Breach — Privacy Policy
Effective: 13 September 2026
Who we are: Warewolf Technologies ("Warewolf", "we") runs Breach at playbreach.net.
This policy says what information Breach collects, why, where it's kept, who else handles it, how long we keep it, and what you can ask of us. Breach is built to hold as little about you as it can: there's no advertising, no analytics tracking, nothing is sold, and nothing in the game is bought with real money.
1. What we collect, and why
If you play as a guest
- A random account id and a session token, kept in your browser so it recognises you next time. No name, no email. A guest can practise against the bot and nothing else, and the account is gone when you clear your browser.
When you register
- Email address — to verify that the address is yours, to reset your password, and to send you the occasional notice about your account (a suspension, a change to these documents, a shutdown). We don't send marketing.
- Password — stored only as a salted hash (scrypt). We can't read it.
- Callsign — your public name in Breach. Opponents see it unless you turn on Remain anonymous in-match, in which case they see OPERATOR.
- Your look and settings — Emblem, Banner, colour, worn Title, display and sound options — so they follow you between devices.
- Sessions — a hashed token and timestamps for each device you're signed in on, so you can be signed in on more than one and sign them out.
While you play
- Match records — for every online match: who played (by account id), the mode and clock, every move in order with timestamps, the result, both ratings before and after, and which build of the rules it was played on. This is what lets a match resume after a disconnect, be replayed to check a report, and be settled correctly.
- In-match chat — every line, with the Callsign it was sent under and the time. Chat is relayed through our server and kept with the match, so a player who reconnects can see what was said and a report about an opponent has something to show.
- Ratings, Tokens and progress — your Datacores, a ledger of every Token granted, won or spent, your win streak, daily mission progress, record (played / won / drawn), kills, and which Agents and Provisions you've fielded.
- What you own — your inventory, and the squad and kit you've arranged.
- Practice matches — saved in your browser only, never sent to us.
When you report something
- Bug reports and feature requests (Report a Bug in the header) — what you typed, the name you optionally give for a reply, your account id and Callsign at the time, and which build of the game you were on.
- Player reports (Report Opponent in the match Menu) — the reason, what you typed, the match it's about, the reported account and its Callsign at the time, and whether you flagged the chat log. The whole conversation is already stored with the match and is read as part of handling the report, whichever way the flag is set.
Technical information
- Your IP address — used while you're connected to limit how fast frames and guest accounts can be created from one place, and to avoid pairing two accounts from one network in a ranked match. It isn't stored in our database, and it reaches our server logs only when a connection is refused before it has signed in (see section 4).
Moderation
- If your account is suspended: when it lifts, and the reason, which is shown to you.
- Titles handed out by us.
We don't collect your real name, date of birth, location, payment details, or anything from your device beyond what's listed here.
2. Where it's stored
Our game server runs on Fly.io and our database on Neon, both in Sydney, Australia. Nothing during a match touches the database; a match is written when it ends.
3. Who else handles your information
We use a small number of providers to run Breach. Each receives only what it needs:
| Provider | What they do | What they see |
|---|---|---|
| Fly.io | Runs our game server (Sydney) | All game traffic passes through their infrastructure, including your IP address; they hold our server logs |
| Neon | Hosts our Postgres database (Sydney) | Everything in section 1 that's stored |
| Resend | Delivers our email — verification links, password resets, account notices | Your email address and the message. Resend is a US company and processes mail in the United States |
| Google Fonts | Serves the fonts the page uses | Your IP address and browser details when the page loads, as with any request to Google |
We don't use analytics, advertising networks or social plug-ins, and we don't sell or rent personal information to anyone.
We'll disclose information where the law requires it — to a court, or to the eSafety Commissioner under the Online Safety Act, for example — or where it's necessary to protect a player or the service from serious harm.
4. How long we keep it
While your account is open, everything above stays, so the game works.
