Privacy Policy
Last updated: 9 October 2026
This is a translation for convenience. Only the German version is legally binding.
This policy applies to the website atromy.app, the game at play.atromy.app and the apps for iOS and Android (together "Atromy"). It describes which personal data we process, for what purpose, on which legal basis and for how long. Features that are not yet live are marked "once activated"; the respective section only applies from the moment they are switched on.
1. Controller
Nils Berenbold
Heckenweg 5
26605 Aurich
Germany
Phone: +49 151 15268680
Email: [email protected]
We have not appointed a data protection officer because there is no legal obligation to do so. Please send all data protection questions to the address above.
2. Principles
Atromy uses no advertising trackers, no third-party analytics services, no pixels and no marketing cookies. We serve fonts and images from our own servers. We do not sell personal data and only pass it on to the recipients named in this policy.
3. Hosting
The website, game server and database run on a server at Leaseweb (contracting entity and location: [[Leaseweb-Standort prüfen]]). Leaseweb processes the data stored on or passing through the server on our behalf.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and reliable operation) and, where your account is concerned, Art. 6 (1) (b) GDPR.
4. Cloudflare (CDN, protection, Turnstile)
All requests to atromy.app and play.atromy.app pass through Cloudflare, Inc. (USA) as network service provider (content delivery network and reverse proxy). Cloudflare accepts the encrypted connection, caches static files, fends off attacks and forwards the remaining requests to our server. In doing so, Cloudflare processes in particular your IP address, the requested address, date and time, browser and device information and the transmitted content.
Turnstile: If an IP address shows many sign-ups or failed sign-ins, we require a check with Cloudflare Turnstile (protection against automated access) for further attempts. For this, your browser or the app (once activated) loads a check element from Cloudflare, and our server sends the result together with your IP address to Cloudflare for verification. Without suspicious activity, Turnstile is not loaded.
Cloudflare is certified under the EU-U.S. Data Privacy Framework; the transfer to the USA is based on the European Commission's adequacy decision (Art. 45 GDPR) and additionally on standard contractual clauses (Art. 46 (2) (c) GDPR).
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in fast delivery and in protection against abuse and attacks).
5. Server log files and technical logs
Our own web server writes no access logs. Our game server processes the IP address it receives from Cloudflare with every request, as follows:
- Rate limits: counters per IP address and sign-in route in the database to limit mass sign-in and sign-up attempts. A counter applies to a time window of at most one hour and then starts over; we delete the entries themselves after 24 hours automatically.
- Bot protection: counters of sign-ups and failed attempts per IP address in memory, for at most one hour; they are gone after a restart.
- Error messages of the server end up in the technical logs of the containers. They are deleted after [[Speicherdauer Container-Logs festlegen]] at the latest.
Cloudflare keeps its own logs of the requests passing through its network (see section 4).
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in operational security, troubleshooting and protection against abuse).
6. Cookies and similar technologies
Under § 25 TDDDG, information may only be stored on or read from your device with your consent, unless this is strictly necessary for us to provide a service you have explicitly requested (§ 25 (2) no. 2 TDDDG). We currently only use such strictly necessary cookies and storage entries:
- Game session (browser): After you sign in, play.atromy.app sets a session cookie (
better-auth.session_token, over HTTPS with the prefix__Secure-). It keeps you signed in, cannot be read by scripts and expires after seven days without use or when you sign out. - Sign-in via a provider: While you sign in via Apple, Google, Discord or X, we set short-lived cookies that secure the sign-in process.
- Session in the app: The apps store the session token in your device's protected storage (iOS Keychain or Android Keystore).
- Consent cookie on the website: The website stores your choice in the cookie notice (
atromy_consent, six months) with version and date so it does not ask you again on every visit. - Cloudflare and Turnstile: Cloudflare may set technically necessary cookies to protect against attacks and automated access, Turnstile only during the check described in section 4.
The exact list with names and lifetimes: [[Cookie-Liste prüfen]]
Google Analytics (only with consent): On the website atromy.app we use Google Analytics 4 by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), but only if you agree to the "Statistics" category in the cookie notice. Before that, the website loads no script from Google and sends no request to Google. Google Analytics counts page views and evaluates where visits come from (e.g. UTM parameters), which pages are viewed and with which device, browser and from which region. For this, Google sets the cookies _ga and _ga_<ID> with a lifetime of up to two years. We do not transmit query parameters of the address other than UTM parameters (such as confirmation codes from the newsletter). Google Analytics 4 does not store full IP addresses. Google deletes the data after 14 months at the latest. Access from the USA cannot be ruled out; Google is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). The legal basis is your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG).
We set no marketing cookies. You can change or withdraw your choice at any time via the "Cookie settings" link in the website footer; after withdrawal the website stops measuring and deletes the Google Analytics cookies.
The legal basis for storing on your device is § 25 (2) no. 2 TDDDG, for the subsequent processing Art. 6 (1) (b) GDPR (session) or Art. 6 (1) (f) GDPR (protection, storing your choice).
