Grimmarch privacy policy

Version: 2026-09-18
Effective from: 2026-09-18
Analytics consent version: 2026-09-16

This policy explains what Grimmarch collects about you, why, who else handles it, how long it is kept, and how to have it deleted or sent to you. It covers the Grimmarch game, the online service the game connects to, the grimmarch.com website, and email you exchange with us.

A Polish version of this policy is available at grimmarch.com/legal/pl/privacy. For consumers in Poland, the Polish version prevails.

It does not cover Steam or Google. When you buy Grimmarch on Steam or sign in with a Steam or Google account, those services handle your data under their own privacy policies, linked in section 6.

The short version

1. Who we are

Grimmarch is published by AppsByLuke. The data controller for the personal data described here is:

Łukasz Ziaja, trading as AppsByLuke (sole proprietorship)
al. Wiśniowa 36a/304, 53-137 Wrocław, Poland
NIP 6152032776 (EU VAT number PL6152032776), REGON 369734845

Contact for privacy questions and requests: support@grimmarch.com

We have not appointed a data protection officer or an EU representative.

2. What we collect and why

2.1 Your account

The first time you start the game, it creates an account for you without asking for anything. This is a guest account.

We need this to give you an account at all, so it is part of providing the game you bought.

2.2 Signing in with email, Steam or Google

A guest account lives on the computer that created it. You can add a way to sign in to it, and you can also sign in instead of starting as a guest. Once your account has a sign-in method, your progress is kept on that account: you can reach it from another computer by signing in, and losing your computer or deleting the game's files no longer loses your progress. What we store depends on which you choose:

For each sign-in method we also store when you added it, when you last used it, and, if you remove it, when.

Removing a sign-in method. You can remove a sign-in method as long as your account keeps at least one other. The last one cannot be removed, because your account could then be reached only from computers already signed in to it; to stop using your account, delete it instead, as described in section 8. Removing an email sign-in also deletes the stored password. We keep the record that the method was attached and when it was removed until your account is deleted.

2.3 Playing the game

To keep your progress, we store what happens in your game:

We need this to provide the game you bought.

Finished quest records that are only needed for support are deleted 30 days after the quest ends.

2.4 Playing with other people

Grimmarch has friends, Expeditions and Free Companies. It has no free-text chat.

What other players can see:

We process this to provide the social features of the game you bought.

2.5 Reports and moderation

You can report another player's name or Free Company name. A report stores who made it, who it is about, the name as it was when you reported it, where in the game you reported it from, and the reason you wrote (up to 500 characters). We use reports to keep names in the game acceptable. When we act on a report, we record what we did, when and why, so the decision can be explained to you and appealed.

Reports and moderation decisions are kept, in a reduced form if either account is deleted, for 12 months after the decision, or 12 months after the report if we took no action, so that we can answer appeals and complaints and defend our decisions. They are then deleted. Section 8 explains what remains after an account is deleted. Our basis for this is our legitimate interest in keeping the game safe for other players and in handling appeals and legal claims.

If we close an account for a serious or repeated breach of our terms, we keep its data for 12 months after the closure, so that we can handle an appeal, restore the account if the appeal succeeds, and deal with legal claims. It is then erased as described in section 8. You can still ask for a copy of your data during that time.

When you first play, the game asks whether you want to share play statistics. They are off until you agree, and the game plays the same either way. You can change your answer at any time in Settings.

If you agree, the game sends us events such as which screens you open, when you start and finish a quest, and when a battle starts. These events are linked to your account identifier. They do not include your name or email address, but they are not anonymous, because they are tied to your account.

Separately from that choice, our servers record when a play session starts and when it ends, linked to your account identifier. They work this out from your connection and sign-in activity, which reaches them anyway; the game does not send anything extra for it. We use these records to run the service, notice outages and plan server capacity, so they do not depend on your answer. Our basis for them is our legitimate interest in keeping the service running.

We record your answer, when you gave it, and the analytics consent version shown at the top of this policy. That version changes only when what statistics collect, why, who receives them or how long they are kept changes. When it does, we ask you again, and until you answer, statistics are treated as off.

Our basis for statistics is your consent. You can withdraw it at any time in Settings, and withdrawing does not affect anything collected before.

2.7 Crash and error reports

The game sends crash reports unless you turn them off. The Send crash reports switch is in Settings, is on until you change it, and is shown to you in the privacy prompt when you first play. It is separate from your choice about play statistics.

