Legal
Privacy policy
Last updated . Also see the terms of service.
The short version
- Your Discord account is your RPG Thunder account. We keep your Discord user id, your Discord display name and your game progress.
- We never read your Discord messages. We don't collect your email address or payment details.
- Some things are public by design: obituaries, leaderboards, wiki credits and the posts the bot makes in servers show your character's name, and sometimes your Discord display name.
- Direct messages from the bot are off until you turn them on. The website and wiki use Google Analytics.
- We don't sell your data. To get a copy of it or have it deleted, contact us through the RPG Thunder Discord community.
Who we are
RPG Thunder is a free roguelike RPG you play in Discord, as a bot and as a Discord Activity, and in a web browser at play.rpgthunder.com. It is in beta. This policy covers the game, this website and the wiki at wiki.rpgthunder.com.
In this policy, "RPG Thunder", "we", "us" and "our" mean the people who make and run the game.
What we collect
From your Discord account
- Your Discord user id. It is your account id everywhere you play: in Discord servers, in DMs and in the browser.
- Your Discord display name (or your username, if you have no display name), as it was when you started playing. We store it with your account.
- Your avatar is passed to the game client when you log in, so it can show your picture. We don't store it.
- Purchases through Discord. If you buy a cosmetic in Discord's store, Discord tells us which item you own (an "entitlement"), so we can unlock it.
When you play
- Your game data: your characters and their names, class, level, stats, gold, inventory, gear, progress through the cities, achievements, cosmetics, earned currencies (Sparks and Stormglass) and the history of your past lives.
- Battles and runs, stored as their starting state and the moves you made, so a fight can be rebuilt exactly.
- Dealings with other players: market listings, purchases, trades, parties and respects paid to fallen heroes.
- Your settings: which DM notifications you turned on, your story setting and whether your name appears in wiki credits.
- The server you first played in (its Discord id), which decides where your obituaries and world boss notices go.
- Game events (telemetry): things like "started a battle", "died to this enemy in this city", "reached level 10" or "used this button", with your user id, the server id and the time. They hold ids and numbers, never message text.
From Discord servers
When a server manager sets the bot up, we store for that server:
- its Discord server id, and its name, which we fetch when
/setupruns; - the channels picked for the graveyard, game posts (
/setup) and changelog posts (/changelog channel); - whether the server publishes its chronicle on the wiki;
- for parties, the channel, the party thread and the party message, so the bot can update them.
Technical data
- Server logs. Our game server logs each request's method, address, host and the connecting IP address (usually one of Cloudflare's or Discord's proxies rather than yours). Slow actions and errors are logged with your user id so we can find the cause.
- Rate limits. To stop abuse, the server counts requests per IP address and per Discord user. These counts live in memory and are gone within minutes, or when the server restarts.
- Login tokens. When you log in, Discord gives the game an access token. The server checks it with Discord and holds it in memory for a few minutes. We don't store it in our database.
- Hosting logs. Cloudflare, which serves this website, the wiki and the game server's traffic, keeps its own request logs.
On this website and the wiki
We use Google Analytics to count visits. It records the pages you view (including wiki searches, which are part of the page address), how you arrived, your device and browser, and your approximate location. See cookies and local storage.
What we don't collect
- Your messages. The bot works only through slash commands, buttons and forms that you send it. It never asks Discord for the messages people write, and never reads them.
- Your email address. We don't ask Discord for it.
- Payment details. Any purchase happens in Discord's store, so Discord handles the payment and we never see your card or billing details.
- Your server's member list. The bot doesn't ask Discord for it.
Discord permissions and scopes
When a server adds the bot
The install link asks for the bot and applications.commands scopes and these permissions:
- View Channel: see the channels it posts in.
- Send Messages, Embed Links and Attach Files: post obituaries, game moments and changelog entries, with their image cards.
- Read Message History: work with the bot's own earlier posts, such as updating an obituary. It isn't used to read what members write.
- Create Public Threads and Send Messages in Threads: run a party in its own thread.
- Create Events: add a Discord scheduled event when a party leader books a party night.
You can also add RPG Thunder to your own Discord account and use it in DMs. When you do, Discord sends us your commands and button presses, as it does in servers.
When you log in
identify: your Discord user id, username, display name and avatar. This is the only scope you need to play. The Discord Activity asks for it alone when it starts.rpc.activities.write: shows what you are doing in the game (for example "In Birchfall") on your Discord status. It is off until you turn it on in the Activity's settings.application_identities.write: lets us show game stats on your Discord profile: your Discord username, your character's name and class, level, deaths, deepest city and legacy level. In the Activity it is off until you turn it on in settings. The browser login asks for it together withidentify. Nothing is sent to your profile unless the profile stats feature is switched on for the game, and at the time of writing it is switched off.
You can remove the game's access at any time in Discord, under User Settings, Authorized Apps. Stats already on your profile stay there until you do.
How we use it
- To run the game: your account, characters, battles, parties and trades.
- To show your play to others: leaderboards, obituaries, the wiki and posts in servers (see what other people can see).
- To send the DMs you asked for. The bot can tell you when your stamina or rested XP is full, when a new world boss appears in your home server, when your party is waiting on you, or when an egg is ready to hatch. Every type is off until you turn it on with
/settings notificationsor in the game's settings, and each DM can turn itself off. If Discord refuses a DM (for example, you blocked DMs), we turn them all off. - To keep the game fair and safe: rate limits, spotting automated play and investigating cheating or abuse.
