PRIVACY POLICY
Last updated: 14 March 2026
1. WHO WE ARE
SUBSTRATE ("we", "us", "our") is operated by R3TR0S0FT. This privacy policy explains how we collect, use, store, and protect your personal data when you use our website and game service at substrate.game (the "Service").
For GDPR purposes, we are the data controller. If you have questions about your data, contact us at privacy@substrate.game.
2. DATA WE COLLECT
Account Data
- Email address
- Hashed password (we never store plaintext passwords)
- Account creation date
Game Data
- Character profiles, stats, inventory, and progression
- Game session history and action logs
- In-game choices and narrative interactions
Payment Data
- Subscription tier and billing cycle
- Payment processing is handled entirely by Stripe — we do not store your card number, CVV, or full billing details
Technical Data
- IP address
- Browser type and version
- Device type
- Pages visited and session duration
3. HOW WE USE YOUR DATA
- Provide the Service: authenticate you, save your game state, process actions
- Process payments: manage subscriptions and usage tracking via Stripe
- AI narrative generation: your in-game actions and character state are sent to third-party AI services (Anthropic) to generate narrative responses — no personal account data is included in these requests
- Improve the Service: aggregate, anonymised usage analytics to understand how the game is played
- Communicate with you: service updates, security alerts, and subscription-related emails
- Prevent abuse: rate limiting, fraud detection, and enforcing our terms
4. LEGAL BASIS (GDPR)
We process your data under the following legal bases:
- Contract: processing necessary to provide the Service you signed up for (account, game data, payments)
- Legitimate interest: security, fraud prevention, service improvement
- Consent: marketing emails (if you opt in) and non-essential cookies
5. THIRD-PARTY SERVICES
We share data with the following third parties, only as necessary to operate the Service:
- Anthropic: in-game action text and character state for AI narrative generation — no personal data included
- Stripe: payment processing — subject to Stripe's Privacy Policy
- OVH: infrastructure hosting (EU-based servers)
We do not sell your personal data to anyone. Ever.
6. DATA RETENTION
- Account data: retained while your account is active, deleted within 30 days of account deletion request
- Game data: retained while your account is active
- Action logs: retained for 90 days for debugging and abuse prevention, then anonymised
- Payment records: retained as required by tax and financial regulations (typically 7 years)
7. YOUR RIGHTS (GDPR)
If you are in the EU/EEA, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data ("right to be forgotten")
- Restriction: restrict processing of your data
- Portability: receive your data in a machine-readable format
- Object: object to processing based on legitimate interest
- Withdraw consent: where processing is based on consent
To exercise any of these rights, contact privacy@substrate.game. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority.
8. DATA SECURITY
We protect your data with:
- Passwords hashed with bcrypt
- HTTPS/TLS encryption for all connections
- JWT-based authentication with short-lived access tokens
- Infrastructure hosted within the EU
- Regular security reviews
No system is 100% secure. If we discover a breach affecting your personal data, we will notify you and the relevant authorities within 72 hours as required by GDPR.
9. CHILDREN
SUBSTRATE is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. CHANGES
We may update this policy. If we make material changes, we will notify you by email or through the Service. Continued use after changes constitutes acceptance.
11. CONTACT
For privacy-related enquiries: