Rules and policy content can be versioned by the authorised operator. The deployed business must publish its complete legal identity and official contact details before commercial launch.
1. Scope and responsibility
This notice applies to the website, accounts, card creation, moderation, decks, matches, rankings, VIP, support and enabled payment or advertising features. Arcane Nexus is operated under the supervision of Relconn. Before accepting real users, the deployed operator must publish its complete legal identity, contact channel and any locally required privacy contact in this policy.
2. Data we collect
We collect only data needed for the purposes described below.
- Account data: email, display name, password hash, verification state, locale, roles and consent evidence.
- Social sign-in data: Google or Discord account identifier, verified email and display name when enabled and chosen. Provider access and refresh tokens are not retained.
- Game and UGC data: cards, revisions, artwork, decks, rooms, commands, events, results, ratings, reports and moderation records.
- Security data: IP address, device/browser data, sessions, timestamps, diagnostic logs and anti-abuse signals.
- Payment data: payment intent, amount, status, hashed transaction/slip references, transaction time, receiving bank and masked receiver details. Uploaded slip bytes are discarded by this application after verification.
3. Purposes and legal basis
Data supports account and contract delivery, gameplay, content and deck validation, moderation, rankings, security, fraud prevention, support, service improvement and legal compliance. Depending on applicable law, processing may rely on performing the service agreement, legitimate interests in security and operation, consent for optional features, or a legal obligation. Consent can be withdrawn where it is the applicable basis without affecting prior lawful processing.
4. Public content
Approved cards, creator display names, public rooms, match results and leaderboard entries may be visible to others and indexed where the public page permits. Do not include sensitive personal data in names, lore or artwork. Private account and admin surfaces are not intended for search indexing.
5. Providers, transfers and disclosure
Configured hosting, database, storage, email, identity, anti-abuse, monitoring, payment and advertising providers process data only for their role. These may include Google, Discord, Cloudflare, Resend, SlipOK and Google AdSense when the operator enables them. SlipOK receives a submitted slip and transaction data for verification; Cloudflare Turnstile may process browser, device, network and interaction signals. A provider may process data in another country under its terms and applicable transfer safeguards. Data may also be disclosed when lawfully required or necessary to protect users and the service. Personal data is not sold.
6. Cookies, ads and device storage
Essential cookies or similar storage support secure sessions, abuse prevention and continuity. The language selector stores the chosen language on the device. Google Ads remain disabled until the operator configures valid AdSense details, policy approval and any required Google-certified consent management platform. Non-essential advertising storage must follow the user's applicable consent choice. VIP suppresses Google ad units and their script, while clearly labelled Sponsor content may remain visible. Blocking essential storage can prevent sign-in.
7. Retention and deletion
Active account and game data is retained while needed to provide the service. Payment ledgers and integrity hashes may remain for accounting, fraud prevention, disputes and legal duties. Security, moderation and audit records may remain longer to resolve incidents or repeat abuse. The deployed operator must define and publish exact retention periods that match its real infrastructure. Deletion requests are subject to lawful exceptions, backups and records needed to establish or defend claims.
8. Security and automated integrity checks
Access controls, password hashing, encryption in transit, rotating sessions, Admin TOTP, audit logs, file-signature checks and least privilege reduce risk. Server validation and deterministic integrity checks may automatically reject illegal decks, commands, files, duplicate slips or abusive traffic. Significant moderation decisions remain reviewable by authorised staff. No online system is risk-free.
9. Your choices and rights
Depending on applicable law, you may request access, a copy, correction, deletion, restriction, objection, portability or consent withdrawal and may complain to the competent data-protection authority. Identity may be verified and lawful exceptions may apply. Use the official support/privacy channel published by the deployed operator; never send a password, one-time code or unnecessary identity document.
10. Children, updates and contact
A user must be legally able to consent to the service or have valid parent or guardian permission where required. The service is not designed to solicit sensitive data from children. Material policy changes update the version and effective date and may require notice or renewed consent. The operator must replace placeholder support destinations before launch.
English is the default service text. If a translation differs in meaning, the English text controls, without reducing mandatory rights under applicable law.