Legal

SHARDFALL privacy policy

This policy applies to the app SHARDFALL and its online services. A separate privacy policy applies to the website.

Last updated: 8 October 2026

This English version is provided for convenience. The German version is legally binding; mandatory consumer rights under the law of your country of residence remain unaffected.

Table of contents
  1. Controller
  2. Your rights
  3. Right to lodge a complaint
  4. SHARDFALL (app and online services)
  5. Controller
  6. Which data is processed?
  7. No advertising, no tracking
  8. Legal basis & purpose
  9. Retention period
  10. Disclosure to third parties
  11. Rights of users
  12. Data security
  13. Children
  14. Changes to this policy
  15. Contact

Controller

The controller for data processing on this website and for SHARDFALL is:

Peppox Entertainment, owner Michael Burgemeister
Am Becherweg 6, 55270 Ober-Olm, Germany
E-mail: kontakt@peppox.de

We have not appointed a data protection officer, as this is not legally required. For questions about data protection, you can reach us at the e-mail address above.

Your rights

You have the following rights against us: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21) to processing based on a legitimate interest. You can withdraw any consent you have given at any time with effect for the future. Please contact kontakt@peppox.de for this.

Right to object: Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), for example with the contact form, you may object at any time on grounds relating to your particular situation.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz), Hintere Bleiche 34, 55116 Mainz, Germany, datenschutz.rlp.de.

SHARDFALL (app and online services)

This policy describes which data SHARDFALL (Android, iOS, macOS, Windows) and the associated online services process. SHARDFALL contains no advertising and no third-party tracking (no advertising SDK, no analytics SDK, no reading of the advertising ID).

1. Controller

Peppox Entertainment, owner Michael Burgemeister. Address and contact details: see “Controller” above and the legal notice; e-mail: kontakt@peppox.de. General information on your rights and on the right to lodge a complaint can also be found above under “Your rights”.

2. Which data is processed?

2.1 Guest account (automatic, no registration)

On first launch, the app locally generates a random guest account ID (unrelated to the name, e-mail address or advertising ID of any store provider). In addition, the server stores a random device identifier generated by the app so that the same guest account is found again on the same device instead of a new one being created at every start. This ID is stored on the device together with your progress (campaign, achievements, settings) (localStorage/Capacitor Preferences) and – only if online mode is used – transmitted to the SHARDFALL server so that leaderboards, matchmaking and profile work across devices. The server account is only created when online mode is opened for the first time. Guest accounts that have not been used for 30 days and have never played an online match are deleted automatically by the server (provided that no subscription, friends, clan or open report is attached to them).

2.2 Optional username

Players can voluntarily choose a display name of their own. It is visible to other players in the lobby, leaderboards and replays. If none is given, a generic placeholder name is used.

2.2a Registered account

Friends, groups, chat, clans, leagues and the subscription require a registered account. To register, the user chooses a name and a password. The name, password hash, time of registration and the linked account ID are stored. No e-mail address is requested.

2.3 Game and match data

In online games (leaderboard search, quick play, friendly match of the group), the server processes: timestamps, game result, Glicko-2 rating, the game commands sent (for the netcode, in which all participants execute the same commands, and for the server-side fair-play checks of the result) and, optionally, a stored replay. This data is required to provide leaderboards/matchmaking and is not used for advertising purposes or sold.

2.3a Activity values for fair-play checks

For rated online matches, the server stores a few figures per player about their own play activity: commands per minute, credits harvested, value of the army built, time to the first factory, game duration and whether the match was flagged as suspicious. They serve solely to detect pre-arranged or “gifted” wins (a player who suddenly does much less than in their own recent matches is compared with themselves, not with others) and to keep achievements and the leaderboard fair (legitimate interest, Art. 6(1)(f) GDPR). Per account, only the last 50 matches are retained; older values are deleted automatically; they are also deleted together with the account. Entries on the review list (e.g. “suspicious match”) are retained for moderation decisions until the account is deleted and are viewed by the operator only.

