Legal Information

Privacy Policy

This policy explains how personal data is handled across The City of Gold website, accounts, community features, and game services.

Effective and last updated: 24 August 2026

1. Controller and scope

The controller is Mirco Cantelmo, operating The City of Gold under the public developer and publisher brand IAMDEXTER, Switzerland. Privacy questions and requests may be sent to support@thecityofgold.net.

This policy applies to thecityofgold.net, the project's account and community services, the launcher and game authentication services, and gameplay data connected to a City of Gold account. Third-party sites reached through links have their own privacy practices.

2. Personal data we process

Account and authentication data

Registration requires a public Community Identity, an email address, and a password. Passwords are stored only as one-way password hashes. We also process email-verification, password-reset and email-change records; hashed session and recovery tokens; session expiry and revocation state; optional device labels; login and security-event timestamps; hashed user-agent values; hashed network-address prefixes; and request identifiers.

Profile, character, and gameplay data

An account may be associated with profile details such as an avatar, biography, roles, badges, relationships and blocks. Character and game records can include character identity and appearance, attributes, skills, vitals, survival state, inventory, equipment, action-bar assignments, gameplay sessions, current or last persisted world and position, progression, and player-created world relationships. Those relationships can include Houses and heraldry, family and marriage records, citizenship, institutions, religions, territorial or governance roles, and related histories.

Some identity, character, House, organisation, world-history, forum, and governance information is intentionally public as part of the persistent-world and community experience. Private login credentials, email addresses, session tokens, and private communications are not intended for public display.

Community and communications data

Forum and social features process content and activity such as threads, posts, edits, reactions, follows, polls and votes, reports, moderation actions, notifications, friendships and blocks. Golden Messenger processes conversations, membership, messages, replies, reactions, pins, read and delivery state, and media or voice-message metadata. Uploaded avatars, heraldry, community media, attachments, and voice messages may include file metadata, content hashes, moderation or malware-scan status, and licence acceptance records where the upload flow requires them.

Forms and direct contact

Support submissions contain the name and Community Handle supplied by the sender, subject, message, and submission time. Project applications additionally request a Discord username, intended role or subject, and may include up to three submitted attachments. Application attachments are scanned and sent with the application email; the current database record stores the submission and an attachment summary rather than the attachment file itself. We also process correspondence sent directly to us.

Technical and security data

The services create operational, security, abuse-prevention, audit, and error records, including timestamps, route or event information, request and correlation identifiers, session state, rate-limit activity, and hashed network-address prefixes or user-agent values where implemented. Web-server and infrastructure logs may also contain ordinary connection metadata such as an IP address, browser or client information, requested URL, response status, and time of access. Sensitive credentials and tokens are designed to be redacted from application logs.

Data we do not currently collect

The current website does not operate a payment checkout and does not collect payment-card details. We found no advertising network or third-party website analytics tracker in the current application. The service does not ask for a date of birth during registration.

3. Why we process data

We process the data described above to:

  • create, verify, secure, and administer accounts and authenticated sessions;
  • provide the website, community, social, launcher, and game features requested by users;
  • maintain persistent characters, world state, relationships, progression, and public histories;
  • deliver service emails, answer support requests, and assess voluntary project applications;
  • moderate content, enforce permissions, investigate abuse, and protect users and infrastructure;
  • diagnose faults, maintain service reliability, and establish or defend legal claims; and
  • comply with applicable legal obligations.

Swiss data-protection law applies to our processing. Where the GDPR applies, processing necessary to provide requested account, community, and game services is based on performance of a contract or steps requested before entering one. Security, moderation, service integrity, troubleshooting, and appropriate project communications rely on our legitimate interests and those of the community, balanced against affected rights. We rely on legal obligations where required and on consent where a specific optional activity expressly requests it. Consent may be withdrawn for future processing, without affecting earlier lawful processing.

4. Cookies and browser storage

The website uses an essential HTTP-only session cookie to keep a user signed in. It is configured with SameSite protection and, in production, the Secure attribute. A normal session expires after seven days; a session created with “remember me” can expire after thirty days and may be revoked earlier. Blocking this cookie prevents authenticated features from working.

