bugfu.io

Privacy Policy

Version draft-1 · last updated 2026-10-05

Draft. This document is being prepared for review and is not yet in force. The marked callouts are decisions still to be made.

1. The short version

What this means: You can play anonymously. If you make an account we hold your email. There are no ads, no third-party trackers, and our analytics never leaves our servers.

bugfu.io is built to need very little about you. You can play without an account, identified only by a random token in your own browser. If you create an account, we hold your email address and the security records that protect it. Our analytics is our own, running on our own servers, and is not tied to your IP address or your name. There are no advertising networks, no third-party analytics, no external fonts or CDNs — the pages you load come from us.

Pending decision. The operator (data controller) has not been legally named yet. Until it is, the controller is the operator of bugfu.io, reachable at the contact address below.

2. Playing without an account

What this means: Anonymous play stores a random token in your browser. We cannot connect it to you — and if you lose it, neither can you.

When you first play, your browser generates and keeps an owner token — a random identifier stored in your browser's local storage. Your bugs, their names, and their fight records attach to that token. It contains nothing about you, and we cannot link it to a person unless you later create an account and claim it.

That cuts both ways: the token is the only key. If it is cleared with your browser data, we cannot restore what belonged to it — see the Terms.

3. What an account stores

What this means: Email, a hashed password, your display name, and your preferences.

Creating an account stores: your email address, a one-way hash of your password (never the password), your display name and its public handle (e.g. Name#1234), whether your email is verified, your email preferences, your control bindings and interface preferences, your chosen avatar, and your privacy toggles (public profile, findable by handle, friends may spar your bugs).

Signing in with your email also updates when you last signed in and from what IP address.

4. Security records: sessions and the sign-in log

What this means: Sign-ins, sessions, and account-security events are recorded with IP address and browser info, and the security log is deliberately permanent.

To keep accounts safe we record:

Our web server also keeps standard access logs (IP address, URL, time) for operations and abuse prevention.

5. Game data

What this means: Your bugs, their fights, and public replays. Replays are public recordings and a few hundred are kept at a time.

The game stores your bugs (name, species, appearance, experience, learned behavior), match results (who fought, who won, how long, what kind of room), and replays. Replays are recordings of matches: they carry the fighters' bug names and are watchable by anyone with the link. The jar keeps a pool of a few hundred recent recordings and retires the oldest as new ones arrive; archived ones are kept separately. A match that happened is a record with two participants — deleting an account does not retract replays of matches already played.

6. Purchases

What this means: Orders, subscriptions, and an append-only currency ledger. Payment providers handle your card; their receipts land in our records.

If you buy something we store the order (product, amount, status, and the payment provider's reference), any subscription (including the provider's customer and subscription identifiers), your entitlements, and an append-only amber ledger — every grant, purchase, and spend, kept permanently because the ledger's arithmetic is what makes balances trustworthy. We never see or store your card number; the payment happens on the provider's own pages.

Payment providers confirm events to us by webhook, and we keep those confirmations verbatim for audit. They can include details the provider collected from you — typically your name, email, country, and card brand and last four digits.

7. Analytics — self-hosted, and deliberately blunt

What this means: Our analytics runs on our own servers, keyed to a one-way hash, without your IP or browser fingerprint. Nothing is shared with anyone.

To understand whether the game works we record product events (a page viewed, a fight started, a purchase completed) on our own servers. An event carries: its name and time, a one-way hash of the owner token (never the token itself), the page path, the referring site (its hostname only), campaign tags if you arrived through one, a per-tab session identifier, platform, and locale. No IP address and no browser fingerprint are stored with analytics events. The data never leaves our infrastructure and is not shared with, or collected by, any third party.

8. Friends and invitations

What this means: Friend links use account IDs. Inviting someone by email stores only a hash of the address — declining is remembered forever, the address is not.

The friend graph stores which accounts are connected, blocked, or invited. If you invite someone by email, we send one invitation and store only a one-way hash of the address — enough to prevent repeat invitations and to honour an opt-out permanently, while holding no contact information for someone who never joined. Whether an address has an account is never revealed to the person asking. Notifications store references, not sentences.

9. Cookies and browser storage

What this means: Three first-party cookies, all for signing you in. Game preferences live in your browser’s local storage. No advertising or tracking cookies, so there is no consent banner.

Every cookie we set is first-party, same-site, and functional:

CookieWhat it does
bb_jwtYour sign-in credential. HttpOnly — scripts cannot read it.
bb_authenticatedLets the page render “signed in” without touching the credential.
bb_session_expiresDrives the idle sign-out countdown.

Your browser's local storage holds the anonymous owner token (section 2) and gameplay preferences — selected bug, camera, theme, presentation settings — and its session storage holds the per-tab analytics session id. All of it stays in your browser except where this policy says otherwise.

We set no advertising cookies, no third-party cookies, and load no third-party scripts, which is why there is no cookie consent banner. If that ever changes — for example, personalized ads in a portal build — consent will be asked first and this policy updated.

10. Who else receives data

What this means: Payment providers when you buy, an email delivery service when we mail you, our email platform for your email preferences and the newsletter, and our hosting. That is the list.

We share personal data only with the services that make the product work:

We do not sell personal data, run advertising networks, or share data with data brokers or analytics companies.

11. Email

What this means: Four kinds of mail, each with its own switch, and one-click unsubscribe that always works.

We send account email (verification, password resets, receipts), and — each under its own preference — notifications, digests, and product news. Every non-essential message carries a one-click unsubscribe that works without signing in, and an “unsubscribe from everything” that we honour permanently. Account-security messages cannot be disabled while the account exists, because they protect it.

12. Your rights: access, export, deletion

What this means: Download your data or delete your account yourself, from your profile page. Deletion detaches your bugs; security and financial records are kept because they must be.

Export: your profile page has a “download my data” button that hands you a JSON file of everything this policy describes — account, bugs, match results, purchases, ledger, sessions, security log, analytics events.

Deletion: the same page deletes your account, behind your password. Your account and email address are removed and your sessions revoked. Your bugs and their match history are detached and become anonymous rather than erased — match records and replays involve other players and remain, without your account attached. The append-only security log and the financial ledger are retained, because they are the records that disputes, refunds, and fraud prevention legally require. An active subscription must be cancelled first, so nothing keeps billing a person who has left.

Anything else — corrections, questions, data older than the export's caps — write to support@bugfu.io from the account's email address. We answer within 30 days.

Pending decision. Fixed retention windows for the security log, analytics events, and provider webhook records still need setting.

13. Children

What this means: Not for under-13s. If a child slips through, tell us and we close the account.

The service is not directed at children under 13, and we do not knowingly collect personal information from them. We collect no date of birth today. A parent or guardian who believes a child under 13 has an account can write to support@bugfu.io and we will delete it.

Pending decision. The age posture decision (see the Terms) may add an age declaration or gate, and with it stronger child-data handling; this section will be rewritten when it is made.

14. Changes and contact

What this means: Material changes are announced, not slipped in. One address reaches us.

When this policy changes materially we will say so on the site, and where the change affects data already collected, ask again rather than assume. The current version and its date are at the top of this page.

Privacy questions and requests: support@bugfu.io.