Privacy Policy & Cookies

Last updated: 14 July 2026

The short version

  • We set no cookies of our own — no advertising, no tracking, no third-party pixels.
  • The game stores your save file and settings on your own device, because that is how a game works. That is the only thing it stores unless you sign in.
  • If you sign in, your display name, email and game progress are stored in Google Firebase so you can play across devices and appear on the leaderboard.
  • You can play as a guest and nothing leaves your device.
  • You can delete your account and all its data yourself, from the in-game Settings screen. No email required, no waiting.
  • We do not sell your data. There is nobody to sell it to.

1. Who is responsible for your data

Mystvale is a free browser game at mystvale.org, built and run by a single independent developer based in Sweden. That developer is the data controller — the person who decides why and how your data is used — and is personally accountable for everything in this policy.

For anything at all — access, correction, deletion, complaints, or a request for the controller's full legal identity, which we will provide on request — write to privacy@mystvale.org. We answer within 30 days, as the GDPR requires.

2. What we collect, why, and on what legal basis

Only what the game actually needs. There is no marketing profile, no ad tech, and no behavioural targeting anywhere in Mystvale.

WhatWhyLegal basis (GDPR Art. 6)
Account — display name, email address, password (handled by Firebase Authentication; we never see your password) To create your account, sign you in, and keep your progress attached to you Contract — Art. 6(1)(b): you asked us to give you an account
Game progress — matches, wins, kills, damage, XP, gold, rank, unlocks, achievements, cosmetics, match history To save your progress and run the ranked ladder Contract — Art. 6(1)(b)
Public leaderboard entry — display name, rank, wins, kills, damage. Never your email. The ladder is a core feature of a competitive game Contract — Art. 6(1)(b): you chose to play ranked
Multiplayer session — your class pick, your inputs, a session ID, and your IP address while connected to the relay server To run the match. Inputs and positions are simulated on the server and discarded when the match ends Contract — Art. 6(1)(b)
Bug reports — the text you write, plus your account ID To reproduce and fix the bug, and to reply to you Legitimate interests — Art. 6(1)(f): keeping the game working
Server & security logs — IP address, browser type, timestamps, and audit records of changes to your save To stop cheating, abuse and fraud, and to investigate incidents Legitimate interests — Art. 6(1)(f): security and anti-cheat
Anonymous analytics — a random ID, page views, button clicks. No name, no email, no account data. To see which parts of the site people use Consent — Art. 6(1)(a). Off unless you turn it on; see §3

Playing as a guest? Then none of the above applies. Your save stays in your browser, no account exists, and nothing is sent anywhere except the multiplayer relay if you choose to play online.

3. Cookies and local storage

Mystvale sets no cookies of its own. What it does use is your browser's local storage — and under EU law that is treated exactly the same as a cookie, so here is the complete list. Everything below is strictly necessary to run the game or to remember a setting you chose yourself, which is why it needs no consent. Nothing here tracks you across other websites.

NameWhat it's forKept forNeeds consent?
mystvale_save_v1Your game save — progress, unlocks, settingsUntil you clear it or delete your accountNo — it is the game
mv_consent_v1Remembers the privacy choice you made on this pageUntil you clear itNo — we must store your choice to honour it
mvRenderQuality, mvMoveScheme, mvViewportV2*, mvHaptics, mvSpriteSheets, mvPremiumSpritesDisplay, control and performance settings, kept per deviceUntil you clear themNo — settings you chose
mvGateSeen, mvFsTipShown, mvThreshold, mv_resume_dismissedRemembers that you have already seen the title sequence, the fullscreen tip, and similar one-time promptsSession, or until clearedNo — functional
mystvale_sp_worker, mvConquest, mvSwKilled, mvNoGateSupport/debug switches, only ever written if you or we deliberately toggle themUntil clearedNo — functional
Firebase Authentication / Firestore (IndexedDB)Keeps you signed in and caches your cloud save. Only ever created if you sign in.Until you sign outNo — you asked to sign in
Cloudflare (__cf_bm, _cfuvid)Bot and abuse protection set by our host to keep the site online. We cannot read them.Up to 30 minutes / sessionNo — security
mv_anonAnalytics only. A random ID sent to PostHog with page views and anonymous in-game product events (e.g. which class you pick, when a match starts or ends). No name, no chat, no account data. Never created unless you opt in.Until you clear it or withdraw consentYes — opt-in

Analytics is currently switched off entirely. If we ever turn it on, you will be asked first, "reject" will be exactly as easy as "accept", and nothing will be stored or sent until you choose. You can review or withdraw your choice at any time:

4. Who else handles your data

Four companies process data on our behalf. Each is bound by a data-processing agreement, and none of them may use your data for their own purposes.

WhoWhat they doWhere
Google (Firebase)Sign-in, account storage, cloud save, leaderboardEU + United States
CloudflareHosts and delivers the website; blocks bots and attacksGlobal edge network
RailwayRuns the multiplayer relay server that hosts live matchesEU (Netherlands)
PostHogAnonymous product analytics, landing page and in-game — only if you opt inUnited States

5. Data leaving the EU

Google and PostHog are US companies, so some data reaches the United States. Those transfers rely on the EU–US Data Privacy Framework and, where it does not apply, on the European Commission's Standard Contractual Clauses. If you never sign in and never opt into analytics, no personal data of yours goes to either.

6. How long we keep things

7. Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to how it is used, take it with you (portability), and to withdraw consent at any time without it costing you anything.

In practice:

If you think we have handled your data wrongly, you can complain to the Swedish supervisory authority: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm — imy.se. You may also complain to the authority in your own EU country.

8. Children

Mystvale is not directed at young children, and we do not knowingly collect data from anyone under 13. In Sweden, 13 is the age at which a child can consent to their own data being processed online. If you are a parent and believe your child has created an account, email privacy@mystvale.org and we will delete it.

9. Security

The site is served over HTTPS only. Passwords are handled by Firebase Authentication and never reach our servers. Competitive data — rank, gold, unlocks — is written only by the server, never by your browser, so it cannot be tampered with from the client.

10. Changes to this policy

If this policy changes in a way that matters, we will update the date at the top and, where the law requires it, ask for your consent again.

← Back to Mystvale