Privacy Policy
Last updated: 31 August 2026
Translation notice: this localized page is an automated translation provided for convenience. The English version controls if the texts differ. Choose EN in the language menu to read it.
Delete your FableBrawl account: use Account Settings → Delete Account → Delete Forever in the app, or read the exact deletion details and email-request option under Account deletion and retention.
FableBrawl is an online fantasy auto-battler game available at fablebrawl.com. This policy explains what we collect, why, and who we share it with. We have tried to keep it specific rather than generic — if something here is unclear, please ask.
Without an account, you may complete one solo run—either a standard run or the guided First Tale—and continue to use the Second Tale lessons and private rooms. Signing in is required to begin additional complete runs, enter ranked matchmaking, save match history, or use Premium.
Data we collect when you sign in
On the website and in the Android app, when you choose “Sign in with Google”, we request only the three basic sign-in scopes: openid, email, and profile. We do not request, receive, or have any access to your Gmail, Drive, Contacts, Calendar, Photos, or any other Google service.
| What we receive | Why | Do we store it? |
|---|---|---|
| Your Google account identifier | To recognise you as the same player on your next visit | Yes — this is your permanent account key |
| Your email address | To send monthly season results, contact you about your account or subscription. If you explicitly opt in, we may also send the helpful gameplay email described below | Yes |
| Basic profile information | Returned by Google as part of sign-in | No — we do not store your Google name or profile picture |
In the iOS app, Sign in with Apple provides an Apple account identifier and, if you choose to share it, your email address or Apple's private relay address. We use the identifier to recognise your FableBrawl account and use the email for the same account and season communications described above. Apple provides the email only on the first authorization, so we store it with your account.
Your in-game name is one you choose yourself. It is never derived from your email address or provider profile.
While a signed-in player with a completed profile has FableBrawl open, the public Live Court panel may show that chosen in-game name with one coarse status: online, in queue, or in a game. For a game in progress it also shows the current turn number. After ten minutes without keyboard, pointer, or touch activity in any open FableBrawl tab, the panel may mark the player as idle. It does not publish the account identifier, email address, room, screen, connection details, activity time, idle duration, or activity history. This is short-lived presence held in server memory rather than a stored public log; a name normally disappears within about three minutes after its verified heartbeat stops.
Every sign-in exchange is verified on our server. We do not keep Google access tokens, ID tokens, or refresh tokens after sign-in completes: once your account is identified, we issue our own session token and never call Google on your behalf again. For Apple, we retain the refresh token in server-only storage solely so we can revoke Sign in with Apple authorization if you delete your account, as Apple requires. It is never exposed to the app or used to access another Apple service.
Data we collect as you play
- Account and progress: your chosen name, rating, monthly season record, tutorial progress, and referral code.
- Language choice: if you sign in and choose a language,
we save that supported language code so the choice follows your account to
another device. If you leave the app on automatic language selection, your
browser resolves one supported language and we may save only that language
code as a separate server-only hint. We use the hint for account,
subscription, and optional marketing email when you have not chosen an
account language. We use English if neither value exists. We do not save the
browser's raw language list, the
Accept-Languageheader, a country, or an IP address for localization. - Tournament participation: if you are selected for an event, we store the eligibility name and rating captured for that event plus any Discord name or stream URL submitted for tournament logistics.
- Match history: completed games, the hero you played, your final board and treasures, your placement, and rating change. For server-authoritative ranked matches, and for rostered private, unrated tournament matches when their lobby states that board retention is on, we also retain battle-state recordings linked internally to their source match so eligibility can be checked. They let computer-controlled seats in a later match fight with a board that a real player built; tournament recordings are collected for future in-game AI opponents and are not served by the current tournament feature. The replayed combat-state payload contains game pieces, combat-relevant hand contents, and combat state. We also retain one de-identified post-battle handoff for each recorded run, containing its remaining shop, Gold and experience, pending game rewards, and progression state. That checkpoint lets the computer continue playing if a later match lasts longer than the recorded run. Neither payload contains the source player's name, account identifier, email address, portrait, or random-number state, and the private handoff is never sent to another player's device. The source player is not notified and receives no reward, result, or rating change when a recording is used.
- Gameplay telemetry: in-game events used to find bugs and balance the game.