Crash reports are kept on our own servers, in an error tracker we run ourselves. Like all traffic to our servers, they pass through Cloudflare on the way, but no other service receives or stores them. Reports are deleted automatically within about 14 days.

Our basis is our legitimate interest in finding and fixing faults in the game you bought. You can object by turning the switch off.

2.8 Technical data

Our basis is our legitimate interest in keeping the service secure and running.

2.9 Email

2.10 What stays on your computer

The game keeps these files in its own folder on your computer: your device key, your audio and frame rate settings, downloaded game content, art and audio, a record used to resume a battle after a disconnect, and a small file used to notice whether the game closed cleanly. Uninstalling the game and deleting its folder removes them. If your account has no sign-in method added, deleting the device key means that computer can no longer reach that account.

2.11 What we do not do

3. Summary of why we use your data

What Why Legal basis under the GDPR
Account, sign-in, game progress, social features, account emails To provide the game you bought Performance of a contract, Article 6(1)(b)
Crash and error reports, IP address for rate limiting, server logs To keep the service working and secure Legitimate interests, Article 6(1)(f)
Reports and moderation decisions, including those kept after an account is deleted To keep the game safe for other players Legitimate interests, Article 6(1)(f)
Play statistics To learn which parts of the game are used Consent, Article 6(1)(a)
Session start and end records To run the service, notice outages and plan server capacity Legitimate interests, Article 6(1)(f)
Support email from players about their account or the game To answer you Performance of a contract, Article 6(1)(b)
Support email from anyone else, and keeping all support email for 2 years after the conversation ends To answer you, and to handle follow-up questions, complaints and legal claims Legitimate interests, Article 6(1)(f)
Data of an account closed for a breach of our terms, kept for 12 months To handle appeals and legal claims Legitimate interests, Article 6(1)(f)

Where we rely on legitimate interests, you can object, as described in section 9.

4. Automated decisions

We make no decisions about you based solely on automated processing that have legal or similarly significant effects. The name filter refuses names automatically, and you can simply choose another.

5. Where your data is stored

Our servers are run by Hetzner Online GmbH in its data centre in Falkenstein, Germany. Your account and everything the game stores about you are kept there. Apart from the providers listed in section 6, we keep no copy anywhere else.

6. Who else handles your data

Service providers working for us

Provider What they do Where Safeguards
Hetzner Online GmbH Hosts our servers Falkenstein, Germany; Hetzner processes our data only in the European Union or European Economic Area Data processing agreement
Cloudflare, Inc. Sits in front of our servers and our website, protecting them from attacks and delivering game art; forwards email sent to support@grimmarch.com Cloudflare's global network, inside and outside the European Economic Area Cloudflare's Data Processing Addendum. Transfers to the United States rely on the EU-US Data Privacy Framework; other transfers outside the European Economic Area use the European Commission's Standard Contractual Clauses
Brevo (Sendinblue SAS) Sends account emails Stores send records in France (OVH) and Belgium (Google Cloud) See below
Google Workspace (Google Cloud Poland Sp. z o.o., with Google LLC) Holds support email Google's data centres, inside and outside the European Economic Area Google's Cloud Data Processing Addendum. Transfers to the United States rely on the EU-US Data Privacy Framework; other transfers outside the European Economic Area use the European Commission's Standard Contractual Clauses

Brevo. For each email Brevo receives your email address, which email it is, and the code it contains, if it has one. Brevo keeps a record of each send: your address, the subject, the date and time, and IP addresses. We do not measure whether you open account emails or click links in them. We have switched off Brevo's storage of the email's content, so the stored record does not contain your code, and Brevo deletes the record 1 month after the email is sent. Brevo's hosting is in the EU, but Brevo may process data outside the European Economic Area for support, dashboards, network protection and maintenance, including in the United States and India. Brevo covers those transfers with the European Commission's Standard Contractual Clauses with additional safeguards, and the EU-US Data Privacy Framework for the United States.

You can get a copy of the Standard Contractual Clauses that apply to a transfer by emailing support@grimmarch.com. Parts that protect confidential information may be removed.

Services that handle your data as their own

These services are independent controllers. We do not control what they do with your data, and their own privacy policies apply.

Other players

Other players see what section 2.4 lists.

Authorities

We disclose personal data to authorities only when the law requires us to.

