Privacy Policy — Duelsmith
Last updated: 7 September 2026 (version 2 — public launch). Written to match what the Game actually does at launch; when the implementation changes, this document changes with it.
1. Who we are
Duelsmith is a browser-based game at duelsmith.com, operated by Ramiro Joaquin Alves Pinto. Contact for anything in this policy: admin@duelsmith.com.
2. What we collect, and why
| Data | Source | Why | Legal basis |
|---|---|---|---|
| Email address, name and sign-in identity | Our sign-in provider (Kinde), when you create an account (email, or a social login you choose) | Account access; the emails the Game sends you (clause 2b) | Contract — running the game you asked for |
| Game data: champions, builds, plans, items, duels, ratings, medals, purchases of in-game goods with BP, trades on the black market | Your play | The game itself; your champion fights others asynchronously | Contract |
| Gameplay analytics events (fights fought, pages seen, features used), keyed to a pseudonymous account id — plus the country your connection appears to come from | Server-side, and in your browser (PostHog) | Understanding what's fun, broken or ignored; counting where players come from (the link you arrived by carries its campaign tags) | Legitimate interest |
| Session replays: a recording of how you move through the Game's pages — clicks, scrolls, page structure and timing — with every text field masked and anything we mark as sensitive hidden; plus your browser's console messages | Your browser (PostHog), while you use the Game | Seeing where the interface confuses people or breaks | Legitimate interest |
| Error reports (stack traces, request context, no request bodies) | Sentry | Fixing crashes | Legitimate interest |
| Email delivery data (address, sends, bounces) | Resend | Sending the PvP digest and notifications you're due, and purchase confirmations | Contract |
| Payment data: name, email, payment method, billing country, amount, and the purchase record | Stripe (payment), our database (the record) — only if you buy something | Taking and delivering a purchase; refunds, disputes, tax and accounting | Contract; legal obligation (tax) |
| Bug reports, ideas and support requests you send from inside the Game | You → BetaHub (our feedback tool) | Fixing what you reported. Bug reports and ideas carry your account id, never your email; a private support ticket carries your email so we can answer you | Contract (you asked) |
| Reports you file about other players, and reports filed about you | You, other players | Moderation | Legitimate interest |
| Custom avatar image | You, if you upload one | Displaying your chosen avatar to other players — only after a moderator approves it | Contract (you asked for it) |
We never see or store your card details — Stripe does, under its own terms. Our analytics person profiles carry no email property (targeting and identification happen by pseudonymous id only). We do not sell data, run ads, or share data with anyone except the processors listed in clause 4, who act on our instructions.
2a. What is public, by design
Duelsmith is an async PvP game, so some of your game data is visible to other players and to anyone with a link — never your email, real name or sign-in identity:
- your champion page (
/u/…): champion names, class, lineage, level, rating, medals and cosmetics; - replays: every duel has a public link; anyone with it sees the fight and both champions' builds (your tactical plan is not shown to viewers who own neither champion);
- the leaderboard: champion names and ratings.
2b. Emails we send
Account and purchase emails (a purchase confirmation from Stripe and, when live, a branded confirmation from us) and the PvP digest — a summary of fights that happened while you were away, with an unsubscribe link in every one. Unsubscribing is one click and needs no login. We send no marketing email.
Custom avatars. Images are re-encoded server-side and metadata is stripped (photo EXIF — e.g. GPS location — never reaches storage). They are stored in a private Vercel Blob store and are visible to no one but you and moderators until a moderator approves them; only approved images render to other players. Deleting your account deletes your uploaded images and their stored files; a moderation rejection or revert also deletes the stored files.
3. Cookies and local storage
We keep this deliberately minimal — there is no cookie banner because there is nothing to consent to:
- Sign-in session cookies (our sign-in provider's, httpOnly, on
.duelsmith.com): strictly necessary to keep you signed in. Consent-exempt. - Analytics is cookieless by configuration: our in-browser analytics runs with in-memory persistence only — no analytics cookie, no localStorage or sessionStorage entries. Events key to your pseudonymous account id once you sign in, never to your email. Some ad-blockers block it entirely; the game works fine anyway.
- Session replay runs under the same rule: no cookie, no identifier stored in your browser. The recording is keyed to the same pseudonymous id, every input field is masked before it leaves your browser, and payment happens on Stripe's own page, which is never part of a recording.
