AEONFOLD

LegalPrivacy Policy

Aeonfold asks for as little as a game can. You can play the whole thing — first FLOPS to the bottom of Layer 9 — with no account, no name, and nothing about you reaching us.

In one screenThe short version

The detail below is binding, but nothing in it contradicts these four lines.

No account needed

The whole game is playable signed out. Signing in is one optional feature — cloud save — and nothing else in Aeonfold depends on it.

No trackers

This site runs no analytics, no tracking pixels, no advertising cookies and no third-party profiling. The game ships no analytics or crash-reporting SDK.

Your save is yours

Progress lives on your device. It only reaches our server if you sign in and choose to save to the cloud, and we delete it whenever you ask.

We never see your card

Payments run entirely inside Stripe's own checkout. Our server asks Stripe one question — paid, yes or no — and stores no payment details of any kind.

We do not sell, rent or trade personal information, and we never have. There is no advertising profile of you anywhere in this project.

Section 1Who is responsible

Aeonfold is made and operated by a single independent developer (“we”, “us”) based in Vietnam. For data-protection law we are the controller of the small amount of personal data described here.

Privacy questions and data requests reach us at aeonfold@gmail.com. Anything else — bugs, ideas, reviews — is best sent through the feedback form on the About page. Both are read by the same person.

Section 2What stays on your device

Almost everything Aeonfold knows about you is stored locally and never transmitted anywhere.

None of this is personal information to us: we cannot read it, and it never leaves your device unless you sign in and press save to cloud. Clearing your browser data — or uninstalling the app — deletes it permanently, and there is no copy on our side unless you made one.

Section 3What we receive, and why

Everything our server ever holds about a player is in this table. There is no other collection, anywhere.

DataWhenWhyKept for
Google account id, email address, display name, profile picture URL, and whether Google has verified the address Only if you choose to sign in with Google To recognise which cloud save is yours, show your name in the play bar, and gate the owner-only admin console Held in a signed session that expires after 30 days. A one-way hash of the account id names your save file for as long as the save exists
Your game save (the same progress data described above) and the time it was uploaded Each time you press “Save to cloud” So you can restore progress on another device or after clearing your browser Until you overwrite it or ask us to delete it. It is never expired for inactivity
Feedback you send: type, message, and any optional title, star rating, platform note and contact detail Only when you submit the form yourself To fix bugs, weigh suggestions, and reply if you asked for one Until the report is dealt with, then deleted
Standard server logs: IP address, timestamp, requested URL, referrer and browser user-agent Every request to the site, the browser game, or the small links file the mobile app fetches at launch To keep the service running, diagnose faults, and detect abuse Short-term operational retention only; never joined to your game account or used to profile you
Rate-limit counters keyed to your IP address Every request To stop spam, brute force and flooding Held in memory for at most one minute, then discarded
A Stripe checkout session id and its paid / not-paid status Only if you buy the premium theme on the web To confirm the purchase and unlock the item Not stored by us — we ask Stripe each time. Stripe keeps its own payment record

Nothing here expires on a timer. Your cloud save is not deleted because you stopped playing, however long you are away — come back in five years and it will be waiting. The only things that end on a schedule are your 30-day session and the one-minute rate-limit counters.

What we never collect

Legal bases (UK/EU GDPR)

Section 4Cookies and local storage

One cookie, set only after you sign in. Nothing on this site tracks you between visits or across other sites.

We set no analytics or advertising cookies. Third-party code that you invoke — Google's sign-in button, Stripe's checkout, and ad code where ads are enabled — may set its own storage under its own policy; see the next two sections.

Section 5Third parties we rely on

A short list, each with a narrow job. We share no data with anyone else, for any purpose.

GGoogle Sign-In

Loaded only on the play page, and only to offer cloud save. Google handles authentication and tells us the account id, email, name and picture URL. Google Privacy Policy.

$Stripe

Processes web purchases on its own hosted checkout. It receives your payment details directly; we receive only a session id and a paid flag. Stripe Privacy Policy.

Google AdMob & AdSense

Serve the optional rewarded ads described in section 6. Google may process device and ad identifiers under its own policy and the consent choice you make.

Hosting & network

The site runs on a rented virtual server behind a standard reverse proxy / CDN, which processes your IP address to route and protect the connection.

When the mobile apps ship, purchases made inside them are handled by Google Play or the Apple App Store under those stores' own privacy terms; we receive only the fact that a purchase succeeded.

Section 6Advertising and consent

Aeonfold has no banners and no interstitials, and it never interrupts you with an ad. The only ads are rewarded ones you deliberately start by tapping WATCH for a temporary boost.

Section 7Children

Aeonfold is not directed at children under 13 (or under the minimum age of digital consent where you live, which is up to 16 in parts of the EEA), and we do not knowingly collect personal data from them. Signing in and making purchases are for people over that age; everything else in the game works without either.

If you believe a child has sent us personal data — for example in the feedback form — contact us and we will delete it promptly.

Section 8Your rights, and how to use them

Depending on where you live you have rights over your personal data — under the GDPR, the UK GDPR, the CCPA/CPRA and similar laws. We honour all of them for everyone, regardless of where you are.

Deleting everything, right now

We do not sell or share personal information, and we run no cross-context behavioural advertising of our own — so there is nothing to opt out of under the CCPA. Exercising any right will never degrade your game.

Section 9Transfers, changes and contact

Where your data is processed

We are based in Vietnam and the server holding cloud saves and feedback is a rented virtual machine reached over the public internet. If you play from elsewhere, the limited data described above is processed outside your own country. It is protected by the measures on our security page wherever it sits.

Changes to this policy

If this policy changes materially, the new version is published here with a new “last updated” date and noted in the changelog. Continuing to play after that means the updated policy applies; if you disagree with it, deleting your data is a request away.

Contact

Privacy questions, data requests and complaints: aeonfold@gmail.com. Everything else can go through the feedback form. A real person reads every one.