Privacy Policy
This policy explains how RivalCrest handles information when you visit our website, download the Android app, or use the game and its online services.
Last updated: August 23, 2026
Introduction
RivalCrest is a real-time strategy game available through the RivalCrest website, web game, Android app, and related online services. This Privacy Policy describes the information those current services process and the limits of the present beta.
Player Account and Profile Data
When online services are available, the game automatically creates or resumes an anonymous Supabase account. Supabase and RivalCrest process an internal user ID, authentication session and token data, account creation or update timestamps, and the accepted Terms and age-gate versions and confirmation timestamps. RivalCrest does not ask players for an email address, password, legal name, full date of birth, postal address, or telephone number.
Profile data associated with the account includes a player-chosen display name, active deck slot, decks and card identifiers, language, music and sound preferences, visual filter preference, and clan-chat preference.
Gameplay and Progression Data
RivalCrest stores or processes player level, experience, trophies, highest trophies, gold, gems, owned cards, card levels and experience, active and saved decks, chests, chest rewards and timers, daily rewards, trophy-road claims, arenas, seasons, ranks, percentiles, reward eligibility, and related timestamps.
For training, Quick Match, and private matches, the game processes authentication and session identifiers, player names, selected decks, trophies and declared progression, matchmaking state, private room codes, match and command identifiers, card plays and logical positions, simulation snapshots, scores, outcomes, end reasons, rewards, and reconnect tokens. Live battle state is handled by the Render game server; the Supabase database stores progression, reward, anti-duplication, and limited match-result records rather than a complete server-side replay history.
The game also keeps a limited recent-match history and progress continuity data on the player's device.
Clan and Player-Provided Content
Current clan features process clan names, tags, descriptions, preset flag choices, trophy requirements, join type, membership, roles, join requests, and clan messages. Messages include the author account, clan, text, client nonce, creation time, and any deletion timestamp.
Display names, leaderboard data, match-facing profile data, and clan information are shown to other players as required by those features. Clan messages are made available to members of the relevant clan. Do not include sensitive personal information in a display name, clan description, or message.
A player may privately report another player's clan message or display name, or another clan's name and description, using the same limited reason categories. Moderation records store the target type and identifier, pseudonymized reporter and subject identifiers, the reason, status, timestamps, service-action context, any internal moderation note, and only the private snapshot needed for review: the reported message text, display name, or clan name, description, and tag. Direct reporter and subject account references are kept only while needed and are removed or pseudonymized when the related account is deleted. Reports and their snapshots are not available to ordinary players.
A personal block stores the blocking and blocked account identifiers and creation time. It hides the blocked player's clan messages only from the blocking player; it does not remove the blocked player from the clan or affect that player's progression. A player can view and remove their own blocks in Settings.
Technical Data
The RivalCrest game server processes IP addresses in memory for connection limits and abuse prevention, together with request or connection identifiers, user IDs, timestamps, request origins, protocol and validation errors, and rate-limit events. The longest configured in-memory IP rate-limit window is currently one hour. Render, Vercel, Cloudflare, Supabase, and other network providers may separately process standard request and service-log data such as IP address, requested URL, browser or device details, and timestamps; their exact log-retention periods are not defined in the RivalCrest repositories.
The website and game do not currently include a dedicated analytics service, advertising SDK, marketing tracker, or marketing cookie. RivalCrest does not request precise location, contacts, camera, microphone, or advertising identifiers through the Android app. The Android manifest currently requests internet access only, apart from a generated app-specific receiver permission.
Device Storage
The web game and Android app use local and session storage for player profile and progression continuity, decks, card and chest display state, settings, selected arena, navigation state, anonymous authentication, network sessions, room and reconnect state, an active-PvP marker, cloud-save synchronization markers, wallet connection state, and pending purchase recovery. Session-only data is cleared by the applicable browser or app session; persistent local data remains until the game removes it or the player clears site or app data or uninstalls the app.
On Android, Supabase and Phantom session material is stored through the platform-sensitive encrypted storage adapter when it is available. RivalCrest does not receive or store a wallet private key or recovery phrase.
Optional Wallet and Purchase Data
If a player chooses the current Phantom wallet feature, RivalCrest processes the public Solana wallet address, a short-lived verification challenge and message, a wallet signature checked by the game server, provider and chain labels, and verification timestamps. The linked wallet can be unlinked from the player account, but unlinking does not delete the player account or past transaction records.
If a supported USDC purchase is initiated, RivalCrest processes the player ID, product, payer and treasury wallet addresses, USDC amount, mint address, transaction reference and signature, signed transaction payload needed for broadcast or recovery, transaction message hash, block-height data, status or failure code, fulfillment receipt, rewards, and timestamps. Solana transactions and wallet addresses are public on the blockchain and are processed by Phantom, Solana network infrastructure, and the configured RPC service under their own terms and policies.
