Starforged Legacy — Gameplay Data Privacy Policy

SECOND SHIFT GAMES

Starforged Legacy — Gameplay Data Privacy Policy

Effective date: August 26, 2026
Policy version: 1

The short version

  • We collect gameplay data only if you opt in. Nothing is sent before you say yes, and you can turn it off at any time.

  • The data is tied to a random identifier created on your device — not to your name, Steam account, or hardware.

  • We use it for one purpose: balancing and improving the game. We do not sell it, do not use it for advertising, and do not try to identify you from it.

  • You can opt out, reset your identifier, or ask us to export or delete your data at any time. This policy explains exactly how, and is honest about the few things deletion cannot reach.

  1. Who we are and what this covers

Second Shift Games ("we", "us"), the developer of Starforged Legacy, is the data controller for the gameplay analytics described here. Contact: privacy@secondshiftgames.com.

This policy covers the optional gameplay analytics ("telemetry") built into Starforged Legacy, including its demo and Steam playtest builds. It does not cover Steam itself (Valve's privacy policy applies to your Steam account), or our store pages, websites, and community channels.

  1. What we collect — only with your consent

If you opt in, the game sends small, structured records ("events") about how the game is played. They describe things like:

  • Runs — when a run starts and ends, its outcome (victory, death, abandoned, restarted), difficulty, game mode, and score.

  • Maps — which maps and sectors you enter and leave, and when.

  • Ship and loadout — the ship, weapons, and augments you equip and how they change during a run.

  • Upgrade choices — what options the game offered and what you did (pick, reroll, banish, lock, skip).

  • In-game economy — in-game currency earned and spent (never real money; we receive no payment information).

  • Combat — weapon performance (damage dealt, kills), enemy kills, and your in-game deaths (in-game position and cause).

  • Progression — skill unlocks.

  • Session and technical — session start/end, game version, build environment (live / demo / playtest), timestamps, and telemetry-health records (for example, a count of events the game had to discard).

Each record carries a telemetry identifier: a random ID (a UUID) generated on your device when you opt in. It is not derived from your Steam account, your hardware, or anything about you. It also carries run and session IDs so we can reconstruct a single run.

What we deliberately do not collect: your name, Steam ID, or Steam display name in gameplay data; hardware or device identifiers; IP addresses in gameplay data (see section 5); anything you type; file paths; voice or chat. Every value the server stores is checked against a fixed catalog of allowed events and values before it is stored — free-form text cannot enter the dataset, even from a modified game client.

We treat the telemetry identifier and the gameplay records linked to it as pseudonymous personal data — not directly identifying, but not anonymous — and protect them accordingly.

  1. Consent — nothing is sent unless you opt in

  • On first launch you are asked whether to share gameplay data. Until you answer yes, nothing is collected, no network request is made, and no Steam authentication is requested. Declining is a complete answer — the game never sends telemetry silently.

  • You can change your answer at any time in Settings.

  • Opting out stops collection immediately, cancels in-flight uploads, deletes any queued or unsent gameplay data stored on your device, and deletes the telemetry identifier from your device. If you later opt back in, a brand-new identifier is created — the new data cannot be linked to the old.

  • Boundary of withdrawal: data our server had already accepted before you opted out remains stored under its normal retention (section 7). You can have it deleted on request (section 8).

  • If we materially change this policy, the game shows the notice again and asks for your consent before collection continues under the new version.

Builds we use internally for development record telemetry without a prompt; those builds are never distributed to players. Every build players receive — live, demo, or playtest — requires opt-in.

  1. Steam authentication — proving the data comes from a real copy

If (and only if) you have opted in, the game asks Steam for an authentication ticket at launch, and our server validates it with Valve to confirm the data comes from a genuine Steam user running the game. This exists to keep fake or flooded data out of the dataset.

  • Our server sees your Steam ID for a fraction of a second during this check. It is never stored, never logged, and never attached to gameplay data.

  • It is used only to derive a scrambled, per-day code that enforces daily fair-use limits per account. That code, and the random daily key used to make it, are deleted at the end of each day and cannot be recomputed afterwards.

  • Valve processes the authentication on its side under Steam's own privacy policy; we do not control what Steam retains about it.

  1. IP addresses and infrastructure logs

IP addresses are not stored in gameplay data. Like any online service, our infrastructure processes your IP address in transit, and our hosting provider keeps short-lived request logs that include your IP address — currently about 7 days — for security and abuse prevention. We do not use these logs to identify players, and we cannot delete individual entries; they expire on their own schedule. Our own application logs are sampled, contain only status codes and counts, and never contain your IP address or telemetry identifier.

  1. Who processes the data, and where

We use a small number of service providers ("processors") who handle the data only on our instructions, under data-processing agreements:

  • Cloudflare, Inc. — runs the relay server that authenticates, validates, and rate-limits gameplay data before storage, and holds short-lived processing state (delivery receipts and in-transit batches). Also provides the network edge, whose short-lived request logs are described in section 5.

  • Tinybird — the analytics database that stores gameplay records and computes the aggregate statistics we actually look at.

  • Valve Corporation (Steam) — the authentication check in section 4, on Valve's side.

  • Our email provider — export and deletion requests are handled by email (section 8). The email you send us contains your telemetry identifier, so the mail service processes and stores that message — and its own backups of it — until we complete your request and delete it; our long-term records keep only a scrambled reference and the encrypted register described in section 8.

We do not sell personal data, do not share it for advertising, and no provider receives it for its own purposes.

