Privacy policy
Data & Privacy
Last updated: June 4, 2026.
This privacy policy explains how the Castle & Compliance marketing website handles personal data. It covers this static marketing website only, not future game builds, storefronts, Discord/community spaces, newsletters, playtest forms, or third-party download platforms.
Short version: we do not run accounts, newsletters, analytics pixels, advertising trackers, social media embeds, third-party video embeds, or active download tracking on this site. We do not set our own cookies. The site is delivered through Cloudflare, which necessarily processes technical request data to serve, cache, and protect the website. The download button links to itch.io, which handles downloads under its own terms and privacy notices. The download key request form sends your email address to us through a Cloudflare Worker so we can reply manually. The audio mute button may store a local browser preference so it can remember your choice.
Controller
The controller for this website is Jan Landowski, Togostraße 29B, 13351 Berlin, Germany.
Privacy contact: [email protected]
Website Hosting
This website is hosted and delivered through Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you visit the site, technical request data is necessarily processed so the page and media files can be delivered, secured, cached, and protected from abuse.
This technical data may include your IP address, requested files or URLs, date and time of access, user agent, referrer information, Cloudflare Ray ID, TLS and routing metadata, and security-related request metadata. We use this only to operate, secure, troubleshoot, and maintain the website.
We do not operate our own additional server logs for this static site. Cloudflare may make operational, security, cache, performance, or aggregate traffic information available in its dashboard depending on the enabled Cloudflare services.
The legal basis is our legitimate interest in providing a secure and available website under GDPR Article 6(1)(f), where the GDPR applies. Cloudflare may process data outside the EEA/UK/Switzerland and describes its transfer safeguards in its Data Processing Addendum and Privacy Policy.
Cloudflare references: Privacy Policy, Data Processing Addendum, and Cloudflare Cookies.
Cookies and Local Storage
We do not set first-party cookies. The current site does not use Google Analytics, Meta Pixel, newsletter tracking, advertising identifiers, embedded social widgets, or third-party video embeds.
Cloudflare may set strictly necessary cookies if Cloudflare security, bot protection, challenge, rate limiting, load balancing, or similar availability features are enabled. Examples may include cookies such as __cf_bm, cf_clearance, or _cfuvid, depending on the Cloudflare configuration. These cookies are used to provide and protect the website, not for our advertising or profiling.
The audio mute button may store the key cac-theme-muted in your browser's local storage. Local storage is not a cookie, remains on your device, is not sent with normal page requests, and can be removed by clearing site data in your browser.
Analytics and Tracking
We do not currently use client-side analytics, advertising pixels, fingerprinting, heatmaps, or behavioral profiling. Cloudflare may provide aggregated traffic, performance, cache, and security metrics based on its edge network logs and service operation.
If Cloudflare Web Analytics, an embedded store widget, newsletter signup, feedback form, telemetry, crash reporting, or any other analytics tool is added later, this policy must be updated before that feature goes live.
Contact by Email
If you contact us by email, including through the download key request form, we process the email address you provide or send from, your name if provided, the content of your message, and normal technical email metadata. We use this data to answer your message and manage the related communication.
The legal basis is our legitimate interest in responding to inquiries under GDPR Article 6(1)(f), and GDPR Article 6(1)(b) if your message relates to a possible contract, playtest access, or download request. We retain email communication only as long as needed for the relevant conversation, documentation, and legal obligations.
Downloads and Playtests
The download button on this website opens a password prompt and then links to the Castle & Compliance page on itch.io. Following that link leaves this website and takes you to an external platform operated by itch.io. We do not embed an itch.io widget on this website and do not collect download, purchase, playtest, account, telemetry, crash report, or feedback data through this static website.
itch.io may process personal data and use cookies or similar technologies when you visit, download, purchase, log in, comment, or otherwise use itch.io. Please review the itch.io Privacy Policy and itch.io Cookie Policy for details.
If embedded store widgets, direct downloads, playtest forms, Discord/community channels, crash reporting, in-game telemetry, or feedback tools are connected later, their data processing details must be added to this policy.
User Rights
Depending on the law that applies to you, you may have rights to request access, correction, deletion, restriction of processing, data portability, or objection to processing. Where processing is based on consent, you may withdraw that consent at any time.
You may contact us through the privacy contact above to exercise your rights. If GDPR applies, you also have the right to lodge a complaint with a competent data protection supervisory authority.
No Sale or Targeted Advertising
We do not sell personal data and do not share personal data for cross-context behavioral advertising. The current site does not include targeted advertising or ad measurement technologies.
Automated Decisions
The current site does not make automated decisions about visitors and does not profile visitors for legal, financial, access, pricing, or similar effects.
Changes
We will update this policy when the website, hosting setup, contact options, analytics, cookies, downloads, playtest flow, or legal provider details change. The date at the top shows the current version.