Skip to content

Version 1.0 — in force from 30 September 2026

Privacy Policy

1. The short version

We are a one-person game studio. We collect as little as we can get away with, and we would rather tell you plainly what we keep than hide it in long sentences.

  • We never get your email address from Steam. Steam does not give it to us. If we have an email address for you, it is because you typed it into a form.

  • We do not use analytics. No Google Analytics, no tracking pixel, no beacon, no advertising network, no third-party tag of any kind. We verified this rather than assuming it. A trailer, the Steam store widget and avatar images are still loaded by your browser from Google and Valve, which sees your IP — section 15 says so.

  • We do not store your IP address or your browser's user agent against your account. Your IP is used in the moment to rate-limit requests and to check you are not a bot, and then it is gone. The one exception is a document you sign — see section 9.

  • We strip location and camera data out of every photo and video you send us, before the file is written to storage. We never keep the original.

  • We do not sell your data, and we do not share it for advertising. There is nobody to sell it to.

  • Most of what we hold, we hold indefinitely. Three automatic deletion jobs exist and run; the rest is kept until somebody deletes it by hand. Section 17 says which is which, and does not round the honest answer up.

The rest of this document is the detail.

2. Who we are and how to reach us

TIMMYG Studios LLC is the controller of the personal data described here.

Email us at info@timmygstudios.com. That is the contact address for any privacy question and for every request under section 18. A person reads it, and it is the fastest way to reach us.

We are an online-only studio and email is the way to reach us. If you need our postal details for a formal legal purpose, ask at that address and we will provide them.

We do not have a data protection officer, and we do not believe we are required to have one.

3. What this policy covers

  • The Tornado Emergency website, including the playtest application, the brand and vehicle licensing flow, the community media flow, your player profile and the public leaderboards.

  • The Tornado Emergency game client and the service it talks to.

It does not cover Steam itself, Discord, or any other site we link to. Those have their own policies.

Some of what is described here is not open yet. The brand and vehicle licensing flow collects data today. The playtest and community media flows collect data today, but cannot yet produce a signed agreement. Where a section describes something that is not open, it says so.

4. Signing in, and your account

You sign in with Steam. We use Steam's OpenID sign-in: you are sent to Steam, you approve it there, and Steam tells us one thing — your SteamID64, a 17-digit number. We then ask Steam's public API for your display name and your avatar image URL, and we refresh both each time you sign in.

Steam never gives us your email address, your real name, your password, or your age. We never see them and we cannot ask for them.

Because the software we use for sign-in insists on storing an email address for every account, your account row holds a fake, undeliverable placeholder of the form <your-steam-id>@steam.invalid. Nothing is ever sent to it. It is not an email address; it is a space-filler, and the .invalid suffix is reserved precisely so that it can never reach a real mailbox.

What your session stores

Signing in creates a session that lasts 7 days and is not extended by use — after 7 days you sign in again. The session row deliberately stores an empty string in place of your IP address and your user agent: our code blanks both before the row is written. That is a deliberate promise in code, not a side effect, and the rows written before we did it were blanked too.

Your player profile contains your display name and avatar, your in-game currency balance and lifetime earnings, your titles and when you were granted them, your progression statistics (distance driven, storms chased, strongest wind reported, probes recovered and lost), your account role, whether you are banned — with the reason, who applied it, and the moment it expires — and how many game sessions are currently signed in.

Signing in from the game is a different mechanism

The game client does not use the web sign-in above. It asks Steam for a one-time authentication ticket and sends it to our service; we hand that ticket to Valve, who confirm it is genuine and tell us your Steam ID, and we then ask Valve for your public display name and avatar. The ticket itself is never stored and never logged.

  • A hash of the ticket, kept 21 days. Steam's own rule is that a ticket must be used once, and Steam gives us no way to enforce that — present the same ticket twice and Steam approves it twice. So we store a one-way hash of each spent ticket, with your Steam ID and the time, and refuse a repeat. It is deleted 21 days later. That is a deliberately generous ceiling rather than a measurement: Steam does not publish how long this kind of ticket stays valid, and erring short would silently reopen the hole.

  • A game session token, stored only as a hash. It lasts 7 days, it is never written down in a form anyone could use, and it can be revoked. Signing in on a second machine revokes the first one's session, and a ban revokes all of them. Unlike the website's session rows — see section 21 — the game's session tokens are hashed.