Where: gameplay data is stored in the United States (US East region). Where data about players in the EEA, UK, or Switzerland is transferred to the United States, it is protected by safeguards recognized under those laws: our providers' certification under the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions) where held, and the European Commission's Standard Contractual Clauses incorporated in their data-processing agreements otherwise.

  1. How long we keep it

  • Raw gameplay events: 180 days

  • Per-run summaries: 365 days

  • Daily aggregate statistics (no identifier; small groups suppressed): up to 3 years

  • Diagnostics for rejected or unrecognized events (scrambled names plus your identifier): 14 days

  • Invalid rows held by the database vendor ("quarantine"): about 1 month

  • Relay processing records (delivery receipts; batch contents deleted once delivered): up to 8 days

  • Daily per-account limit counters (scrambled daily code, no telemetry identifier): deleted at the end of each day

  • Hosting-provider request logs (including IP address, section 5): about 7 days

  • Provider disaster-recovery backups: Cloudflare up to 30 days; Tinybird up to 7 days. If a backup is ever restored, completed deletions are re-applied before the service resumes.

  • On your device, unsent gameplay data: up to 7 days (records of failed sends up to 30 days); all of it is removed if you opt out or reset your identifier.

  • On your device, settings (identifier, consent choice): until you opt out, reset the identifier, or uninstall.

Aggregate daily statistics contain no telemetry identifier, and any statistic that would cover fewer than 5 players is suppressed rather than shown.

  1. Your rights and choices

These choices are available to every player, wherever you live:

  • Opt out at any time in Settings. Collection stops immediately and the identifier is deleted from your device (section 3).

  • Reset your identifier in Settings. This resets the identifier used for future gameplay data. Data already collected is not deleted by a reset — if you may want that data deleted or exported later, note your identifier (shown in Settings) before resetting, because it is the only key to those records.

  • Export: request a copy of the raw gameplay records linked to your identifier by emailing privacy@secondshiftgames.com with the identifier (shown in Settings). We aim to deliver it within 30 days, by reply; our copy of the export file is deleted 14 days after delivery.

  • Deletion: request it at the same address. We delete the gameplay records linked to your identifier. Aggregated statistics that do not contain your telemetry identifier and are not used to identify you (for example, daily totals per weapon) are retained for up to three years. When we receive your request, the identifier is blocked immediately (any further data for it is refused), the records are deleted from every table — including the vendor's quarantine of invalid rows — and an automated daily sweep re-deletes anything that arrives late, for at least 31 days. We aim to complete deletion within 30 days.

You will need your telemetry identifier (shown in Settings) to make an export or deletion request. Because we hold no link between the identifier and your name, email, or Steam account, the identifier is the only way we can find your records — if it has been reset or deleted and you did not note it, we cannot locate the data (which also means it cannot be used to identify you).

Records we keep about a deletion request: a scrambled (hashed) accountability record of the request for 3 years, and an encrypted copy of the identifier kept until 30 days after the deletion completes — solely so we can re-run the deletion if a provider disaster-recovery restore were to bring deleted rows back — after which it is destroyed. Because requests arrive by email, we move the identifier from your email into that encrypted register on receipt and delete the email itself once your request is complete.

What deletion cannot reach — an honest note. A few vendor-managed operational records are outside our per-record control: the database vendor's job logs (the deletion command itself contains the identifier it deletes), its service request logs, the hosting provider's short-lived edge logs (section 5), Steam's side of the authentication check (section 4), and any backups our email provider keeps of your request email. These expire on the vendors' own schedules, and none of them is used to identify players.

If you are in the EEA, UK, or Switzerland: our legal basis for gameplay telemetry is your consent (which you may withdraw at any time, without affecting the lawfulness of earlier processing); for the authentication check, rate limiting, and short-lived security logs it is our legitimate interest in keeping the service and dataset trustworthy. You additionally have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.

If you are a California resident (or resident of a US state with a similar law): you have the right to know, access, and delete the personal information described here, and to non-discrimination for exercising those rights. We do not "sell" or "share" personal information as those terms are defined by the CCPA/CPRA, and we do not use it for targeted advertising or profiling that produces legal or similarly significant effects. Exercise these rights by emailing privacy@secondshiftgames.com.

We make no automated decisions about you: the data feeds aggregate game-balance analysis only — it is never used for per-player decisions, offers, matchmaking, pricing, or advertising.

  1. Security

Data is encrypted in transit (HTTPS/TLS). The analytics dashboard is private to the development team behind authenticated access. The server accepts only cataloged, validated data, enforces per-account daily limits, and uses encrypted session tokens; secrets are rotated on a schedule. Session credentials are held in memory only and expire daily. No system is perfectly secure, but the platform was designed so that the data it holds is of little use to anyone: it contains no names, no account identities, and no contact details.

  1. Children

Starforged Legacy is not directed at children under 13 (or the higher age your country sets for consent to data processing, e.g., under 16 in parts of the EEA), and we do not knowingly collect gameplay data from them. The data contains no age information. If you believe a child has opted in, contact us at privacy@secondshiftgames.com and we will delete the associated records.

  1. Changes to this policy

The version and effective date at the top identify the text you agreed to. If we make a material change, the game will show the updated notice and ask for your consent again before any further data is collected under the new version.

  1. Contact

Questions, requests, or complaints: privacy@secondshiftgames.com
Second Shift Games

Copyright © 2025 Second Shift Games

Copyright © 2025 Second Shift Games