Your data, explained

Privacy Policy

Cloud-Hilfe auf Deutsch — German information about optional accounts and cloud saves.

Absturz- und Fehlerberichte auf Deutsch — German information about automatic diagnostic reporting.

At a glance

Who is responsible

Elysia is developed and published by Birol Aksu, Am Volkspark 77, 10715 Berlin, Deutschland. For privacy questions or data requests, email contact@playelysia.com. The same operator and contact are listed in the Impressum.

The game

Local saves and settings

Your city, progress and settings are stored on your device. The game may keep a previous autosave so it can recover from a damaged current save. Your operating system's device backup may include app data if you have enabled that feature in your Apple or Google settings.

You can choose to export a city file and select where it goes through the system share sheet, or import one you previously exported. The file contains game state and technical version information, not your name, contacts, email address or advertising identifier.

Optional accounts and cloud saves

You can always play offline as a guest. In builds with account cloud enabled, you can create an account with an email address and passphrase or use Sign in with Apple.

For an email account, the service stores a keyed digest used to find the account and an encrypted copy of the address used to show the account inside the game. Passphrases are stored as salted scrypt hashes. The service does not send marketing email. The email address is not currently verified and passphrase recovery uses the recovery key described below.

For Sign in with Apple, Apple authenticates you and sends Elysia a signed identity token, a single-use authorization code and, when Apple provides it, your chosen email or private relay address. Elysia verifies the signed token and exchanges the code with Apple on the server. It stores a keyed digest of the Apple identifier, an encrypted copy of any supplied address, and encrypted Apple identity, access and refresh tokens for account authentication and revocation. Deleting an Apple account in Elysia requires fresh Apple authentication and revokes the Apple refresh token before the cloud account is removed. Apple handles that authentication under your Apple account settings and Apple's Privacy Policy.

If you choose cloud saves, the service processes account and authentication records, session records, cloud-save metadata and the cities you link to the account. It provides four cloud slots, each with three earlier revisions in addition to the current city. Local-only cities are not uploaded just because you play the game.

The cloud service processes and stores its data on a Hetzner server in Helsinki, Finland, and uses HTTPS. Cloud cities use server-side encryption: the service manages the encryption keys. This is not end-to-end encryption.

An email-account passphrase reset uses a single-use recovery key, not an email reset. Resetting the passphrase revokes all previous sessions and returns one new session and a replacement recovery key. The used key no longer works; store the replacement safely. Sessions expire after 30 days, with a maximum of six sessions per account. Keep the recovery key somewhere safe and separate from your device. Do not send your passphrase or recovery key to support.

Active cloud account data is kept until you delete the account, subject to the slot and revision limits above. Account deletion immediately removes your cloud account, cloud cities and sessions from the active service. Your local city and store purchases remain, as do your local achievements. Cloud-account deletion does not uninstall the game or cancel a store purchase.

A separate deletion ledger retains only the random account UUID and deletion timestamp, not the email address, Apple identifier or city, to prevent deleted accounts from being resurrected during restoration. It has no automatic expiration during alpha. Records are retained until their entire backup lineage is retired: all related backups and any copies derived from them must be retired before the corresponding deletion records are no longer needed.

Daily database backups are encrypted with AES-256-GCM and stored on the same Hetzner host, with automated retention of no more than seven days. Data deleted from the active service can remain in an older backup until that backup expires. No automated off-machine backup is configured; these backups do not protect against losing the entire host. A full restore test verified that the deletion ledger is applied before the restored service begins accepting requests.

The cloud application does not keep request or access logs. Its operational container log records startup and error information and is capped at 2 MiB. This is a size limit, not a fixed time-based retention period. Website hosting logs are described separately below.

Optionale Konten und Cloud-Spielstände

Du kannst immer offline als Gast spielen. In Versionen mit aktivierter Konto-Cloud kannst du ein Konto mit E-Mail-Adresse und Passphrase erstellen oder „Mit Apple anmelden“ verwenden.

Bei einem E-Mail-Konto speichert der Dienst einen schlüsselgebundenen Prüfwert zum Auffinden des Kontos und eine verschlüsselte Kopie der Adresse, die im Spiel angezeigt wird. Passphrasen werden als gesalzene Scrypt-Hashes gespeichert. Die Adresse wird nicht für Marketing verwendet. Sie wird derzeit nicht verifiziert; zur Wiederherstellung dient der unten beschriebene Schlüssel.

