BREACH

Breach — Privacy Policy

Effective: 13 September 2026

Who we are: Warewolf Technologies ("Warewolf", "we") runs Breach at playbreach.net.

This policy says what information Breach collects, why, where it's kept, who else handles it, how long we keep it, and what you can ask of us. Breach is built to hold as little about you as it can: there's no advertising, no analytics tracking, nothing is sold, and nothing in the game is bought with real money.

1. What we collect, and why

If you play as a guest

When you register

While you play

When you report something

Technical information

Moderation

We don't collect your real name, date of birth, location, payment details, or anything from your device beyond what's listed here.

2. Where it's stored

Our game server runs on Fly.io and our database on Neon, both in Sydney, Australia. Nothing during a match touches the database; a match is written when it ends.

3. Who else handles your information

We use a small number of providers to run Breach. Each receives only what it needs:

ProviderWhat they doWhat they see
Fly.ioRuns our game server (Sydney)All game traffic passes through their infrastructure, including your IP address; they hold our server logs
NeonHosts our Postgres database (Sydney)Everything in section 1 that's stored
ResendDelivers our email — verification links, password resets, account noticesYour email address and the message. Resend is a US company and processes mail in the United States
Google FontsServes the fonts the page usesYour IP address and browser details when the page loads, as with any request to Google

We don't use analytics, advertising networks or social plug-ins, and we don't sell or rent personal information to anyone.

We'll disclose information where the law requires it — to a court, or to the eSafety Commissioner under the Online Safety Act, for example — or where it's necessary to protect a player or the service from serious harm.

4. How long we keep it

While your account is open, everything above stays, so the game works.

Verification links expire 24 hours after they're sent and password reset links after one hour; both are single-use, and expired ones are cleaned up.

An unfinished registration — an address you registered but never verified — is removed after 7 days, and the Callsign it reserved is released. You can ask for a new verification link at any time before then; afterwards, register again. If you registered from a guest account, that account stays as a guest account with its practice record.

Sessions are removed when you sign out, when you reset your password (which signs out every device), and when you close your account.

In-match chat is kept for 90 days after a match, then deleted — or, where a report was made about the match, for as long as the report is kept.

Reports and feedback are kept for 90 days, then deleted — longer only while we're still acting on one, such as a suspension under appeal.

Server logs are held by our hosting provider for as long as its platform keeps them; the server itself holds only its last few hundred lines, in memory. An IP address appears in them only when a connection is refused before it has signed in.

Match records and the Token ledger are kept indefinitely. They're the record of the ladder and of every Token that ever moved, and they're your opponents' history as much as yours. After you close your account they're no longer linked to anything that identifies you.

When you close your account (Account screen → Delete account):

Guest accounts hold nothing that identifies you. We may clear unregistered ones that haven't been used for a while.

5. Cookies and browser storage

Breach doesn't use cookies. It uses your browser's local storage for:

Clearing your browser's site data for playbreach.net removes all of it and signs you out. Google Fonts sets no cookies; the font request itself is covered by Google's privacy policy.

6. Security

All traffic is over HTTPS, and we send an HSTS header so browsers refuse plain HTTP. Passwords are hashed with scrypt; session, verification and reset tokens are signed and stored only as hashes. Recovering a password signs out every device. Sign-in doesn't reveal whether an address is registered. Your email address is never shown in the interface unless you press Reveal on the Account screen.

No system is perfectly secure. If we become aware of a data breach likely to cause you serious harm, we'll tell you and the Office of the Australian Information Commissioner, as the Privacy Act requires. To report a vulnerability: security@playbreach.net (see playbreach.net/.well-known/security.txt).

7. Your choices and rights

8. Children

Breach is for players 16 and over, and players under 18 should have a parent or guardian's permission. We don't knowingly collect information from anyone under 16; if you believe we have, contact us and we'll delete it. Parents can ask us to close a child's account and to see what it holds.

9. Changes

We'll update this policy when Breach changes — new social features, a new way to sign in, or a new provider on the list above. The date at the top says when. For changes that matter, we'll say so in the game and, if your address is verified, by email.

10. Contact

Warewolf Technologies