← Back to Typocalypse

PRIVACY POLICY

Effective date: 2026-07-21

This policy explains what information Typocalypse ("we", "us", "the service") collects when you visit the site or play the game, why we collect it, the legal bases on which we rely, and what your rights are. We try to keep what we collect to the minimum needed to run the game.

1. Data controller

Typocalypse acts as the data controller responsible for the processing of your personal data described in this policy. You can reach us at admin@typocalypse.fun for any privacy-related question, including data access, correction, restriction, portability, and deletion requests.

2. What we collect

2.1 Information you give us by signing in

We support sign-in with Discord and Google. When you complete the OAuth flow with one of these providers, the provider sends us:

  • A stable user identifier ("provider user id") - Discord's id, or Google's sub.
  • Your email address, which the provider has verified.

We discard everything else the provider would let us see (avatar, real name, locale, MFA status, Discord username/discriminator, etc.). We do not see or store your password - that stays with Discord or Google.

2.2 Information you give us directly

  • Username - the in-game display name you choose after signing in. This is public: visible to other players in your lobby, on public leaderboards, on your own profile page, and to search engines (see "Search engines and the public" in §4).
  • Avatar image - if you upload one. Stored as a small image associated with your account.
  • Marketing consent - whether you ticked "email me about new modes, events, and tournaments". We store the answer and the timestamp it was given so we can honour an unsubscribe later.
  • Community-mode content - text and media you upload when authoring a custom game mode. By publishing a mode, you make its content visible to other players.

2.3 Information collected automatically

Cookies and equivalent local-storage entries fall into two categories. Strictly-necessary ones are set the moment they're needed, regardless of where you're visiting from - without them the service can't function. Analytics ones are gated behind consent for visitors in the EU/EEA, the UK, and Switzerland, where ePrivacy / PECR require it; for visitors elsewhere they're set automatically. You can change the analytics choice at any time on the Settings page.

Strictly necessary (always on):

  • Session cookie - a random opaque token (tc_session) so you stay signed in. Expires after 30 days.
  • OAuth state + PKCE - short-lived cookies (tc_oauth_state, tc_oauth_pkce) used during sign-in and deleted immediately afterward. They prevent CSRF / auth-code-injection attacks.
  • Anonymous identifier - a random id stored in your browser's localStorage so we can recognise the same browser across a brief disconnect (e.g. to reclaim your lobby seat) and to enforce account bans. Not used for analytics on its own.

Analytics (consent-gated in the EU/EEA/UK/CH):

  • Gameplay events - counters tied to your anonymous identifier (and, once you sign in, your account id) covering page views, lobby joins, games started/completed, purchases, and similar. Used to understand how the service is used, measure conversion and retention, and improve the game. No third-party analytics provider - these events stay on our own infrastructure.
  • Analytics cookie (tc_aid) - mirrors the anonymous identifier so that, if you later sign in, we can attribute your earlier visits to your new account. Set only after you accept analytics in the consent banner.

Other automatic data:

  • Network metadata via Cloudflare - IP address, user agent, and IP-derived country code, captured by our hosting provider (Cloudflare) for every request as standard for any website. We use the country code to pick the right currency, to show the cookie banner where law requires it, and to place game servers nearer to you. Where we store IP for analytics or abuse-prevention purposes we do so as a one-way hash, not as a raw address.

We do not use device fingerprinting, advertising SDKs, or third-party trackers of any kind.

3. How we use your data, and the legal basis

Where the GDPR or UK-GDPR applies, every processing activity rests on one of these lawful bases (Article 6):

  • Contract performance - to authenticate you, keep you signed in, run the game (matchmaking, lobbies, displaying your username, recording wins/losses, processing your Pro subscription or gem purchases), and let you author and publish community modes.
  • Consent - for analytics where you're in a jurisdiction that requires consent, and for marketing emails. You can withdraw consent at any time on the Settings page without affecting any processing carried out before withdrawal.
  • Legitimate interests - for preventing abuse and fraud (including a minimal tombstone record retained for banned accounts to prevent ban evasion), debugging, security monitoring, and improving the service in aggregate. We balance these interests against your rights and freedoms; you can object to processing on this basis at any time.
  • Legal obligation - to comply with applicable law, regulatory requirements, or valid legal process.