The application also uses local or session browser storage for functional state: unsent forum and Holy Scripture drafts, Messenger layout and last-conversation preferences, character-presentation updates, Atlas interface and camera preferences, and one-session forum view de-duplication. This information stays in that browser until the application or user removes it, or browser storage is cleared. We do not currently use these technologies for behavioural advertising or third-party analytics, so no non-essential analytics-cookie consent banner is presently deployed.

5. Service providers, disclosures, and international transfers

Current processing involves the following infrastructure and external services:

  • Production hosting and PostgreSQL: the application, game services, and primary database run on the project's hosted server infrastructure in Germany. The repository does not identify the commercial host by name.
  • Backup storage: the deployment supports encrypted off-site backups to an S3-compatible storage provider. The provider and destination depend on the protected production configuration and are not identified in the public repository.
  • Resend (Plus Five Five, Inc., United States): email addresses and the contents needed for verification, recovery, security notices, support messages, or applications are sent through Resend for delivery. See the Resend Privacy Policy.
  • Discord and X: configured publishing integrations can send public project announcement content, public URLs, artwork, and associated public author information to official project channels. Following our Discord invitation or links to X sends the visitor to those independent services. See the Discord Privacy Policy and X Privacy Policy.
  • YouTube and Vimeo: community messages can display supported video links as embedded players. Loading an embed connects the browser to YouTube's privacy-enhanced domain or Vimeo, which can receive connection and browser information under its own policy.

We may also disclose limited data where required by law, to protect the service or its users, or in connection with the establishment or defence of legal claims. We do not sell personal data.

Data is primarily processed in Switzerland and Germany. Use of the email and social services above can involve processing in the United States and other countries used by those providers. Off-site backup destination details are controlled by the production configuration. Where required, transfers are assessed under applicable Swiss and European rules and the provider's available transfer mechanism. Contact us for the current destination or safeguard applicable to a particular transfer.

6. Retention

We keep personal data for as long as needed for the purpose for which it was collected, the persistent-world and community record, account and service security, dispute handling, and legal obligations. Retention is therefore determined by the kind and status of the record rather than one universal period.

  • Expired rate-limit records are removed after their window or block has ended.
  • Authentication email-throttling events are removed after one hour.
  • Completed worker heartbeat records are removed after thirty days.
  • Active account, character, community, relationship, world-history, moderation, and security records can remain while the account or persistent service needs them. Deleted forum and Messenger content is currently soft-deleted; a comprehensive permanent-purge workflow is not yet available.
  • Backups and operational records can remain for their recovery or security lifecycle and may not be removed immediately when a live record changes.

We review data in response to a verified deletion or restriction request and remove, anonymise, or retain it as applicable. Some records may need to remain to preserve other users' conversations, public world history, moderation evidence, security, legal compliance, or legal claims.

7. Security

Safeguards implemented in the project include one-way password hashing, hashed authentication tokens, scoped and revocable sessions, access-control checks, HTTPS in production, request-origin protections, rate limits, malware scanning for supported uploads, restricted private media storage, secret-aware log redaction, and encrypted off-site database backups. Access is limited according to operational need. No Internet service can guarantee absolute security; users should choose a unique password and report suspected account misuse promptly.

8. Your privacy rights

Subject to applicable law, you may ask whether we process data about you and request access, correction, deletion, restriction, objection, or a portable copy of eligible data. Where processing relies on consent, you may withdraw it for the future. EEA users may also object to processing based on legitimate interests and lodge a complaint with their local supervisory authority. Swiss users may contact the Federal Data Protection and Information Commissioner.

Send requests to support@thecityofgold.net from the account email where possible and describe the request. We may need to verify identity and may withhold or limit data where required to protect another person, security, legal obligations, or legal claims. There is not yet a self-service privacy export or permanent account-erasure control.

Profile settings currently allow users to change their verified email, password, active sessions, and editable profile information. A request to close an account is handled manually. Closing access revokes sessions but is not by itself an erasure of all associated persistent-world or community records; ask explicitly for deletion if that is what you seek.

9. Children and young users

The City of Gold is not designed specifically for children, does not request a date of birth at registration, and does not currently operate automated age verification. A person who cannot lawfully consent to the relevant data processing or agree to use the service in their country should use it only with the involvement of a parent or legal guardian. A guardian who believes a child supplied personal data without appropriate authority should contact us so the circumstances can be reviewed.

10. Changes to this policy

We may update this policy when the service, processors, or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through an appropriate project or account channel when required.