Bei „Mit Apple anmelden“ authentifiziert Apple dich und übermittelt Elysia ein signiertes Identitäts-Token, einen einmal verwendbaren Autorisierungscode sowie, falls von Apple bereitgestellt, deine gewählte E-Mail- oder private Relay-Adresse. Elysia prüft das signierte Token und tauscht den Code auf dem Server bei Apple ein. Der Dienst speichert einen schlüsselgebundenen Prüfwert der Apple-Kennung, eine verschlüsselte Kopie einer übermittelten Adresse sowie verschlüsselte Apple-Identitäts-, Zugriffs- und Aktualisierungs-Token für Anmeldung und Widerruf. Das Löschen eines Apple-Kontos in Elysia erfordert eine erneute Apple-Anmeldung; das Apple-Aktualisierungs-Token wird widerrufen, bevor das Cloud-Konto entfernt wird. Für die Authentifizierung gelten deine Apple-Kontoeinstellungen und die Datenschutzrichtlinie von Apple.

Wenn du Cloud-Spielstände nutzt, verarbeitet der Dienst Konto- und Anmeldedaten, Sitzungsdaten, Metadaten der Cloud-Spielstände und die mit deinem Konto verknüpften Städte. Es gibt vier Cloud-Speicherplätze mit jeweils drei früheren Revisionen zusätzlich zur aktuellen Stadt. Rein lokale Städte werden nicht allein durch das Spielen hochgeladen.

Der Cloud-Dienst verarbeitet und speichert seine Daten auf einem Hetzner-Server in Helsinki, Finnland, und verwendet HTTPS. Cloud-Städte werden serverseitig verschlüsselt. Der Dienst verwaltet die Schlüssel; es handelt sich nicht um Ende-zu-Ende-Verschlüsselung.

Zum Zurücksetzen der Passphrase eines E-Mail-Kontos verwendest du einen einmal verwendbaren Wiederherstellungsschlüssel, keinen Link per E-Mail. Dabei werden alle bisherigen Sitzungen widerrufen; du erhältst eine neue Sitzung und einen neuen Wiederherstellungsschlüssel. Der verwendete Schlüssel funktioniert danach nicht mehr. Bewahre den neuen Schlüssel sicher auf. Sitzungen laufen nach 30 Tagen ab; pro Konto sind höchstens sechs Sitzungen möglich. Sende deine Passphrase oder deinen Wiederherstellungsschlüssel niemals an den Support.

Aktive Cloud-Kontodaten werden bis zur Kontolöschung aufbewahrt; für Städte gelten die oben genannten Speicherplatz- und Revisionsgrenzen. Beim Löschen werden das Cloud-Konto, seine Cloud-Städte und seine Sitzungen sofort aus dem aktiven Dienst entfernt. Deine lokale Stadt und deine Store-Käufe bleiben erhalten, ebenso deine lokalen Erfolge. Das Löschen des Cloud-Kontos deinstalliert das Spiel nicht und storniert keinen Store-Kauf.

Ein separates Löschregister enthält nur die zufällige Konto-UUID und den Löschzeitpunkt, weder E-Mail-Adresse noch Apple-Kennung oder Stadt. Es verhindert, dass gelöschte Konten durch eine Wiederherstellung erneut entstehen. Während der Alpha gibt es dafür keine automatische Löschfrist. Die Einträge bleiben erhalten, bis alle zugehörigen Sicherungen einschließlich sämtlicher daraus abgeleiteter Kopien außer Betrieb genommen wurden.

Tägliche Datenbanksicherungen werden mit AES-256-GCM verschlüsselt und auf demselben Hetzner-Server gespeichert. Sie werden automatisiert nach spätestens sieben Tagen entfernt. Bereits aus dem aktiven Dienst gelöschte Daten können bis zum Ablauf einer älteren Sicherung darin verbleiben. Eine automatisierte Sicherung auf einem anderen Rechner ist nicht eingerichtet. Diese Sicherungen schützen daher nicht vor dem Verlust des gesamten Servers. Ein vollständiger Wiederherstellungstest hat bestätigt, dass das Löschregister angewendet wird, bevor der wiederhergestellte Dienst Anfragen annimmt.

Die Cloud-Anwendung führt keine Anfrage- oder Zugriffsprotokolle. Das Betriebsprotokoll des Containers enthält Start- und Fehlerinformationen und ist auf 2 MiB begrenzt. Das ist eine Größenbegrenzung, keine feste zeitliche Aufbewahrungsfrist. Protokolle des Website-Hostings werden weiter unten separat beschrieben.

Unabhängig von der Cloud-Anmeldung sendet Elysia Absturz- und Fehlerdiagnosen automatisch an Sentry. Technischer Kontext in diesen Berichten kann personenbezogene Informationen enthalten. Weitere Angaben stehen im Abschnitt zu Absturz- und Fehlerberichten.

Bei Datenschutzfragen erreichst du Birol Aksu unter contact@playelysia.com; die Anschrift steht im Impressum.

Diagnostics you choose to share

The game keeps a small local diagnostics log with technical details and gameplay milestones such as the tutorial step reached or a completed mission. It is never sent automatically. If you tap Share diagnostics, your device opens its share sheet and you choose the destination. Closing the sheet sends nothing.

