// Legal

PRIVACY POLICY

Datenschutzerklärung · Last updated 2026-09-21

The short version

This site sets no tracking cookies, builds no advertising profiles, and sells nothing about you to anyone. Everything it holds about you, you handed over yourself: the email address you leave on the alpha waitlist, and — if you create a commander — the account that address signs into. If you ever buy credits for the forge, Stripe takes the payment on its own page and your card never touches our servers. The rest of this page is the detail behind that.

Who is responsible

The controller for this site is the operator named in the imprint. For any privacy request, use the contact address given there.

The waitlist

When you join the waitlist we store: your email address, the time you signed up, the wording of the promise you signed up under, which page the signup came from (including, where present, a referrer hostname or a UTM source tag), and the IP address the signup was made from. The IP address and timestamp exist to prove the signup was real and yours — under the GDPR the burden of demonstrating consent lies with us (Art. 7(1)).

Legal basis: your consent (Art. 6(1)(a) GDPR). The purpose is a small number of one-off notifications about the game becoming available — the alpha opening. There is no newsletter, and the address is never shared with third parties for their own purposes.

Withdrawing is as simple as it should be: email the address in the imprint, or reply to any mail we send, and the row is deleted. All waitlist data is deleted once its purpose is fulfilled — after launch notifications have gone out.

The data is stored in a Cloudflare D1 database. Cloudflare, Inc. operates as our processor (see Hosting below).

Your commander account

Creating a commander stores your email address, the commander name you choose, the empire name if you found a charter, your password as a one-way hash — never the password itself — the language you read the site in, and the ordinary bookkeeping of an account: when it was created, the day it was last active, whether early access has been granted, and the game state that belongs to it. The email address is how you sign in and how we write to you about your own account: a password reset, a security notice, the day the galaxy opens for you. It is not a mailing list. Mail of that kind goes out through the mail provider configured for the site, which receives your address and the text of the message. Legal basis: performance of the contract you enter into by creating the account (Art. 6(1)(b) GDPR). Ask at the address in the imprint and the account and its game state are deleted — the purchase records described below are the only thing that outlives them, because the law requires us to keep those.

Buying credits (Stripe)

Credits for the forge are bought through Stripe Checkout, on a page that belongs to Stripe rather than to us: your card number is never sent to our servers, and we never store it. Stripe receives your account email address on a first purchase — later ones go by the customer id Stripe hands back to us — together with the pack you chose, the amount, the currency, and our own internal reference for the order, so that a refund can be matched to the purchase it reverses. Stripe Payments Europe, Ltd. is our payment processor and draws on Stripe, Inc. in the United States; that transfer is covered by the data processing terms we have with them. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) — the payment cannot be taken without being processed. What stays with us is the purchase record: the pack, the amount, the currency, the Stripe identifiers and whether it was paid or refunded. That record is an accounting document, kept for as long as German commercial and tax law require us to keep it (§ 147 AO, § 257 HGB), and it outlives the deletion of the account. Stripe describes its own handling in its privacy policy.

The forge and the Prompt Designer (OpenAI)

The emblem forge and the Prompt Designer are the only places on this site where something you wrote leaves it for a third party. What goes to OpenAI is what the picture is made of and nothing beside it: the prompt, the conversation you are having with the designer, and — for a revision — the earlier picture you asked to have changed. No account data travels with it: not your email address, not your commander name, not your account id. The only identifier attached to a conversation is a random one your browser mints for that conversation alone. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) — it is the thing you asked the forge to do. On our side, the designer conversation is never written to our database at all: your browser holds the transcript and sends it back with each turn. The prompt stays on the sheet or the picture it produced, until you discard it. The metering record we keep for the books holds how many tokens a call used, what it cost and any error it returned — never the prompt, and never the reply. OpenAI acts as our processor for these calls; under the API terms we are on, what is sent through the API is not used to train its models. The calls are served from the United States, and that transfer is covered by the data processing addendum that forms part of those terms. OpenAI describes its own handling in its privacy policy.

Bot protection (Cloudflare Turnstile)

The waitlist form is protected by Cloudflare Turnstile, which distinguishes people from bots. Turnstile evaluates technical signals from your browser (including your IP address) to make that call. It sets no tracking cookies and is loaded only when you interact with the form. Legal basis: our legitimate interest in keeping automated abuse out of the list (Art. 6(1)(f) GDPR).

Analytics

We use Cloudflare Web Analytics — a cookieless, privacy-first measurement tool that counts page views and referrers without fingerprinting individual visitors, storing client-side state, or tracking anyone across sites.

Hosting

The site is served by Cloudflare Pages (Cloudflare, Inc., USA). Cloudflare processes connection data (such as IP addresses) technically to deliver the site and defend it against attacks. Cloudflare is certified under the EU-U.S. Data Privacy Framework, and we rely on that adequacy decision together with Cloudflare's standard data processing addendum for any transfer outside the EU. The game itself — the API, its database, your account and everything it owns — runs on a rented server in Germany (Hetzner Online GmbH). Nothing held there leaves the EU except the payment and the model calls described above. That server writes a short technical log of requests, IP addresses included, which is overwritten as it rolls over; it exists to find faults and to see off attacks (Art. 6(1)(f) GDPR).

External links

Links to external communities (such as Discord) lead to services with their own privacy policies. Nothing is transferred to them by this site — they only learn about you if you follow the link.

Your rights

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21), plus the right to withdraw consent at any time with effect for the future (Art. 7(3)), and to lodge a complaint with a supervisory authority (Art. 77). One email to the address in the imprint exercises any of them.