Back to the tower gates

Wersja polska

Privacy Policy
and Cookies - "Krucza Wieża"

This Policy sets out how personal data of users of the game and service "Krucza Wieża" (kruczawieza.com) are collected, processed and protected under the GDPR and Polish data protection law.

This is an English translation of the Polish "Polityka Prywatności". It is provided for convenience. In case of any discrepancy, the Polish version prevails.

§ 1. Data Controller

  1. The controller of personal data of players and users of the service is: Mateusz Włodarczyk, running a sole proprietorship under the name Keka Studio Mateusz Włodarczyk, address: ul. Portowa 31 lok. B/4, 47-205 Kędzierzyn-Koźle, Poland, NIP (tax ID): 7492116633, REGON: 525298125, e-mail: kruczawieza@gmail.com (the "Controller"). Publishing brand / studio: Keka Studio (kekastudio.pl).
  2. For matters concerning the processing of personal data and the exercise of data protection rights, you can contact the Controller directly at the e-mail address above or through the dedicated support channels in the game / on Discord.

§ 2. Definitions and Scope of Processing

Personal data means any information relating to an identified or identifiable natural person. To provide the browser game we collect and process data:

  1. Directly from the User: when registering an account, contacting support, buying virtual currency or taking part in community initiatives (e.g. login, e-mail address, encrypted password).
  2. Automatically: when using the service and the game (e.g. IP address, cookies, server logs, data on activity and game progress).
  3. From third parties: e.g. from the payment operator (transaction statuses) and external security and authentication providers.

§ 3. Purposes and Legal Bases of Processing

Purpose of processing Type of data Legal basis (GDPR)
Creating and running the game account Login, e-mail address, encrypted password, account identifier Art. 6(1)(b) (performance of the contract / Terms of Service)
Payments and handling of PSS Tokens Transaction history, payment status, billing data (no access to full card numbers) Art. 6(1)(b) and (c) (tax and accounting obligations)
Security and abuse detection IP address, server logs, browser and system information, security signals (Cloudflare) Art. 6(1)(f) (legitimate interest: protection against bots and multi-accounts)
Handling reports, complaints and support E-mail address, identifier, communication tags (e.g. Discord), content of correspondence Art. 6(1)(b) and (f)
Analytics and service optimisation (optional) Traffic data, analytics events (Google Analytics 4, Meta Pixel) Art. 6(1)(a) (consent in the cookie banner)
Ads on the Chronicle and guide pages (Google AdSense) Advertising identifiers, Google partner cookies, approximate location, data on visits to content pages Art. 6(1)(a) (consent) and legitimate interest for non-personalised ads
Rewarded ads in the mobile app (Google AdMob), started only by the player Device advertising identifier (on iOS only after consent to tracking), IP address, device model and system, information on ad display and viewing Art. 6(1)(a) (consent in the Google window) and legitimate interest for non-personalised ads
Service messages about the account and the game (not marketing) E-mail address, account identifier, necessary technical data Art. 6(1)(b) (performance of the contract) and (f) (security and stability of the service)
Direct marketing, newsletter, promotions, win-back campaigns for inactive players E-mail address, nickname / identifier, account activity status (when needed for selection) Art. 6(1)(a) (separate, voluntary consent); does not follow from creating an account

§ 3a. E-mail, Marketing and Win-back Campaigns

  1. Service messages (not marketing) may be sent to the e-mail address linked to the account when needed to provide the game or protect the account. Examples: registration confirmation, password reset, security alert, important changes to the Terms or the Policy, outages, settlement of PSS Token purchases, answers to a player's report.
  2. Direct marketing includes, among others, the newsletter, promotional offers, advertising information about events and news, and campaigns encouraging inactive players to return ("ghost" accounts / accounts not logged into for a long time).
  3. Having an e-mail address on the account is not consent to marketing. We do not treat registration or signing in as automatic consent to marketing messages or win-back campaigns.
  4. We send marketing messages and win-back campaigns only when the User gives separate, voluntary consent (a field at registration, a one-time window after a change of this Policy, or the "Game e-mails" switch in the game Options, Account tab). The consent field is never pre-ticked. Consent can be withdrawn at any time as easily as it was given: with the same switch in the game Options or by e-mail to kruczawieza@gmail.com. Withdrawal does not affect the lawfulness of earlier processing or service messages.
  5. Text of the consent (version of 25 September 2026, translated from Polish): "I agree to receive, at the e-mail address I provided, messages about Krucza Wieża, including news, events, new features, offers and promotions. I know that consent is voluntary and I can withdraw it at any time." We store the decision, its date, the version of the text and where it was given (registration, window, Options) with the account, to be able to demonstrate consent.
  6. Until such consent is collected, the Controller does not run mass marketing mailings or win-back campaigns to addresses from player accounts based on registration alone.
  7. Apart from the GDPR, in electronic communication we also apply the requirements of Polish law on electronically supplied services and electronic communications (in particular the requirement of consent to e-mail marketing towards natural persons, where the law requires it).

