1) Summary (plain language)
- We collect minimal personal data required to run the game.
- We use limited product analytics to understand acquisition and gameplay usage.
- No session replay, automatic click tracking, device fingerprinting, or advertising.
- We process limited security data such as IP address data for rate limiting, abuse prevention, and debugging.
- Browser push notifications are optional. If enabled, we store the browser push subscription needed to deliver notifications.
- Account deletion is available and designed to be deliberate (typing "DELETE").
2) Information we collect
A) Personal information (via Google sign-in)
When you sign in with Google OAuth, we may collect and store:
- Email address
- Name (if available from Google)
- Google account identifier data needed for sign-in
- OAuth tokens (Google access/refresh/ID tokens) stored server-side
B) Profile, settings, and game data
We store game data to operate gameplay and the shared economy, including:
- User profile (display name, friend tag, role, settings, push preferences)
- User currency (gold and gems are stored on your user account)
- Characters (name, current zone, last town, online heartbeat, gank and random-encounter settings, creation date)
- Inventory and storage (items, quantities, rarity, equipped/listed state, durability, repair charges, town storage)
- Activities (type, start/completion times, results, parameters, dungeons, travel, gathering, crafting, refining, and random encounters)
- Market transactions (buyer/seller IDs, items, prices, fees, timestamps)
- Auctions, trades, combat, skills, friendships, and social profile data
C) Chat data
- Chat messages (content, channel, timestamps, author display name)
- Private messages (content, participants, timestamps, sender display name and character name)
D) Authentication & session data
- Session tokens stored in the database with expiry dates
- JWT tokens for API and WebSocket authentication
- Cookies used by authentication and admin tools (details below)
E) Push notification data
If you enable browser push notifications, we store:
- Push subscription endpoint
- Push subscription keys (
p256dh and auth)
Private-message push notifications identify the sender but do not include private message content.
F) Admin, security, and diagnostic data
- IP address data may be forwarded to the backend and used for rate limiting, abuse prevention, security, and debugging.
- API and WebSocket authentication events may be processed to keep the Service secure.
- An admin log viewer stores up to the last 5,000 log entries in memory, which may include user IDs, IP-derived rate-limit context, actions, and errors.
G) Product analytics data
We use PostHog Cloud in the United States to collect limited product analytics, including:
- Account signup, character creation or selection, game sessions, and activity starts
- Internal user and character IDs, character names, account role, zone, and activity type
- Device category, operating system, browser, and browser/PWA/Android app usage
- Public page views, referring domain, landing page, and UTM campaign parameters
- Daily activity markers used to measure daily, weekly, and monthly retention
First-touch and latest-touch campaign information may be stored in your browser and linked to your account after sign-in. We disable PostHog session replay, automatic click capture, precise-location enrichment, and capture of chat or other written content.
3) What we do NOT collect
We do not collect:
- Passwords
- Precise geolocation
- Device fingerprinting
- Session recordings or automatic click tracking
- Payment information
- File uploads
- Tracking pixels
4) Cookies and local storage
Cookies
We use cookies for authentication, app behavior, and analytics:
- NextAuth session cookies (authentication)
aruvia-last-game-path (the last game page, used to resume signed-in players without showing the public homepage)aruvia-last-chat (the last selected chat channel or private conversation, used to restore the chat view on this device)- PostHog may store an analytics identifier and related SDK state
Local storage (browser)
We may store local UI or admin-support state, including:
aruvia-nav (last game navigation state)aruvia-town-storage-zone (selected town storage)aruvia:auto-push-enable-disabled (push notification preference helper)aruvia-admin-sql-draft (admin SQL draft, only for admins using that tool)- PostHog analytics identifiers and SDK state, plus Aruvia first-touch, latest-touch, daily-active, and signup-attribution state
Service worker and browser caches
In production, Aruvia may register a service worker that caches app shell/static assets and limited reference data such as zones and crafting recipes for offline support. It does not intentionally cache authenticated mutation responses.
5) How we use information
We use the information above to:
- Authenticate you and maintain sessions
- Provide core gameplay (characters, inventory, activities, market, chat, private messages)
- Prevent abuse, enforce rules, and moderate chat and private messages
- Send optional browser push notifications you enable
- Debug issues and maintain security
- Measure acquisition sources, feature usage, and player retention
- Operate admin tools (including impersonation for support/moderation)
6) Legal basis (Ontario/Canada)
We generally process your information based on:
- Your consent (e.g., choosing to sign in with Google and use the Service)
- Reasonable purposes necessary to provide and secure the Service (consistent with Canadian privacy principles)
7) Sharing of information
We do not sell your personal information.
We share information only in limited ways:
- Google OAuth (for authentication)
- Browser push services (only if you enable push notifications)
- PostHog Cloud (United States) for the limited product analytics described above
- Public-facing game features: your character name and chat display name may be visible to other players in-game. Social profile data, friend tags, character summaries, marketplace listings, auction listings, combat logs, trade context, and chat messages may also be visible to other players depending on the feature. Private messages are visible to the intended conversation participants and may be reviewed by admins for support, safety, moderation, or enforcement.
- Service providers that host, operate, secure, or support the Service.
- Legal/safety: if required by law, subpoena, or to protect users and the Service.
External links:
- Discord is an external link only; we do not load Discord SDKs or trackers.
8) Data retention and account deletion
Deleting your account
You can delete your account from the Settings menu in-game. To reduce accidental deletion, you must type "DELETE" to confirm.
See the account deletion instructions to delete your account from any supported browser or request help if you cannot sign in.
Deletion may be blocked while one of your characters has an active auction or leading bid that has not expired or settled.
What is deleted through the account deletion flow
When account deletion succeeds, the user row is deleted and database cascade rules delete account-owned records such as:
- authentication accounts and sessions
- characters, inventory, activities, skills, town storage, and push subscriptions
- friendships, trade sessions, combat requests, market listings, and most owned gameplay rows
Records that may remain after deletion
- Your chat messages and private messages are retained for moderation purposes, but are no longer linked to your deleted account or character rows.
- Only the display name and character name at the time of sending are preserved with those messages.
- Resolved combat history and other historical snapshots may remain for game integrity, logs, debugging, moderation, or legal reasons.
- Analytics records held by PostHog may remain until their configured retention period expires or a separate deletion request is processed.
9) Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data. However, no online service can guarantee absolute security.
10) International access and data transfers
Aruvia may be accessed from outside Canada. If you use the Service from another country, your information may be processed in Canada, the United States, or other locations where the Service or its providers operate, subject to this Policy.
11) Your choices and rights
Depending on your location and applicable law, you may have rights to:
- Request access to personal information we hold about you
- Request correction of inaccurate information
- Request deletion (available in-product as described above)
To make a request, contact: contact@qedized.com
12) Children
Aruvia is not available to users under 13. We do not knowingly collect personal information from children under 13. If you believe a user under 13 has used the Service, contact us.
13) Changes to this Privacy Policy
We may update this Policy by posting changes on aruviarpg.com. We also intend to announce and summarize changes transparently on the Game's Discord server (linked in the Game's About section). Continued use after changes means you accept the updated Policy.