  • No IP address and no user agent. A game session row holds your Steam ID, the token hash, its timestamps, and nothing else that identifies a device or a network.

If you are playing a copy borrowed through Steam Family Sharing, we record that. Valve tells us at sign-in whether the copy belongs to you. We store a yes/no flag on that sign-in — a borrowed copy can play, chase and save, but does not earn in-game money — and we do not keep the lender's Steam ID in our database. It is written once to a server log line explaining why earning is off for that session, which means its lifetime is our host's log retention. That is the open item in section 13.

5. Public leaderboards

The leaderboards are public — anyone can read them without signing in.

A leaderboard entry shows your rank, your display name, your equipped title, and the score. It does not contain your Steam ID. The Steam ID is removed before the data ever reaches the website, because a Steam ID is a permanent identifier that resolves to your real Steam profile and a display name is something you chose and can change.

You can take yourself off the leaderboards. There is a control on your profile page. When it is on, you are excluded inside the calculation itself, so there is no way for a page to render the standings and ignore your choice. You can turn it back on at any time.

6. Linking Discord (optional)

You can link a Discord account from your portal. You never have to.

When you link, we store one thing: your Discord user ID. We deliberately throw away the access token and the refresh token Discord issues, on both the first link and any re-link. We keep no credential and we cannot act on your behalf on Discord — we only hold proof that the account is yours. We do not fetch your Discord username, your email, your avatar or your server memberships.

You can unlink at any time from the same page. Unlinking deletes the row. One Discord account per player.

7. Applying to the playtest, to moderate, or suggesting something

The playtest application

You have to be signed in with Steam to apply. We collect what you type: your name, email address, Discord handle, your region, your timezone, your age bracket, whether you are a creator and your channel link, whether you want a free copy, your reason for applying, and a free-text description of your PC. We take the Steam account from the session you are signed in to rather than asking you for it, so it is always the account you applied from. Staff may add private notes to your application that you never see.

This form accepts nobody under 18, and refusing you means we keep nothing. If you tell it you are under 13, or that you are 13 to 17, it refuses and no row is written — see section 20. The 13-to-17 route still exists, but it is arranged by hand rather than through this form, and only then does a guardian's name and email address get collected.

We email you a confirmation link and do nothing further until you click it. If you never click it, the whole application is deleted after 7 days by an automatic daily job, and the link expires at the same moment.

One record outlives that deletion. Our log of email we attempted keeps your address and the subject line, and it is not deleted when the application is. Section 10 says so plainly rather than leaving this section to imply otherwise.

Once you confirm, your application goes to a signing flow (section 9) and we keep it. That signing step is not open yet.

Applying to moderate the Discord

You have to be signed in and have a Discord account linked. We take your Steam ID and your linked Discord user ID from those two things rather than asking for them, and we store your answers to about twenty questions as a single block of text — your timezone, how much time you could give and when, how you use Discord, how long you have been around, what moderation you have done before, your written answers to three judgement scenarios, and why you want to do it. Staff decisions on your application, including an internal reason you never see, are recorded and kept. There is no age question on this form and no automatic deletion for it.

Suggesting something for the roadmap

You have to be signed in. We take what you typed and post it to the studio's own work board as a card, with your Steam ID written into the card's text so we can see who asked. Nothing is stored in this site's own database. Section 15 has the detail, because that card leaves this site.

8. Brand, vehicle and device licensing

This flow is for a company or an individual licensing a trademark, a vehicle or a piece of equipment into the game. It has no age question and does not require a game account. It is open today.

We collect the legal name of the party, whether it is a company or a person, entity type, jurisdiction, principal address, a notice email, the signer's name and title, and optionally a separate approval contact's name and email; details of each mark (name, registration number, notes); details of each item (name, kind, base hardware, year built, owner or operator, distinguishing features); the commercial choices you make on the form; and the files you upload — logos, brand guidelines, reference material and photographs of the item, each kept under the filename you gave it.

This form also asks for other people's details. If a real person appears in the material, or another party holds rights in it, you give us their name, their email address, and their relationship to the material — and our signing system emails them directly so they can sign. If you are naming somebody else, please make sure they are expecting to hear from us.