7. How long we keep your data

Data How long
Your account, sign-in methods, characters, progress, social data and statistics choice Until your account is deleted
Your account after you ask to delete it 14 days, then erased, see section 8
Finished quest records kept for support 30 days after the quest ends
Recently played with 14 days after you last played together
A guest account with no sign-in method that is not used Deleted automatically after 12 months without use
Presence marker 5 minutes after your last update
Sign-in rate limit counters Up to 24 hours
Session tokens 15 minutes
Renewal tokens A token stops working after 90 days; our stored records of your tokens are kept until your account is deleted
Crash and error reports Within about 14 days
Server logs About 15 days
Internal event streams that carry your account identifier Rolling windows: statistics and session events 7 days, progress and failed messages 30 days, in-game currency events 180 days, each plus a short technical delay
Internal message records, including accepted statistics events 30 days after they are written
Reports and moderation decisions 12 months after the decision, or 12 months after the report if no action was taken
An account closed for a breach of our terms 12 months after the closure, then erased
Support email 2 years after the conversation ends
Brevo's record of each email we sent you 1 month after the email is sent

8. Deleting your account

In the game: you can delete your account from Settings while signed in. Deletion signs you out on every device straight away, although a device that was already signed in can keep working for up to 15 minutes. Your account is then kept for 14 days in case you change your mind: signing in during those 14 days cancels the deletion. After 14 days your data is erased, and it is gone from our live systems within one month of your request. Copies in internal event streams, which cannot be edited record by record, are not used for anything and expire automatically on rolling windows, the longest of which is 180 days, plus a short technical delay. If your account has an email address, we email you when deletion is requested and if it is cancelled, so a deletion you did not ask for cannot go unnoticed.

By email: if you write to support@grimmarch.com instead, we will point you to Settings. If your account has an email address, we can instead confirm the request by sending a code to that address, and delete the account once you give us the code. A friend code alone does not prove an account is yours, because other players can see it. A guest account that has no sign-in method and can no longer be reached from its computer cannot be proven to be yours, so we cannot delete it on request. If we cannot confirm that an account is yours, we will tell you why, and you can give us further information that would let us confirm it.

Unused guest accounts: a guest account with no sign-in method that has not been used for 12 months is deleted automatically, in the same way. The game reminds guests to add a sign-in method so that this cannot happen to an account they still want.

What is erased: your account, sign-in methods, characters, progress, cards, items, friends, requests, blocks, invitations, Free Company membership, statistics choice, and the link between your account and any crash reports.

What remains, and why:

Deleting a single character in the game removes that character and everything that belonged only to it. It is not a request to delete your personal data.

9. Your rights

Under the GDPR you have the right to:

How to use these rights: most of them are in the game. You can delete your account from Settings (section 8), change your player name, and switch play statistics off.

A copy of your data: ask for one from Settings while signed in. We prepare a machine-readable file (JSON) holding what we store about your account, and you download it inside the game while signed in. If your account has an email address, we also email you when it is ready; that email contains none of your data and no link. The file stays available to download for a limited time and is then deleted, and you can ask for a new one later. If you want a copy of personal data that is not in the file, such as support email or reports, email us.

For any other request, or if you need help, email support@grimmarch.com. We confirm that a request comes from the holder of the account the same way as for deletion in section 8, and if we cannot confirm it, we will tell you and cannot act on the request.

We answer every request within one month. If a request is complex we may extend that by up to two more months, and we will tell you why within the first month.

10. Children

You must be at least 13 years old to play Grimmarch. We do not ask for your date of birth and do not store your age. Play statistics can only be switched on after you confirm you are 16 or older. We record that you confirmed, but not your age or date of birth. If you are under 18, you need your parent's or guardian's permission to play, as our terms say. Steam sets its own minimum age for a Steam account.

11. Security

The game and the website reach Cloudflare, which sits in front of our servers, over encrypted connections. Passwords are stored only as one-way hashes, using a method designed to make guessing them slow and expensive, and device keys and sign-in tokens only as hashes. Access to our servers is limited to the people who run Grimmarch. No system is perfectly secure; if a breach affects your personal data, we will tell the authority and, where the law requires it, you.

12. Changes to this policy

We publish every version of this policy with its version and the date it takes effect. The analytics consent version at the top moves only when what statistics collect, why, who receives them or how long they are kept changes, and only then do we ask for your consent again, as described in section 2.6. Other changes to this policy do not re-ask. We announce a material change in the game and on grimmarch.com at least 30 days before it takes effect.

13. Contact

support@grimmarch.com

Łukasz Ziaja, trading as AppsByLuke
al. Wiśniowa 36a/304, 53-137 Wrocław, Poland