← HomePRIVACY POLICY

Veil of Steel is a real-time strategy game in closed alpha. This policy describes what data is involved, why, and how long it stays. It is derived from the actual program rather than from a template — what is written here is what happens, and what happens is written here.

Last updated: 2026-08-29
The German version of this policy is the authoritative one. The translations are provided for convenience.

Controller

The person named in the legal notice is responsible for the processing. For any data protection question an email to the address given there is sufficient; given the size of this service we are not required to appoint a data protection officer.

Sebastian Streichhan
kontakt@veilofsteel.com

If you only visit this website

This website sets no cookies, embeds no analytics and loads nothing from third-party servers. The typeface, the emblems and all images are hosted on our own server. There is therefore no consent banner either: there would be nothing for you to consent to.

Exactly one value is stored in your browser: the language you chose, so that the prompt does not appear on every visit. It stays on your device, is never transmitted to us, and disappears when you clear your browser data.

When any page is requested, our server necessarily receives your IP address — without it, it could not deliver the reply. We do not, however, keep an access log: nowhere is it recorded which pages were requested from which address.

Technical logs about malfunctions and repelled attacks may, by contrast, contain an IP address. We need them to operate the service and keep it secure (Art. 6(1)(f) GDPR, legitimate interest in a working and secure service), we do not link them to an account, and we delete them after 30 days. Addresses temporarily blocked for repeated attack attempts are removed after 24 hours at the latest.

Player account

The game cannot be played without an account — it needs an identity to recognise you in multiplayer, to attribute your progress and to protect your account. The legal basis is Art. 6(1)(b) GDPR: the processing is necessary to perform the contract of use.

Username
your identity in the game, visible to other players
Email address
account confirmation, password reset, unavoidable service messages
Password
never stored in plain text, only as a verification value (scrypt with an individual random value). We cannot read your password either

Alpha application

The alpha is closed. Anyone wishing to take part answers a few questions about experience and expectations; an administrator reviews the answers and decides. We store the answers together with the time of application in order to keep the decision traceable (Art. 6(1)(b) GDPR). If the application is rejected, it is deleted along with the account.

Device identifier

To stop a single person from obtaining an unlimited number of alpha accounts, and to keep bans meaningful, the game assigns an identifier to each device and limits how many accounts may run on it. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in a fair, limited test phase.

Only a verification value (a hash) is stored, not your computer’s characteristics themselves. It does not allow any conclusions about your hardware; it serves solely for the comparison “seen before or not”. You may object to this processing under Art. 21 GDPR — in that case, however, alpha access is not possible.

What playing produces

During a match the simulation runs on our server. To do that it has to know who is ordering what — otherwise there would be no multiplayer. The basis is Art. 6(1)(b) GDPR for everything that constitutes the game itself, and Art. 6(1)(f) GDPR for the analysis with which we find bugs and imbalances.

IP address
technically unavoidable for the connection to the game server; it is not stored permanently against your account
Match recording
we do not record the picture, only your commands. From those the match can be recomputed — for replays, for debugging and to examine suspicion of cheating
Match analysis
faction, map, duration, result, economy and combat figures, in order to balance the game
Rank and profile
the results of your ranked matches and a play style derived from them. These are visible to other players
Friends, groups, praise
who you add, who you play with and what commendations you give or receive
Play time and time online
how long you have spent in matches in total, and how long connected to the server at all. Both figures appear in your profile and are visible to other players
Last seen
the time of your last connection and the program version you played with, so we can tie faults to a particular build

Bug reports

If you report a problem via the bug button, your text is submitted together with its context: program version, faction played, map, elapsed match time, the most recent technical error messages and a reference to the match concerned. Without that context a report is usually not actionable. The report is linked to your account so that we can follow up (Art. 6(1)(f) GDPR).

Emails we send

We only write to you when the service requires it: to confirm your address, to reset your password, to inform you about the decision on your application and about important changes to the service. We send no advertising and we do not pass your address on.

Who else sees the data

Our servers are hosted with a provider inside the European Union which processes the data solely on our behalf and on our instructions (processing agreement under Art. 28 GDPR). No transfer to countries outside the EU takes place.

Beyond that we pass on no data. We do not sell data, we run no advertising and we embed no ad networks. Disclosure occurs only where we are legally obliged to make it.

Should the game later be offered through a distribution platform such as Steam, that provider’s own privacy policy will apply to registration and payment there. This policy will be extended accordingly beforehand.

How long we keep data

Account data remains for as long as your account exists. Web server access logs are deleted after 30 days. Match recordings and analyses are kept for as long as they are useful for debugging and balancing, but at the longest until the end of the alpha.

If you delete your account, we remove your account data, your application, your device identifier and your bug reports. Matches already played are retained in anonymised form, because they also contain your fellow players’ data and cannot sensibly be separated — your name no longer appears in them.

Deleting your account

You may have your account deleted at any time. An informal email to the address in the legal notice, sent from the address registered with us, is sufficient; we will confirm the deletion. Deletion is final — rank, profile and progress cannot be restored afterwards.

Your rights

You have the following rights in relation to us. An email is enough to exercise them; no form is required and you incur no cost.

Access (Art. 15)
to learn what data we hold about you
Rectification (Art. 16)
to have incorrect data corrected
Erasure (Art. 17)
to have your data deleted
Restriction (Art. 18)
to have the processing temporarily suspended
Portability (Art. 20)
to receive your data in a common format
Objection (Art. 21)
to object to processing that we base on a legitimate interest
Complaint (Art. 77)
to complain to a data protection supervisory authority

Automated decisions

No automated decision-making or profiling with legal effect takes place. Admission to the alpha is decided by a human being. The computed play style is a description of how you play, not an assessment of you as a person.

Security

The connection to this website and to the game server is encrypted. Passwords are stored only as a verification value. If you find a security flaw, please report it to the address in the legal notice before publishing it — we will deal with it.

Changes to this policy

The game keeps being developed, and so does this policy. The version currently in force is the one on this page; the date of the last change is shown above. We will point out substantial changes inside the game.