← Back to WarForge

Privacy Policy

Last updated: March 1, 2026

This Privacy Policy describes how WarForge ("we," "us," or "our") collects, uses, stores, and protects information when you use the WarForge software application, website, and related services (collectively, the "Service"). We are committed to protecting your privacy and being transparent about our data practices.

Key Principle: Your game credentials (username, password) are stored locally on your machine only and are never transmitted to our servers. We collect the minimum data necessary to operate the license system and improve the Service.

1. Information We Collect

1.1 Information Stored Locally (On Your Machine Only)

The following data is stored exclusively on your local machine and is never transmitted to our servers:

  • Game credentials: Your Total Battle username and password, stored in an encrypted local configuration file
  • Browser profile data: Cookies, localStorage, and session data from the automation browser instance
  • Configuration settings: Your preferences for crypt types, captain settings, speed-up options, and activity limits
  • Exploration logs: Detailed logs of automated actions including timestamps, crypt types, loot collected, and captain usage

1.2 Information Collected by Our License Server

When the Software communicates with our license validation server, we collect:

DataPurposeRetention
License KeyValidate your subscription and feature accessDuration of account
Machine FingerprintBind license to a single device (hardware hash — not your hostname or personal identifiers)Duration of account
IP AddressRate limiting, fraud prevention, and general security30 days (logs), then deleted
Software VersionEnsure compatibility and deliver updatesDuration of account
Subscription TierEnforce usage limits per tierDuration of account
Heartbeat TimestampsVerify active sessions and concurrent usage7 days, then deleted
Daily Exploration CountEnforce daily limits per subscription tierRolling 24-hour window

1.3 Information Collected via Our Website

When you visit our website, we may collect:

  • Usage analytics: Pages visited, time on site, referral source, browser type, device type, and operating system (collected via privacy-respecting analytics)
  • Language preference: Stored in your browser's localStorage to remember your selected language

1.4 Payment Information

All payment processing is handled by Stripe, Inc. We do not directly collect, store, or process your credit card number, bank account details, or other financial information. Stripe's handling of your payment data is governed by Stripe's own Privacy Policy. The only payment-related data we receive from Stripe is:

  • Transaction confirmation (success/failure)
  • Subscription status (active, cancelled, past due)
  • Email address associated with your Stripe payment
  • Last four digits of your payment method (for display purposes only)

1.5 Information We Do NOT Collect

We want to be explicit about data we never collect:

  • Your game username or password (these never leave your machine)
  • Your real name (unless you voluntarily provide it in support communications)
  • Your physical address or geolocation
  • In-game data, screenshots, or gameplay footage
  • Contents of your exploration logs
  • Data from other applications on your machine
  • Keystrokes, clipboard contents, or screen recordings

2. How We Use Your Information

We use the information we collect for the following purposes:

  • License validation: To verify that your License Key is valid and active, and to enforce subscription tier limits
  • Security and fraud prevention: To detect and prevent unauthorized use, license sharing, and abuse of the Service
  • Service improvement: To understand aggregate usage patterns and improve the Software (we use anonymized, aggregated data only)
  • Customer support: To assist you with technical issues or account inquiries
  • Communications: To send you critical service notifications such as security alerts, billing issues, or Terms changes (we do not send marketing emails unless you opt in)
  • Legal compliance: To comply with applicable laws, regulations, or legal processes

3. Data Sharing

We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:

3.1 Service Providers

We use the following third-party service providers who may process data on our behalf:

  • Stripe, Inc. — Payment processing (Privacy Policy)
  • Fly.io — License server hosting (Privacy Policy)
  • Cloudflare, Inc. — Website hosting and CDN (Privacy Policy)

These providers are contractually obligated to protect your data and may only use it for the specific services they provide to us.

3.2 Legal Requirements

We may disclose your information if required to do so by law, subpoena, court order, or other legal process, or if we reasonably believe that disclosure is necessary to: (a) comply with applicable law; (b) protect our rights, property, or safety; (c) prevent fraud or abuse of the Service; or (d) protect the rights, property, or safety of others.