Verification links expire 24 hours after they're sent and password reset links after one hour; both are single-use, and expired ones are cleaned up.
An unfinished registration — an address you registered but never verified — is removed after 7 days, and the Callsign it reserved is released. You can ask for a new verification link at any time before then; afterwards, register again. If you registered from a guest account, that account stays as a guest account with its practice record.
Sessions are removed when you sign out, when you reset your password (which signs out every device), and when you close your account.
In-match chat is kept for 90 days after a match, then deleted — or, where a report was made about the match, for as long as the report is kept.
Reports and feedback are kept for 90 days, then deleted — longer only while we're still acting on one, such as a suspension under appeal.
Server logs are held by our hosting provider for as long as its platform keeps them; the server itself holds only its last few hundred lines, in memory. An IP address appears in them only when a connection is refused before it has signed in.
Match records and the Token ledger are kept indefinitely. They're the record of the ladder and of every Token that ever moved, and they're your opponents' history as much as yours. After you close your account they're no longer linked to anything that identifies you.
When you close your account (Account screen → Delete account):
- your email, password hash, sessions, inventory, loadout and anything else that identifies you are deleted, and your Callsign is released;
- a de-identified account record stays, with the ratings, records and Token ledger attached to it, so the matches and Tokens of the players you played stay consistent;
- your matches stay, with your seat unlinked from you; chat you sent stays with the match under the Callsign it was sent with, but linked to no account;
- reports you made, or that were made about you, stay, unlinked from your account (the Callsign as it stood at the time remains on them);
- we keep a keyed hash (HMAC) of your email address — not the address — so that if you register again we can recognise a returning player and number the accounts. The address can't be recovered from it.
Guest accounts hold nothing that identifies you. We may clear unregistered ones that haven't been used for a while.
5. Cookies and browser storage
Breach doesn't use cookies. It uses your browser's local storage for:
- your session token and a cached copy of your account, so you stay signed in;
- a practice match in progress, so you can resume it;
- the Signal Feed of an online match in progress, so a reload can show it again;
- where the music was up to, and which Titles you've already seen.
Clearing your browser's site data for playbreach.net removes all of it and signs you out. Google Fonts sets no cookies; the font request itself is covered by Google's privacy policy.
6. Security
All traffic is over HTTPS, and we send an HSTS header so browsers refuse plain HTTP. Passwords are hashed with scrypt; session, verification and reset tokens are signed and stored only as hashes. Recovering a password signs out every device. Sign-in doesn't reveal whether an address is registered. Your email address is never shown in the interface unless you press Reveal on the Account screen.
No system is perfectly secure. If we become aware of a data breach likely to cause you serious harm, we'll tell you and the Office of the Australian Information Commissioner, as the Privacy Act requires. To report a vulnerability: security@playbreach.net (see playbreach.net/.well-known/security.txt).
7. Your choices and rights
- See what we hold. Your Account and Profile screens show most of it. For a full copy, email privacy@playbreach.net from your registered address and we'll send it within 30 days.
- Correct it. Callsign, look and options are yours to change in the game. For your email address, write to us.
- Stay anonymous to opponents. Turn on Remain anonymous in-match on your Profile.
- Delete it. Account screen → Delete account, or write to us. Section 4 says what remains.
- Ask a question or complain. Email privacy@playbreach.net; we'll respond within 30 days. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
8. Children
Breach is for players 16 and over, and players under 18 should have a parent or guardian's permission. We don't knowingly collect information from anyone under 16; if you believe we have, contact us and we'll delete it. Parents can ask us to close a child's account and to see what it holds.
9. Changes
We'll update this policy when Breach changes — new social features, a new way to sign in, or a new provider on the list above. The date at the top says when. For changes that matter, we'll say so in the game and, if your address is verified, by email.
10. Contact
Warewolf Technologies
- Privacy: privacy@playbreach.net
- Security: security@playbreach.net
- Support: support@playbreach.net