2.3b Friends, online status, groups and chat (registered accounts only)

These functions are only available with a registered account (name + password); guests can only send the fixed quick messages in a match. - Friends, requests, blocked, muted, friend code: are stored in the database (account IDs of the players involved and timestamps) for as long as the relationship exists. Open friend requests expire after 30 days. When an account is deleted, all of its friendships, blocks and reports are deleted too. Anyone who blocks a player becomes invisible to the blocked player (no status, no messages, no invitations). - Online status (online, in group, searching, in game, since when): only in the server memory (RAM) and only visible to friends; discarded immediately on disconnect. Not stored. - Groups and invitations (up to 4 players, invitation valid for 60 s): only in server memory (RAM); not stored. - Chat messages (group, direct, in match): are not stored in the database. For each channel, the server keeps the last 99 messages in server memory (RAM) so that fellow players can see the history and unread direct messages of an offline friend can be delivered; after a server restart everything is gone. Messages are filtered before being sent (permitted characters, no links/e-mail addresses/phone numbers, profanity filter; the player can switch off the profanity filter). - Reports (“Report”): If a player reports a message or a player, the server stores a snapshot: the reported message, the 10 messages before it in the same channel, reporter, reported player, reason and time. Purpose: abuse moderation (Art. 6(1)(f) GDPR, obligations of the app stores and the Digital Services Act). Reports are viewed only by the operator – every viewing of a snapshot in the operator tool is recorded with user and time in the operator log – and are deleted automatically after 30 days. Three reports from different players within 24 h mute the reported player’s chat for 24 h pending review; moderation decisions (muting, ban, name reset) are recorded in the operator log. - Name change: The time of the last change and the previous name (locked for 30 days, to prevent name swapping/identity confusion) are stored.

2.3c Subscription “Kommandant Online” and daily limit (registered accounts only at purchase)

  • Purchase data: Anyone who takes out the subscription pays via Google Play, Apple or (web/desktop) Paddle as seller (merchant of record). We never see payment data (card, PayPal, address). For each subscription, the server stores only: account ID, source (Google/Apple/Paddle/unlock), status, expiry date, renewal yes/no, test purchase yes/no and the technical identifier of the purchase (purchase token, transaction ID or subscription ID, Paddle customer ID for the customer portal). For this purpose, it queries the providers’ interfaces and receives their notifications. Purpose: performance of the contract (Art. 6(1)(b) GDPR).
  • Daily counter: per account and calendar day (Europe/Berlin), the number of counted online games, for each match the origin of the game (daily allowance, gift, bonus) and whether it was refunded; also gift actions and personal bonus games with a note by the operator. Purpose: to enforce the daily limit (legitimate interest).
  • Subscription badge: An active subscription appears as a small badge on the profile and in leaderboards (visible to other players); whether and how it was paid for is visible to no one except the operator.
  • Console: Unlocks and gifts by the operator are recorded with time and processor in the admin log.

2.3d Clans (registered accounts only)

  • Clan membership is public: Who is in which clan is visible to all players – on the profile and in leaderboards as [TAG] before the name, on the public clan page as a member list with role (leader/officer/member), rating, rank and achievement points. Anyone who does not want this should not join a clan (leaving is possible at any time; afterwards a 3-day switch lock applies, which prevents clans from being circumvented in leaderboards and leagues by constant switching).
  • Stored (database, for as long as the membership lasts): clan (name, tag, emblem, description, join type, time of founding, leader), membership (account ID, role, time of joining), open join requests (14 days) and invitations (7 days), the time of the last leaving/kick (switch lock) and the clan rating and ranking calculated by the server. On leaving, the membership is deleted; an empty clan is deleted; when an account is deleted, membership, requests and invitations are deleted too.
  • Visible to members only: online status (in server memory (RAM), as with friends), the time of the last visit and the clan chat. Like any chat, the clan chat is not stored (only the last 99 messages in server memory (RAM), gone on server restart); reports from the clan chat as in §2.3b.
  • If the server automatically takes over the leader role from a leader who has been inactive for 30 days, this is recorded with clan, names and time in the operator log. Moderation actions by the operator (renaming a clan, removing a member, disbanding) are also recorded there.
  • The description and name of a clan are filtered like chat texts (no links/contact details, profanity filter).

2.3e Leagues and events (registered accounts only)

  • Participation is voluntary (registration by the player; clan league by leader/officer, duo with the partner’s consent) and publicly visible: Who plays in which league group, the group table (name, clan tag, games, wins, losses, points, rank) and the league titles (group win with cycle, tier, rank) are visible to all players – in the league, on the profile and on the clan page.
  • Stored (database): registrations (account ID, duo pair or clan, time, who registered), the drawn group including the frozen clan roster (account IDs of the members at the start), for each league match the participants involved, winner, points, duration, time, Berlin day and whether it counted, for each player side/win/points, the table cache and, for each cycle, the final rank of each participant (history, promotion/relegation). Duo invitations and challenges exist only in server memory (RAM) (10 min and 2 min respectively). A clan frame on the emblem (winner of the top clan group) is stored on the clan.
  • Purpose: league rating, daily and pair limits (against point farming and collusion), evaluation, rewards (titles, emblem frames, achievement). The operator can disqualify participants in the event of a violation (entry in the operator log).