This form saves what you type before you submit it. The licensing application is the one flow you do not need an account for, and to make that work we keep your draft on our server rather than in your browser. A draft is created when the page opens, and what you have typed is saved a second or two after you stop typing — so anything on the form, including the name and email address of somebody you have named, is stored before you press anything. If you never finish, the whole draft and every file on it is deleted after 30 days, and editing it starts that 30 days again. Section 17 has the table.

Staff decisions on your application — who acted, an internal reason, and the message you were sent — are recorded in an append-only log that is never deleted, including after the application itself is gone. See section 17.

9. Signing documents

The playtest agreement, the media release and the licensing order forms are signed through DocuSeal. DocuSeal is self-hosted on the studio's own server — it is not a third-party signing service holding your documents on someone else's platform. The studio runs it, the studio holds the database, and nobody else has an account on it.

When a document is fully executed we copy the merged signed PDF and the signing audit trail into our storage, because the signing system's own download links expire and a link is not a record. An executed agreement is a legal record and we keep it indefinitely.

A signature record contains the signer's IP address, and this is the exception to section 1. The audit trail prints, for each person who signs, their IP address, a session identifier, their browser's user agent and their time zone. That is what makes a signature evidence rather than a picture of one. It is inside the PDF we keep indefinitely, it applies to everyone on the document including a parent or guardian and anyone you named, and it is the only place on this site where we retain an IP address.

The signing system also keeps its own copy of everything on the document, including signers' email addresses and its own event history, in its own database on the studio's server.

10. Email we send, and email other people receive

We send email through the studio's own mail system. A small bridge on the studio's own server accepts the message over HTTPS and hands it to the studio's own mail server, which relays it out through Cloudflare's mail relay — so the address, the subject and the words we wrote to you pass through Cloudflare on the way. Mail comes from noreply@tornadoemergency.net, with replies directed to info@timmygstudios.com.

We send only these messages: a playtest confirmation link; a licensing status link; a licensing decline notice; and, when a contributor withdraws a media item, a confirmation to the contributor and a notice to the studio. We do not send a newsletter and there is nothing to unsubscribe from.

We keep a log of every email we attempt. It records the recipient's address, the subject line, which template it was, which application it concerned, whether it succeeded, the provider's message id, and the timestamps. It does not contain the message body — there is no body column and nothing writes one.

The mail log is not deleted, ever, and it outlives the thing it refers to. When we delete an abandoned licensing draft or an unconfirmed playtest application, the mail log row — including that person's full email address and the subject line — survives. This qualifies our own 7-day deletion promise in section 7, and we are stating it rather than hiding it.

Email sent by the signing system, not by us

DocuSeal emails signers directly. That includes people you named on a licensing form, additional rights holders, playtest testers, and the parent or guardian of a 13-to-17-year-old — and the guardian receives the full document. Those messages do not go through our mail system and do not appear in our mail log.

11. Community media you send us

If you send us clips, screenshots or video under the Community Media License and Release, you must be signed in and have a release that we have countersigned — a release only you have signed is not enough, and the upload is refused until then. That countersigning step is not open yet.

We collect, on the agreement: your Steam ID, your full legal name, your email address, your Discord username, the credit handle you want, your country or region, your age bracket, your credit preference, which likeness permissions you grant (face, voice, name, channel branding), whether it is playtest material, and — if you are 13 to 17 — your parent or guardian's name, email address and relationship to you.

We collect, on each file: the filename you gave it, the file type, the kind, the size, a checksum, the likeness permissions for that specific item, how you obtained it, whether it was recorded before release, and any withdrawal you later make.

We strip location and camera data out of your files

This is the part we want you to be able to check. Before a file is written to storage, we take the embedded metadata out ourselves, byte by byte, with no image library involved — JPEG, PNG, WebP and MP4. Out goes everything that says who, where, when or with what: GPS coordinates, camera make and model, lens, serial numbers, capture timestamps, the XMP and IPTC blocks, the embedded preview thumbnail, anything appended after the end of the file, and for video the creation and modification times, the track handler name and the encoder name. We never re-encode your file, so nothing is lost but the metadata.

The original file, with its metadata, is never stored. The stripping happens before storage is written to, and there is no code path that can store the original — for images the file is fully processed first, and a file we cannot parse is rejected with an error rather than stored.