- To improve the game: telemetry and analytics tell us where players get stuck, which fights are too hard and whether a change helped. We look at totals and trends, not at individual players, unless we are investigating a bug or abuse.
Where the law asks for a legal basis (as the GDPR does), we rely on running the game you asked to play, on our legitimate interest in keeping it working, fair and safe and in improving it, and on your consent for the extras you turn on.
What other people can see
RPG Thunder is a social game, and some of what you do is public on purpose:
- Obituaries and legends. When a character dies or retires, the game records their name, class, level, city, day, cause of death and epitaph. It posts them in the server's graveyard channel and lists them on the wiki.
- Game posts in servers: boss kills, unlocks, level milestones, rare loot, achievements, creature hatches and daily gauntlet winners, under your character's name.
- Leaderboards and gauntlet boards, in the game and on the wiki, by character name.
- Wiki credits. The first player to find something is credited on its wiki page with their character's name and Discord display name.
/settings wiki_credithides your credits (they read "an adventurer") and your family history page. - Parties. A party's thread is public in its server and is named after the leader's Discord display name. Invites mention the invited player. Party night events list the members' character names.
- Profiles, the market and trades. Other players can open your profile with
/profile, and see you on your market listings and trades. - Server chronicles. If a server turns its chronicle on, the wiki shows the server's name, its top players by name and who found things first there.
Characters created before heirs existed use your Discord display name as the character's name. Public pages and image links show names, not your Discord user id.
Who we share it with
We don't sell your personal information and we don't show ads. These services process data for us to run the game:
- Discord, where the game lives. Everything the bot posts or sends goes through Discord, and Discord handles any purchases. Its own privacy policy covers what Discord does with your data.
- DigitalOcean hosts the game server and its database, in the United States.
- Cloudflare runs our domain and proxies traffic to the game server, hosts this website and the wiki, and runs an uptime check.
- Google provides Google Analytics on this website and the wiki.
We don't use an email service, an ad network, an outside error tracker or a payment processor of our own. Error reports go to a private channel on Discord that only we can see.
We may also share information when the law requires it, to protect players or the game from harm, or with whoever takes over the game if it changes hands, under this policy.
Where your data is stored
Our game server and database are in the United States. Discord, Cloudflare and Google process data in many countries. If you play from outside the United States, your data is transferred to and stored in the United States.
How long we keep it
- Your account and game data stay while your account exists. We don't delete inactive accounts automatically. During the beta, progress may be reset (see the terms).
- Obituaries and legends are part of your account's history and stay with it.
- Telemetry events have no automatic deletion yet. We delete yours along with your account when you ask.
- Server logs are kept by our hosting providers for their standard log periods. We don't keep a separate archive.
- Rate-limit counts and login tokens are held in memory for minutes.
- Server settings stay until a server manager changes them.
Your choices and rights
- DMs: turn each type on or off with
/settings notificationsor in the game's settings. - Wiki credits: hide them with
/settings wiki_credit. - Discord extras: the status and profile stats in the Activity are off until you turn them on. Remove the game's access in Discord under Authorized Apps.
- Analytics: block cookies for this site in your browser, or use Google's opt-out add-on.
There is no delete button in the game yet. To ask for a copy of your data, a correction or deletion, contact us through the RPG Thunder Discord community. We may ask you to confirm the request from your Discord account, so we know it's you. We answer within 30 days.
When we delete an account:
- We delete your account, characters, progress, settings and telemetry, and with them your obituaries, legends and family history on the wiki.
- We remove your names from wiki credits and server firsts.
- Posts the bot already made in Discord servers stay, because they belong to those servers. Their moderators can delete them.
Depending on where you live (for example the European Union, the United Kingdom or California), the law may give you more rights over your data: to access it, correct it, delete it, take a copy with you, object to or restrict how we use it, and complain to your data protection authority. We handle these requests the same way for every player, wherever they live.
Security
What we do to protect the game and your data:
- All traffic uses HTTPS.
- The game server accepts traffic only through Cloudflare, and checks Discord's signature on every command and button press.
- Logins are checked with Discord, and login tokens are never saved in our database. Logging out of the browser version revokes your token at Discord.
- Public image links carry an encrypted token instead of your Discord user id.
- Secrets such as the bot token are stored encrypted by our host, never in our code.
- Rate limits slow down anyone hammering the game.
No system is perfectly secure. If a breach affects your data, we will tell you as the law requires.
Children
RPG Thunder is not directed at children under 13, and you must meet Discord's minimum age to use it (13 in most countries, older in some). We don't knowingly collect data from children under 13. If you think a child under 13 is playing, contact us through the RPG Thunder Discord community and we will delete the account.
Cookies and local storage
- This website and the wiki set Google Analytics cookies (named
_gaand_ga_followed by an id). They let Google count visits and tell new visitors from returning ones. We set no other cookies. - The game (in Discord and at play.rpgthunder.com) sets no cookies and loads no analytics. It keeps your motion, sound and Discord-extras settings in your browser's local storage, on your device only.
- In the browser version, your login token and a one-time login check are kept in session storage, which clears when you close the tab. The browser version also saves the game's files and recent screens on your device, so it opens faster and works briefly offline. Logging out clears the saved screens.
Changes to this policy
We will update this policy when the game changes what it collects or how it uses it, and change the date at the top. For a big change, we will also announce it in the game's changelog. If you keep playing after a change, the new policy applies.
Contact
For anything about your data or this policy, contact us through the RPG Thunder Discord community.