Privacy Policy
Last updated: February 17, 2026
1. Information We Collect
When you create an account, we collect your username, email address, and an encrypted hash of your password. We also collect game-related data such as battle results, team configurations, and API usage statistics.
2. How We Use Your Information
We use your information to operate the game, process payments, improve our services, and communicate with you about your account. We send transactional emails only (welcome, password reset, email verification, account deletion) — never marketing emails.
3. Cookies & Local Storage
We use essential cookies only. No analytics, advertising, or tracking cookies are used anywhere on this site. You cannot opt out of essential cookies because the site cannot function without them.
HTTP Cookies
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
.AspNetCore.Cookies |
Keeps you logged in to the web interface. Contains your encrypted session — not readable by JavaScript. | 8 hours (default) or 30 days ("Remember Me") | Strictly necessary |
.AspNetCore.Antiforgery.* |
Protects forms against cross-site request forgery (CSRF) attacks. Automatically generated by ASP.NET Core. | Session (cleared when browser closes) | Strictly necessary |
Browser Local Storage
These values are stored in your browser's local storage and are never sent to our servers.
| Key | Purpose | Duration |
|---|---|---|
theme |
Remembers your dark/light mode preference. | Persistent (until you clear browser data) |
cookie_consent |
Records that you've acknowledged the cookie notice so it doesn't reappear. | Persistent (until you clear browser data) |
That's it. No Google Analytics, no Facebook Pixel, no fingerprinting, no third-party trackers of any kind.
4. Payment Processing
Payment processing is handled by Stripe. We do not store your credit card information on our servers. Please review Stripe's Privacy Policy for details on how they handle your payment data.
5. Data Security
We use industry-standard security measures to protect your data, including bcrypt-hashed passwords, HTTPS-only connections, HttpOnly/SameSite cookies, and secure API key management. Passwords are never stored in plain text.
6. Data Retention & Deletion
We retain your account data for as long as your account is active. You can delete your account at any time from your Account Settings page. When you delete your account:
- Your username and email are permanently anonymized
- Your password hash and security tokens are removed
- Game data (battle history, ratings) is retained in anonymized form for service integrity
7. Third-Party Services
We use the following third-party services:
- Stripe — payment processing (privacy policy)
- Google reCAPTCHA v3 — bot protection on login/registration (privacy policy)
No data is shared with any other third parties.
8. Contact
Questions about this privacy policy? Reach out through our contact form or email support@apicombat.com.