1. Who is responsible
The data controller is STOIC AS, organisation no. 926 193 880, Vulkan 10, unit H0408, 0178 Oslo, Norway. Contact: support@hardblocklife.com.
2. The quick version
- The beta has no player account, advertising profile, payment data or cloud save.
- Your world save, settings and chosen player name are stored in your browser. STOIC does not receive them during ordinary single-player play.
- Cloudflare receives normal request and security metadata to deliver and protect the website. The beta-session cookie is an opaque signed token with no player identity.
- Cloudflare Web Analytics is not currently enabled. If enabled later, its cookie-free beacon will run only on public marketing and legal pages—not inside gameplay.
- If you join an online room, selected live game state and your player name pass through Supabase Realtime in Stockholm so the room can work. The persistent main world uses STOIC’s own world server instead.
- Proximity voice chat is optional, push-to-talk only, and transmits live through STOIC’s self-hosted voice relay. Neither STOIC nor the relay records or stores it.
- If you send an in-game bug report or feature request, it is anonymous: no account, email address or IP address is stored with it. Diagnostics, a screenshot, a coarse location and an optional alias are each a separate choice you make per report.
- Report screenshots are stored privately with no public link and are readable only by STOIC through an authenticated review tool.
- If you email support, Cloudflare forwards the message to STOIC’s support inbox hosted by Google.
3. What we process and why
| Data | Purpose and legal basis | Where it goes |
|---|---|---|
| Website request and security metadata IP address, date/time, requested URL, browser/user-agent, response status, network and Cloudflare security signals. | Deliver the site, prevent abuse, rate-limit code attempts and investigate faults. Legal basis: performance of the beta service you request and STOIC’s legitimate interests in security, reliability and fraud prevention. | Cloudflare’s network and limited STOIC Worker logs. We never log the beta code, session token or request body. |
| Beta access attempt The code you submit and a per-IP rate-limit key. | Check authorised closed-beta access and prevent brute force. Legal basis: performance of the requested beta service and legitimate security interests. | The code is compared in Worker memory against an encrypted Worker secret and is not written to application logs or storage. Rate-limit counters are held by Cloudflare. |
| Beta-session cookie A random, signed, opaque token containing only a version and expiry—not your name, code or player ID. | Remember that this browser was unlocked. Legal basis: necessary to provide the access you expressly request. | Your browser and Cloudflare Worker verification. See the Cookie Notice. |
| Optional aggregate public-site analytics When enabled: page path without query string, page-load performance and general browser/device metrics. No cookie, localStorage, stored IP address or cross-visit fingerprint. | Understand whether public information loads and works. Legal basis: STOIC’s legitimate interest in measuring and improving a low-data public site. | Cloudflare Web Analytics when configured. The beacon is never included in /play/. |
| Local game data World save, settings, key bindings, high scores and chosen player name. | Save your local progress and preferences. This processing happens on your device at your request. | Your browser storage. STOIC receives none of it in ordinary single-player play. Clearing site data deletes it. |
| Online room traffic Five-letter room code, chosen player name, positions, vehicle/player state, block edits, score/combat events and connection metadata. | Put 2–8 players in the same temporary room. Legal basis: performance of the online feature you choose to use and legitimate interests in service security. | Other players in the room and Supabase Realtime in the North EU (Stockholm) project. |
| Main-world play A random device identity token, chosen player name, positions, health, block edits, combat events, optional six-character party codes and connection metadata. | Run the shared persistent world, keep your builds and spawn between visits, and let a friend join you once with a party code. Legal basis: performance of the online feature you choose to use and legitimate interests in fairness and security. | STOIC’s own world server. The identity token is a random credential stored on your device; it carries no name, email or account. Losing it simply starts a fresh profile. |
| Proximity voice audio Your live microphone audio while you hold the push-to-talk key, plus who may hear whom (nearby players only). | Let nearby players in the main world hear you, only while you deliberately transmit. Voice is off until you enable it and grant microphone permission. Legal basis: performance of the voice feature you expressly switch on. | Transmitted in real time through STOIC’s self-hosted voice relay to at most eight nearby players, then discarded. It is never recorded, stored or analysed — by STOIC, the relay, or the report tool (reports carry metadata only, never audio). |
| Bug report or feature request Your report type, summary, description, category, surface, an optional alias you type, and — only with your separate per-report consent — technical diagnostics (build, device class, viewport, graphics/settings profile, world seed, recent redacted events and errors) and a location coarsened to a 16-metre grid. | Fix faults and decide what to build next. Legal basis: STOIC’s legitimate interest in improving beta software you chose to report on. The report itself is anonymous. | A private Cloudflare D1 database. Your IP address is used only as a transient rate-limit key and is never stored with the report or written to logs. No email address, account, installation identifier, room code, beta code or save data is collected. |
| Report screenshot The image you explicitly attach to a report. | Show the fault. Legal basis: your separate per-report choice to attach it. | A private Cloudflare R2 bucket with no public link. It is served only through an authenticated STOIC review endpoint. Do not attach an image showing information you do not want STOIC to see. |
| Support email Your address, headers, message, attachments and any diagnostic details you choose to send. | Answer questions, investigate bugs and enforce rules. Legal basis: responding to your request, legitimate support/security interests, and legal obligations where relevant. | Cloudflare Email Routing forwards to STOIC’s Gmail inbox; authorised STOIC personnel can read it. |
4. Temporary rooms and other players
The game connects directly from your browser to the Supabase Realtime service when you choose online play. It uses broadcast channels; the game creates no room tables and STOIC does not build a replay archive. Live messages are shared with the other players who know the room code.