- Feedback reports: if you submit feedback, we store your
free-text message plus a snapshot of your own game state. The message is kept
as you submit it, so please do not type passwords, payment details, or other
sensitive personal information into it. Names, room codes, email addresses,
and anything resembling a credential are stripped from the diagnostic
snapshot in your browser and stripped again on our server; that automatic
scrubbing does not rewrite the free-text message. Feedback never includes
other players' hidden shops or hands. Current initial alerts sent through
Resend to our private triage mailboxes contain the category and free-text
message, your internal account identifier or
Anonymous, current verified contact addresses, bounded screen/game/build context, and the privacy-scrubbed diagnostic snapshot. The opaque report UUID appears in both the subject and body. If your account has exactly one current verified email address, the alert uses it as Reply-To so we can answer from the mailbox. If there are zero or multiple verified addresses, the alert has no automatic reply target. We derive those addresses from the signed-in account and ignore identity fields supplied with the feedback request. - Session token: stored in your browser's local storage so you stay signed in. On our side we store only a one-way hash of it, so the token itself cannot be recovered from our database.
Payment data
Premium subscriptions are processed by Stripe. Card numbers and payment details are entered directly into Stripe's own fields and are never seen by, sent to, or stored on FableBrawl's servers. We store only the Stripe customer and subscription identifiers, your subscription status, and its renewal date, so we know whether your Premium benefits are active.
Who we share data with
We do not sell your data, and we do not share it for advertising. We use a small number of service providers to run the game:
- Google — sign-in in the Android app and website.
- Google Workspace and Gmail — messages addressed to hello@fablebrawl.com are retained in that Workspace mailbox and forwarded to a restricted private Gmail inbox used for triage. Both can hold report alerts, replies we send from the mailbox, and messages you choose to send or reply with.
- Apple — sign-in in the iOS app and website.
- Stripe — subscription payments.
- Railway — game server and database hosting.
- Vercel — website hosting.
- Resend — sending email.
We may also disclose data if legally required to do so, or to investigate cheating, fraud, or abuse of the service.
Account and subscription messages that are necessary to operate your account may be sent without marketing consent. Marketing email is optional. The choice is selected by default when you name your Chronicle. Clear the box before submitting if you do not want gameplay tips, product news, tournament announcements, monthly season results, or reminders to return. You can also change this choice later in Your Chronicle settings.
If you opt in during your first seven account days, we may send up to three new-player messages before account day 14. The series starts with a welcome. A second message may point you back to the First Tale or share beginner strategy, based on your progress. A final reminder may arrive around day seven. Completing three qualifying games stops any messages that have not been sent.
Once your account is at least 21 days old, the same choice can allow inactive-player messages after 7, 14, and 30 days without recorded play. If you return and later become inactive again, a new three-message period can begin. New-player messages finish before inactivity reminders can start.
We record whether you opted in or out, when the choice was made, where in the game it was made, and the version of this notice that applied. You can change the choice in Your Chronicle at any time. Every marketing email also includes a one-click unsubscribe link; using any such link stops all future marketing email unless you later opt in again. We do not treat creation of an account, acceptance of this Privacy Policy, or a cleared box as consent.
Campaign outboxes record the step or inactivity period, destination, eligibility and retry times, delivery state, send time, provider identifier, and any delivery error. We use account age, profile and tutorial progress, completed games, and recent activity to decide whether a message is due. Resend receives the destination address, player name, message, unsubscribe headers, and delivery data needed to send it. For aggregate counts in our private operator dashboard, we retain the signed provider event ID, message ID, email category, recipient count, and timestamp. That event ledger does not store recipient addresses, subjects, or message bodies.
Account deletion and retention
We keep account data for as long as your account exists. In the iOS and Android apps you can start permanent deletion from Account Settings. Your account access and active sessions end immediately once the app confirms that deletion succeeded. While a deletion request is running, a renewable 30-minute security lease blocks account changes; if the request is interrupted before it is confirmed, that lease expires so you can regain access and retry. Deleting your account deletes the feedback reports you submitted while signed in from our database in the same transaction. Within 30 days of a confirmed request, we remove the remaining account-associated data from our active database and submit applicable deletion or invalidation requests to our service providers. A provider's internal deletion queue, disaster-recovery backup, or legally required hold may retain a residual copy for that provider's standard additional period or as required by law. We do not use residual copies for ordinary product, support, analytics, or marketing purposes. The narrow Apple revocation-credential exception is described below. On iOS deletion also revokes your Sign in with Apple authorization. On both platforms deletion stops active billing associated with the account and removes the account, sign-in links, active sessions, profile, progress, referral data, tournament eligibility and entry details (including any Discord name or stream URL), monthly Top 10 entry, and feedback reports and diagnostic snapshots submitted while signed in.