2.4 Technical connection data

As with any network connection, the server processes technically necessary connection information (e.g. IP address during the active connection, to provide the service and to prevent abuse). The IP address is used only in server memory (RAM) for abuse protection (e.g. limiting new guest accounts and requests per address) and is discarded at the latest when the server restarts. The IP address is not stored in the database. Server error logs may contain an IP address and are rotated and overwritten automatically.

2.4a Statistics on active days

For each account and calendar day on which the account was active, the server stores the account ID and the date, in order to determine the number of daily and monthly active players for operations. These entries are deleted automatically after 400 days.

2.5 Local data (offline)

Campaign progress, achievements, settings, replays and saved games are stored primarily locally on the device. In offline mode/skirmish against the AI, none of this data leaves the device.

3. No advertising, no tracking

  • No advertising network; no advertising ID (IDFA/AAID) is read.
  • No third-party analytics/tracking SDK.
  • Storing the guest ID and settings on your device is strictly necessary for the service you requested (Section 25(2) no. 2 TDDDG); no consent is required for it.
  • No disclosure of data to third parties for marketing purposes.
  • The optional subscription (§2.3c) does not change any game values; purchase data serves only to process the purchase, never for advertising.

We process the guest ID, device identifier (§2.1), name, account, match data, leaderboards, friends, groups, chat, clans and leagues to perform the contract of use for online mode (Art. 6(1)(b) GDPR). Fair-play checks, abuse protection (limiting new guest accounts per IP address), the daily limit, the reporting procedure and moderation, as well as the statistics on active days (§2.4a), are based on our legitimate interest in a functioning, fair and secure game operation (Art. 6(1)(f) GDPR). Where we keep and process reports in the context of the Digital Services Act, this is done to comply with a legal obligation (Art. 6(1)(c) GDPR).

Providing the data is neither required by law nor by contract. Without an account or name, however, you cannot use online mode; the campaign and skirmishes against the AI work without any data transmission.

Right to object: Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR). Please write to kontakt@peppox.de.

5. Retention period

  • Local data: until the app is uninstalled or reset manually in the settings.
  • Server-side account/leaderboard data: until deletion by the player in the app or on request (see §7), or after 24 months of inactivity.
  • Activity values for fair-play checks (§2.3a): the last 50 rated matches per account.
  • Friends/blocked/muted (§2.3b): until removal or account deletion; open friend requests 30 days.
  • Chat histories and online status (§2.3b): server memory (RAM) only, at most the last 99 messages per channel, gone on server restart.
  • Reports with snapshot (§2.3b): 30 days, then deleted automatically.
  • Clans (§2.3d): membership until leaving/kick or account deletion; requests 14 days, invitations 7 days; time of leaving for the switch lock until account deletion.
  • Leagues (§2.3e): match rows and player assignments 60 days after the end of the cycle (deleted automatically); final ranks/titles (history), registrations and groups until the account or clan is deleted; invitations/challenges server memory (RAM) only.
  • Subscription data (§2.3c): for as long as the account exists (proof of the contract; tax-law retention lies with the payment provider as seller). Daily counter 3 days, assignment of games to the match 7 days, providers’ notification IDs 30 days.
  • Match results and command logs (replays, §2.3): for as long as they are needed for ratings, replays and fair-play checks; the link to a deleted account is removed.
  • Statistics on active days (§2.4a): 400 days.
  • Operator log admin_log (moderation/console commands, deletion records, viewing of chats): currently no automatic deletion (audit trail and proof of account deletions; entries contain names/IDs, never chat texts); the operator sets the retention period and enters it here.
  • Database backups: 14 days, then overwritten.

6. Disclosure to third parties

No data is disclosed to advertising or analytics service providers. - Hosting: The server runs at netcup GmbH, Karlsruhe, in a data centre in Nuremberg (data processing under Art. 28 GDPR). - Google Cloud: For notifications about the Google Play subscription we use Google Cloud (Pub/Sub) as a processor; purchase identifiers and subscription status are transmitted, no payment data. - Subscription page on the web: On the page play.peppox.de/abo your browser loads the Paddle payment window; your IP address is transmitted to Paddle. Paddle is the controller for this. We do not use any tracking there. - Subscription: For the subscription, the server exchanges purchase identifiers with Google Play (Google), the App Store (Apple) and – on web/desktop – Paddle (Paddle.com Market Limited, United Kingdom, as seller) (§2.3c). These providers process your payment data as independent controllers in accordance with their privacy policies; an adequacy decision of the EU Commission exists for the United Kingdom. - Third-country transfers: Purchase identifiers go to Google and Apple (USA; basis is their certification under the EU-US Data Privacy Framework or standard contractual clauses) and to Paddle (United Kingdom; adequacy decision of the EU Commission). - Stores: When the app is downloaded and updated, Google, Apple or Microsoft process data as independent controllers in accordance with their privacy policies; we have no influence over this. - Beyond this, we disclose data only where we are legally obliged to do so.

