Version 1.0.0 · Effective 2026-09-23
Privacy Notice
This notice describes how the current beta processes information based on the application's actual behavior.
Who operates this beta
RumpelCoin operates the Rumpelstiltskin public beta website and browser game.
Privacy questions: legal@rumpelstiltskin.life. Support: support@rumpelstiltskin.life.
Adult beta audience
This beta is intended for adults 18 years of age or older. We do not knowingly collect personal information from anyone who indicates they are under 18.
Self-attestation is not government ID verification and does not by itself prove legal age.
Information we process
- Anonymous player IDs such as player-{uuid} stored in slug-scoped HttpOnly cookies.
- No account username, email address, or birth date is collected for public gameplay.
- Gameplay progress JSON including inventory, quests, chapter progress, crafting state, NPC relationships, and virtual Gold/Credits balances.
- Stored locally in development file persistence when enabled, or in Postgres JSONB when DATABASE_URL/POSTGRES_URL is configured.
- Optional player-generated recovery codes in RUMPEL-XXXX-XXXX-XXXX format.
- Only a SHA-256 hash and a four-character hint are stored server-side; plaintext recovery codes are shown once to the player.
Information we do not currently collect
- Birth date or government ID
- Wallet addresses for gameplay
- Payment card or bank account data
- Precise geolocation
- Contacts or address book data
- Advertising identifiers
- Cross-site behavioral profiles
- Sale or sharing of personal information
Cookies and similar technologies
- clf-game-player-{coin-slug}: Stores an anonymous gameplay player identifier so progress can be loaded on return visits. HttpOnly, SameSite=Lax.
- clf-consent-preferences: Stores consent policy version, necessary/analytics/advertising choices, timestamp, and whether Global Privacy Control was detected when saved.
- clf-legal-ack: Stores a signed adult beta acknowledgment (document version, issue time, expiry, nonce). HttpOnly, SameSite=Strict.
- clf_admin_session: Admin-only signed session for the internal dashboard. Not used on public gameplay pages.
Browser storage on your device
- localStorage clf-game-audio-settings: Optional gameplay audio volume and mute preferences on the player device.
- localStorage clf-game-muted: Legacy/simple mute flag used by some gameplay UI paths.
- sessionStorage clf-phase810-landscape-dismiss: Remembers dismissal of a landscape-orientation helper during the current browser session.
Why we process information
- Provide gameplay, save progress, and optional recovery codes.
- Remember consent choices and adult beta acknowledgment.
- Secure the admin dashboard separately from public gameplay.
- Operate hosting, database, and asset storage infrastructure.
- Run admin-only production tooling that may call OpenAI.
Analytics and advertising
Optional first-party analytics may run only after valid 18+ legal acknowledgment, analytics consent, and an anonymous player cookie. When enabled, events are pseudonymized, allowlisted, and retained for up to 90 days. Advertising integrations remain disabled in the current build.
If analytics or advertising is authorized in a future release, this notice and the consent manager will be updated before those tools load.
Wallets, tokens, and virtual currency
Public gameplay does not require a wallet. Virtual Gold and Credits have no cash or cryptocurrency value. $RUMP is not currently earned through gameplay in this beta.
Gold and Credits are entertainment-only balances with no cash or cryptocurrency value in the current beta.
Service providers
- Netlify hosting/runtime when deployed for public beta.
- Cloudflare DNS/registrar/security when configured by the site owner.
- Neon Postgres when DATABASE_URL or POSTGRES_URL is configured.
- Optional Sentry error monitoring when OBSERVABILITY_PROVIDER=sentry and DSN values are configured.
- Vercel Blob when generated art storage is enabled for admin write workflows.
- OpenAI API for admin-only coin asset generation workflows (not player gameplay requests).
OpenAI usage
OpenAI image/content generation runs only from authenticated admin workflows for coin production tooling. Player gameplay requests do not call OpenAI.
Where data is stored
- game_players: coin_slug, player_id, save_data (JSONB), recovery_code_hash, recovery_code_hint, created_at, updated_at
- game_art_manifests: coin_slug, manifest_data (JSONB), updated_at (when Postgres-backed generated art is enabled)
- analytics_events: coin_slug, player_pseudonym (HMAC), event_name, idempotency_key, properties (JSONB), created_at (optional when ANALYTICS_ENABLED=true and consent is granted)
- analytics_player_daily: coin_slug, player_pseudonym, day, event_count (rate-limit bookkeeping for optional analytics)
- Generated game art binaries and manifests may be stored in Vercel Blob when GENERATED_ART_STORAGE and BLOB_READ_WRITE_TOKEN are configured.
- Public beta read-only assets are served from Git-tracked coin files via /coin-assets/ and do not require Vercel Blob.
Server and security logs
- Standard hosting/server logs may include request timestamps, paths, user agents, and IP addresses depending on deployment platform configuration.
- This application does not currently implement its own long-term IP profiling or behavioral tracking database.
Retention
Gameplay saves persist until deleted through beta maintenance, account reset, or a supported deletion request, subject to backup and legal retention limits.
Consent and legal-acknowledgment records persist for the life of their cookies unless you clear cookies or change preferences.
Hosting logs are retained according to the deployment provider's settings.
Security
We use HttpOnly cookies, signed admin and legal-acknowledgment tokens, access controls on admin routes, and server-side validation for gameplay mutations.
No online service can guarantee absolute security. Report suspected security issues using the support page.
Your choices and requests
- Use Privacy choices to accept or reject optional analytics and advertising categories.
- Email privacy requests to the contact address above for access, correction, or deletion where applicable.
- California residents may submit privacy requests to the same contact address.
Global Privacy Control (GPC)
When we detect GPC (Sec-GPC: 1 or navigator.globalPrivacyControl), Advertising is treated as off and cannot be turned on through Accept optional.
We do not currently sell or share personal information. GPC preferences are honored prospectively if those practices change after updated notice and consent.
Children
This beta is not directed to children under 13 and is limited to adults 18+.
If you believe a child provided information, contact us and we will take appropriate steps to delete it where required.
International access
If you access the beta from outside the United States, you understand information may be processed in the United States and other countries where our service providers operate.
Changes to this notice
Version 1.0.0, effective 2026-09-23. Material changes will update the version and effective date and may require renewed adult acknowledgment before gameplay.