Hearthsea

Privacy policy

What we collect when you play Hearthsea, why we need it, who else handles it, and how to get it changed or deleted. Effective 6 October 2026.

Who we are

Hearthsea is an online board game at hearthsea.com, run by a small independent team based in Amman, Jordan. In this policy, “Hearthsea”, “we” and “us” mean that team, and we are responsible for the personal data described here.

For any privacy question or request, email hello@hearthsea.com.

What we collect

Your account

  • Your email address and username.
  • Your password, stored only as a scrypt hash. We can’t read it, and nobody at Hearthsea ever sees it.
  • The avatar and colour you pick.
  • When the account was created and when you were last active, plus the dates (not times) you played, which we use to count daily players.
  • Your friends list and friend requests, if you use them.

If you sign in with Google

Google Identity Services sends us a signed token. From it we keep your Google account ID and email address. Google also includes your name, which we use only to suggest a username the first time you sign in; we don’t store it. We never receive your Google password.

Your games

  • Game stats, levels and achievements tied to your account.
  • For online games: who sat at the table, the map and mode, start and end times, the number of turns, final scores and the winner. While a game is running, we also keep its moves so it can be resumed if the server restarts; those are deleted when the game ends.

Online games have no free-text chat. The emotes are a fixed set, and we don’t store them.

Purchases

When you start a trial or buy something, we keep a record of what you bought, the price, the currency, its status, the Stripe references for the payment and your Stripe customer ID, along with what your account is entitled to and until when. Stripe handles the card itself, so we never see or store your full card number.

Technical data

Every request to our server comes with your IP address. The game uses it in memory to limit how fast one address can send requests (for example, failed sign-ins and password-reset emails), and forgets it within an hour. We don’t write IP addresses to our database. Our web server keeps no access logs for Hearthsea. Its error log can record an IP address when a request fails, and we use it only to find faults and stop abuse.

We also count page views per day as a single total, with nothing that identifies who viewed.

How we use it

  • To run your account: sign you in, keep you signed in, and show your username, avatar and stats to the people you play with.
  • To run online games and keep your progress, achievements and friends in sync across devices.
  • To take payments, unlock what you paid for, and handle trials, renewals, cancellations and refunds.
  • To send account emails you need, such as password reset links and a notice when your password changes. We don’t send marketing email.
  • To keep the game fair and safe: rate limiting, spotting abuse, and acting on cheating or harassment reports.
  • To understand, in aggregate, how many people play and which modes and maps they use, so we know what to fix and build next.

We don’t show ads, we don’t sell or rent your data, and we don’t use third-party analytics or tracking scripts.

Legal bases

If you’re in the European Economic Area or the United Kingdom, the GDPR asks us to name the legal basis for each use.

  • Contract: running your account, your games and your purchases is the service you signed up for.
  • Legitimate interests: security logs, rate limiting, preventing cheating and fraud, and aggregate counts of how the game is used. We keep these to the minimum that does the job.
  • Legal obligation: keeping payment records that tax and accounting law require.

Who else handles it

A few companies process data for us so the game can work. Each gets only what its part needs.

  • Stripe processes payments. It receives your card details directly from you, and your email so it can send receipts. Stripe’s own privacy policy covers what it does with them.
  • Google provides “Sign in with Google”, if you choose it. When you use the Google button, Google’s script loads from Google’s servers and Google’s privacy policy applies to that sign-in.
  • Brevo sends our account emails, so it receives your email address, your username and the message itself.
  • DigitalOcean hosts our server and database, and Laravel Forge is the tool we use to manage that server.

We may also share data when the law requires it, such as a valid court order, or to protect players or the service from fraud or abuse. If Hearthsea were ever sold or merged, your data would move with the game and this policy would continue to apply until you’re told otherwise.

Where it’s stored

Our server and its MySQL database are hosted by DigitalOcean in New York, in the United States. If you play from elsewhere, your data travels to and is stored in the US. Where the GDPR applies, we rely on our providers’ standard contractual clauses or equivalent safeguards for those transfers.

Cookies and device storage

We set one cookie, hs_session. It keeps you signed in, lasts up to 30 days, and is marked HttpOnly, so scripts on the page can’t read it. It’s essential: without it you can’t stay signed in, so we don’t ask for consent to it. We use no advertising or analytics cookies.

The game also saves things in your browser’s local storage, on your own device: your sound and game settings, a note of whether you’re signed in, your chosen face and table setup, tutorial progress, and saved offline games and progress. The game also caches its own files so it loads quickly and works offline. None of this is sent to us unless you sign in and sync. Clearing your browser’s site data removes it.

If you click “Sign in with Google”, Google may set its own cookies under its policy.

How long we keep it

  • Account data, stats, achievements, friends and purchase records: while your account exists.
  • Sign-in sessions: up to 30 days, or until you sign out.
  • Password reset links: they expire after one hour.
  • IP addresses used for rate limiting: up to one hour, in memory only.
  • Server error logs: rotated daily and deleted after 52 days. We keep no access logs.
  • Backups of the server are made weekly and replaced as new ones are made, so deleted data disappears from backups as older copies are overwritten.

When an account is deleted, we purge it 30 days later, as explained in Deleting your account. Two things stay after that. Summaries of finished online games keep the usernames that played in them, so the other players’ histories stay correct. And our internal admin log keeps a short record of actions taken on accounts (for example, that an account was deleted), which can include the username and email at the time. Stripe keeps its own payment records for as long as financial law requires.

Your rights

Wherever you live, you can ask us to:

  • tell you what personal data we hold about you and send you a copy;
  • correct anything that’s wrong;
  • delete your account and its data;
  • export your data in a machine-readable format (JSON);
  • stop or limit a particular use, or object to it.

Email hello@hearthsea.com from the address on your account, or tell us your username. We may ask you to confirm the request from that address before acting on it. We reply within 30 days, and requests are free.

In the EEA and UK you can also complain to your local data protection authority. California residents have the rights the CCPA gives them, including to know, delete and correct. We don’t sell or share personal information for cross-context advertising, and we won’t treat you differently for using any of these rights.

Deleting your account

Email hello@hearthsea.com and ask us to delete your account. We mark it deleted straight away: you’re signed out everywhere and the account can no longer sign in. Thirty days later it’s purged for good, together with its sessions, friends, purchases, entitlements, stats, achievements, game seats, trial record and activity dates. The 30-day gap is there so a mistaken or malicious request can be undone; write to us within that time if you change your mind.

Deleting your Hearthsea account doesn’t cancel a subscription by itself. Cancel your Pass first, or tell us in the same email and we’ll cancel it for you.

Children

Hearthsea isn’t directed at children under 13, and you must be at least 13 to create an account. If you’re under the age of digital consent where you live, a parent or guardian needs to agree to you using it. If you think a child under 13 has given us personal data, email us and we’ll delete the account.

Security

The site is served only over HTTPS. Passwords are hashed with scrypt, session tokens and password reset tokens are stored as hashes, and the session cookie is HttpOnly. Access to the server and database is limited to the people who run Hearthsea. No system is perfectly secure, but if a breach affects your data we’ll tell you and the relevant authorities as the law requires.

Changes to this policy

If we change this policy, we’ll update the effective date at the top. If a change affects how we use data you’ve already given us, we’ll tell you by email or in the game before it takes effect.

Contact

Questions, requests and complaints go to hello@hearthsea.com. The terms you agree to when you play are in our terms of service.