7. Account and sign-in
You need an account to play. For this we process:
- Email address and display name, your preferred language for emails and the time of creation and last change.
- Password: We only store a hash, never the password itself.
- Email confirmation: After sign-up we send you a confirmation link valid for 24 hours. Only then can you sign in with your password.
- Magic link: On request we send you a sign-in link valid for ten minutes instead of entering a password. We also send links for resetting your password and deleting your account by email.
- Sessions: For every sign-in we store start and expiry, IP address and browser or device identifier (user agent). This lets you see where you are signed in and lets us detect abuse.
- Bans: If an account breaks the rules, support can ban it temporarily or permanently; we store the reason and end of the ban.
The legal basis is Art. 6 (1) (b) GDPR (terms of use), for session data used to detect abuse and for bans Art. 6 (1) (f) GDPR.
8. Sign-in via Apple, Google, Discord and X
Instead of email and password you can also sign in via Apple, Google, Discord or X (Twitter); only the providers we have set up are offered. Atromy then redirects you to the provider's sign-in page, and after your approval the provider sends us:
- your identifier at the provider,
- your email address and whether the provider reports it as verified,
- your name and, if available, the address of your profile picture,
- the provider's access tokens with their expiry and the granted permissions.
If the provider reports the email address as verified and it belongs to an already verified account with us, we link the two; otherwise we create a separate account. What the provider itself stores about the sign-in is governed by its privacy policy. Apple, Google, Discord and X are based in the USA or belong to companies there; data may be transferred to the USA. Where the provider is certified under the EU-U.S. Data Privacy Framework, the transfer is based on the adequacy decision (Art. 45 GDPR), otherwise on the provider's standard contractual clauses (Art. 46 (2) (c) GDPR).
The legal basis is Art. 6 (1) (b) GDPR; signing in via a provider is voluntary.
9. Game data
When you play, we store what belongs to the game: your captain per universe with name, people, level, experience, credits, tutorial progress, reputation with the factions, time zone and last activity, plus inpace, resources, fleets, battles, quests and other game states as well as scheduled game events.
Your captain name and parts of your game state are visible to other players in the same universe, for example on the map and, once activated, in leaderboards.
The legal basis is Art. 6 (1) (b) GDPR.
10. Chat, reporting, blocking and moderation
Reporting and bans: You can report other players (category and a description). We store the report with you as reporter, the reported account, time, processing status and outcome. Reports are handled by support, which can ban accounts (section 7).
Chat (once activated): We store messages in the global and system chat with universe, channel, captain and time for seven days. We keep reported messages longer, until the report has been handled. A word filter hides inadmissible terms, and support can mute players.
Blocking (once activated): You can block other players; you will then no longer see their messages and invitations. For this we store whom you have blocked.
The legal basis is Art. 6 (1) (b) GDPR (chat and blocking as part of the game) and Art. 6 (1) (f) GDPR (legitimate interest in safe interaction and in protecting minors).
11. Support and audit log
Support and administration work via a protected interface of the game server with the roles support and admin. Every call of this interface is recorded with the acting person, role, action, its details (for example the identifier of an affected account), reason, outcome and time in an audit log that cannot be changed afterwards. This keeps it traceable who intervened in an account and when.
If you write to us by email, we process your message and your contact details to handle your request.
The legal basis is Art. 6 (1) (f) GDPR (traceability and protection against errors and abuse) and, if your request concerns your account, Art. 6 (1) (b) GDPR. We keep the audit log for 6 months and then delete the entries automatically.
12. Sending emails
We send confirmation, sign-in, password and deletion emails as well as newsletter emails via our own SMTP access at [[E-Mail-Anbieter (SMTP) eintragen]]. The provider processes your email address and the content of the email on our behalf.
The legal basis is that of the respective purpose (sections 7 and 13).
13. Newsletter
You can sign up for our newsletter on the website. We store your email address, the chosen language, the time of sign-up and of the confirmation email and, if present, the UTM details of the link you came from (source, medium, campaign, term, content).
Double opt-in: After you sign up we send you a confirmation email. Only once you confirm the link in it do we add you to the mailing list. We store the time of confirmation as proof of your consent. Unconfirmed sign-ups receive a new confirmation email at most every ten minutes.
Unsubscribing: Every email contains an unsubscribe link. After unsubscribing you will no longer receive the newsletter; we store the unsubscription with its time so we can prove it. On request we delete your address completely.
The legal basis for sending is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time with effect for the future. The legal basis for logging sign-up, confirmation and unsubscription is Art. 6 (1) (c) in conjunction with Art. 7 (1) GDPR (obligation to provide proof) as well as Art. 6 (1) (f) GDPR.
14. Origin of visits (attribution)
To learn which channels and campaigns bring players, we evaluate the origin of visits without cookies and without storing anything on your device:
- UTM parameters and referral codes: If a link carries UTM details (source, medium, campaign, term, content) or a referral code, the website reads them from the address bar and appends them, together with the page and the clicked button, to the link to sign up in the game. When you sign up for the newsletter we store them as described in section 13.
