Ravelin

Privacy Policy

Effective 19 September 2026

Who we are

Ravelin is a tower-defense game operated by the operator of playravelin.com. This policy describes what we collect, why, and your choices. It is not legal advice, and it does not stop anyone from suing anyone — it tells you how this keep actually handles data.

Questions or requests: privacy@playravelin.com.

What we collect

Account: email, display name, and a sign-in method (Google, X, or email and password). We do not receive your Google or X password. Apple Sign In is not offered.

Keep data: commander rank, field XP, map records, settings, friend handles, and Warden marks (when a hold looks impossible).

Purchases: Stripe processes cards. We store checkout session ids, Aether balances, Keepers Pass expiry, and claimed payment ids. We never see full card numbers.

Yards (optional): a short-lived signaling record so WebRTC can connect you to keepers you chose. Peers in a yard can see your network address as part of a direct connection. That is how peer-to-peer works; we do not sell it.

Device: game progress may sit in this browser (local storage) so a guest hold survives a refresh. Session cookies keep you signed in.

We do not run advertising pixels or sell lists of commanders.

Why we use it

To run the game: sign-in, cloud save, friends, yards, and the armory.

To take payment and grant what you bought — only after Stripe marks the session paid.

To keep the yard honest: Warden flags impossible gold, skipped waves, and cooked reports. Those marks can show as “Warden watch” to keepers you added.

To secure the keep: rate-limit friend invites, session cookies, and fraud checks on checkouts.

Legal bases (EEA/UK): contract (play and purchases), legitimate interests (security, Warden, abuse), and consent where a law requires it for a non-essential cookie. We currently only set strictly necessary cookies.

Cookies and similar tech

A session cookie (and, in some embeds, a token) keeps you signed in. That is strictly necessary. See the Cookie Policy.

Local storage holds guest progress, mute, and that you acknowledged this notice. That is not a third-party ad cookie.

Sign-in with Google or X, and Stripe Checkout, are their services with their own cookies on their domains.

Who else sees it

Stripe — payments and subscriptions.

Google or X — only if you choose that sign-in.

Infrastructure that hosts this app and its database.

Friends you add — they see handle, rank, map records, and whether Keepers Pass is active. They do not see your email or Aether balance.

Yard peers — game state you send, and typical WebRTC connection data.

We do not sell personal information as that term is used in the CCPA/CPRA. We do not share it for cross-context behavioral advertising.

Children

Ravelin is not directed at children under 13. Do not create an account if you are under 13. Purchases are for users 18 or older, or with a parent or guardian who pays.

If you believe a child under 13 gave us an account, write to us and we will delete the keep data we hold.

How long we keep it

Account and keep data last until you delete the keep or we close the service.

Claimed Stripe session ids stay long enough to stop double-grants.

Yard signaling is short-lived.

Backups, logs, and legal holds may last longer when the law requires.

Your rights

You may access, correct, or delete keep data. In Yards, use Delete keep — that erases handle, save, friends, and Warden marks on this game. It does not erase Stripe’s payment record or Google/X accounts.

EEA/UK: you may object, restrict, port, and complain to a supervisory authority.

California: you may request know/delete/correct. We do not sell or share personal information for ads. We will not discriminate for exercising rights.

Email requests to privacy@playravelin.com. We may need to verify it is your account.

International transfers

Providers (including Stripe, Google, and X) may process data in the United States and other countries. Those laws may differ from yours. We use them because the game cannot run without sign-in and payment rails.

Security

We use hashed passwords for email accounts, signed sessions, and server-side entitlements so a browser cannot mint Keepers Pass. No method is perfect. Do not share your password. Guest gold in one browser is not an account entitlement.

Changes

We will post updates here with a new date. Continued play after a change is acceptance of the revised policy where the law allows.