The diagnostics file may include the app version, device model and operating-system version. It does not include your email, contacts, advertising identifier, location, city-save contents or free text.

Crash and error reports

Elysia uses Sentry to report crashes and errors automatically, including some nonfatal errors and unhandled promise rejections. Reports are sent without a separate confirmation for each event and help us investigate faults.

Reports may contain error messages, stack traces, app/build and SDK information, device and operating-system details, technical identifiers, and console or network context. Depending on its contents, this context can include personal information. Sentry may also infer an IP address from an incoming request. The SDK can send event-delivery diagnostics.

The build disables Sentry's default-personal-data option and automatic session tracking, and sets performance-event sampling to zero. These settings do not guarantee that every report excludes personal information or that all instrumentation is absent.

The configured destination is a Sentry EU-region ingestion endpoint. This alone does not establish all storage locations or retention periods. The project's actual storage locations and retention period have not yet been verified.

Separately exportable in-game diagnostic files stay on your device until you choose to share them. Apple or Google may also provide developers with crash information if you have enabled the operating system's diagnostics-sharing setting. Those platform reports are governed by your Apple or Google settings.

Automatische Absturz- und Fehlerberichte

Elysia verwendet Sentry, um Abstürze und Fehler automatisch zu melden. Dazu gehören auch manche Fehler, bei denen die App weiterläuft, und nicht behandelte Fehler in asynchronen Vorgängen. Die Berichte werden ohne einzelne Bestätigung gesendet und helfen uns bei der Fehleranalyse.

Berichte können Fehlermeldungen, Stacktraces, Angaben zu App-Version, Build und SDK, Geräte- und Betriebssysteminformationen, technische Kennungen sowie Konsolen- oder Netzwerkkontext enthalten. Je nach Inhalt können dabei personenbezogene Informationen übermittelt werden. Sentry kann außerdem aus einer eingehenden Anfrage eine IP-Adresse ableiten. Das SDK kann Diagnoseinformationen zur Ereignisübermittlung senden.

Die Option für standardmäßig erfasste personenbezogene Daten und die automatische Sitzungsverfolgung sind deaktiviert; die Stichprobenrate für Performance-Ereignisse beträgt null. Diese Einstellungen garantieren weder, dass jeder Bericht frei von personenbezogenen Informationen ist, noch, dass sämtliche Instrumentierung deaktiviert ist.

Konfiguriertes Ziel ist ein Sentry-Eingangsendpunkt in der EU-Region. Daraus allein lassen sich nicht sämtliche Speicherorte oder Aufbewahrungsfristen ableiten. Die tatsächlichen Speicherorte und die Aufbewahrungsfrist des Projekts sind noch nicht verifiziert.

Separat exportierbare Diagnosedateien des Spiels bleiben auf deinem Gerät, bis du sie selbst teilst. Apple oder Google können außerdem Absturzinformationen bereitstellen, wenn du die Diagnosefreigabe des Betriebssystems aktiviert hast. Dafür gelten deine Apple- oder Google-Einstellungen.

Datenschutzfragen und Datenanfragen: contact@playelysia.com.

Purchases

The full-game unlock is a one-time in-app purchase. Apple processes the transaction. We do not receive your payment-card details. The store may return a product and entitlement record so the game can grant or restore the unlock.

This website

This website does not use analytics or advertising scripts, and it does not include an email sign-up form. Its App Store links open Apple's App Store.

Hosting and logs

The site is hosted by Vercel. Like most web hosts, Vercel receives standard request information such as IP address, browser headers, requested path and timing in operational logs. We do not add page analytics, advertising pixels, fingerprinting or cross-site tracking.

Cookies and local storage

The public pages do not set marketing, analytics or preference cookies and do not use browser local storage.

Your choices and rights

You may ask us to access, correct or delete personal data we control, object to or restrict certain processing, or withdraw consent where consent is the legal basis. You may also complain to your local data-protection authority. We may need enough information to verify that a request belongs to you, but we will not ask for unrelated data.

Local-only game data can be removed using the game's controls or by deleting the app. Operating-system device backups are controlled through your Apple or Google account settings; Elysia cloud accounts and their server backups are separate and follow the deletion rules above.

Children

Elysia is not directed at children under 13 and does not knowingly collect personal data from children through the website.

Security and transfers

We use access controls, HTTPS and the server-side encryption described above. Elysia cloud data is processed and stored on our Hetzner server in Helsinki, Finland. If you use the service from another country, your data is sent to that server. The website is separately hosted by Vercel.

Changes

When this policy changes, the revised text and a new last-updated date will appear here. Material changes to an optional online game feature will be explained before that feature is enabled.

Read the support page