# Privacy Policy

_Last updated: 2026-09-05_

This Privacy Policy explains what personal data WorldSweeper ("the Service",
"we", "us") collects when you create and use an account, why we collect it,
where it is stored, and the rights you have over it. By creating an account you
agree to the practices described here.

## 1. Data we collect

When you create an account and sign in, we collect and process:

- **Email address** — used as your login identifier.
- **Display name** — stored as the canonical game profile in the Service and
  shown to identify worlds and territory you own. We do not write game names to
  Firebase Authentication.
- **Representative color** — shown with your account identity, territory,
  presence, and ranking in every world you join.

We do **not** collect your password in our own systems: authentication is
handled by Google Firebase Authentication (see Section 4), which verifies your
password on its infrastructure. For visitors outside the European Union, we
use Cloudflare Web Analytics to measure aggregate page views and visits, viewed
page paths, referrer hosts, approximate country, device, browser and
operating-system categories, and page-performance metrics. Its browser beacon
does not use cookies or `localStorage`, and Cloudflare states that it does not
fingerprint or track individuals across sites or over time for analytics. We do
not use analytics data for advertising.

## 2. Why we collect it

- **Account authentication** — to verify who you are when you sign in.
- **World ownership** — to associate the worlds and territory you create with
  your account so your progress persists across sessions.
- **Shared-world appearance** — to show a consistent name and color to other
  players across joined worlds.

We do not sell your personal data, and we do not use it for advertising.

## 3. Where your data is stored

Authentication tokens and a copy of your account profile are stored **in your
own browser** using `localStorage`, under the keys:

- `ws.authState.v2` — while signed in, your session (includes email, display
  name, representative color, appearance revision, Firebase user ID, and
  refresh/ID tokens). On sign-out this is replaced by a version marker and
  generation number without the session or tokens.
- `ws.pendingProfileSync.v2` — temporary ambiguity-only command-receipt state,
  including an account key, desired display name and representative color,
  operation ID, expected profile revision, retry stage, and attempt time. It is
  cleared after the Worker confirms the canonical D1 write or a conflict
  supersedes it; it does not mean that room fan-out is still pending.
- `ws.accountDeletionPending` — account-keyed deletion-retry state created
  immediately before a self-service deletion request; it includes the account
  type, Firebase user ID, Firebase ID and refresh tokens, and optional email
  needed to retry safely if the response is lost or the ID token expires.
- `worldsweeper.question-marks.v1:*` — private question-mark notes scoped to
  the current account and world. These notes stay in the browser and are not
  sent to the shared-world server.

The signed-in session stays on your device until you sign out or clear browser
storage. A command-receipt entry can remain after a lost response until a retry
confirms the same operation or the account is signed out. A deletion-retry entry remains until deletion is
confirmed or unambiguously recovered, or until you clear browser storage. Your
email and authentication records are also held by Google Firebase
Authentication as our processor (see Section 4); the game display name is
stored canonically by the Service rather than written to Firebase. The Service stores
your representative color and appearance revision in its account database and
copies that appearance to each joined world's profile so other players receive
consistent realtime presentation. Room propagation is owned by a server-side
outbox; a successful profile response confirms the D1 canonical profile and
durable propagation target, not immediate convergence in every room. To make
interrupted profile updates safe to retry, the Service also stores an
account-scoped update record containing the operation ID, expected and applied
revisions, target display name and color, status, and timestamps until the
account is deleted. Older clients without operation/revision fields retain a
last-write-wins limitation during the server-first rollout.

## 4. Third-party processors

We use **Google Firebase Authentication** (operated by Google LLC) to create
accounts, verify passwords, and issue authentication tokens. When you sign up or
sign in, your email and password are sent over HTTPS to Google's identity
endpoint (`identitytoolkit.googleapis.com`). Google processes and stores this
data on its infrastructure as part of providing the authentication service.
Google's handling of that data is governed by Google's own privacy policy.

We also use **Cloudflare, Inc.** to deliver and protect the Service and to
provide Cloudflare Web Analytics. On production pages viewed from outside the
European Union, Cloudflare automatically injects a lightweight browser beacon
and receives the traffic and performance measurements described in Section 1
through the Service's `/cdn-cgi/rum` endpoint. Cloudflare's handling of those
measurements is governed by Cloudflare's own privacy policy.

## 5. Retention and deletion

- **On sign-out**, the signed-in data in `ws.authState.v2` is replaced by a
  signed-out marker without authentication tokens, and pending profile-update
  state is removed. If the browser cannot verify that removal, account sign-in
  is blocked with a storage error until cleanup succeeds. A pending
  deletion-retry entry, if any, remains available for the same account until
  deletion is completed or browser storage is cleared.
- **Account deletion**: you can permanently delete your account from the account
  controls in the Service. The Service deletes the corresponding Firebase
  Authentication identity, server account and profile, account-linked D1
  authentication-event records, profile-operation records, and room-propagation
  outbox targets. Territory
  opened and owned by the account is
  reset to hidden and unowned, and flags placed by the account are removed.
  Private browser question-mark notes and any command-receipt state are also
  removed.
  Fixed map coordinates and terrain and other users' data are not deleted.
- Within the active account database, the Service retains one-way digests of
  the Firebase user identifier and deletion recovery token while Firebase
  identity deletion is pending. The recovery digest lets only the same pending
  deletion exchange its browser-held refresh token with Firebase after the ID
  token expires; the Service does not store the raw recovery token in its
  database. After Firebase confirms deletion or absence, the recovery digest is
  cleared. The user-identifier digest remains only until the latest deletion
  token expires plus a short clock-skew allowance, and is then removed or
  ignored.
- Operational Analytics Engine events and structured request logs are separate
  infrastructure records used for service reliability, abuse prevention, and
  incident diagnosis. They may contain an internal user ID, a Firebase user
  identifier, or a hashed Firebase identifier and are not retroactively erased
  by the self-service deletion transaction. The application currently applies
  no separate per-account erase job or custom retention period to those
  provider-managed operational records.
- Cloudflare Web Analytics traffic and performance measurements are
  provider-managed and are not associated by the Service with application
  account IDs. Account deletion therefore does not target those measurements.
- We retain account data only for as long as your account exists or as required
  to provide the Service.

## 6. Your rights

Depending on your jurisdiction (including the EU GDPR and Korea's Personal
Information Protection Act), you have the right to:

- access the personal data we hold about you;
- correct inaccurate data;
- request deletion of your data;
- withdraw your consent at any time (note: an account cannot function without
  the data in Section 1, so withdrawal of consent means account deletion).

Use the self-service account controls for deletion. To exercise another right
or ask for assistance, contact us using the details in Section 7.

## 7. Contact

For privacy questions or data requests, contact: **hello.dn.apps@gmail.com**.

## 8. Changes to this policy

We may update this Privacy Policy. Material changes will be reflected by the
"Last updated" date above. Continued use of the Service after an update
constitutes acceptance of the revised policy.
