← Back to RuneTD
Privacy Policy
Last updated: July 10, 2026
RuneTD is a small, independently-run game. This policy explains what data we collect and why,
in plain language. If anything here is unclear, contact us at
[email protected].
1. What this covers
This policy applies to runetd.com, runetd.pages.dev, and the RuneTD
game client (together, the "Service"). It describes what information we collect when you play as a
Guest, when you sign in with a Google or email account, and how that information is stored, used,
and protected.
2. Information we collect
Guest play (no account)
- Your character save (level, inventory, gear, quest progress) is stored only in your
browser's local storage. It never reaches our servers unless you sign in or manually
export/import a save file.
- A randomly generated guest name (e.g. Guest-4F2A) is created locally and is not linked
to any personal information.
Signed-in play (Google or email account)
- Google Sign-In: if you choose to sign in with Google, we receive your Google
account ID, display name, and email address, via Google's OAuth service. We do not receive your
Google password, and we do not read your Gmail, Drive, or other Google data.
- Email sign-in: if you choose email sign-in, we collect the email address you
provide and send a one-time verification code to it (via our email provider, Resend). We never
ask you to create or enter a password.
- Gameplay data: once signed in, your character save, chosen character name,
in-game currency, inventory, and progress are stored on our servers so you can play across
devices.
- Multiplayer & chat (planned feature): when hub chat and friends lists go
live, messages you send in global or hub chat, and your friends list, will be stored so the
feature can function. Chat messages may be visible to other players in the same hub.
Automatically collected data
- Standard web server logs (IP address, browser type, request timestamps) collected by our
hosting provider, Cloudflare, for security and abuse prevention.
- We do not use third-party advertising trackers or sell any data to advertisers.
RuneTD does not run ads.
3. How we use this information
- To let you create an account, save progress, and play across devices.
- To operate multiplayer features (hub presence, chat, friends) once they launch.
- To detect and prevent cheating, abuse, spam, and security threats.
- To send you account-related email (e.g. sign-in codes) — never marketing email without your
opt-in.
4. Who we share it with
We do not sell your personal information. We share limited data only with the service providers
that make RuneTD work:
- Google — for Google Sign-In authentication.
- Resend — to deliver one-time email sign-in codes.
- Cloudflare — for hosting, our database (D1), and multiplayer infrastructure
(Durable Objects / WebSockets).
Each of these providers has its own privacy policy governing how they handle data on our behalf.
We may also disclose information if required by law.
5. Children's privacy
RuneTD is intended for a general audience and is not directed at children under 13. We do not
knowingly collect personal information from children under 13. If you believe a child has created an
account or provided personal information to us, please contact us at
[email protected] and we will delete it.
6. Data retention & deletion
- Guest saves live only in your browser and are removed if you clear your browser storage or use
the "Reset save data" option in the Support menu.
- Account data is retained while your account is active. You can request deletion of your account
and associated data at any time by emailing us — we'll confirm and remove it within a reasonable
timeframe.
7. Your choices
- Play entirely as a Guest and never share personal information with us.
- Export your save at any time from the Support menu to keep your own backup.
- Request access to, correction of, or deletion of your account data by contacting us.
8. Security
We use industry-standard practices to protect your data, including encrypted connections (HTTPS),
passwordless authentication (so there's no password to leak), and a strict content security policy
that limits what the game client can connect to. No method of transmission or storage is 100% secure,
but we don't ask for or store anything more sensitive than we need to run the game.
9. Changes to this policy
We may update this policy as RuneTD's features change (for example, when multiplayer chat launches).
We'll update the "Last updated" date above when we do. Continued use of the Service after changes means
you accept the updated policy.
10. Contact
Questions about this policy or your data: [email protected]