Legends of Arthengard
Privacy Policy
This policy describes which personal data is processed when you use Legends of Arthengard, for what purpose, and which rights you have. Personal data is any data with which you can be personally identified.
Hosting
IONOS VPS
Our website is operated on servers of IONOS SE (Elgendorfer Str. 57, 56410 Montabaur, Germany). IONOS provides us with virtual private servers (VPS) for this purpose within the framework of a commissioned data processing agreement in accordance with Art. 28 GDPR.
Processed Data: In particular IP addresses, meta and communication data, contact data, names, website access, and other data generated via the website.
Legal Basis:
- The hosting serves the purpose of fulfilling the contract with our potential and existing users (Art. 6 para. 1 lit. b GDPR).
- In the interest of a secure, fast, and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR).
We have concluded a Data Processing Agreement (DPA) with IONOS SE. The server location is in a data center within Germany. Within the scope of hosting, no data transfer to third countries takes place. Independently of this, third-country implications arise from the integration with Twitch and Discord — see the section "Transfer to Third Countries".
Database Backups
To protect against data loss, an encrypted backup copy of the database is created daily.
- Storage location: exclusively on the server in Germany. Backups are not transmitted anywhere and not shared with third parties.
- Encryption: backups are stored in encrypted form.
- Retention: a maximum of 2 days, after which they are deleted automatically.
- Legal Basis: Legitimate interest in data security and recoverability (Art. 6 para. 1 lit. f GDPR), implementing the obligation to ensure security of processing (Art. 32 GDPR).
If you delete your account, your data is removed from live operation immediately. It disappears from backup copies at the latest when those are deleted after 2 days.
General Information and Mandatory Disclosures
Note on the Controller
The controller for data processing on this website is:
Patrik Witzke
Otto-Nuschke-Str. 8
19370 Parchim, Germany
Email: loabeta@insanestudios.de
The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.
Storage Duration
Unless a more specific storage period has been mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, deletion will occur after these reasons cease to apply.
General Information on the Legal Basis
Processing is based on various legal grounds:
- Consent: Art. 6 para. 1 lit. a GDPR, Section 25 para. 1 TDDDG (access to your end device). Consent can be revoked at any time.
- Performance of a contract / pre-contractual measures: Art. 6 para. 1 lit. b GDPR.
- Compliance with a legal obligation: Art. 6 para. 1 lit. c GDPR.
- Legitimate interest: Art. 6 para. 1 lit. f GDPR.
Special categories of personal data within the meaning of Art. 9 GDPR (such as health, religious, or biometric data) are not processed.
Recipients of Personal Data
We only transmit personal data to external bodies if this is necessary for the fulfillment of a contract, if we are legally obliged to do so, if we have a legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in the transmission, or if another legal basis permits the data transfer.
- IONOS SE (Montabaur, Germany) — hosting provider and technical processor, DPA in accordance with Art. 28 GDPR.
- Twitch Interactive, Inc. (USA) — login, chat bot, and channel events. Twitch acts as an independent controller.
- Discord Inc. (USA) — only if you voluntarily link your Discord account. Discord acts as an independent controller.
Transfer to Third Countries
Hosting and the database are located entirely in Germany. However, the integration with Twitch and Discord creates connections to the USA. These differ in nature and extent as follows:
- Retrieving data: Our server retrieves data from the Twitch interface (e.g., stream status, channel events). In doing so, the relevant channel and user identifiers are transmitted to Twitch so that the request can be attributed.
- Redirection by you: When logging in, you are redirected to the servers of Twitch or Discord. These providers then process your IP address and browser data — not us.
- Active transmission: If your Discord account is linked, we transmit your Discord identifier to Discord in order to assign or remove the appropriate role there. The Twitch bot also outputs player names and game actions in the Twitch chat, unless you have disabled this display (see "Publicly Visible Content").
Legal basis for the transfer:
- Discord is certified under the EU-US Data Privacy Framework and additionally uses Standard Contractual Clauses. The transfer therefore relies on the European Commission's adequacy decision (Art. 45 GDPR).
- Twitch: Insofar as the provider is certified under the EU-US Data Privacy Framework, the transfer likewise relies on the adequacy decision (Art. 45 GDPR); otherwise on Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR) or on your explicit consent (Art. 49 para. 1 lit. a GDPR).
Both providers are independent controllers for the processing on their platforms; their respective privacy policies apply.
Revocation of Your Consent to Data Processing
You can revoke consent already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Object (Art. 21 para. 1 GDPR)
Where we process data on the basis of a legitimate interest (Art. 6 para. 1 lit. e or f GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then no longer process the affected personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the assertion, exercise or defense of legal claims.
