Privacy Policy & GDPR
Version 2026-08-12 · last updated 12 August 2026
The short version: we collect an email address, a phone number, the state of your game, and a log of what you do inside it. We use that to run and improve the game. We do not sell your data.
If you accept the optional advertising cookies, Meta, TikTok and Google also learn that you visited and signed up. That is opt-in, it is off until you say yes, and refusing changes nothing about the game.
1. Who is responsible
The data controller is Grete Invest AB, Mor Annas Brygga 40, 181 30 Lidingö, Sweden. Contact: jenspeter@gmail.com.
2. What we store, and why
| Data | Why | Legal basis |
|---|---|---|
| Email address | Account recovery, and one verification code at registration. | Contract |
| Phone number | Signing in (a code by SMS), and — only if you switch it on — alerts when an army is marching on your village. | Contract; consent for alerts |
| The email/phone pairing | Enforcing one account per person. A shared world is ruined by players running several accounts, and this is the only practical check. | Legitimate interest |
| Game state — villages, buildings, armies, research, battle reports, alliance membership, chat messages | It is the game. Battle reports necessarily name the other player. | Contract |
| Push subscription (if you enable notifications) | Sending browser notifications. Removed when you disable them. | Consent |
| Payment records (if you ever buy gems) | A record that a purchase happened and how many gems it granted. Card details go to Stripe and never reach us. | Contract; legal obligation |
| In-game activity log — which screens you open, and each action you take (queueing a build, training troops, sending an army), with a timestamp | Understanding where players get stuck or give up, and fixing the game accordingly. This is our own data about our own product; it does not follow you anywhere else. | Legitimate interest |
Truncated IP — the first three octets only (e.g. 81.229.44.0/24) | Detecting one person running several accounts, which is the cheating that most damages a shared world. Deliberately truncated so it identifies a household, not a person. | Legitimate interest |
| Advertising identifiers — only if you opt in | Measuring which adverts bring players in. Set by Meta, TikTok and Google, who can link this to profiles they already hold about you. | Consent |
| Server logs — IP address, request line, timestamp | Keeping the service running and resisting abuse. Kept briefly. | Legitimate interest |
We do not collect your name, address, date of birth, precise location, or contacts.
3. Cookies
Strictly necessary — always on
- Session cookie — keeps you signed in.
- Active village — remembers which village you were looking at.
- Consent cookie — remembers your answer to the question below.
All three are first-party and httpOnly where the browser allows it.
Advertising — off unless you accept
If you accept, Meta (Facebook/Instagram), TikTok and Google set cookies and identifiers that let them recognise you across other sites and apps, and tell us how many people who saw an advert went on to sign up.
- They are not loaded at all until you accept — rejecting means the script is never fetched, not merely told to behave.
- You can change your mind by clearing cookies for this site.
- The game plays identically either way. Nothing is withheld for refusing.
4. Who else touches it
Only the processors needed to make the game work:
| Processor | What they receive |
|---|---|
| Hetzner Online GmbH, Helsinki, Finland (EU) | Hosting. All data is stored here, inside the EU. |
| Twilio | Your phone number and the SMS text, to deliver it. |
| Resend | Your email address and the message, to deliver it. |
| Stripe | Payment details, only if you make a purchase. |
| Meta, TikTok, Google | Only with your consent: that a browser visited or signed up, plus the identifiers they set. They act as independent controllers for their own advertising purposes. |
Twilio and Stripe are US companies and may process data outside the EU/EEA under the EU Standard Contractual Clauses and the EU–US Data Privacy Framework. Everything else stays on the server in Finland.
5. What other players can see
Your player name, village names, map positions, population, alliance and ladder rank are visible to other players — that is what a shared world means. Your email address and phone number are never shown to anyone.
Pick a player name you are comfortable being public.
6. How long we keep it
- Account — until you delete it, or after 24 months of no sign-ins.
- In-game activity log — 12 months, then deleted.
- Game state — until the season ends, then it is discarded with the world.
- Verification codes — 10 minutes.
- Server logs — a short rolling window, typically under 14 days.
- Purchase records — as long as accounting law requires (7 years in Sweden).
7. Your rights
Under the GDPR you can ask us to:
- Access — get a copy of everything we hold about you.
- Rectify — correct anything wrong.
- Erase — delete your account and personal data.
- Port — receive your data in a machine-readable form.
- Restrict or object — including to the one-account check.
- Withdraw consent — for SMS alerts or push, at any time, without losing access to the game.
Email jenspeter@gmail.com from the address on your account and we will respond within 30 days, free of charge.
Erasure does not need an email. Open your profile and use Delete account at the bottom: it runs immediately, and the screen lists exactly what is removed and what is kept before you confirm.
What deletion actually does
Your email, phone, verification codes and push subscriptions are erased. Your villages are removed from the map. Battle reports held by other players are anonymised rather than deleted — they are those players’ own records of their game, and removing them would rewrite someone else’s history.
8. Security
- All traffic is encrypted with HTTPS.
- There are no passwords to steal — sign-in is a one-time code.
- Codes expire in 10 minutes and are rate-limited.
- The database is on an EU server, not exposed to the internet.
No system is perfectly secure. If a breach affects your rights we will tell you and the supervisory authority, as the GDPR requires.
9. Children
Eldrn is not for under-16s. If we learn that an account belongs to a child under 16, we will delete it.
10. Complaints
If you think we have handled your data badly, please tell us first. You also have the right to complain to a supervisory authority — in Sweden that is Integritetsskyddsmyndigheten (IMY), Sweden, or the authority where you live.
Alpha notice. This policy is an accurate description of what the software does today, written by reading the code rather than copying a template. It has not been reviewed by a lawyer. Before Eldrn opens beyond a closed test, a qualified reviewer should check it and the operator’s registered legal entity, address and — if required — a data protection representative should be named above.