
Português · English · Español · 日本語
Privacy Policy
Version 1.0, base template aligned with the LGPD (Brazil's General Data Protection Law, Law 13,709/2018). English translation of the Portuguese text (Política de Privacidade). Have it reviewed by a lawyer and name the controller and the data protection officer (DPO) before launch.
1. Data we collect
- Account: username, e-mail (optional) and password; the password is stored only as a hash (scrypt), never in plain text.
- Progress: the game save and up to 20 earlier copies for recovery.
- Security: IP address, browser (user-agent) and login times, used to protect the account and prevent fraud.
We do not collect payment data. We do not use advertising cookies: the only cookie is the session cookie (mv_session), which is essential to keep you signed in.
2. What we use it for
- To authenticate you and save your progress (performance of the contract).
- To display your username and statistics in the public ranking.
- Security, cheat prevention and compliance with legal obligations (legitimate interest and legal obligation).
3. Sharing
We do not sell your data. It may be processed by contracted hosting providers, under a duty of confidentiality, or provided to authorities when required by law.
4. Retention
We keep the data for as long as the account exists. Sessions expire after 30 days. When you delete the account, the account, the save and the history are erased; server backups are overwritten within 14 backup cycles.
5. Your rights
You can access and download your data (Profile → Account → Download data), correct your name, revoke sessions and delete the account. Accessing and downloading your data, correcting your name and deleting the account correspond to the rights of access and data portability, rectification and erasure under Article 18 of the LGPD and, where the GDPR applies to you, under its Articles 15, 20, 16 and 17. For other requests provided for in Article 18 of the LGPD, contact the data protection officer: [DPO's e-mail].
6. Security
We use hashed passwords, HttpOnly cookies, CSRF protection, a limit on login attempts, HTTPS in production and periodic backups.