4. Who we share it with

We do not sell or rent your personal information, and we do not share it for cross-context behavioural advertising. The third parties below process data on our behalf or as separate controllers acting on your sign-in / payment instructions; in either case our relationship with them is governed by their published terms and (where applicable) data processing agreements under GDPR Article 28.

  • Cloudflare - our hosting provider. They process every request to the service (Workers compute, D1 database, R2 storage, edge DNS/DDoS protection).
  • Stripe - payment processing for Pro subscriptions and gem packs. We send Stripe the email and plan choice needed to bill you; Stripe processes your card data directly and acts as a separate controller for it. We only receive back a customer id, subscription id, and status - we never see your card number.
  • Discord and Google - only as part of the OAuth sign-in flow you initiated. They act as separate controllers in providing identity verification.
  • Other players - your chosen username, avatar, equipped cosmetics, and any chat messages or game results you produce are visible to other players in the same lobby (and on public leaderboards where applicable).
  • Search engines and the public - your profile page (username, rank, and public stats), and any community mode you publish, live at pages designed to be crawled and indexed. Like most sites with public profiles or public content, this means Google and other search engines may index and display them - visible to anyone, including people who have never played Typocalypse and aren't signed in. Deleting your account (§10, "Erase") removes your profile from future search-engine discovery.
  • Authorities - if compelled by valid legal process, or where we believe in good faith that disclosure is necessary to investigate fraud, protect users' safety, or respond to a government request.

5. Linking accounts

If you sign in with Discord and later with Google using the same email address, both linkages will point at the same Typocalypse account. Tell us if you'd prefer them kept separate.

6. How long we keep it

  • Account record - until you ask us to delete it.
  • Sessions - 30 days, or until you log out.
  • Marketing consent record - kept while your account exists, including for a reasonable period after you opt out so we can prove the unsubscribe.
  • Analytics events - up to 365 days, after which they are pruned. You can opt out at any time, after which no further analytics events will be written for your browser or account.
  • Gem and Pro purchase records - kept for as long as required by tax and accounting law (typically 6 years), as these are receipts of a paid transaction.
  • Banned-account tombstone - if your account is banned for abuse, we retain a minimal record (account id plus a ban-evasion identifier) under Article 17(3)(e) / legitimate-interests grounds to prevent the banned user from evading the ban. All other personal data on a banned account is deleted on the same terms as any other account.
  • Aggregated / fully anonymised data - kept indefinitely in non-personal form.

7. International transfers

Cloudflare and Stripe run on global infrastructure, so data may be processed outside your country (including outside the EEA / UK). Where required, these transfers rely on safeguards recognised under GDPR Chapter V, including:

  • European Commission adequacy decisions for jurisdictions that provide an equivalent level of protection.
  • Standard Contractual Clauses (SCCs) approved by the European Commission, where adequacy doesn't apply.
  • Other safeguards or derogations recognised under GDPR Chapter V where strictly necessary.

Cloudflare and Stripe publish their own DPAs and SCC terms; these are incorporated by reference when we use their services.

8. How we keep your data secure

We use physical, electronic, and procedural safeguards appropriate to the data we hold. In practical terms this includes TLS for all transport, hashed (not raw) IP addresses in our analytics, no plaintext storage of OAuth tokens, no storage of your password at any point, and access limited to the operator who needs the data to run, develop, or debug the service. We rely on Stripe's PCI-DSS-compliant infrastructure for card data - we never touch it. No security system can prevent every possible breach; if one happens we'll respond per the next section.