Two things we keep on purpose, and we would rather say so:

  1. 1.

    Image orientation. We read one EXIF value — which way up the image is, a number from 1 to 8 — and store it beside the file as a label rather than inside it, so the picture displays the right way round. That value says which way up and nothing about who, where or when.

  2. 2.

    The colour profile. The ICC profile stays in the file, because removing it changes how the image looks. A camera-specific colour profile can name the capture device in its text tags. It cannot contain a location, a serial number or a timestamp.

Alongside each file we store: the agreement id, the filename you chose exactly as you typed it, a no-AI-training marker, the licence name, the orientation value, and a flag recording that the file was stripped.

A filename is often personal, and we keep yours as-is. People name files after dates, places and other people. We do not currently normalise or rewrite the name you gave the file.

We also keep our own notes on your media. Staff can tag an item, write private notes against it, and record where it has been used. You never see any of that, and a record of who changed it and what it said before is kept as well. If you ask us what we hold about you, this is part of the answer.

Files with a GPS or timecode track are refused, not cleaned. If a video carries telemetry — an action-camera or drone GPS track — we reject it rather than delete the track, because deleting the track would leave the coordinates in the file while making it look clean.

Withdrawing media. You can withdraw an item. That sets a withdrawal on the record and starts a 30-day deadline for us to stop using it. It does not currently delete the file — the stored object and the record remain. If you want the file itself gone, email us and say so.

Nothing serves this media publicly today. There is no page that reads it, every object is stored marked as a download rather than something a browser displays inline, and the storage bucket holding it has public access switched off, as does the one holding signed documents. Neither is addressable from the internet.

12. Playing the game

The game client sends us, keyed to your Steam ID: what you own and have unlocked, your upgrades and loadouts, every in-game money movement, each storm scan you score (intensity, proximity, pressure and temperature drop, peak wind, crew size — all measurements inside the fictional world, never your real location), your chase runs (when one opened and closed and who was hosting it), your progression and achievements, and a per-day record of the days you played, when we first and last heard from you that day, and how many sessions. That last one is an activity log and is the one that most reads as tracking, so we are naming it.

Diagnostics are the largest thing we collect. If you file a bug report we receive what you typed, your build and platform, the map, a tail of your game log, and — if you attached one — a full-screen screenshot, which contains whatever was on your screen. Crash reports include the crash signature and type, the error message, the call stack, a log excerpt, and a full hardware profile (GPU brand, adapter, driver and driver date; CPU brand and core count; OS version; RAM; graphics API and feature level). Performance reports include frame statistics and your entire graphics settings profile. Player-on-player reports contain both Steam IDs, the reported player's name, the reason you typed, and which lobby it happened in.

  • Aggregated fault counters carry no identifier at all. Repeated warnings from your game log are folded into a count against a fingerprint of the message, with the build, platform and map. There is no Steam ID on them, not even a hashed one, and they cannot be traced back to you.

  • A crash is stored once, not once per player. We keep one record per distinct crash per build, identified by a signature derived from the call stack, with a count of how many players hit it and the Steam ID of only the most recent one. Being the fifth person to hit a known crash does not add your ID to anything.

  • You can switch the last two off. There is a diagnostics setting in the game covering the fault counters and the performance sessions. It is on unless you turn it off, and the game tells you so on first run rather than leaving you to find it. Turning it off stops collection immediately and deletes anything still queued on your disk. It does not cover a bug report you chose to send, or a crash report.

Bug reports are copied onto the studio's internal work board, which has some public cards. The card carries what you typed, your build context, your log tail and your screenshot — but not your Steam ID. Instead it carries a short handle of the form Chaser <handle>, derived from your Steam ID by a keyed one-way function using a secret that never leaves our server. It lets us see that the same person reported two things without putting a permanent, cross-service identifier on a card that might become public. If that secret is ever absent, the card carries no handle at all; it never falls back to your Steam ID.

The screenshot and the text are yours, and they go onto that card as you sent them. A full-screen capture can contain anything that was on your screen, including other applications. Check it before you attach it.

Chat and voice

The game has text chat and push-to-talk voice chat. Both are carried inside your session — TORE sessions are usually hosted on another player's machine — and anything you say or type is heard by the people in it. We do not record voice chat, we do not store it, and no voice audio is ever sent to our servers. Chat messages are not sent to our servers either. Your mute list and your microphone choice are saved on your own computer, not on ours; the mute list contains the Steam IDs of the players you muted.