Room codes are short coordination codes, not passwords. Do not use a room code, player name or chat-like field to share a real name, address, beta access code or other private information. Other players can see what is broadcast to their room and may record their own screen.
Supabase can keep operational connection and error logs according to the project plan and its processor terms. STOIC does not export room-message logs for profiling, advertising or resale.
Voice chat is live and unrecorded. Push-to-talk voice in the main world is transmitted in real time and never stored. Remember that the players who can hear you may still record their own device, exactly as they may record their screen. Voice is optional: the game is fully playable with it off or with the microphone denied, and you can mute or block any player on your own device.
5. Service providers and international transfers
- Cloudflare, Inc. provides DNS, TLS, static hosting, Worker execution, rate limiting, security and email forwarding, plus Web Analytics only when the public-site build enables it.
- Supabase, Inc. provides Realtime room transport in the North EU (Stockholm) project.
- Google LLC provides the Gmail inbox that receives forwarded support messages.
The persistent main world and proximity voice run on STOIC’s own self-hosted servers (the voice relay uses the open-source LiveKit software). No third-party voice cloud is involved, and voice audio never becomes stored data anywhere.
These providers may use group companies and subprocessors in the EEA and other countries, including the United States. Where personal data is transferred outside the EEA, STOIC relies on the providers’ applicable data-processing terms and recognised GDPR Chapter V safeguards, such as adequacy decisions or standard contractual clauses. Contact us if you want more information about the safeguard relevant to your data.
We do not sell personal data and do not use it for behavioural advertising or automated decisions with legal or similarly significant effects.
6. How long information lasts
- Beta cookie: 30 days from unlock, unless you use “Lock beta access” or clear cookies sooner.
- Local game data: until you clear site data, the game resets it, or your browser removes it. STOIC cannot restore it.
- Worker application logs: sampled operational errors and request events are kept no longer than 30 days. Codes, session tokens and request bodies are not logged.
- Cloudflare Web Analytics, when enabled: Cloudflare currently keeps unsampled beacon data for 7 days and makes aggregated/sampled reporting available for up to 6 months.
- Online rooms: live game messages are not stored in game-owned room tables. Provider security and operational logs follow the Supabase project’s current plan; STOIC does not retain exported room logs.
- Main world: world edits, your spawn point and profile survive between visits — that persistence is the feature. The device identity token lasts until you clear it; clearing it starts a new profile. Party codes expire after 15 minutes.
- Voice audio: not retained at all. It exists only in transit between you and the nearby players entitled to hear it.
- Report screenshots: deleted 90 days after the report is received.
- Reports: deleted 180 days after they are marked resolved or declined. An open report is kept until it is closed.
- Report drafts and the retry queue: held in your browser (IndexedDB) until the report is sent and you dismiss it, or you clear site data. See the Cookie Notice.
- Support email: ordinarily deleted 12 months after the issue is closed, unless needed longer for an active dispute, security investigation or legal duty. Backup deletion may take longer.
We may keep a minimal record longer where necessary to establish, exercise or defend legal claims, or to comply with law.
7. Your privacy rights
Depending on the circumstances, you can ask for access, correction, deletion, restriction, portability or objection to processing based on legitimate interests. Where processing is based on consent, you can withdraw it; this beta does not currently rely on consent for tracking or advertising.
Some rights do not apply to data that STOIC never receives, such as a world save that exists only in your browser. To exercise a right, email support@hardblocklife.com. We may need enough information to locate the relevant support message or request record, but we will not ask you to disclose the beta code.
You may complain to Datatilsynet, the Norwegian Data Protection Authority, or the supervisory authority where you live or work.
8. Security, age and changes
Report screenshots have no public link: they are stored privately and released only through an authenticated review endpoint with no-store caching and content-sniffing protection. Review access uses its own credentials, separate from the beta code.
The site uses encrypted HTTPS, an HttpOnly signed access cookie, secret values stored as encrypted Worker secrets, constant-time code comparison, rate limiting, same-origin checks and restrictive browser security policies. No system is perfectly secure, especially beta software.
The service is only for adults aged 18 or older and is not directed to children. If you believe a child has provided personal information, contact us.
We will update this notice when data practices change. The effective date at the top identifies the current version. Material changes will be made visible before or during continued beta access where practical.
9. Contact
STOIC AS
Organisation no. 926 193 880
Vulkan 10, unit H0408
0178 Oslo, Norway
support@hardblocklife.com