§ 4. Data Recipients and International Transfers

  1. We share data only with entities without which the game and the service do not work, or with services the User chooses to use. With processors acting on our behalf we conclude data processing agreements (Art. 28 GDPR). Current list of recipients:
    Recipient Purpose Country Basis for transfer outside the EEA
    Seohost (seohost.pl) Game VPS server, database, backups, mail relay Poland (EEA) not applicable
    Cloudflare, Inc. Content delivery network, protection against attacks and bots (IP address, request headers) USA (servers also in the EEA) European Commission adequacy decision (EU-US Data Privacy Framework) for certified entities, otherwise Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Stripe Payments Europe, Ltd. and Stripe, Inc. Payments on the game website and in the Windows client (card, BLIK, Przelewy24 as payment methods handled by Stripe) Ireland (EEA), USA European Commission adequacy decision (EU-US Data Privacy Framework) for certified entities, otherwise Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Google Ireland Ltd and Google LLC Google Play (installation and in-app payments), sign-in with a Google account, Google AdSense on content pages, Google AdMob in the app, push notifications (Firebase Cloud Messaging) and Google Analytics 4 on the game website (fonts are served from our own server, without Google Fonts) Ireland (EEA), USA European Commission adequacy decision (EU-US Data Privacy Framework) for certified entities, otherwise Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Apple Distribution International Ltd App Store: installation of the iOS app and in-app payments Ireland (EEA), USA European Commission adequacy decision (EU-US Data Privacy Framework) for certified entities, otherwise Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Valve Corporation (Steam) Steam release of the game: sign-in with a Steam account (Steam identifier), Steam payments, achievements USA European Commission adequacy decision (EU-US Data Privacy Framework) for certified entities, otherwise Standard Contractual Clauses (Art. 46(2)(c) GDPR); for sign-in with a Steam account also Art. 49(1)(b) GDPR (performance of a contract at the User's request)
    Discord Inc. Linking the game account with Discord (OAuth, Discord identifier), reports (tickets) and announcements on the Discord server USA European Commission adequacy decision (EU-US Data Privacy Framework) for certified entities, otherwise Standard Contractual Clauses (Art. 46(2)(c) GDPR); for account linking also Art. 49(1)(b) GDPR
    Resend, Inc. Sending service e-mails (registration, password reset, purchase confirmations) and, after consent, marketing e-mails: e-mail address and message content USA European Commission adequacy decision (EU-US Data Privacy Framework) for certified entities, otherwise Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Meta Platforms Ireland Ltd Meta Pixel on the game website and landing pages, only after consent in the cookie banner Ireland (EEA), USA European Commission adequacy decision (EU-US Data Privacy Framework) for certified entities, otherwise Standard Contractual Clauses (Art. 46(2)(c) GDPR)
  2. Player data are not sold. Google receives only the data needed to display an ad: in AdSense on content pages (Chronicle, guide) after cookie consent, and in AdMob in the mobile app when the player chooses to watch an ad. We do not give Google the e-mail address, nickname or game progress.
  3. Data may also be disclosed to public authorities when the law requires it (e.g. at the request of a court, prosecutor or tax office).
  4. A copy of the safeguards used for transfers outside the EEA (e.g. Standard Contractual Clauses) can be obtained by writing to the Controller's address given in § 1.

§ 5. Data Retention

  1. Data linked to a player account are stored for as long as the game account is active.
  2. After an account is deleted or erasure is requested, data may be kept for the limitation period of possible civil law claims and as required by tax and accounting law (up to 5-6 years for financial records).
  3. Server logs and IP addresses collected for technical and security purposes are regularly reviewed and deleted or anonymised after no more than 90 days.