Chat text does get written into your local game log, and a bug report uploads part of that log. The game logs each chat line and who sent it so that a playtest log can show what was said. That log stays on your machine — but the tail of it is exactly what a bug report sends us, so a report filed shortly after a conversation can carry that conversation to us. That is the one route by which anything from chat reaches our servers.

What the game writes on your own computer

None of this is uploaded unless you send a bug report or a crash report. We are describing it because some of it has your identifier in it and because you may want to delete it.

  • Your save games, one of which has your Steam ID in its filename. Under the game's saved-data folder. The per-account archive slot is named after your SteamID64, and your Steam ID is also stored inside the save.

  • Your game log, which in tester builds names people. In the builds we hand to testers it carries diagnostic detail including Steam IDs — yours and, in a multiplayer session, other players' — and chat lines. Sign-in tokens are stripped out before anything is written.

  • Your settings, including your mute list. Your settings file holds the Steam IDs of players you muted, your chosen audio devices, your accessibility choices and your diagnostics preference.

  • An economy cache, which can name other players. Its filename is deliberately hashed so that no account identifier appears in it, but where you owe or are owed something on another player's behalf, their Steam ID is inside the file. One folder of preserved unreadable cache files is never cleaned up.

  • Crash folders, bug reports you created, and the odds and ends. A crash folder holds a description of your PC and that session's log; they accumulate and are never cleaned up automatically, and we deliberately do not send them to the engine vendor. A bug report holds your typed description, the technical context and a full-screen capture, and the 20 most recent are kept. Alongside those sit diagnostics waiting to be sent — turning the diagnostics setting off deletes them at once — plus a cached shop catalogue, cached feature flags, timing ledgers and the last 200 console commands you typed, none of which carries an identifier. You can delete any of it yourself.

One of these is not in the game's folder at all. The game writes a live stream-overlay snapshot to a TORE folder in your Documents, and it is on unless you turn it off. It contains your in-game name along with the state of the current match. Deleting the game's saved-data folder does not remove it — this file has to be deleted separately, and we are saying so because the obvious assumption is wrong.

13. Bot protection, rate limits, and logs

  • Bot protection. Cloudflare Turnstile runs on our public forms. Its widget loads with the page, which means your browser reaches Cloudflare as soon as a page with a form on it opens, before you have typed anything — section 15 covers that. Then when you submit, we send Turnstile's token and your IP address to Cloudflare to be checked. We store neither. If Turnstile is not configured, the form refuses the submission rather than accepting it unchecked.

  • Rate limiting. We count requests against your IP address, and for media uploads against your Steam ID, in a short rolling window. Nothing is written down.

  • Server logs. Our host keeps request logs for our code, currently at full sampling rather than a sample. One identifier reaches those logs and nowhere else: if you play a Family Shared copy, the Steam ID of the person who owns it is written to a log line at sign-in (section 4). It is never stored in our database.

  • Store link clicks. Our wishlist and share links, and the Wishlist on Steam buttons on this site, log which link was pressed, which channel it was published on or which place on the page the button sits in, where it pointed, the host of the referring site, and the country the request came from. Deliberately no IP address, no user agent, no cookie and no full referring URL. The buttons do this by sending you to Steam through a short link on our own site rather than by running anything in your browser — there is still no pixel, tag or beacon anywhere.

  • No analytics. We checked the whole codebase: there is no analytics SDK, no tag, no pixel and no beacon. If that ever changes, this policy changes with it before the change ships.

How long those logs last. At most 7 days. Our host deletes them on its own schedule — 7 days is the longest it keeps them — and we do not copy them anywhere else, so when they go they are gone. Logging is on at full sampling rather than a sample, so that is a real retention period and not a theoretical one.