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged infringement. The right to lodge a complaint exists irrespective of other administrative or judicial remedies.
Right to Data Portability
You have the right to have data that we process automatically based on your consent or in fulfillment of a contract handed over to yourself or to a third party in a common, machine-readable format (Art. 20 GDPR). If you request the direct transfer of the data to another controller, this will only take place insofar as it is technically feasible. Please contact us at the email address given above for this purpose.
Information, Rectification, and Deletion
You have the right at any time to receive free information about your stored personal data, its origin and recipient, and the purpose of the data processing (Art. 15 GDPR), as well as a right to rectification (Art. 16 GDPR) or deletion of this data (Art. 17 GDPR).
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data (Art. 18 GDPR). The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data happened/is happening unlawfully, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need them to assert, exercise, or defend legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balance must be struck between your and our interests. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
SSL or TLS Encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
Data Collection on this Website
Server Log Files and Operational Data
When the website is accessed, technical access data is generated that is necessary for operation:
- IP address of the requesting device
- Requested address, time, and HTTP status code
- Browser type and operating system
This data serves to deliver the page, troubleshoot errors, and protect against misuse. To limit request frequency (protection against automated attacks), counters are briefly maintained based on the IP address.
Cache (Redis): For ongoing operation, we use a server-side cache on the same server. It holds your session data, the counters mentioned above, and short-lived processing data for communication between server processes.
Legal Basis: Legitimate interest in secure and trouble-free operation (Art. 6 para. 1 lit. f GDPR).
Reach Measurement
To assess server load, we record how many people use the game within a given time window. This happens exclusively server-side.
- Method: For each 5-minute window, your user identifier is added to a list so the same person is not counted twice. This list is deleted automatically after at most 15 minutes.
- Permanently stored are only the resulting figures (e.g., "42 active users") and technical measurements such as response times and memory usage — without any personal reference.
- No tracking on your device: No analytics cookies are set and no third-party analytics services are integrated.
- Purpose: Technical performance analysis, stability, and estimation of required server capacity.
- Legal Basis: Legitimate interest in technical optimization and resource planning (Art. 6 para. 1 lit. f GDPR).
Development Logs
This website is in active development (beta phase). For troubleshooting, temporary additional technical logs may be collected (e.g., timestamps, HTTP status codes, error messages).
These logs are viewed exclusively by the operator, are not passed on to third parties, are deleted after a maximum of 30 days, and do not contain passwords or plain-text email addresses.
Legal Basis: Art. 6 para. 1 lit. f GDPR (Legitimate interest in technical stability and security).
Cookies and Storage on Your Device
The website stores data on your device — partly as cookies, partly in the browser's local storage, and in the mobile app in the app storage. Legally, all of these accesses are treated alike (Section 25 TDDDG).
- Session cookies: Are automatically deleted after the end of your visit.
- Permanent cookies: Remain stored on your end device until you delete them yourself or an automatic deletion is carried out by your web browser.
- First-party: Come from us. We currently do not use third-party cookies.
Legal Basis:
- Necessary entries: They are strictly necessary for us to provide the service you have expressly requested (Section 25 para. 2 no. 2 TDDDG). The subsequent processing relies on performance of a contract (Art. 6 para. 1 lit. b GDPR) or our legitimate interest in a technically error-free service (Art. 6 para. 1 lit. f GDPR).
- Entries requiring consent: Based on your consent (Section 25 para. 1 TDDDG, Art. 6 para. 1 lit. a GDPR). You can revoke it at any time via "Change cookie settings" in your settings.
You can set your browser so that you are informed about the setting of cookies and generally exclude them. The functionality of this website may be restricted if cookies are deactivated.
Overview
Necessary (always active):
- connect.sid (cookie, 30 days) — encrypted session identifier for login and session management. Contains no personal data in plain text.
- __Host-psifi.x-csrf-token (cookie, session duration) — protection against cross-site request forgery for forms and actions.
- i18n_locale (cookie) — remembers your language selection.
- loa_ref (local storage, 30 days) — retains a referral code you opened until the login process. Technically required for the login flow.
- consent_marketing (local storage) — stores your decision from the consent banner so you are not asked again.
- Dismissed announcements (local storage) — remembers which notices you have already closed.
- Mobile app login tokens (app storage, 7 and 30 days respectively) — keep you signed in within the app.
With consent (category "Marketing"):
- loa_ref (cookie, 30 days) — carries a referral code from the "Refer a Streamer" programme even if you are already signed in. It is deleted if consent is missing or revoked.
Note: The "Marketing" category currently covers this referral cookie only. No advertising is served and no third-party advertising or analytics services are integrated (no Google Ads, no AdMob, no Google Analytics). Should this change, we will update this policy beforehand and ask for your consent again.
