Privacy Policy
Psythons (the "Service") is operated by Sandhill Works, LLC ("we", "us", "our"), a limited liability company registered in the State of Florida, United States. This policy explains what personal information we collect, how we use it, and the rights you have over it.
1. Information We Collect
When you create an account we collect:
- Email address — used for login, password recovery, and essential service notifications.
- Username — the public identifier displayed to other players.
- Password — stored only in hashed form; we never see or keep your plain-text password.
During normal play we also store gameplay data associated with your account (Psythons you own, breeding history, battle records, trades, messages, currency balance, achievements, dex progress, and similar). This data is necessary for the Service to function and cannot be disabled while your account is active.
Our web server logs standard request metadata (IP address, timestamp, user-agent, URL path) for security, rate-limiting, and debugging purposes. These logs are automatically rotated and deleted after 30 days.
2. Cookies
We use only strictly-necessary cookies:
PHPSESSIDandpsython_session— used to keep you logged in.
We do not use advertising cookies, analytics cookies, or third-party tracking cookies. Because our cookies are strictly necessary for the Service to function, no consent banner is required under GDPR or the ePrivacy Directive. If this ever changes (e.g. we add analytics), we will update this policy and present a consent banner first.
3. How We Use Your Information
- To operate your account and provide the Service.
- To send essential account notifications (password resets, security alerts, service outages).
- To enforce our Terms of Service and prevent abuse.
- To send optional communications (newsletters, announcements) only where you have opted in. You can toggle these under Settings → Privacy & Notifications.
We do not sell or rent your personal information to anyone. We do not share it with third parties for advertising or profiling.
4. Legal Basis (GDPR)
If you are in the European Economic Area or United Kingdom, we rely on the following lawful bases:
- Contract — to create and maintain your account and provide the Service you signed up for.
- Legitimate interests — for server logs, security, and fraud prevention.
- Consent — for optional newsletters and announcements, which you can withdraw at any time.
5. Your Rights
You have the right to:
- Access your data — email us and we will provide a copy.
- Correct inaccurate data — update your username or email, or contact us.
- Delete your account and all associated data — available self-service under Settings → Account. Account deletion is permanent and immediate.
- Object to processing and withdraw consent for optional communications.
- Data portability — request an export of your account data.
- Lodge a complaint with your local data protection authority.
6. Data Retention
We keep your account data for as long as your account is active. When you delete your account, all personal data associated with you is removed immediately. Aggregated, non-identifying statistics may be retained. Security logs are rotated out after 30 days.
7. Children
The Service is not available to anyone under 13 years of age. You must confirm you are at least 13 when registering. If we discover that we have collected information from a child under 13, we will delete it promptly. Please contact us if you believe this has happened.
8. Security
Passwords are hashed before storage. Connections to our servers use HTTPS. We maintain reasonable administrative and technical safeguards. No Internet service can guarantee absolute security, and you use the Service at your own risk.
9. International Transfers
Our servers are located in the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. By using the Service you consent to this transfer.
10. Changes to This Policy
We may update this policy as the Service evolves. When changes are material, we will update the "Last updated" date above and, where appropriate, notify you in-game or by email.
11. Contact
Questions, requests, or complaints: privacy@sandhillworks.com.