Player Privacy

Privacy Policy

A plain-language explanation of the information Ashen Bastion needs to run accounts, save progress, protect Rankings and answer messages.

Who operates Ashen Bastion

Ashen Bastion is operated by Adrian Cojocaru. If you have a privacy question, want to exercise a data right, or cannot access your account, use Send a raven and include the email address connected to your account. Do not send a password.

Data we process

  • Account data: email address, username, a password stored as a cryptographic hash, account creation date and email-verification or password-reset records.
  • Gameplay data: cloud save state, equipment, hero progression, Crystals, public crest/profile choices, message inbox data, fortress data and submitted score records.
  • Security data: a session-token hash, a hashed IP address and a hashed browser identifier used to protect accounts, rate-limit requests and validate score submissions.
  • Contact data: the name, email and message you send through Send a raven, so we can reply and handle the request.

Why we use it

  • Run the game and account: sign you in, save your cloud progress, show your chosen identity and deliver account recovery.
  • Run fair Rankings: connect valid runs to the correct account and detect abuse, impossible submissions or attempts to manipulate scores.
  • Respond to you: read and reply to support, feedback, deletion and privacy requests you send us.
  • Keep the service secure: protect sessions, apply rate limits, investigate abuse and maintain the service.

What is public

Your username, selected crest, player profile choices, fortress identity and accepted Ranking entries can be visible to other players. Your email address, password hash, session information and cloud save are not public.

Guest play is possible. Guest progress is normally stored only in that browser; it becomes cloud-account data only when you choose to sign in and sync it.

Service providers

The game uses Netlify for hosting and server functions, Neon for the game database, and Resend for transactional email such as verification and password recovery. These providers process information only to provide their service to Ashen Bastion. Their infrastructure may process data outside your country; safeguards and processing locations are governed by their applicable terms and data-protection commitments.

Ashen Bastion does not currently use advertising pixels, behavioural advertising, Google Analytics, Meta Pixel or cross-site marketing trackers.

Retention

Account and cloud-game data are kept while your account exists. Session cookies expire after up to seven days. Password-reset and email-verification records are short-lived and are periodically cleaned after expiry.

Contact messages and security records are retained only as long as reasonably needed to reply, resolve an issue, protect the game or meet a legal obligation. Some minimal security or moderation audit information may be retained where necessary for abuse prevention or legal compliance.

Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing of your personal data, and to complain to your local data-protection authority. Contact us to make a request.

You can change account details in Account. You can permanently delete your account from Account or follow the external Delete account instructions.

Security and updates

We use password hashing, secure server-side sessions in production, origin checks and abuse controls. No online service can guarantee absolute security, so please choose a unique password and never share it.

We may update this policy when the game or its data practices change. The latest version and its update date will always appear on this page.