- Counting views and clicks: We count how often a landing page of the website is viewed and how often its main button is clicked. For this the website sends one message to our server per view or click, without cookies, without storing anything on your device and without an identifier. We only store the landing page (and its variant, if any), the button, where the button leads (App Store, Google Play, the game in the browser or the newsletter), the campaign details from the link, the language, roughly the kind of device (desktop or mobile) and the time, never your IP address, your user agent or any device or personal identifier. The IP address is only used to briefly limit requests in memory. Individual visits cannot be recognised or followed this way.
- Origin stored with the account: If you sign up through such a link, we store the details it carried (landing page, button, campaign details, referral code and the preselection from the website's configurator) once with your account. The app keeps them only in memory for this, not on your device. They are deleted with the account.
- Google Play Install Referrer: On Android devices, the website's button leads directly to Google Play and passes these details there as referrer. The Android app reads them after installation via Google Play's Install Referrer interface, once activated.
We only evaluate these details in aggregate by landing page, channel and campaign. We do not combine them with data from other sources.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in measuring the success of our advertising without tracking).
15. Error reports (Sentry)
When error reporting is switched on, the game server, the game in the browser and the apps send an error report to Sentry (Functional Software, Inc., USA) when a program error occurs. We use Sentry's EU region; the data is stored in data centres in the EU. A report contains the error message, the program flow up to the error, the program version and details about device, operating system and browser. Server and browser explicitly do not collect user data, cookies, request headers, request bodies or URL parameters; in the apps, sending default personal data is switched off. Access from the USA cannot be ruled out; Sentry is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR), and standard contractual clauses apply in addition.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in an error-free game).
16. Push notifications (once activated)
Atromy can notify you, for example of an attack, when a construction is finished or when a battle is waiting for you. You can switch off the categories individually in the game. For this we store your device's push address or token and your settings per category.
- Browser on a computer (web push): The message goes through your browser's push service (for example Google, Mozilla, Apple or Microsoft).
- Apps: The message goes through Expo's push service (650 Industries, Inc., USA) and from there to Apple Push Notification Service (iOS) or Google Firebase Cloud Messaging (Android).
These services receive the device token and the content of the message; providers in the USA may transfer data there (basis as in section 8). You only receive push notifications if you allow them in your browser or on your device; you can withdraw this permission there at any time.
The legal basis is your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG).
17. App stores and test distribution
We distribute the apps via Apple (App Store and TestFlight) and Google (Google Play, including open testing). Downloading is subject to the terms and privacy policies of these providers; they process your data in their own responsibility. Apple and Google provide us with statistics and crash reports, usually without details that identify you directly. Feedback you send in TestFlight reaches us with the details you attach to it.
18. Recipients and transfers to third countries
Your data is only received by us and the service providers named in this policy. With service providers that process data on our behalf (Leaseweb, Cloudflare, Sentry, Google Analytics, email provider) we conclude contracts under Art. 28 GDPR. [[Abschluss der AV-Verträge prüfen]]
We only transfer data to countries outside the EU or EEA in the cases named (Cloudflare, Sentry, Google Analytics, sign-in providers, push services) and only on the basis of an adequacy decision (Art. 45 GDPR) or appropriate safeguards such as standard contractual clauses (Art. 46 GDPR).
19. Retention
- Account and game data: until you delete your account. You confirm the deletion via a link sent by email; we then remove the account, sign-in methods, sessions and all game data.
- Reports: Reports against your account are deleted with the account. Reports you filed are kept for moderation but lose their link to your account.
- Sessions: expire after seven days without use.
- Links sent by email: confirmation links 24 hours, magic links ten minutes.
- Newsletter: until you unsubscribe or ask for deletion, proof as in section 13.
- Rate limits and bot protection: as in section 5.
- Counting of landing pages: at most 400 days, after which an hourly job deletes the entries; the origin stored with the account stays until the account is deleted (section 14).
- Backups: We back up the database daily and delete backups after seven days. Deleted data therefore disappears from the backups no later than seven days after deletion.
- Audit log: as in section 11.
Statutory retention obligations remain unaffected.
20. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7 (3)).
Right to object: Where we process data on the basis of Art. 6 (1) (f) GDPR, you can object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
You can request an export of your account data as a JSON file and the deletion of your account by email to [email protected], and once activated directly in the account settings.
21. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony)
https://www.lfd.niedersachsen.de
22. Children and young people
We do not ask for your age. Where processing is based on your consent (newsletter, push notifications), you can give it yourself in Germany from the age of 16 (Art. 8 GDPR). If you are younger, you need the approval of your parents or legal guardians. If we learn that consent was given without this approval, we delete the data concerned.
23. Changes
We update this policy when Atromy or the legal situation changes. The version published here applies; the date is shown at the top.