform security, and facilitate live instructional classrooms:

  • Direct Correspondence: We collect your contact information, email address, and the contents of your messages when you reach out for customer support, technical troubleshooting, or academic inquiries.
  • Automated Telemetry: We may collect technical telemetry—including IP addresses, hardware specifications, device identifiers, and anonymized crash logs—to ensure runtime stability across our software configurations.
  • Platform Authentication Data (Track A): We receive unique account identifiers, display tokens, and language preferences from partners like Steam and Epic Games Store to verify your software ownership.
  • Epic Account Services (EOS): We process Epic Account Data solely for internal authentication and cross-platform multiplayer social synchronization (such as friends list populating).
  • Live Classroom Instructional Data (Track B): For students participating in our live academic sessions, we process real-time data necessary for classroom instruction. This includes live Zoom video conferencing streams, classroom audio, interactive chat transcripts, and remote-input variable data generated when students interact with our visual simulation software.

3. Children's Privacy and Educational Compliance (COPPA / GDPR)

We are deeply committed to protecting the safety and digital privacy of young learners.

  • Storefront Products (Track A): We do not knowingly collect personal information from children under the age of 13 through our commercial gaming storefronts without verifiable parental consent. We actively support platform-level parental controls on Xbox, PlayStation, and Nintendo ecosystems.
  • Academic Services (Track B): In full compliance with the Children’s Online Privacy Protection Act (COPPA) and global youth data protection standards, we collect classroom data from minor students under 13 only after verifiable parental consent has been secured via our partner marketplaces (e.g., Outschool’s secure parental vetting pipeline) or through authorized school/district administrative agents acting contractually on behalf of the parent.
  • Parental Rights: Parents and legal guardians maintain the absolute right to review, update, or demand the immediate deletion of their child's personal data or classroom records at any time. To audit, restrict, or wipe your child's data footprints, please submit a direct request to privacy@mosasom.com. Upon receiving a verified request, we will permanently purge the target records within 45 calendar days.

4. How We Use and Share Your Data

We process user data strictly to fulfill our contractual obligations to provide the game or live classroom service, comply with statutory laws, or optimize engine stability. We do not sell, rent, trade, or monetize personal information or student profiles for targeted advertising or commercial marketing under any circumstances. We share data only with the following essential entities:

  • Infrastructure Service Providers: Necessary backend infrastructure providers strictly required to execute the service core. This includes Epic Games, Inc. (for Track A authentication infrastructure) and Zoom Video Communications, Inc. (for Track B live video delivery). These entities are contractually bound to treat our data with strict security safeguards and are prohibited from using the data for independent commercial manipulation.
  • Legal & Safety Moderation: We may disclose data to third parties if required to comply with law enforcement subpoenas, investigate material terms-of-service violations, or execute mandated child safety and welfare reporting protocols.
  • Business Transfers: User data may be securely transferred as an operational asset solely as part of a formal corporate merger, consolidation, or asset sale.

5. Use of Automated Decision-Making and AI

  • Gameplay Tuning: We may utilize basic automated tracking algorithms to analyze anonymized player performance metrics solely to balance game difficulty layers dynamically.
  • Opt-Out Rights: Users maintain the right to opt-out of significant automated decision-making profiles. We do not use behavioral tracking or algorithmic profiling for commercial monetization or predatory engagement loops.
  • Human Oversight: All safety, grading, behavior moderation, and classroom compliance systems are anchored by direct human oversight to ensure equitable, objective application of our codes of conduct.

6. Global Data Rights and Regional Compliance

You maintain the right to access, correct, delete, restrict, or export a machine-readable copy of your personal data footprints at any time.

  • Missouri State Protections: In the event of a verified systemic data breach, we will notify all affected individuals and platform administrators within 45 days of discovery, in strict compliance with Missouri statutory consumer laws.
  • GDPR, UK GDPR, and CCPA: Users residing in the European Union, United Kingdom, and California may exercise their expanded consumer data privacy rights at any time. We systematically utilize Standard Contractual Clauses (SCCs) to govern international data routing and infrastructure replication.
  • Privacy Signals: We fully respect universal browser privacy flags and do not engage in the commercial tracking of personal profiles, aligning completely with the intent of Global Privacy Control (GPC) signals.

7. Security and Data Retention

We employ robust technical safeguards—including transport layer encryption protocols (TLS/SSL), mandatory multi-factor authentication (MFA) for all internal administrative systems, and isolated local storage frameworks—to maintain digital runtime integrity.

  • Retention Limits: We retain personal data and classroom metadata only as long as necessary to fulfill the targeted instructional unit or to satisfy legal and accounting data audit requirements.
  • Classroom Recordings: Outschool live session recordings are hosted inside the secure, encrypted Outschool cloud architecture and are retained solely for internal safety moderation, parental review, and student review purposes before auto-deletion, per marketplace guidelines.
  • User Security Tip: Do not use your real name as your public multiplayer or classroom username, and avoid broadcasting private sensitive data (phone numbers, addresses) inside open public chat arrays.

8. Epic Account Services Account Policy

For Epic Account Services, Epic Games manages player data on our behalf, with the user's consent. Epic Games is an independent data controller for the Epic account information it processes. You can view the Epic Games Privacy Policy for more information on how Epic Games collects, uses, and shares player data at: www.epicgames.com/privacypolicy.

9. Changes and Contact

We may update this privacy policy periodically to reflect evolving data privacy amendments or changes in platform compliance parameters. Material updates will be stamped via the updated date below. For all privacy compliance questions, parental rights audits, or data deletion requests, contact:

MOSASOM LLC Attn: Privacy Coordinator

Email: privacy@mosasom.com