3.3 Business Transfers

If WarForge is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website of any change in ownership or use of your information.

4. Data Security

We implement appropriate technical and organizational measures to protect your information:

  • Encryption in transit: All communications between the Software and our license server use TLS 1.2 or higher
  • Local encryption: Game credentials stored on your machine are encrypted using industry-standard encryption
  • Access controls: Access to our license server and databases is restricted to authorized personnel only
  • Minimal data collection: We follow the principle of data minimization — we only collect what is strictly necessary
  • No credential transmission: Your game credentials are never transmitted over any network
  • JWT authentication: License validation uses cryptographically signed JSON Web Tokens
  • Regular security review: We periodically review and update our security practices

While we take reasonable precautions to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

5. Data Retention

We retain your information only for as long as necessary to fulfill the purposes described in this policy:

  • Active account data: Retained for the duration of your account
  • Server access logs (IP addresses): 30 days, then automatically deleted
  • Heartbeat data: 7 days rolling window
  • Payment records: Retained for 7 years as required for tax and accounting compliance
  • Support communications: Retained for 2 years after last communication
  • After account deletion: All account data is permanently deleted within 30 days of your deletion request, except where retention is required by law

6. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

6.1 Access & Portability

You may request a copy of all personal data we hold about you. We will provide this in a commonly used, machine-readable format within 30 days of your request.

6.2 Correction

You may request that we correct any inaccurate personal data we hold about you.

6.3 Deletion

You may request that we delete all personal data we hold about you. Upon receiving a deletion request, we will permanently delete your data within 30 days, except where retention is required by law (such as payment records for tax compliance).

6.4 Objection & Restriction

You may object to or request restriction of our processing of your personal data in certain circumstances.

6.5 Withdrawal of Consent

Where we process your data based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.

6.6 Local Data

Data stored locally on your machine (game credentials, browser profiles, logs, settings) is entirely under your control. You can delete this data at any time by uninstalling the Software or deleting its data directory.

To exercise any of these rights, contact us at fullcentral@gmail.com. We will respond within 30 days.

7. Cookies & Local Storage

7.1 Website

Our website uses minimal cookies and browser localStorage:

  • Language preference: Stored in localStorage to remember your selected language (no expiration, cleared by clearing browser data)
  • Analytics cookies: If we use analytics, we use privacy-respecting services that do not track individuals across websites

We do not use advertising cookies, tracking pixels, or third-party marketing cookies.

7.2 Software

The Software's built-in browser instance uses cookies and localStorage to maintain your game session. This data is stored locally in the Software's data directory and is not shared with us.

8. Children's Privacy

The Service is not directed to individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at fullcentral@gmail.com.

9. International Data Transfers

Our license server is hosted in the United States. If you are accessing the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers maintain facilities. By using the Service, you consent to such transfer. We ensure that appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws.

10. European Users (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following additional provisions apply:

10.1 Legal Basis for Processing

  • Contract performance: Processing necessary to provide the Service you've subscribed to (license validation, feature access)
  • Legitimate interest: Security, fraud prevention, and service improvement
  • Legal obligation: Compliance with applicable laws (such as retaining payment records for tax purposes)
  • Consent: Where required, such as for optional marketing communications

10.2 Data Protection Officer

For GDPR-related inquiries, contact us at fullcentral@gmail.com with the subject line "GDPR Request."

10.3 Supervisory Authority

You have the right to lodge a complaint with a supervisory authority in your member state if you believe our processing of your personal data violates applicable data protection laws.

11. California Users (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know: You may request details about the categories and specific pieces of personal information we have collected
  • Right to delete: You may request deletion of personal information we have collected
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights
  • No sale of personal information: We do not sell personal information as defined by the CCPA

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Updating the "Last updated" date at the top of this page
  • Sending notice through the Software for significant changes

Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

WarForge
Email: fullcentral@gmail.com
Discord: Coming soon

We aim to respond to all privacy-related inquiries within 30 days.