Privacy Policy
This is a translation provided for convenience. In case of any discrepancy, the Portuguese version prevails.
This policy explains what personal data One Punch Idle collects, what we use it for, who we share it with, how long we keep it and how you exercise your rights, in accordance with Brazil's General Data Protection Law (LGPD, Law 13,709/2018). It applies to the game at play.onepunch-idle.com and to the website at onepunch-idle.com, and complements the Terms of Use.
1. In short
- We collect only what is needed for the game to work and stay secure: username, email, password (stored only as a hash), game data and some technical security data.
- We do not sell your data, we do not run advertising and we use no third-party analytics or trackers.
- Your card number and Pix details stay with the payment provider, not with us.
- The IP address is stored masked or as a hash in our security logs.
- You can ask for access, correction or deletion of your data by emailing [email protected].
2. Who looks after your data
One Punch Idle is the controller of the personal data processed in the game and on this site. Contact channel for any privacy and data protection matter: [email protected].
3. What the game collects and why
| Data | Purpose | Legal basis (LGPD) |
|---|---|---|
| Username | To identify you in the game, rankings, chat, Guilds, friendships and the Market. It is public to other players. | Performance of a contract (art. 7, V) |
| To confirm the account, recover the password, notify you of security changes (password change, email change, 2FA activation), remind you to confirm your email and contact you about donations and support. It also prevents mass fake accounts: we store a standardized form of the address to stop variations of the same email from creating several accounts. | Performance of a contract (art. 7, V) and legitimate interest in fraud prevention (art. 7, IX) | |
| Password | To authenticate you. We store only a strong hash (argon2id), never the password in plain text. | Performance of a contract (art. 7, V) |
| Two-step verification (2FA), if you turn it on | To protect your login. The authenticator app secret is stored encrypted and the recovery codes are stored only as a hash. | Performance of a contract (art. 7, V) |
| Game data: cards, currencies and items, transaction history, progress, fights and replays, missions, Pass, mail, friendships, gifts, blocks, Guilds, invites, listings and trades on the Market | To make the game work, calculate results on the server, keep the history of your items and fix errors. | Performance of a contract (art. 7, V) |
| Chat messages and reports | To show chat to other players and enable moderation. When someone reports a message, its text is kept together with the report. | Performance of a contract (art. 7, V) and legitimate interest (art. 7, IX) |
| IP address (stored as a hash or masked) and a summary of the device and browser (for example, "Chrome · Windows") | Account security, limiting login attempts, preventing fraud and multiple accounts by the same person, and the list of active sessions you see in your account settings. | Legitimate interest (art. 7, IX) |
| Session cookie | To keep you logged in. See section 5. | Performance of a contract (art. 7, V) |
| Security, anti-fraud, moderation and audit logs | To record account events (sign-up, login, password or email change, 2FA, sessions ended), detect and investigate fraud and abuse, and record moderation and game administration actions. | Legitimate interest (art. 7, IX) and regular exercise of rights (art. 7, VI) |
| Donation data: amount, currency, payment method (card or Pix), date, status and Stripe transaction identifiers | To deliver the reward, handle refunds and disputes, and meet legal and tax obligations. Card and Pix data are handled only by Stripe. | Performance of a contract (art. 7, V) and compliance with a legal obligation (art. 7, II) |
| Anti-bot check (Cloudflare Turnstile) | At sign-up, login and password recovery, to keep bots out. Cloudflare analyzes technical signals from the browser and sends us back only the result. | Legitimate interest (art. 7, IX) |
| Messages sent to support | To answer your request and keep the support history. | Performance of a contract (art. 7, V) and legitimate interest (art. 7, IX) |
We do not ask for your full name, tax ID, address, phone number, date of birth or sensitive personal data. We do not use your data for advertising. We do not currently send promotional emails; if we ever do, it will be only with your permission and with a simple way to unsubscribe.
4. What this site collects
The presentation site (onepunch-idle.com) has no sign-up, forms, first-party cookies, analytics or third-party trackers. Fonts and images are served by the site itself. Like any web server, it records technical data about each visit (IP address, date and time, page requested and browser) for security and to fix problems. These records are automatically deleted on a rotation, normally within a few weeks.
5. Cookies and browser storage
- The game uses a single first-party cookie, the session cookie, which is strictly necessary to keep you logged in. It is protected (it cannot be read by page scripts, it only applies to the game's address and it is only sent over a secure connection), expires after 7 days without use and lasts at most 30 days from login. Logging out deletes it.
- The game also stores some preferences in your own browser (for example, language, volume, animations and tutorial progress). This information stays on your device and you can erase it by clearing the site's data in your browser.
- Cloudflare, which protects the game and the site, may set its own technical security cookies, used to tell people from bots. We use no advertising or tracking cookies.
6. Who we share it with
We do not sell or rent your data. We share only what is necessary with service providers (processors), who handle the data on our behalf and for the purposes above:
- Stripe: processes donations by card and Pix. You enter your payment details directly on Stripe's page; we get back only the confirmation and the transaction identifiers.
- Hostinger: the service that sends the game's emails (email confirmation, password recovery and security notices). It receives your email, your username and the content of the message.
- Cloudflare: network, protection against attacks and anti-bot check (Turnstile). All access to the game and the site goes through it, so it handles your IP address and technical connection data.
- Vultr: hosting of the game's server and database, in the United States.
Other players see what is public in the game: username, progress shown in rankings and profiles, Team, Guild, chat messages and Market listings. Your email is never shown to other players.
We may also share data when the law or an order from a competent authority requires it, or to defend ourselves and protect other players in cases of fraud, scams or attacks.
7. International transfers
The game's server is in the United States, and Stripe, Hostinger and Cloudflare may process data in other countries. These transfers are necessary to provide the service you asked for and take place under art. 33 of the LGPD, with providers that adopt recognized standards of security and data protection.
8. How long we keep it
- Account and game data: as long as the account exists. After a deletion request, we delete or anonymize this data within 30 days, except what must be kept under the items below.
- Sessions: expire after 7 days without use and, at most, 30 days after login.
- Links sent by email: the email confirmation link is valid for 24 hours; the password reset link, 30 minutes. We store only a hash of them.
- Unconfirmed email: is removed from the account after 7 days without confirmation (with a reminder beforehand), freeing the address.
- Chat: each channel shows only the most recent messages, which are kept for up to 7 days. The copy used for reports lasts 24 hours. Reported messages are kept with the moderation record (below).
- Fights: PvP replays for 30 days; for the Abyss, only each player's latest fights.
- Game mail and friend requests: deleted about 30 days after they expire or are collected.
- Donations: 5 years, for tax and consumer-protection obligations, even if the account is deleted.
- Security, anti-fraud, moderation and audit logs: at least 6 months and at most 5 years, for as long as needed to prevent fraud and defend rights, even if the account is deleted.
- Web server access logs: automatically deleted on a rotation, normally within a few weeks.
- Database backups: automatically replaced within 14 days. Data deleted from the account disappears from the backups within that period.
9. Your rights
Under the LGPD (art. 18), you can ask, free of charge and at any time, for:
- confirmation that we process your data and access to it;
- correction of incomplete, wrong or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law;
- portability of your data;
- deletion of your data and of your account;
- information about who we share your data with;
- information about the possibility of not giving consent and the consequences of that, and withdrawal of consent, when consent is the basis for the processing;
- objection to processing carried out on the basis of legitimate interest, when it does not comply with the law;
- review of decisions made solely by automated means (see section 10).
Some things you can already do yourself in the game: change your password and email, turn 2FA on or off, view and end sessions. For other requests, write to [email protected] from the email registered on your account, stating your username. We may ask for identity confirmation to protect your account. We reply within 15 days.
Some data must be kept even after a deletion request, for the periods in section 8 (for example, donation and security records). If you are not satisfied with our reply, you can complain to Brazil's National Data Protection Authority (ANPD).
10. Automated decisions
Some of the game's protections work automatically: limits on login attempts, rules against multiple accounts and against artificially moving value on the Market, temporary holding of Diamonds received in trades, chat filters and the suspension of the account when a donation is disputed with the bank. They do not use sensitive data or build a profile for advertising. If an automated decision affects you, ask support for a review and a member of the team will look at the case.
11. Security
We protect your data with: encrypted connection (HTTPS), passwords stored with a strong hash, a protected session cookie, an encrypted 2FA secret, tokens and codes stored only as a hash, masked or hashed IPs, limits on attempts, anti-bot checks, restricted administrative access with mandatory 2FA, and audit logs that cannot be altered. No system is 100% secure. If a security incident occurs that may bring you relevant risk or harm, we will notify you and the ANPD, as the law requires.
12. Children and teenagers
The game is for people aged 16 or older and is not directed at children. Donations are for adults aged 18 and over only. We handle the data of players aged 16 to 18 in their best interest (art. 14 of the LGPD): we collect the minimum and do not run advertising or build profiles for commercial purposes. If we find an account belonging to someone under 16, it will be closed and the data deleted. Parents or guardians can write to support to request this.
13. Changes to this policy
We may update this policy when the game or the law changes. The version and date are at the top of the page. In case of a relevant change, we will announce it in the game or by email before it takes effect.
14. Contact
Questions or requests about your data: [email protected]. See also the Terms of Use.