Privacy Policy

Last updated: February 17, 2026

1. Information We Collect

When you create an account, we collect your username, email address, and an encrypted hash of your password. We also collect game-related data such as battle results, team configurations, and API usage statistics.

2. How We Use Your Information

We use your information to operate the game, process payments, improve our services, and communicate with you about your account. We send transactional emails only (welcome, password reset, email verification, account deletion) — never marketing emails.

3. Cookies & Local Storage

We use essential cookies only. No analytics, advertising, or tracking cookies are used anywhere on this site. You cannot opt out of essential cookies because the site cannot function without them.

HTTP Cookies

Cookie Name Purpose Duration Type
.AspNetCore.Cookies Keeps you logged in to the web interface. Contains your encrypted session — not readable by JavaScript. 8 hours (default) or 30 days ("Remember Me") Strictly necessary
.AspNetCore.Antiforgery.* Protects forms against cross-site request forgery (CSRF) attacks. Automatically generated by ASP.NET Core. Session (cleared when browser closes) Strictly necessary

Browser Local Storage

These values are stored in your browser's local storage and are never sent to our servers.

Key Purpose Duration
theme Remembers your dark/light mode preference. Persistent (until you clear browser data)
cookie_consent Records that you've acknowledged the cookie notice so it doesn't reappear. Persistent (until you clear browser data)

That's it. No Google Analytics, no Facebook Pixel, no fingerprinting, no third-party trackers of any kind.

4. Payment Processing

Payment processing is handled by Stripe. We do not store your credit card information on our servers. Please review Stripe's Privacy Policy for details on how they handle your payment data.

5. Data Security

We use industry-standard security measures to protect your data, including bcrypt-hashed passwords, HTTPS-only connections, HttpOnly/SameSite cookies, and secure API key management. Passwords are never stored in plain text.

6. Data Retention & Deletion

We retain your account data for as long as your account is active. You can delete your account at any time from your Account Settings page. When you delete your account:

  • Your username and email are permanently anonymized
  • Your password hash and security tokens are removed
  • Game data (battle history, ratings) is retained in anonymized form for service integrity

7. Third-Party Services

We use the following third-party services:

No data is shared with any other third parties.

8. Contact

Questions about this privacy policy? Reach out through our contact form or email support@apicombat.com.