Privacy Policy
Effective: March 5, 2026
1. Information We Collect
Account Information
When you create an account, we collect your email address, commander name, and authentication credentials. If you sign in via Google or GitHub, we receive your name, email, and profile picture from those providers.
Game Data
We collect data generated through your use of the Service, including: agent configurations (genome sliders, rule cards, code), match results, rankings, replay data, and performance statistics.
Feedback
When you submit post-match feedback, we collect your responses along with your user ID (if logged in) and the associated match ID.
Usage Data
We automatically collect technical information such as browser type, device information, IP address, pages visited, and interactions with the Service. We use PostHog for product analytics.
2. How We Use Your Information
- Operate the Service: Run matches, display leaderboards, generate replays, manage your account
- Improve the game: Analyze match data and feedback to balance gameplay and fix issues
- Communicate: Send service updates, security alerts, and (with consent) marketing communications
- Prevent abuse: Detect cheating, enforce fair play, and protect the competitive integrity of the arena
- Analytics: Understand how players use the Service to improve the experience
3. Information Sharing
We do not sell your personal information. We may share data with:
- Service providers: Supabase (database/auth), Vercel (hosting), Stripe (payments), PostHog (analytics), Cloudflare (CDN/storage)
- Public game data: Your commander name, rankings, match results, and replays are publicly visible on leaderboards and in shared replays
- Legal requirements: When required by law, legal process, or to protect our rights
4. Data Storage & Security
Your data is stored in Supabase (hosted on AWS) with row-level security policies. Authentication tokens are encrypted. We use HTTPS for all data transmission. While we implement reasonable security measures, no system is 100% secure.
5. Your Rights
You have the right to:
- Access your personal data through the Settings page
- Update your profile information at any time
- Delete your account and associated data through Settings
- Export your agent configurations and match history
- Opt out of marketing communications
To exercise these rights or request a full data export, contact us at privacy@crucibots.io
6. Cookies & Tracking
We use essential cookies for authentication and session management. PostHog may use cookies or local storage for analytics. You can disable non-essential cookies through your browser settings.
7. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.
8. International Users
The Service is operated from the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US. By using the Service, you consent to this transfer.
9. Data Retention
We retain your account data for as long as your account is active. Match replays and leaderboard data may be retained indefinitely for historical purposes. When you delete your account, we remove your personal information within 30 days, though anonymized game data may persist.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via the Service or email. The "Effective" date at the top indicates when the policy was last revised.
11. Contact
Privacy questions or concerns? Contact us at privacy@crucibots.io
