◈ AimRPG

Privacy Policy

Last updated: July 2, 2026

This policy explains what data AimRPG ("the Game", "we") collects, why, and your rights. The Game is in beta and online-only: you must sign in to play.

Section 1

Who we are

AimRPG is an independent, solo-developed aim-training RPG. Contact for privacy requests: Crin on Discord (ceviatacringe). Service host: a self-managed server (EU) behind Cloudflare; domain rpgaimgame.com.

Section 2

What we collect and why

  • Discord user ID — your account identity / login. Kept while your account exists.
  • Discord display name, username, avatar, and country — shown on leaderboards and the online list (the country flag is cosmetic). Kept while your account exists.
  • Username & profile picture you set (optional) — shown next to your name. Kept while set, or until you change or remove it.
  • Uploaded images and their moderation-scan results — to show your picture and run automated (NSFW) plus manual safety moderation. Flagged or removed images are kept with a moderation case.
  • Linked Steam account ID and public aim-benchmark stats (optional) — to display aim-training ranks on your profile. Removed when you unlink.
  • Game progression (skills, items, gold, etc.) — the save the server computes for you. Kept while your account exists.
  • Leaderboard scores + run metadata (accuracy, combo) — public leaderboards. Kept until you delete the score or account.
  • Replays (your recorded aim for a run) — leaderboard "watch" and anti-cheat review. Your best replay per scenario is kept; others are pruned.
  • Run timing telemetry (frame rate, clock ratio) — anti-cheat (detecting time manipulation). Last ~60 runs per account, rolling.
  • Device fingerprint (a one-way hash of your hardware) — to stop banned cheaters making new accounts. Kept while your account exists.
  • Anti-cheat & integrity signals (technical game-integrity / anti-tamper checks; presence of cheating tools) — to detect cheating and tampering. Short / rolling; kept with a case if one is opened.
  • Crash & diagnostic reports (technical state, environment snapshot, build/session identifiers) — to fix bugs and tell a genuine fault from tampering. Limited retention.
  • IP address — to deliver and protect the service and detect/limit ban-evasion and abuse. Kept with the connection / incident log.

We do not sell your data, run third-party ad/tracking SDKs, or collect your real name, email (beyond what you provide for support), payment data, or precise location.

Section 3

Discord login

We use Discord OAuth solely to authenticate you and read your public profile (id, username, display name, avatar, locale/country). We do not read your messages, servers, or friends, and we never receive your Discord password. You can revoke the Game's access in your Discord settings at any time.

Section 4

Cloudflare

Traffic passes through Cloudflare (CDN / DDoS protection). Cloudflare processes connection metadata (including IP) to deliver and protect the service. See Cloudflare's privacy policy.

Section 5

Legal basis (EU/GDPR)

  • Contract — account, save, and leaderboards are needed to provide the Game you asked for.
  • Legitimate interest — anti-cheat and content moderation (telemetry, replays, image scanning, incident IP logging) to keep competition fair and the service safe and secure, balanced against your rights.
Section 6

Your rights

You can request to access, correct, export, or delete your data, and object to processing. Account deletion removes your save, leaderboard entries, replays, uploaded images, and telemetry. Message Crin on Discord (ceviatacringe); we aim to respond within 30 days. EU users may also complain to their data protection authority.

Section 7

Children

The Game is not directed at children under 13 (under 16 in some EU countries). Do not use it if you are under the applicable age. If we learn we hold a child's data, we delete it.

Section 8

Security

The server is the authority for your economy and scores; saves are owner-read / server-write. Secrets live only on the server. No system is perfectly secure — see Section 9.

Section 9

Public security challenge

We may run an authorized public security/break-in challenge against a dedicated test environment. Participants test only the systems and scope we explicitly invite, and must not access, exfiltrate, or disclose other players' personal data. Findings should be reported privately to Crin on Discord (ceviatacringe). Out-of-scope or destructive activity (DoS, mass-targeting, real-user data theft) is not authorized.

Section 10

Changes

We may update this policy; material changes will be posted on rpgaimgame.com with a new date.