1. The cookies this site sets
| Name | Purpose | Lifetime | Properties |
|---|---|---|---|
__Host-hbl_beta | Remembers that this browser successfully entered the shared closed-beta code. The value is a random signed token with a version and expiry. It contains no name, email, player identity or copy of the beta code. | 30 days, or until you lock access or clear cookies. | HttpOnly, Secure, SameSite=Lax, Path=/, no Domain attribute. JavaScript cannot read it. |
__Host-hbl_feedback_admin | Set only for STOIC review staff who sign in to the private report tool. It is never set by playing the game or entering the beta code, and it contains no report data. | 8 hours. | HttpOnly, Secure, SameSite=Strict, Path=/, no Domain attribute. |
The access cookie is strictly necessary to provide the 30-day access you ask for. Without it, every protected game file would have to ask for the beta code again.
2. Local game storage
When you play, the game uses browser local storage to keep a world save, settings, key bindings, high scores and your chosen player name. This is not used to track you across sites. The data stays on the browser and device unless you choose online room play or send it to support.
If you write a bug report or feature request, the draft and any report waiting to be sent are kept in browser IndexedDB (at most ten queued reports) so a lost connection does not lose your words. A queued report is retried until it is accepted; a receipt stays visible until you dismiss it. Clearing the draft and outbox is in the report screen, and clearing site data removes them too. Report screenshots you attach are uploaded to STOIC and are not kept in this local store once sent.
Local game storage remains until you clear site data, use a game reset, or the browser removes it. This domain launch starts with fresh worlds; data from the old GitHub Pages origin cannot be read here. These storage operations are necessary for the save and preference features you request.
3. Public analytics
Cloudflare Web Analytics is not currently enabled, so no analytics beacon is included on these pages. If STOIC enables it later, this notice will remain the source of truth: the cookie-free beacon will run only on public marketing and legal pages, never inside /play/.
When enabled, the beacon measures public page paths and performance without storing or reading cookies, localStorage, sessionStorage, IndexedDB or an advertising identifier. Cloudflare says it discards the request IP address at the nearest data centre and does not use IP address or browser fingerprinting to follow a person across visits.
4. Why there is no consent banner
If the site later adds optional analytics, advertising, personalisation or another non-essential browser technology, STOIC will reassess this notice and add a real consent choice before that technology runs.
5. How to control or remove data
- Use Lock beta access in the site footer after unlocking to expire the access cookie immediately.
- Use browser settings to remove cookies or site data for hardblocklife.com. Removing all site data also deletes local game saves and settings.
- Blocking the strictly necessary cookie means protected game access cannot remain unlocked.
- Browser privacy tools may block the Cloudflare beacon when it is enabled; the public site and game gate still work.
Questions: support@hardblocklife.com.