Inquiry by E-mail
If you contact us by email, your inquiry including all resulting personal data will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.
Legal Basis:
- If your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures (Art. 6 para. 1 lit. b GDPR).
- In all other cases, processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR).
Storage Duration: The data sent to us will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage ceases to apply. Mandatory legal provisions - in particular statutory retention periods - remain unaffected.
Twitch OAuth Login
This website uses the OAuth authentication of Twitch Interactive, Inc. ("Twitch") to enable you to log in.
Purpose of Data Processing
When you log in via Twitch, the following data is transmitted from Twitch to us and stored:
- Your Twitch User ID (for unique identification).
- Your Twitch Username.
- Your Twitch Display Name.
- Your Email Address (stored encrypted with AES-256-GCM).
This data is used exclusively for authentication, provision of our services, and contact (e.g., in case of account deletion).
Further Account Data
In connection with your player account, we additionally store:
- Associated city and your role within the game
- Your game characters with attributes, inventory, and progress
- Settings: vacation mode, reduced motion (accessibility — disables animations), public display of your activities, consent decision
- Timestamps for last activity and last city access
Data Security
Your email address is stored encrypted in our database. Your Twitch password is never transmitted to or stored by us. Session management is carried out via encrypted, HTTP-only cookies. All connections are SSL/TLS encrypted (HTTPS).
Legal Basis
Performance of a contract (Art. 6 para. 1 lit. b GDPR): Logging in via Twitch is a prerequisite for us to provide the game to you — without it there is no player account. You can end the processing at any time by deleting your account.
Data Transfer
When logging in, you will be redirected to the Twitch servers. The data transfer between your browser and Twitch is encrypted. After successful authentication, Twitch transmits the above-mentioned data to our server.
Further information on data processing by Twitch can be found in Twitch's privacy policy: https://www.twitch.tv/p/en/legal/privacy-notice/
Storage Duration
The data transmitted by Twitch is stored as long as you use our service. You can delete your account at any time via the settings. After confirmation, all your data will be irrevocably deleted from live operation; it disappears from backup copies after at most 2 days (see "Database Backups").
Login in the Mobile App
In the iOS and Android apps, authentication uses access tokens instead of session cookies.
- The tokens are stored on your device in the protected app storage.
- In parallel, our database records which tokens are valid so that they can be invalidated on logout or misuse.
- Validity: 7 days for the access token, 30 days for the refresh token.
- Legal Basis: Performance of a contract (Art. 6 para. 1 lit. b GDPR).
Twitch Channel Points, Subscriptions, and Bits
In order for the bot to be added to a Twitch channel, the streamer grants our service permissions for their own channel during the connection process. This authorization is a prerequisite for the bot to operate in the channel — without it, the channel cannot be set up.
Granted Permissions
The authorization covers permission to read and manage channel point redemptions and to read subscriptions and bits. The access tokens required for this are stored encrypted and are assigned exclusively to the respective streamer account.
Processed Data
- Subscriptions and bits: Only aggregated counters are formed, from which a bonus for the city is calculated. It is not stored which person subscribed or sent bits.
- Channel point redemptions: A redemption triggers a game action. The Twitch name of the redeeming person is processed in order to assign the action to the correct game character. It is not stored permanently and not logged.
Legal Basis and Revocation
Performance of a contract (Art. 6 para. 1 lit. b GDPR): The authorization is a necessary component of the service the streamer makes use of. The streamer can revoke it at any time in the Twitch settings or through us; the stored tokens are then deleted and the bot ceases its work in the channel.
For individual channels from the earlier beta phase, this authorization does not exist. There, subscription events are instead counted from the notices publicly visible in chat — likewise only as an aggregated figure.
Twitch Bot Integration (VoiceOfArthengard)
For certain features, we use a Twitch bot named "VoiceOfArthengard". This bot is only active in selected Twitch channels whose owners have explicitly authorized us.
Functionality
The bot connects to the Twitch chat and processes commands entered by viewers in the chat. The bot reacts exclusively to predefined commands and does not store chat logs.
Processed Data
- Twitch channel names of streamers for whom the bot has been activated.
- Commands entered in the chat (only for processing, no permanent storage).
No private messages or user IPs are processed.
Legal Basis
Legitimate interest (Art. 6 para. 1 lit. f GDPR) in providing the game service.
Data Deletion
If the bot is deactivated for a channel, the channel name is removed from the bot's configuration.
Discord Linking (Voluntary)
You can voluntarily link your Discord account to your player account in order to automatically receive the appropriate role on our Discord server.
Processed Data
- Your Discord identifier (user ID), which we store with your account.