7. Rights of users

You have the rights of access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR; see “Your rights” above).

7.1 Deleting your account yourself (in the app)

Every online account – guest or registered – can be deleted in the app (Settings; registered accounts confirm with their password). Deletion is immediate and final; there is no cooling-off period and no restoration. Users without app access (e.g. forgotten password) can use the deletion form with their player name and friend code (instructions: Delete account and data); to protect against abuse we verify entitlement and may ask follow-up questions. The operator then deletes the account in the control centre/console in the same way (deadline: one month, Art. 12(3) GDPR; usually immediately). A suspension imposed by the operator does not survive deletion; it only applies to the account, which no longer exists.

What is deleted: the account (name, password hash, device identifier of the guest ID), 1v1 and 2v2 ratings, wins/losses, achievements and points, ranks, activity values (§2.3a), review-list entries about the account, friends, requests, blocked and muted (§2.3b), reports about and by the account including snapshots (in reports by other players that contain chat lines of the account, the sender becomes “(deleted)” without ID and the text “[deleted]”), clan membership including requests and invitations (if the account was leader, a member takes over; a clan without members is deleted), league registrations and league rosters (§2.3e), subscription unlocks, bonus games and daily counters (§2.3c), entries of the daily activity count (operating statistics). The name is free again immediately. Chat messages of the account still in memory and its direct-message channels are discarded.

What remains anonymised: finished matches remain for the opponents’ game histories – the player appears there as “(deleted)”, without account ID and without name (also not in the stored game set-up). League tables and final ranks of earlier cycles keep their figures, the name is replaced by “(deleted)” and the account ID in the league tables (participant key, member lists, match rows, table cache) is replaced by a random identifier (deleted:<random>) that is stored nowhere else (pseudonymisation: the rows can no longer be attributed to a person); a group table in the running cycle is recalculated without the participant.

What remains: (1) payment events of the providers (type, time, event ID) for bookkeeping, without a link to the account (statutory retention lies with the payment provider or store); (2) one entry in the operator log (admin_log: account ID, name, whether guest, “self” or “operator”, time) as proof of deletion – it contains no further personal data; earlier moderation entries about the account in the operator log (e.g. player ban <name>, muting, name reset) remain with the name stated at the time as the operator’s audit trail (legitimate interest: traceability of moderation decisions; they contain no chat texts; retention §5), but are not changed on deletion; viewing chats in the control centre appears there only with account ID and number; (3) database backups until their automatic rotation (14 days). After a restore from a backup, deletions are applied again.

Subscription: Deletion does not cancel a subscription at the store. The user must cancel a running subscription (Google Play, Apple, Paddle) there; the app points this out before deletion. After deletion the server holds no subscription data with a personal reference.

7.2 Operator access to chats (moderation)

Chat is not stored (§2.3b). For moderation the operator can view in the control centre (admin role only, with login and second factor) what is currently in the memory of the game server (the last up to 99 messages per channel, original text, at most 200 messages per account) and the snapshots of reported messages (30 days, §2.3b). **Every such access is recorded in the operator log (admin_log) with user, account ID, number of messages and time**; the text itself is not stored there and the control centre stores no chat content.

7.3 Further rights

Access, rectification, restriction and objection (Art. 15–21 GDPR) can be asserted through the support form; complaints to the competent supervisory authority remain unaffected. Local data can be removed at any time by yourself via “Settings → Reset data” or by uninstalling the app (uninstalling does not delete the server account – see §7.1).

No decision based solely on automated processing with legal effect takes place. The server flags irregularities in online games (fair-play checks) and temporarily mutes a player’s chat after several reports; a human operator decides on suspensions of an account.

8. Data security

All online connections (matchmaking, groups, lockstep relay) run encrypted via TLS (https/wss). An account can optionally be registered with a name and password; passwords are stored only as a salted scrypt hash, login tokens are HMAC-signed and valid for 90 days.

9. Children

SHARDFALL is not specifically aimed at children under 13 years of age. Online mode is intended for persons aged 16 and over; persons aged 13 to 15 may use it only with the consent of their legal guardians. No child-specific categories of data are knowingly collected.

10. Changes to this policy

This policy is updated in the event of functional changes (e.g. the introduction of new online features); the date at the top of the document shows the status of the last change.

11. Contact

Questions about data protection should be sent to kontakt@peppox.de or via the support page.

↑ Back to top