Current initial feedback alerts contain the report data described above and carry the report UUID in both subject and body. When exactly one current verified address exists, the alert's Reply-To makes an ordinary mailbox reply possible; zero or multiple addresses do not auto-target anyone. A reply sent from our mailbox becomes ordinary support correspondence in that mailbox. The separate protected direct-reply action is delivered through Resend and is not Bcc'd to our support mailbox or copied into our database or GitHub Actions. Resend processes the initial alert payload and, for a protected direct reply, the recipient address, subject, and reply body only for delivery; its active delivery copy is scheduled to expire within 30 days, subject to the provider residual-copy terms above. If delivery bounces, is reported as spam, or is unsubscribed, Resend may retain the destination address, delivery status, and suppression reason after that period in a provider-controlled suppression record so unwanted or undeliverable mail is not sent again. We do not use a suppression record for product features, support profiling, analytics, or marketing, and the provider residual-copy and legal-hold terms above still apply. New replies from FableBrawl are one-way messages: they use a replies@feedback.fablebrawl.com sender with no inbound mail target and do not advertise hello@ as a Reply-To address. Some historical messages did advertise hello@ as their reply address. If you intentionally email or reply to hello@ after deletion, that new message is a new user-initiated support correspondence; it does not restore or relink your deleted account. We use it only to answer that new request and delete it by hand if you ask us to, subject to the provider residual-copy terms above.
Emailed copies of a report that already reached the hello@ Workspace mailbox or its forwarding Gmail inbox are ordinary support correspondence. They are not removed automatically when the report or the account is deleted; we delete them by hand if you ask us to, subject to the provider residual-copy terms above.
Anonymous feedback is not linked to an account and therefore is not removed by deleting an account. We retain anonymous reports for support and debugging until we manually delete them.
If Apple is temporarily unable to confirm revocation, we keep the minimum server-only revocation credential in an encrypted retry queue. It contains no account ID, email, name, message, or gameplay data; it is used only to ask Apple to invalidate the authorization and is deleted immediately after Apple confirms that invalidation. If an Apple outage or encryption-key recovery prevents confirmation, this credential may be kept longer than 30 days only for as long as strictly necessary to finish revocation; it is never used for any other purpose. Queue age and failures are monitored, and any item still pending after 24 hours is escalated for manual operator action so an unrevoked authorization is never silently discarded.
Deletion also removes raw gameplay and interface telemetry associated with your account or browser sessions. The app discards queued telemetry and gives the browser a new telemetry session identifier when deletion succeeds. It deletes each match you participated in, including its player rows, events, boards, battle replays, archived replay objects, historical-rival snapshots, and post-battle handoffs. If a compressed analytics object contains any row linked by your account, session, or game identifier, the complete object is deleted rather than rewritten. We keep only an account-to-match deletion link, using random internal match identifiers whose account relationship is established only by an authenticated server write, while your account exists so archived match data can still be found and deleted after shorter-lived database rows are pruned. The link cannot be attached merely by reporting an existing match identifier and is removed with the account, or when the archived match is purged during account deletion. We otherwise keep only statistics that were already combined across players, such as daily game, hero, and unit totals and season participant counts; those aggregate rows have no account, session, game, email, or player-name field. We also retain one-way SHA-256 digests of the deleted account's, affected browser sessions', and affected matches' random internal identifiers solely to prevent a delayed write from recreating deleted data. We also retain a one-way digest of each deleted sign-in provider identifier for 30 days. It blocks sign-in attempts that began before deletion finished and applies a 15-minute re-registration cooldown; a new sign-in begun after that cooldown creates a blank account rather than restoring deleted data. The original identifiers cannot be recovered from those digests.
You may also request deletion of your account and its associated data at any time by emailing hello@fablebrawl.com from the address attached to your account. Account access ends when deletion is confirmed. The active-data removal and provider-deletion requests are completed within 30 days, with the provider residual-copy terms and narrow encrypted Apple revocation-credential exception described above. The email thread carrying your deletion request is ordinary support correspondence and is deleted by hand if you ask us to. Records we are required to keep for tax or accounting purposes (such as payment records held by Stripe) may be retained longer.
You may also request a copy of the data we hold about you at the same address.
Children
FableBrawl is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.
Security
Traffic is encrypted in transit. Session tokens are stored only as one-way hashes, and payment credentials never reach our servers. No system is perfectly secure, but we aim not to hold data we do not need in the first place.
Changes
If this policy changes materially, we will update the date at the top of this page and, where the change affects how we use your data, notify account holders by email.
Contact
Questions, deletion requests, or privacy concerns: hello@fablebrawl.com.