- When connecting, we request only the "identify" permission from Discord — that is, your identifier, no messages and no server lists.
Purpose and Transmission
Based on your role in the game, we automatically assign or remove a role for you on the Legends of Arthengard Discord server. For this purpose, we transmit your Discord identifier to Discord (see "Transfer to Third Countries").
Legal Basis and Revocation
Consent (Art. 6 para. 1 lit. a GDPR). Linking is entirely voluntary — the game works without any restrictions if you do not link an account. You can disconnect at any time in the settings; the stored Discord identifier is then removed.
Discord's privacy policy: https://discord.com/privacy
Temporary Guest Profiles (Chat Participation)
Twitch viewers can participate in the game via chat commands without registering. As soon as such a command is used for the first time, the system automatically creates a temporary guest profile.
Data Stored
- Twitch User ID (stored encrypted)
- Twitch username and display name (stored encrypted)
- Associated city ID (of the active streamer)
- Temporary game character with basic game values
No email addresses, IP addresses, or other identifying data are stored. All stored data is publicly visible in the Twitch chat anyway.
Purpose
- Managing the game session (preventing duplicate jobs)
- Displaying activity in the city feed
- Enabling later transfer of progress upon registration
Legal Basis
Legitimate interest (Art. 6 para. 1 lit. f GDPR): The processing is technically necessary for providing the chat game feature and is directly related to voluntary participation in the game. The data used is publicly accessible in the Twitch chat; no overriding legitimate interest of the data subjects is recognizable.
Storage Duration and Deletion
Guest profiles are automatically deleted as soon as one of the following events occurs:
- 1 hour after the stream ends — all guest accounts of the stream are deleted
- 8 hours after first participation — even while the stream is still running
No permanent storage takes place and no data is passed on to third parties.
Taking Over Your Profile
Within the deletion period, you can permanently save your game progress by registering in the app with your Twitch account. After the period expires, recovery is not possible.
Opt-out
A guest profile is only created through active use of a chat command. Anyone who does not use chat commands will not have any data stored.
Referral Programme "Refer a Streamer"
Streamers can be introduced to Legends of Arthengard via a personal referral link. Two roles are to be distinguished here.
Referring person (who shares the link)
- A referral code is generated and assigned to the account. It is created when the settings are first opened.
- For each successful referral, the identifier of the referring person is stored so that the reward can be attributed.
Referred person (who arrives via the link)
- Upon registration, their identifier is stored together with the code used — so that it is apparent which referral led to which sign-up.
- In addition, the processing status is recorded (registered, conditions met, rewarded) along with the associated timestamps.
- Before registration, the code is merely cached on the person's own device (see below). No entry is created in our database as long as no registration takes place.
Storage on Your Device
If you open a referral link, the code is cached on your device so that it is still available at a later login:
- In local storage (30 days) — technically necessary for the login process.
- Additionally as a cookie (30 days) — only with your consent in the "Marketing" category. Without consent this cookie is not set, and it is deleted upon revocation.
Legal Basis
Performance of a contract for handling the reward (Art. 6 para. 1 lit. b GDPR) and your consent for the referral cookie (Art. 6 para. 1 lit. a GDPR, Section 25 para. 1 TDDDG).
Publicly Visible Content
Parts of the game are deliberately public because they are aimed at the Twitch community. The following is visible without logging in:
- City leaderboard: name of the city, name of the ruling streamer, and the city's game statistics. The streamer name is publicly visible on Twitch anyway.
- Press area: exclusively aggregated totals without any personal reference.
The following is visible only after logging in:
- Player leaderboard within a city, listing individual characters with their values and titles.
Display of Your Activities
Your in-game activities (e.g., completed tasks) may be shown in the city feed and via the bot in the Twitch chat. This display is enabled by default.
You can turn it off at any time in your settings. After that, your activities appear neither in the city feed nor in the chat.
Legal Basis: Legitimate interest in the shared gameplay experience (Art. 6 para. 1 lit. f GDPR); you may object to this display at any time via the setting mentioned above.
Email Communication
We send emails exclusively in the following cases:
Account Deletion
Two-step process: If you request the deletion of your account, we will send you a confirmation email with a time-limited link (valid for 1 hour). Only after clicking this link will your account be permanently deleted.
Email content: Confirmation link for account deletion, note on the irrevocability of the deletion, expiration time of the link.
Future Features
In future, we may also send emails for the following purposes: Confirmation upon account creation, security-relevant notifications.
Technical Details
Legal Basis: Art. 6 para. 1 lit. b GDPR (Performance of a contract) for account deletion; Art. 6 para. 1 lit. a GDPR (Consent) for optional notifications.
Your email address will be used exclusively for the purposes mentioned above and will not be passed on to third parties.