Privacy Policy
1. Controller
NB 22 Games, owner Nico Bökenkröger, Iburger Straße 20, 49170 Hagen a.T.W., Germany
Email: nb@itnb.io
2. Data we process
- Account: player name, email address, chosen country, language, password (only as an Argon2id hash, never in plain text), two-factor login key, one-time recovery codes (only as hashes).
- Guest account (“Play now”): automatically assigned name (e.g. “Wanderer-1234A”), country estimated from the browser language, language, progress and a session cookie. No email address and no password. Guest accounts unused for 30 days are deleted automatically; you can end them yourself at any time under “Menu → Profile”.
- Progress: level, experience, ember cores, weapons, mounts, cosmetic items, play time, number of defeated enemies, progress on goals and daily tasks. To prevent cheating the game reports every defeated enemy (type, level, position) to the server.
- While playing: position and state of your character are sent in real time to players near you. Chat messages are distributed to all players; the server only keeps the last 20 messages in memory and does not store them permanently.
- Feedback: When you send feedback, a rating or a bug report, we store the text, the rating, your player name, level, zone, language, whether you play by touch and the browser identifier (user agent) to understand the issue. We delete feedback after 12 months at the latest.
- Game statistics: To improve the game we count anonymously per day, e.g. causes of death, tutorial completions, play-time ranges and completed goals – without reference to individual players. In addition we store for 90 days on which days an account was active (account ID and date) to determine the number of active players.
- Security log: logins, failed attempts and account deletions with a shortened IP address (last block removed), kept for 90 days.
- Server logs: technically necessary logs of the game server (including IP address, time, requested address) for troubleshooting and defence against attacks. They are kept only up to a limited size and continuously overwritten.
3. Purposes and legal bases
Providing the game and your account (Art. 6(1)(b) GDPR), protection against abuse and attacks and improving the game based on anonymous statistics and your feedback (Art. 6(1)(f) GDPR, legitimate interest in a secure and good game).
4. Cookies and local storage
We only use one technically necessary session cookie (“emb_sid”) to keep you signed in, plus local settings (graphics, sound, language) in your browser storage. There are no ads, no analytics tools and no trackers. Fonts and libraries are loaded from our own server.
5. Hosting
The game runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. A data processing agreement under Art. 28 GDPR is in place.
6. Payments via Paddle
When you buy a cloak you are taken to Paddle’s checkout (Paddle.com Market Ltd., Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom). Paddle is the Merchant of Record and processes your payment and billing data (e.g. email address, country, payment method) as an independent controller under its privacy notice. We pass your account ID and, to pre-fill the form, your account email address to Paddle. From Paddle we receive the order number, purchased items, amount and currency to link the purchase to your account (Art. 6(1)(b) GDPR). We keep these purchase records for up to 10 years due to statutory retention obligations. On the checkout page your browser loads scripts from Paddle (cdn.paddle.com, buy.paddle.com), which transmits your IP address to Paddle. Transfers to the United Kingdom are based on the EU Commission’s adequacy decision.
7. Retention
We keep your account and progress until you delete your account. Expired sessions and incomplete sign-ups are removed automatically. Backups are overwritten after 14 days. Purchase records: see section 6.
8. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. You can permanently delete your account yourself at any time under “Menu → Profile → Delete account”. You may also lodge a complaint with a data protection supervisory authority.
9. Minimum age
Registration is possible from the age of 16.
Last updated: September 2026 · Deutsche Fassung