LOGIN

PRIVACY POLICY

Summary first, then the details. No ads, no tracking, no analytics, no data sales — we store what the game and your optional web account need, nothing else. GDPR applies: the operator is based in Germany, all data is hosted in the EU (Finland).

1. WHO IS RESPONSIBLE

Controller (Art. 4(7) GDPR): the private individual operating this non-commercial hobby server from Germany.
Contact: deco_breaks.9y@icloud.com

2. WHAT WE STORE, WHY, AND ON WHAT LEGAL BASIS

3. WHERE IT LIVES

Everything runs on a rented server hosted by a professional hosting provider on infrastructure located within the EU. Encrypted backups are kept in the EU as well. No data is transferred to third countries, and no third parties process your data beyond that hosting provider (acting as our processor under Art. 28 GDPR).

4. HOW LONG WE KEEP IT

5. YOUR RIGHTS

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Deleting your web account removes email, phone and password immediately; game data tied to your UUID is anonymized on request (the world and the ledger stay consistent, your name disappears). You can also complain to a supervisory authority (Art. 77) — in Germany, the data protection authority of your federal state.

To exercise any right: contact the operator (above) or ask a staff member in game.

Connection fingerprints (staff tool)

To enforce the one-account rule and to stop ban evasion, the server stores a hashed fingerprint of the connection you join from — a one-way SHA-256 of your address combined with a secret server value. Your actual IP address is never written to our database, and the hash cannot be turned back into an address. It lets staff see that two accounts share a connection; nothing more. A flag records whether the connection came through a VPN or proxy. These records are visible to the server owner only, are never shown on public profiles, and are deleted automatically after 90 days.