Privacy & your data
Last updated: September 6, 2026
This notice describes the information used by VoltDuel at voltduel.io. For questions about the game or your personal data, contact the project operator at gustavo.faria1273@gmail.com.
Account and sign-in
We store your account identifier, chosen username and robot appearance. Password accounts use a password hash rather than a readable password. Session cookies keep you signed in. Temporary sign-in challenges help prevent replay and account takeover.
If you choose Google sign-in, we request basic identity permissions: OpenID, email and profile. Google supplies a signed identity token. We use your Google account identifier to create or link your game account, your name to initialize a display name, and the email-verification status to verify eligibility for the Google welcome reward. You choose your name in the arena. We retain the linked Google identifier, verification status and, for a claimed reward, a one-way identifier hash to prevent duplicate claims. We do not request access to Gmail messages, contacts, Drive files or calendars, and do not store Google access or refresh tokens for ongoing access.
You may revoke Google's authorization in your Google account settings. Revoking authorization does not automatically delete your game account or its financial history.
Gameplay and public profiles
We store match results, account balance history, robot customization, friends, messages, referral relationships and reports submitted to moderation. Your game name, robot, match statistics, ranking and profile balance history can be visible to other players. Messages are delivered to their recipients; game administrators can review reports and relevant evidence to handle abuse and support requests.
USDC and wallets
Wallet sign-in uses a public wallet address and a signature. We do not ask for your MetaMask seed phrase or private key. The server separately manages deposit addresses and the keys used by the game's custodial wallet system. Deposit and withdrawal amounts, addresses, transaction identifiers and ledger entries are retained for settlement, reconciliation and account history. Polygon blockchain transactions are public and cannot be erased by deleting a game account.
How data is used and shared
Data is used to run the game, authenticate players, settle matches and transfers, operate referrals and rewards, protect accounts, respond to support requests and investigate abuse. Google Cloud hosts the service in the United States and stores private backups. Google handles Google sign-in, MetaMask and its connection services handle wallet connections, and the configured Polygon RPC provider processes blockchain queries and transactions. These providers also apply their own privacy terms. We do not sell Google user data or use it for advertising profiles.
Browser storage and security
The browser saves settings such as language, graphics and controls. Essential cookies support authentication; invite information may be retained to associate a signup with a referral. IP addresses and connection information are processed for security, rate limits and infrastructure operation. HTTPS protects data in transit. Wallet secrets and integration credentials are encrypted in the application database; access to the production database and backups is restricted.
Optional usage metrics
If you allow usage metrics, we use a short-lived session cookie to count screens, loading outcomes, selected actions, a server-confirmed signup outcome, tutorial steps, device category and a campaign code such as utm_source. We do not record screens, form contents, chat messages, passwords, wallet secrets, full URLs or IP addresses in these usage events, and do not link them to an account identifier. You can disable usage metrics in the game settings; this also deletes the current analytics session and its events. Usage events are retained for up to 90 days. Separately, aggregate API error counts and existing account, tutorial and financial records help us operate and evaluate the service. These operational statistics are not disabled by the optional usage choice.
Retention and requests
Account and gameplay information is retained while the service maintains your account and history. Financial, reward and abuse-prevention records may need to remain after an account is closed to preserve reconciliations, prevent duplicate payouts and resolve disputes. Automated database backups are normally retained for 30 days, followed by the storage provider’s seven-day recovery window for deleted backups. Contact us to request access, correction or deletion of your personal information; we may need to verify control of the account and explain any records that must be retained. A future material change to our use of Google data will be disclosed before that new use begins.
gustavo.faria1273@gmail.com