← Back to the game

PRIVACY FILE / VERSION 13 AUGUST 2026

Privacy notice

This game uses privacy-minimised statistics to understand whether people can play it successfully. It does not use advertising trackers or build behavioural profiles.

What is recorded

Game statistics can record the selected fighter, opponent, difficulty, ladder rung, win or loss, winner, fight duration, remaining health, and completion of the dojo. These aggregate events contain no name, email address, account, chat text, advertising ID, or precise location.

If you finish the prize competition, the game stores your chosen one-to-four-character callsign, final score, fighter, competition month, server time, and a random private claim ID. Your callsign, score, fighter, and completion time appear on the shared public scoreboard. The claim ID remains private: it is both your receipt and secret claim code. Keep its screenshot private and send it only to the game creator if your entry wins.

Each new ladder run also receives a fresh random campaign ID. Fight events and the eventual prize receipt store only the same keyed one-way hash of that ID, allowing the protected admin dashboard to show how the fights connected to one receipt went. This can include attempts, opponents, results, duration, difficulty, ladder rung, and remaining health. The raw campaign ID is never stored in D1, is not reused for the next ladder run, and is not used to identify the player across campaigns or websites.

For future fights that the player wins, the game can also store a compact replay made from sampled combat state: fighter positions, health, guard and super meters, animation and attack states, and active projectiles. It is not video or audio. Losing fights are not stored as replays. Replay recording follows the same analytics opt-out, is available only in the protected admin dashboard, and cannot reconstruct older fights that were completed before replay support existed.

If you explicitly allow the optional unique-fighter count, the game creates a random ID in this browser. It is sent only with fight events. The Worker immediately converts it into a keyed one-way hash before storage, so D1 never stores the browser’s raw ID. The hash is used only to estimate how many consenting browsers or devices fought; it does not prove the number of individual people and is not used across other websites.

Cloudflare Web Analytics provides aggregated visits, page views, page-load performance, Core Web Vitals, country, referrer, browser, operating system, and device type. Cloudflare states that Web Analytics collects the minimum information needed for these reports, does not collect or use visitors’ personal data, and does not track individual users across its customers’ websites. Query strings are not logged.

Cloudflare also processes ordinary network request information as the hosting and security provider so it can deliver and protect the website. The game does not copy IP addresses, user agents, or Cloudflare request logs into its fight-statistics database.

Why it is recorded

The purpose is to measure game balance, find overly difficult fights, understand character choices, improve the game, secure the service, measure basic site usage, and verify how a voluntarily submitted prize receipt was earned. Aggregate game events are not intended to identify anyone. If operational request information is personal data, the intended legal basis is the controller’s legitimate interest in securely operating and improving this free game, balanced against visitors’ privacy through strict data minimisation.

The legal basis for storing and using the optional cross-session browser identifier is your consent. Refusing has no effect on gameplay, and you can withdraw at any time below.

Storage, access, and retention

Game events and compact won-fight replays are stored in a private Cloudflare D1 database connected to this game’s Worker. Only the protected admin dashboard can read the reports or open replays. Raw game events—including an optional keyed browser hash and the keyed single-campaign hash—and their replays are automatically removed after 90 days by default; the dashboard calculates its aggregate reports and receipt fight histories from those retained rows.

Prize receipts are stored separately from anonymous game statistics so the creator can verify winning screenshots. Shared public scoreboard rows are stored in a separate insert-only table that contains only the callsign, score, fighter, completion time, and an internal row reference; it does not expose the private claim ID, submission key, or campaign hash. Neither receipts nor scoreboard rows are removed by the 90-day analytics cleanup. Receipts are kept through the competition and prize-claim period; contact the creator to request access, correction, or deletion where applicable.

The random browser ID stays in localStorage until you withdraw consent, clear this site’s storage, or reset the browser. Withdrawing removes it immediately and stops future unique counting. Previously stored event rows age out under the 90-day retention policy.

Cloudflare hosts the game and processes Web Analytics beacon data. Cloudflare documents that unsampled beacon data is retained for seven days and then aggregated for longer-term reporting, with Web Analytics reports available for the previous six months. See Cloudflare Web Analytics documentation and Cloudflare’s privacy policy.

Your choice

You can disable both the aggregate game-event sender and Cloudflare Web Analytics beacon in this browser. The game will continue to work normally. This preference is stored only in your browser. It does not stop network requests that are essential to load and secure the game.

Optional unique-fighter count

Choose whether this browser may store a random ID for the unique-browser metric. Allowing and refusing are equally optional.

Contact and rights

The game creator is the data controller. Contact: @zzjrdd on X. If information connected to you is processed, European privacy law may give you rights of access, correction, deletion, restriction, objection, and complaint. In the Netherlands you can complain to the Autoriteit Persoonsgegevens.

If advertising, personalised tracking, accounts, or additional personal data are added later, this notice and the consent mechanism must be reviewed before those features go live.