- Local storage holds only preferences you set yourself (for example, replay speed). No tracking, no identifiers.
If we ever want marketing cookies or richer in-browser persistence, a consent prompt ships first and this section changes.
4. Where your data lives, and who processes it
| Processor | What it does for us | Data it handles |
|---|---|---|
| Kinde | sign-in | email, name, social-login identity, session |
| MongoDB Atlas | the game database | everything in clause 2 that we store ourselves |
| Vercel | hosting, and private storage for avatar images | requests, logs, uploaded images |
| PostHog (European Union region) | analytics and session replay | pseudonymous events, session replays (inputs masked), console messages, approximate country |
| Sentry | error monitoring | stack traces, request context |
| Resend | email delivery | your email address, what we sent you |
| Stripe | payments | name, email, payment method, billing country, amount — only if you buy |
| BetaHub | bug reports, ideas, support tickets | what you wrote; your account id; your email only on a support ticket |
Each processes data under its own data-processing terms. Some of these processors are outside your country — our analytics runs in the European Union; several others are in the United States. Where a transfer out of the EU/EEA or the UK happens, it relies on the processor's standard contractual clauses or an equivalent recognised mechanism. We do not use Discord to process your Game data; if you join our Discord server, Discord's own privacy policy applies there.
5. How long we keep it
Account and game data: while your account exists (and see clause 6 for what survives deletion). Analytics events: 12 months. Session replays: 30 days, then deleted automatically. Error data: per-tool retention windows, 12 months or less. Purchase and tax records: the period the law requires (clause 6). Backups roll off on the infrastructure's schedule.
6. Deleting your account — what actually happens
Settings → Delete account. In one transaction this permanently deletes your user record, champions, builds, plans, presets, inventory, notifications, gauntlet runs, daily-duel solves, medals, open black-market listings, and your uploaded avatar images (the stored files immediately after). Your record at our sign-in provider and your analytics profile are then deleted by our internal runbook (manual steps, completed within 30 days), and we stop emailing you.
What survives, and why — stated exactly:
- A one-way hash of your sign-in id (the "tombstone"), whose only purpose is preventing deleted-account re-grant abuse. It cannot be reversed into your identity.
- A record that the deletion happened, keyed to that hash — counts only, no email, no account id.
- Purchase and entitlement records, if you ever bought something: the law requires us to keep tax and accounting records for the statutory tax and accounting retention period in Mexico, counted from the date of purchase, and a refund or a card dispute can post-date deletion. These keep the purchase's link to the account id; they carry no gameplay content.
- Spend records, anonymised: the rows that say a forge roll, a reforge or a BP transaction happened survive with your account id replaced by a random token and the request identifiers removed — deleting an account deletes the person, not the fact that a transaction happened. The same token is used across these rows so they cannot be joined back to you through a shared item.
- The other player's receipts. A duel is a two-party record: the other player keeps their history and their replay link. Your side of every duel is cleared (your champion's identity is removed and the fight renders anonymously); the build snapshots those surviving replays need are kept with the champion identity cleared, and every other snapshot of yours is deleted. Settled black-market trades survive the same way: your side is anonymised with the token above, the other player's side is untouched.
- Shared sprite-generation jobs, anonymised: if a cosmetic sprite you requested is still being generated for other players too, the job survives with your identity removed.
- Reports you filed about other players, as moderation records — deleting a reported account must not erase evidence about other players.
- Admin actions taken about your account (compliance records, for example a moderation decision or a purchase restored by hand). These keep the account id and, where the action was recorded against your email address, that address. They are not used for anything but audit.
- Short-lived abuse-control counters that expire on their own.
Everything else is gone. This list is enforced by an automated check in our code: a new kind of personal data cannot be added to the Game without being either deleted here or listed above with a reason.
7. Your rights
Depending on where you live (GDPR and similar laws, and Mexico's LFPDPPP): access, correction, deletion, portability, restriction, objection, and complaint to your data protection authority. Write to admin@duelsmith.com; we answer within 30 days. Deleting in-app (clause 6) is the fastest path for erasure.
8. Children
The Game is not directed at children under 13 (or your country's digital consent age). We don't knowingly collect their data; if you believe a child is playing, contact us and we'll delete the account.
9. Changes
Material changes to this policy are announced in-game or in our community channels before they take effect, and the date at the top of this page changes.