Legal
Privacy
Last updated 4 August 2026.
What we store
- Your email address, so you can sign in and recover access.
- A hash of your password, made with argon2id. We cannot read your password and could not tell you what it is.
- Your display name, friend code and progression, which are the game.
- Raid history and currency movements, because an economy without an audit trail is an economy nobody can fix.
- A keyed hash of the IP address a session was created from — never the address itself.
What we do not store
Card numbers never reach our servers: checkout is hosted by Stripe, which sends back an identifier and a result. We do not run advertising trackers, we do not sell anything to anyone, and no personal data appears in our logs.
Cookies
Two, both strictly necessary. One holds the rotating refresh token that keeps you signed in; it is HttpOnly, so no script can read it. The other holds a CSRF token, which is readable on purpose because the page has to echo it back in a header. There are no analytics cookies.
Erasure
Delete your account from the account page. It stops working immediately and every session ends. Thirty days later the rows are permanently erased — the window exists so a deletion made in anger at two in the morning can still be undone.
Financial records tied to a completed purchase are kept as long as tax law requires, which is the one exception.
Contact
Access, correction and erasure requests go to contact.