PRIVACY POLICY
Last updated: May 2, 2026
Overview
Sandbox Studios LLC (“we,” “us,” or “our”) operates the website and game at outtotheblack.com (the “Service”). This Privacy Policy explains what information we collect, how we use it, how it is shared with third parties, and the choices you have regarding your information.
By using the Service you agree to the practices described in this policy. If you do not agree, do not use the Service.
Information We Collect
Information you provide via Google Sign-In. The Service uses Google OAuth for sign-in. When you sign in we receive your name, email address, profile picture URL, locale, and a unique Google identifier. We do not see or store your Google password.
Information collected automatically. When you connect to the Service we record your IP address (used solely to determine your country for region-specific features such as US-only subscription availability), your session connection time, and a session identifier. We do not log full request URLs or sell access logs.
Gameplay data. While you play we store your in-game ship name, faction, level, experience, scores (current life and lifetime high), upgraded stat values, position, ownership of in-game structures, and aggregate statistics such as kills, deaths, and total play time. This data is required for the persistent-world gameplay experience.
Subscription data. If you subscribe, payment processing is handled by Stripe (see Third-Party Services below). We store only a Stripe customer reference, the subscription status, and the country code Stripe records on your billing — we do not see or store your full payment card.
Browser local storage. The Service stores small amounts of data in your browser’s local storage to remember client-side preferences (music/SFX volume, sound-effect on/off toggles, AI autopilot navigation state, an in-session info log, a death-counter for tip rotation). This data never leaves your browser unless you explicitly sign in and play.
How We Use Information
- To operate the game (matchmaking-free persistent world, faction routing, leaderboards, daily winner announcements).
- To enforce game rules and security (detecting cheating, abuse, account-sharing).
- To provide customer support and respond to inquiries.
- To process subscription payments and refunds.
- To display relevant advertising to free users via Google AdSense.
- To analyze aggregate gameplay patterns and improve the Service.
- To comply with legal obligations.
Cookies and Similar Technologies
First-party storage. The Service uses browser localStorage for client-side preferences (described above). It does not set first-party cookies for tracking purposes.
Third-party advertising cookies. Google AdSense and its advertising partners may set cookies in your browser to serve and personalize ads, measure ad performance, and prevent fraud. Some of these cookies may also be used for ad personalization across other Google services and partner sites.
Authentication and payment cookies. Google sets cookies during the OAuth sign-in flow. Stripe sets cookies during checkout. Both are operated under the privacy policies of those vendors.
Consent. If you visit from the European Economic Area, the United Kingdom, or Switzerland, a Google-operated Consent Management Platform (CMP) will request your consent for personalized advertising and related data uses before non-essential cookies are set. You may withdraw or change your consent at any time via the CMP control re-opened from your account settings or by clearing site data in your browser.
Third-Party Services
The Service relies on the following third parties. Each operates under its own privacy policy:
- Google AdSense — serves and personalizes advertisements to free users. Google Privacy Policy · Google Advertising Policies.
- Google OAuth (Sign-In) — authenticates accounts. Same Google Privacy Policy as above.
- Stripe — processes subscription payments. Subscriptions are currently offered to US residents only. Stripe Privacy Policy.
- Microsoft Azure — cloud infrastructure where game state and account records are stored. Microsoft Privacy Statement.
- Discord — we publish daily public-leaderboard winners (ship name, faction, level, score) to our Discord channels via webhook. We do not transmit personal account data such as email addresses to Discord.
We do not sell personal information to third parties.
Personalized Advertising
Free users see advertisements served by Google AdSense. Google and its partners may use cookies and similar technologies to serve ads based on your prior visits to this and other websites. You can opt out of personalized advertising by visiting Google’s Ads Settings, or opt out of third-party-vendor cookie use by visiting aboutads.info or youronlinechoices.eu.
Subscribers do not see advertisements and no advertising cookies are set by us during a subscription session.
Children’s Privacy
The Service is not directed at children under 13 and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete that information promptly. Parents or guardians who believe their child has provided personal information should contact us using the contact channels below.
Your Rights
European Economic Area, UK, and Switzerland (GDPR / UK GDPR). You have the right to access, correct, delete, or port the personal information we hold about you, to restrict or object to processing, and to withdraw consent at any time. You may also lodge a complaint with your local data-protection authority. To exercise any of these rights, contact us using the channels below.
California (CCPA / CPRA). California residents have the right to know what personal information we collect, the right to delete it, the right to correct inaccurate information, and the right to opt out of any “sale” or “sharing” of personal information. We do not sell personal information for monetary consideration. Use of advertising cookies served via Google AdSense may qualify as “sharing” under California law; California residents may opt out of personalized advertising via the Google Ads Settings link above. You will not be discriminated against for exercising any of these rights.
All users. You may close your account and request deletion of your gameplay record at any time by contacting us via Discord or X (links below). Deletion requests are processed within 30 days.
Data Retention
Account and gameplay records are retained while the account is active and for a reasonable period afterwards to support analytics, leaderboard history, and dispute resolution. Subscription billing records are retained for the period required by applicable tax and accounting laws. Browser local-storage data is retained until you clear it or sign out (sign-out clears the per-session preference subset described above).
Security
The Service is served exclusively over HTTPS. Sign-in uses Google OAuth so we never see your credentials. Webhook integrations are signature-verified. We use commercially reasonable technical and organizational measures to protect personal information, but no method of internet transmission or electronic storage is 100% secure and we cannot guarantee absolute security.
International Transfers
The Service is operated from the United States. Personal information is stored on Microsoft Azure infrastructure. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service from outside the United States you consent to that transfer.
Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be highlighted on the Service. Continued use of the Service after a change constitutes acceptance of the revised policy.
Contact
Sandbox Studios LLC
“Where your game never ends”
For privacy questions, deletion requests, or to exercise any of the rights described above, reach us via:
- Discord — Join our server
- X / Twitter — @Sand_Box_Studio