Last updated: 27.04.2026
This policy explains what personal data Relic & Ruin ("we", "the Service") collects, why, and what rights you have. It is written to comply with the EU/UK General Data Protection Regulation (GDPR/UK GDPR).
Data controller: Scott Livingstone, contact: info@relicandruin.net.
1. What we collect
1.1 Account data
When you register, we store:
- Your email address
- A hashed password (we never store your password in plain text)
- An email-verification status and a time-limited verification token sent to your inbox
Lawful basis: performance of a contract (Art. 6(1)(b) GDPR) — we cannot provide an account without these.
1.2 Application data
Content you create in the app — warbands, warriors, campaigns, battles, scenarios, stash items, and similar in-game records — is stored against your account so you can retrieve it later.
Lawful basis: performance of a contract.
1.3 Server access logs
Every HTTP request to the Service is logged with:
- HTTP method, URL path, and sanitised query string (auth tokens, passwords, verification codes, and other secrets are stripped before logging)
- Response status, response size, and request duration
- Your IP address
- For server errors only: a stack trace
Logs are retained for 30 days and are used solely for security, debugging, and abuse prevention.
Lawful basis: legitimate interest (Art. 6(1)(f)) — operating a secure, reliable service.
1.4 Client-side error reports
When the in-browser application encounters an error or unhandled exception, your browser automatically sends a small report containing:
- The error type, message (≤ 500 characters), and stack trace (≤ 3000 characters)
- The path of the page you were on (no query string, no fragment)
- The build version of the application
- A random session identifier generated in memory for the current page load. This identifier is not stored in cookies or local storage and is discarded when you close or reload the tab. It cannot be used to identify you or link your sessions over time.
These reports do not include your email, account ID, IP address (beyond what is visible at the network layer), or the contents of any forms. Error messages and stack traces could in rare cases incidentally include text you typed if that text was part of a failure; we make reasonable effort to prevent this but cannot guarantee it. Reports are retained for 30 days.
Lawful basis: legitimate interest — diagnosing and fixing bugs.
1.5 Cookies
The Service uses a single strictly necessary cookie (or equivalent mechanism) to keep you logged in. We do not use analytics, advertising, or tracking cookies, and therefore do not display a cookie banner.
2. What we do NOT collect
- We do not use third-party analytics (Google Analytics, etc.).
- We do not use advertising networks or tracking pixels.
- We do not sell or share your data with marketers.
- We do not profile you or run automated decision-making on your data.
3. Where your data is stored
The Service is hosted on Hetzner, in Germany. Outgoing email (account verification) is sent via noreply@relicandruin.net using AWS SES. These providers process your email address and IP address as our processors under their respective privacy policies.
If any provider is located outside the EEA/UK, transfers are governed by Standard Contractual Clauses or an adequacy decision.
4. How long we keep it
| Data | Retention |
|---|---|
| Account + application data | Until you delete your account |
| Verification tokens | Until used or expired (≤ 24 hours) |
| Server access logs | [30] days |
| Client error reports | [30] days |
| Backups | [e.g. 14 days rolling] |
When you delete your account, your account record and all associated warbands, campaigns, and battle data are deleted within 30 days. Residual copies in encrypted backups are removed on the backup-rotation schedule above.
5. Your rights
Under GDPR/UK GDPR you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Export your data in a machine-readable format (portability)
- Restrict or object to processing
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your national data-protection authority
To exercise any of these rights, email info@relicandruin.net. We will respond within 30 days. You can also delete your account at any time from Account Settings → Delete Account, which performs erasure automatically.
6. Security
Passwords are stored hashed with bcrypt. Traffic is served over HTTPS. Access to the production database and logs is restricted to the site operator. We will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of any personal-data breach that poses a risk to your rights.
7. Changes to this policy
We will post any changes to this page and update the "Last updated" date. Material changes will additionally be communicated by email to registered users.
8. Contact
Questions or requests: info@relicandruin.net