14. Cookies and similar technologies

We use no advertising cookies and no cross-site tracking. What we set:

  • better-auth.session_token

    Why
    Keeps you signed in. Your browser cannot read it.
    How long
    7 days
  • better-auth.session_data

    Why
    A short-lived cache of your own session so every page load does not re-read the database.
    How long
    5 minutes
  • lic_draft_<id>

    Why
    Lets your browser come back to an unfinished licensing application without an account. Contains a secret your browser cannot read.
    How long
    31 days
  • Sign-in state cookie

    Why
    Protects the Steam sign-in round trip against tampering.
    How long
    About 10 minutes
  • Cloudflare Turnstile

    Why
    Turnstile may set its own storage to tell a human from a bot. It is Cloudflare's, not ours.
    How long
    Cloudflare's
  • tore:draft:* (your browser, not a cookie)

    Why
    Keeps a half-finished playtest or moderator application if you reload or press back. We deliberately use the kind of browser storage that is wiped when you close the tab, rather than the kind that keeps things forever or than saving your draft on our server — an unfinished form can carry a lot about you before you have decided to send it, and we would rather it not outlive the tab on a shared computer. We also clear it explicitly the moment the form is finished with.
    How long
    Until you close the tab
  • theme

    Why
    Remembers whether you chose light or dark. It holds one word and nothing else, and it is the only thing we keep in the kind of browser storage that persists.
    How long
    Until you clear your browser data

Does the bot-protection widget set a cookie here? Not one we asked for. Turnstile hands our server a single-use token, and the cookie it can optionally set — the one that would let you skip later challenges — is an option that is off unless somebody turns it on, and we have not. Cloudflare may still keep its own storage in your browser to tell a human from a bot; that is Cloudflare's and it is in the table above.

We have no cookie banner, and the table above is the reason. Every cookie we set is one the site cannot work without: it keeps you signed in, protects the sign-in round trip, or holds an application you started. Nothing we set is for advertising, nothing is for analytics, and nothing follows you to another site — and cookies that are strictly necessary to provide what you actually asked for do not need consent. The single exception is remembering whether you chose light or dark, which stays in your own browser and is never sent to us.

15. Who else sees your data

We do not sell your data. We share it only with the following, and only for the purposes named:

  • Cloudflare

    What they receive
    Everything on this site. Their platform runs the code, holds the databases, holds uploads and signed documents, defends the forms, keeps the request logs, and relays our outbound mail.
    Why
    This is our hosting. Without it there is no site.
    Where
    Global edge network
  • Valve (Steam)

    What they receive
    Your Steam ID, to verify your sign-in and fetch your display name and avatar. Your game session ticket, when the game signs in.
    Why
    Sign-in and identity.
    Where
    Valve
  • Discord

    What they receive
    Only what Discord already knows: that you authorised the link. We send them nothing about you.
    Why
    Optional account linking, if you choose it.
    Where
    Discord
  • TIMMYG Studios (the studio)

    What this is
    Our signing system, our mail system and our work board are all self-hosted by the studio. They are not third-party platforms and using them is not a transfer of your data to anybody else: the studio runs the machine, holds the database, and nobody outside the studio has an account on any of them.
    What they hold
    The signing system holds everything on a document you sign, including other signers' names and email addresses and each signer's IP address and user agent. The mail system handles the recipient address, the subject and the full body of every message we send, and hands it to Cloudflare's mail relay for delivery. The work board holds bug reports — what you typed, your build context, your log tail and your screenshot — carrying a keyed handle instead of your Steam ID, and roadmap suggestions, which do carry it.
    Where
    A server the studio rents in the eastern United States, except the work board, which is at timmygstudios.com.
  • Embedded content your browser loads

    What they receive
    Your IP address and your browser's user agent, because your browser fetches them directly. Google, for a YouTube video embedded in a Steam announcement; Valve, for the official store widget and for player avatar images; Cloudflare, for the bot-protection widget.
    Why
    Showing you a trailer, the store widget and people's avatars. None of them is a tracker we added — there is still no analytics, tag, pixel or beacon anywhere on this site.
    Where
    Their own networks

If you suggest something for the roadmap, your Steam ID travels with it. The suggestion becomes a card on the studio's work board, and your Steam ID is written into the card's text as the attribution. The board is the studio's own, but some of its cards are public, so treat a suggestion as something that carries your identifier off this site. Bug reports do not work this way — they get a keyed handle instead, as section 12 describes.

16. Where your data is held, and transfers

Our code runs on Cloudflare's global network. Our databases and our storage buckets are pinned to ENAM — Cloudflare's Eastern North America region. DocuSeal and our mail system run on a server the studio rents in the eastern United States.