9. Data-breach notification

If a personal-data breach poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay under Article 34, with information about the nature of the breach, the categories of data affected, and what we're doing about it.

10. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you. You can download a full machine-readable copy via Settings → "Download my data" without contacting us.
  • Rectify inaccurate data. Edit your username in Settings, or email us for anything else.
  • Erase your personal data ("right to be forgotten"). Use Settings → "Delete account" or email us. Some data may be retained where the law requires (see §6).
  • Restrict processing - ask us to limit how we use your data in specific scenarios.
  • Object to processing based on legitimate interests. You have an absolute right to object to processing for direct-marketing purposes.
  • Data portability - receive your data in a structured, machine-readable format. The "Download my data" export satisfies this in JSON.
  • Withdraw consent - toggle analytics off in Settings, or unsubscribe from marketing in any email or in Settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Lodge a complaint with your supervisory authority. EU residents can find their national authority at edpb.ec.europa.eu. UK residents can contact the Information Commissioner's Office at ico.org.uk.

To exercise any right that isn't self-service, email admin@typocalypse.fun. We respond within one month, extendable by up to two months for complex or high-volume requests, in line with GDPR Article 12.

11. Automated decision-making and profiling

We do not subject you to decisions based solely on automated processing - including profiling - that produce legal effects or similarly significantly affect you. Bans and other moderation actions are reviewed by a human before they take effect.

12. Artificial intelligence

We do not use AI or machine-learning models to process your personal data, generate game content, or make decisions about you. Game prompts and content are produced by deterministic procedural generators or by human authors (including authors of community modes).

13. California privacy rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act give you additional rights. We do not sell or share your personal information for cross-context behavioural advertising - there is no "Do Not Sell" action to take because we don't sell. Beyond that:

  • Right to know - request disclosure of what we've collected about you. Use Settings → "Download my data" or email us.
  • Right to delete - request deletion of personal information we've collected, subject to limited statutory exceptions.
  • Right to correct - request correction of inaccurate personal information.
  • Right to limit use of sensitive personal information - applicable only where we process such information for inferential purposes, which we do not.
  • Right to non-discrimination - we will not discriminate against you for exercising any CCPA / CPRA right.

You may designate an authorised agent to make a request on your behalf; we will verify the request using the contact information associated with your account.

14. Children

The minimum age to use Typocalypse is 13. We do not knowingly collect personal information from anyone under 13. For users in the EU/EEA, GDPR Article 8 sets the digital-consent age at 16 (some member states have lowered it to 13-15); users in that range require parental consent before their personal data can be processed. We do not currently solicit or verify parental consent - if you are under 16 in the EU/EEA, please obtain that consent (or have a parent / guardian sign up on your behalf) before using the service. If you believe an underage user has signed up without the required consent, contact us at admin@typocalypse.fun and we will delete the account.

15. How you give and withdraw consent

Where processing is based on consent, you provide it by affirmatively opting in - clicking "Accept" in the cookie banner for analytics, or ticking the marketing checkbox in Settings for emails. You can withdraw consent at any time: analytics can be toggled in Settings, and marketing emails include an unsubscribe link in every message.

Strictly-necessary processing (authentication, OAuth security tokens, the in-browser anonymous identifier used for reconnect and ban enforcement) is carried out without consent under the ePrivacy "strictly necessary" carve-out and under contract-performance / legitimate-interests grounds, as the service cannot function without it.

16. Changes to this policy

We may update this policy. Material changes will be announced in-app or by email before they take effect, and where the law requires it we will seek fresh consent before relying on a change. Prior versions are available on request from admin@typocalypse.fun.

17. Contact

For any privacy question or to exercise any right under this policy, email admin@typocalypse.fun.

This policy is specific to Typocalypse and accurate to its current implementation, but it is not legal advice. Have a qualified lawyer review it for your specific jurisdiction before relying on it in a dispute.