§ 6. Your Rights

Under the GDPR every User has the following rights:

  1. the right of access to data and to obtain a copy;
  2. the right to rectification (correction) of data;
  3. the right to erasure ("right to be forgotten"), including by deleting the game account (instructions, also without signing in: Delete your account);
  4. the right to restriction of processing;
  5. the right to data portability (structured format);
  6. the right to object to processing based on the Controller's legitimate interest;
  7. the right to withdraw consent at any time (in particular consent to e-mail marketing and win-back campaigns), without affecting the lawfulness of processing before withdrawal;
  8. the right to lodge a complaint with the supervisory authority, the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland, if you believe the processing breaches the law.

To exercise your rights, contact the Controller: kruczawieza@gmail.com.

§ 7. Cookie Policy

  1. The "Krucza Wieża" service uses cookies (small text files stored on the User's device).
  2. Necessary (session) cookies are essential for the game to work and for authorising the session of a signed-in player (e.g. the kw_session cookie). They are required to provide the service electronically and do not need separate consent.
  3. Analytics and marketing cookies: tools such as Google Analytics 4, Meta Pixel and Google AdSense (on the Chronicle and guide pages) start only after consent in the cookie banner. Without consent the Google Analytics, Meta Pixel and Google AdSense scripts are not loaded. We do not load AdSense ads in the gameplay itself. Rewarded ads in the mobile app are described in § 7b.
  4. Your choice (consent or refusal) is saved locally in the browser so that we do not ask on every visit. You can clear the site data in your browser to see the banner again and change your decision.
  5. The User can change browser settings at any time to block or delete cookies, but this may prevent correct sign-in and gameplay.

§ 7a. Google AdSense Ads

  1. On public content pages of the service (e.g. About the game, Getting started, FAQ, landing pages, Contact) we may display Google AdSense ads. There are no ads in the browser version of the game: the Arena, the Camp and the HUD stay clean. In the mobile app there are only rewarded ads started by the player (§ 7b).
  2. Google, as a third-party vendor, uses cookies to serve ads based on the user's visits to this service and other websites. Google partners may also show ads on our content pages.
  3. How Google uses data from partner sites: policies.google.com/technologies/partner-sites.
  4. You can turn off personalised Google ads at adssettings.google.com. You can also block cookies in your browser. Non-personalised ads may still appear on content pages.
  5. AdSense publisher ID of this site: pub-2809178567337103. Contact about ads and data: contact page or kruczawieza@gmail.com.

§ 7b. Rewarded Ads in the Mobile App (Google AdMob)

  1. In the Krucza Wieża apps for Android and iOS a player may voluntarily watch a short video ad in exchange for an in-game reward (e.g. Echo, Arena entry, support in the Seeker). An ad never starts by itself. There are no banners or ads interrupting gameplay in the app.
  2. Ads are provided by Google Ireland Ltd (Google AdMob). When an ad is shown, Google collects the device advertising identifier, IP address, device model and system, and information on ad display and viewing.
  3. On devices in the European Economic Area the app shows the Google consent window before the first ad. Without consent Google shows non-personalised ads. On iOS the system also asks for consent to tracking; without it the advertising identifier is not shared.
  4. You can withdraw consent in the device settings (Android: Settings → Google → Ads; iOS: Settings → Privacy & Security → Tracking) or by writing to kruczawieza@gmail.com. How Google processes these data: policies.google.com/technologies/partner-sites.
  5. Watching an ad is not a condition of using the game: an ad gives a bonus or shortens a wait that can also simply be waited out.

§ 8. Technical Safeguards

The Controller applies technical and organisational measures that protect personal data against unauthorised disclosure, loss or destruction. This includes in particular encryption of data transmission using SSL/TLS, secure password hashing in the database and regular security reviews of the infrastructure.

§ 9. Changes to the Privacy Policy

This Policy may be updated from time to time due to technological changes, legal requirements or new features. Users will be notified of material changes in advance by a message in the game or directly in the service.

This Policy is available in Polish and in English. In case of any discrepancy between the language versions, the Polish version prevails.