So if you are outside the United States, your data is held in the United States. We accept applicants from the EU and the UK, and for them that is a transfer out of their own country — you should assume United States law can reach it. We would rather tell you plainly where your data sits than print the name of a transfer mechanism as though naming it settled anything. If you need the specific basis and terms that cover your data, ask at the address in section 2 and we will set them out for you.

17. How long we keep things

Some of this is genuinely automatic, and some of it is indefinitely. We would rather say which is which. A daily job runs at 04:10 UTC and handles the first two.

  • Unfinished licensing application, never submitted

    How long
    30 days after you last edited it — editing resets the clock. The application, everything on it and every file you uploaded to it are deleted.
    Automatic
    Yes
  • Unconfirmed playtest application, confirmation link never clicked

    How long
    7 days after you applied. The application is deleted and the link expires at the same moment. The mail log row survives — see section 10.
    Automatic
    Yes
  • Sign-in session

    How long
    7 days, fixed
    Automatic
    It expires
  • Spent sign-in ticket records (game)

    How long
    21 days, then deleted. The hash and the Steam ID filed with it both go. This is the one game-side record that expires on its own today.
    Automatic
    Yes — on the sign-in path, not a nightly job
  • Licensing draft cookie

    How long
    31 days
    Automatic
    Your browser
  • Executed agreements, signed PDFs and their audit trails

    How long
    Indefinitely, including declined, expired and terminated ones and everything uploaded to them. An executed agreement is a legal record of what was agreed. These are also the records that contain a signer's IP address — see section 9.
    Automatic
    No
  • The records that outlive what they refer to

    How long
    Indefinitely. The mail log keeps a recipient's full address and the subject line after the application it was about has been deleted. The staff decision logs on licensing, playtest, media and moderator applications are append-only and survive the deletion of the application, because a refusal with no recorded reason is unanswerable later.
    Automatic
    No
  • Everything else

    How long
    Indefinitely. Media agreements and uploaded media — with no automatic deletion at all, not even for unfinished media drafts, unlike the licensing drafts above. Moderator applications and their answers. Roadmap suggestion cards, which are not in either of our databases and so no sweep here reaches them. Your gameplay, economy, progression and activity data. Bug reports, crash reports, performance reports and player reports.
    Automatic
    No

Two further automatic mechanisms exist on the game side and neither is switched on. Separately from the ticket expiry in the table above, the game service contains a 90-day expiry for the Steam ID on crash and performance records, and an endpoint that erases a player's own account across 22 tables. Both are deliberately left off: an irreversible deletion path must not go live as a side effect of an unrelated deploy, and the first run of the sweep cannot be undone. So the table above is literally true today — there is no 90-day window and no automatic erasure. When either is armed, this section will say so and will state the period it actually enforces.

18. Your rights, and how to actually use them

Depending on where you live you may have the right to see the data we hold about you, get a copy, correct it, delete it, object to what we do with it, and complain to a regulator.

Here is the honest mechanism. Three things you can do yourself, right now:

  • Take yourself off the public leaderboards — a control on your profile page.

  • Unlink your Discord account — a control on your portal page.

  • Turn off diagnostics collection in the game — this stops the aggregated fault counters and the performance sessions described in section 12, takes effect immediately rather than at the next launch, and deletes the not-yet-sent queue from your own disk as you turn it off. It does not affect a bug report you deliberately choose to send, or a crash report.

Everything else is manual, and that is the current truth. There is no data export button and no account deletion button, and nothing you can press deletes data we have already collected. The game service contains a deletion endpoint and it is switched off (section 17). We are not going to describe a self-serve path that does not run.

To ask for access, a copy, a correction, deletion, or to object: email info@timmygstudios.com and tell us what you want. Say which account you mean — your Steam display name or Steam ID for a game account, or the email address you used for a playtest, licensing or media application.

We will confirm we received it, and we will answer within 30 days. It is done by hand, by one person. If a request turns out to need longer than that, we will tell you inside the 30 days and say why, rather than going quiet on you.

What we cannot delete, and why. An executed agreement is a legal record of what was agreed, and we keep it and its audit trail. Our staff decision log is append-only, because a refusal with no recorded reason is unanswerable later. If you ask us to delete and we have to keep something, we will tell you exactly what and why.

