Privacy Policy
Effective: 2026-05-03
This policy describes what data DÛM RUNNER (“the Game,” “we”) collects, why we collect it, who we share it with, and the choices you have. We collect only what we need to run the Game.
1. What we collect
1.1 Account data
- Email sign-up: email address, hashed password, display name.
- Discord sign-in / Activity: when you authorise the Game with Discord (scope
identify), Discord sends us your Discord user ID, username, global display name, and avatar hash. We do not request your Discord email, friend list, server list, or message history. We store the Discord user ID, username, and avatar hash; we do not store the OAuth access token after the sign-in flow completes.
1.2 Game state
- Per-server character data: position, inventory, equipment, statistics.
- Server-membership data: which servers you have joined, who owns them, configuration of servers you create.
- In-game chat messages (server-wide), retained only in transient game-server memory and dropped when the server process restarts.
1.3 Discord Activity instance binding
When you launch the Game as a Discord Activity, we receive an instance_id from Discord that identifies the voice-call session. We store this id alongside the matching game-server row so everyone in the same call lands in the same world. We do not store anything else about the call (no voice data, no participant list beyond who actually launched the Activity into a game session).
1.4 Operational logs
Our hosting providers (Vercel, Fly.io, Supabase) keep short-lived request / connection logs containing IP address, user agent, and request metadata for security and debugging. We do not aggregate these into player profiles.
1.5 Cookies
We use only the cookies needed to run the Game: a Supabase session cookie that keeps you signed in, and a short-lived Discord OAuth state cookie used during sign-in to prevent CSRF. We do not use advertising or analytics cookies.
2. Why we collect it
- To create and authenticate your account.
- To run the multiplayer simulation server-authoritatively.
- To persist your character between sessions.
- To bind a Discord Activity to a game-server instance so you land in the right world.
- To investigate abuse, debug crashes, and protect the service.
3. Who we share it with
We do not sell your data. We share it only with the infrastructure providers we use to run the Game:
- Supabase — authentication and database (account rows, character rows, server rows).
- Vercel — hosts the web app and API routes.
- Fly.io — hosts the game-server processes.
- Discord — only when you choose to use Discord sign-in or launch the Game as an Activity. We send Discord the OAuth code we receive and request your basic profile.
- OpenAI — our asset-generation pipeline sends generic, non-personal prompts (entity kind, biome, palette) to OpenAI’s image API to generate sprite art. No account or player data is included in those prompts.
We may also disclose data when required by law, to enforce these terms, or to protect the rights and safety of users and the public.
4. Retention
We keep account and character data for as long as your account exists. If you ask us to delete your account (see §6), we delete your account row and the associated character rows. Operational logs at our infrastructure providers are retained according to those providers’ defaults (typically 30–90 days).
5. Security
Passwords are hashed; we never store them in plaintext. Sessions use HTTP-only cookies. The game server validates every action server-side. No system is perfectly secure; please do not reuse passwords from other services.
6. Your rights
You may request access to, correction of, or deletion of your personal data by emailing jordansalvi@gmail.com. If you signed in with Discord, you can also revoke our access at any time from Discord’s Authorized Apps settings; doing so will prevent future sign-ins but does not on its own delete your stored profile in DÛM RUNNER.
7. Children
The Game is not directed to children under 13 (or under 16 in the EEA / UK). We do not knowingly collect data from children below those ages. If you believe a child has signed up, contact us and we will delete the account.
8. International users
Your data may be stored and processed in regions where our infrastructure providers operate (primarily the United States). By using the Game you consent to this transfer.
9. Changes
We may update this policy. The “Effective” date at the top reflects the current version. Material changes will be highlighted on the sign-in page.
10. Contact
Questions or requests: jordansalvi@gmail.com.
See also our Terms of Service.