How We Use Information
RivalCrest uses the information described above to create and authenticate anonymous sessions; record required legal and age confirmations; synchronize settings, decks, and progression; operate matchmaking, battles, reconnects, clans, chat, leaderboards, rewards, wallet linking, and purchases; process safety reports and personal blocks; moderate abusive content; prevent duplicate rewards and abuse; enforce fair play; diagnose failures; secure the service; and maintain beta reliability.
RivalCrest does not currently use player information for third-party advertising, behavioral profiling, or marketing analytics, and does not sell player information.
Service Providers
RivalCrest currently relies on Supabase for anonymous authentication, database storage, and realtime clan data; Render for the authoritative game server; Vercel for website and web-game hosting; and Cloudflare for APK distribution and Android live-update delivery. Optional wallet and purchase features involve Phantom, the Solana network, and Solana RPC infrastructure.
When a player follows a link to Discord or X, that external service processes the visit under its own privacy terms. GitHub is used for development and deployment workflows but is not integrated as a player-facing runtime service.
Data Sharing
RivalCrest makes player-facing data available to other players only as needed for matches, leaderboards, clans, and clan chat. Personal block lists and moderation reports are not shown to other players. Trusted RivalCrest operators and service providers may access the minimum information needed to review reports, secure the service, or perform the functions described above. Wallet addresses and transactions used on Solana are publicly visible by design.
No advertising network or dedicated analytics provider currently receives RivalCrest player data. The repositories do not define any sale of player information.
Data Retention
The current code and configuration do not define fixed retention periods for active anonymous accounts, cloud profiles, progression, clans, clan messages, moderation reports, match-reward records, competitive records, purchase records, or provider logs. Those periods are therefore not defined for the current beta. Personal blocks remain until the blocking player unblocks the other player or either related account is deleted.
Wallet-link challenges are valid for no more than ten minutes. Expired challenges, and challenges consumed for more than one hour, are purged in limited batches when a new challenge is created. Quick-match anti-abuse quota records are deleted in limited batches after forty-eight hours when the related reservation process runs. These operational cleanups do not constitute account deletion.
Device-only data remains until RivalCrest removes it, the relevant session ends, or the player clears app or site data or uninstalls the app. Clearing device data does not delete the Supabase account or server-side records.
Account and Data Deletion
Settings provides an authenticated DELETE ACCOUNT flow with two explicit confirmations. It removes the Supabase Auth account and associated profile, progression, cards, decks, settings, legal acceptance, chests, daily rewards, trophy-road, competitive, wallet-link, clan-membership, join-request, block, and other account-scoped records through the implemented database relationships. If the player leads a clan, leadership transfers to an eligible member or the clan is disbanded.
Existing clan messages may remain for conversation continuity with the author replaced by Deleted Player. Moderation reports needed for safety audit may retain the minimum reported-content snapshot and pseudonymized moderation identifiers, while direct reporter, author, or display-name target account references are removed or pseudonymized. Purchase and match-reward evidence needed for payment fulfillment, anti-fraud, accounting, and reward idempotency may be retained with the active account link removed and sensitive pending transaction material cleared. Shared anti-abuse pair references are removed where applicable.
Account deletion removes the RivalCrest wallet link but cannot delete a Phantom wallet or rewrite public Solana wallet addresses and transactions. Uninstalling the app, clearing local storage, or unlinking a wallet alone does not delete the account.
Submit an account or data-deletion requestSecurity
The current service uses HTTPS or secure WebSocket connections, authenticated server operations, Supabase row-level and service-role controls, request and connection limits, Android encrypted storage for sensitive sessions when available, and a signed Android release. No online service or storage method is completely secure.
Keep control of your device, browser profile, anonymous session, room codes, and connected wallet. RivalCrest will never need a wallet private key or recovery phrase.
Minors
RivalCrest is not intended for anyone under 18 or anyone who is otherwise a minor under applicable law. A minor should not use the current service.
Before full use of the game, the current age gate requires an explicit confirmation that the player is at least 18, meets the minimum age required in their country, and can legally agree to the Terms. The server stores only the age-gate version and confirmation timestamp; RivalCrest does not collect a full date of birth. The service does not provide a parental-consent flow, so a player who cannot make that confirmation must not continue.
International Transfers
RivalCrest's service providers operate infrastructure in multiple countries. Information may therefore be processed outside the country where a player lives, where data-protection rules may differ. Provider locations and transfer-retention details are not defined in the RivalCrest repositories.
Your Rights
Depending on applicable law, a player may have rights concerning access, correction, deletion, restriction, portability, or objection. Because accounts are anonymous, the current authenticated session and internal user ID would be needed to locate and verify the correct account without exposing another player's data.
Players can use DELETE ACCOUNT in Settings for account deletion or email Sup_rivalcrest@outlook.fr for another rights request. Do not email an access token, wallet private key, or recovery phrase.
Contact RivalCrest about your rightsChanges to This Policy
RivalCrest may update this policy as the beta changes. The revised version will be posted here with a new last-updated date, and material changes may also be highlighted in the game or on the website when appropriate.
Contact
For support, privacy questions, account or data-deletion requests, and legal inquiries, email Sup_rivalcrest@outlook.fr.
Sup_rivalcrest@outlook.fr