A regulator. If you are in the EU or the UK you can complain to your national data protection authority — the one where you live or work. We have no office or establishment in the EU or the UK, so there is no single lead authority for us and nothing for you to go through first: yours is the right one to approach.

19. Why we are allowed to hold it

This is our reading of what we do, written out so you can see the reasoning rather than take it on trust. If you think one of these does not match what actually happens, tell us at the address in section 2 — that is a bug in this page and we will fix it.

  • To give you what you asked for: your account, your progression and inventory, your leaderboard entry, your playtest application, your licensing application, your media release, and the emails that carry those flows.

  • Because we have to: keeping executed agreements and their audit trails.

  • Because it is in our interest, and we think yours: crash, performance and bug diagnostics, so the game works; bot defence and rate limiting, so the forms are not abused; and the staff decision log, so a decision can be explained later.

  • Because you said yes: linking Discord, appearing on the leaderboards, and every likeness permission on a media release. Each of these you can withdraw.

20. Children

Under 13: we do not accept you, and refusing you means we keep nothing. If you tell the playtest form or a media release you are under 13, we refuse and write nothing down — no row, no email, nothing kept. That is enforced on our server, not just in your browser, and it is checked in more than one place so it cannot be lost in a refactor. We are not collecting a child's name and email address only to tell them no.

  • 13 to 17 cannot use the playtest form at all. It refuses that answer the same way it refuses under-13 — no row is written — and tells you to reach us on Discord or by email instead. The playtest is still open to 13-to-17-year-olds with a parent or guardian signing, but it is arranged by hand, and a guardian's name and email address are collected at that point rather than by this site.

  • 13 to 17 can send us media, and then a parent or guardian has to sign too. The media release does accept that answer, and when you give it we require your guardian's name, email address and relationship to you. Your guardian is emailed the agreement and signs it; you sign as well. We deliberately do not show a guardian's email address on any status page — they consented to one thing, not to being listed.

  • We ask for an age bracket, never a date of birth. It is a radio button — 18 or older, 13 to 17, or under 13 on the playtest form, and the first two on a media release. We never hold your birthday or your age as a number, and we do not verify your answer or your guardian's. An unverified email address is not strong proof of a guardian's consent, and we are not going to claim it is.

  • Sign-in has no age gate, because Steam does not tell us your age. We know the age bracket only of people who filled in a playtest or media form.

  • The licensing flow asks no age question at all, since it is aimed at companies. It does collect the names and email addresses of people the applicant names, and we do not know how old those people are.

Children's data has its own rules in the United States, the EU and the UK, and what we do about them is everything described above: we refuse an under-13 answer on the server and write nothing down, we ask for an age bracket instead of a birthday, and the 13-to-17 playtest route is arranged by hand rather than through a form. What we cannot do is verify an age or a guardian's identity from an email address, and we do not claim to. If you are a parent or guardian and want to know what we hold about your child, or want it deleted, email us at the address in section 2 and we will do it.

21. Security

  • Everything is served over HTTPS. Admin surfaces are behind a staff check that runs on every request, not just at sign-in.

  • Your session cookie cannot be read by JavaScript, and neither can the licensing draft cookie.

  • We store no password, because there is no password — sign-in is Steam's.

  • We keep no Discord credential.

  • The signing webhook is authenticated, and uploads are checked by actually reading the file's bytes rather than trusting what it claims to be. SVG files are refused outright.

  • Uploads are capped at 25 MB for images and 90 MB for video.

  • Our storage buckets have public access switched off. Nothing in them is addressable from the internet.

One honest caveat. Our website session tokens are stored in the database in the form our sign-in library stores them, which is not hashed. The game's session tokens are hashed. It is our library's format rather than our choice, it is recorded as a known issue, and you should know it rather than find it out.

No system is perfectly secure, and we will not claim otherwise.

22. Changes to this policy

If we change what we collect, we change this page before the change ships, not after. The date of the last change is at the top and the bottom. If a change is significant — a new processor, a new category of data, a new purpose — we will say so plainly rather than quietly editing a sentence.

Two specific commitments, because they are the two places this page currently admits a gap: if the automatic retention sweep or the account-erasure endpoint in section 17 is ever switched on, section 17 changes in the same step; and if an analytics tool is ever added, section 13 changes before it ships.