01 · Public site
Delivery and security metadata.
Fields: IP address, user agent, requested URL, referrer when supplied by the browser, request time, response status, request ID and security diagnostics. Source: your browser and infrastructure. Purpose: deliver, secure and troubleshoot the service. Retention: the shortest operational period configured with the production host, extended only for a documented incident or legal duty.
- +Required for network delivery
- +No account matching for advertising
- +No precise device location request
- +Tool calculations remain in page memory
02 · Account
Identity, credentials and sessions.
Fields: user ID, email, display name, role, account status, email-verification time, creation/update time; password hash and password-change time; session ID, token hash, expiry, revocation, last-seen and creation time. Source: you and the authentication service. Purpose: register, authenticate, secure and administer accounts.
- +Required for an account
- +Password itself is not stored
- +Session tokens are returned to the client but stored server-side only as hashes
- +Production retention follows the Privacy Policy and deletion workflow
03 · Game launch and saves
The state required to continue a voyage.
Launch fields: user or anonymous subject ID, game ID, scenario, game version, locale, return URL, entitlement codes, capability scope, ticket/session expiry and use time. Save fields: user ID, game ID, slot, revision, save schema, game version, opaque save payload, checksum, create/update/delete time.
Purpose: open the intended game safely, authorise save access, detect conflicting writes and restore progress. Avoid putting real names, contact details or other unnecessary personal information in game-provided free text.
- +Anonymous launch IDs are not automatically account IDs
- +Save payload content depends on the game build
- +Maximum request size is technically limited
- +Deletion follows account and save controls
04 · Catalogue, order and payment
Release interest, transaction and entitlement records.
Fields can include account ID; product and price; purchase email; Gumroad product, sale, licence and order references; payment, refund, dispute and chargeback status; entitlement grant or revocation; timestamps; and security or audit metadata. Gumroad directly collects payment credentials and risk signals under its own notice; Age of Seas does not receive or store a full card number or security code.
Purpose: show the product, reconcile a verified purchase, bind it to the account using the same email, deliver access, respond to refunds and disputes, provide support, prevent fraud and meet record-keeping duties.
- +Age of Seas PRO: one-time USD 7.99 purchase for unlimited new runs across all playable games
- +Purchase email must match the verified Age of Seas account
- +Refund, dispute or chargeback status can revoke the matching paid entitlement
- +Some transaction records survive account closure where law requires
05 · Support and rights requests
Only send what the request needs.
Fields may include sender email, subject, message, page or account identifier, browser/device description and attachments you choose to provide; for a rights request, proportionate identity-verification evidence and request outcome. Purpose: answer, investigate, document consent or comply with legal rights.
Retention: until the request and reasonable follow-up are complete, then deleted or minimised unless the record is needed for security, transaction, complaint or legal evidence.
- +Never send a password or session token
- +Mask payment and identity-document numbers
- +Remove unrelated people from screenshots
- +Support content is not used for advertising
06 · Analytics
Audience and game-entry measurement.
Google Analytics may receive a pseudonymous client identifier, public page path and title, referrer, browser/device attributes, language, approximate geography derived from the network connection, timestamps and interaction events. URL query strings and page views for account, purchase, admin, game-launch and voyage routes are excluded; bounded game launch and return events may include game, scenario, locale and launch mode.
Purpose: understand aggregate readership and game entry/return performance. Source: browser. Provider: Google LLC. Retention and deletion follow the configured Analytics property and applicable law.
- +Enabled when GA is configured
- +No advertising signals
- +No Google Signals
- +No account identifier sent
07 · Not in the current implementation
Absence is part of the inventory.
The reviewed code does not request contacts, SMS, camera, microphone, photos, precise location, biometric identifiers, government identity numbers, health data, advertising identifiers or social graph data. It contains no advertising or social SDK.
If a future feature needs any such information, it requires a necessity review, an updated inventory, clear just-in-time notice and any separate or explicit consent required by law before collection begins.