‹ BACK TO RIFTBORN

RIFTBORN

PRIVACY POLICY

Last updated 2026-09-30

The short version

Who this covers

Riftborn is a small independent browser game, played at riftborn.us (it used to be at chancrisp.github.io/riftborn). This page explains what the game and its online service (the leaderboard and Riftborn accounts) keep about you. It covers the live game, its classic edition at riftborn.us/classic/ and the test build at dev.riftborn.us.

What is stored if you have a Riftborn account

A “Riftborn account” means you signed in with Google, Discord or GitHub and then chose a username. We store:

Signing in creates a few short-lived working records (for example, while you are choosing a username). They expire within 15 minutes at most, and are deleted when used or by the server’s routine cleanup, which runs about every 10 minutes while accounts are in use.

What is not stored

The sign-in platforms and what we ask for

When you press Continue with a platform, your browser goes to that platform’s own sign-in page, and its privacy policy applies to that step. We ask for the smallest permission each one offers, and read only your account number:

The platform’s temporary access code is used once during sign-in and is not stored. You can remove Riftborn’s access at any time in your platform’s own settings (Google Account security, Discord Authorized Apps, GitHub Applications). That stops future sign-ins with that platform but does not delete your Riftborn data; use Delete account for that.

How the data is used

Only to sign you in, keep your progress and cosmetics with your Riftborn account, and show your username on the leaderboard. It is never sold, never shared except as described on this page, and never used for advertising or profiling. There are no analytics or tracking scripts in the game or on this page.

The game is hosted on Cloudflare Pages, and the leaderboard and accounts run on Cloudflare too (a Worker and its database, at api.riftborn.us). Feedback messages are also posted to Discord (see Feedback messages below). Those services handle your requests in the normal way and may keep their own standard logs under their own policies. Cloudflare’s short-lived operational logs for our Worker record each request, including its web address: a name being checked for availability, or the one-time codes of a sign-in (useless minutes later), can appear there. We read those logs only to fix problems.

Feedback messages

The game’s FEEDBACK form is optional and sends nothing until you press SEND. A message includes what you write, a category, an optional star rating and an optional contact line (Discord or email, only if you type one and want a reply). To help fix bugs it also adds basic technical context: game version, browser and operating system name, screen size, whether you used touch, mouse or a controller, average frame rate, a few game settings and a short summary of your last run. The form shows the exact data under “WHAT GETS SENT”. Your IP address is not stored, and feedback is not linked to your account.

Feedback also goes to Discord. So the developer sees new feedback quickly, each message is also posted to a private channel on the developer’s Discord server: its category, star rating, whether it came from the live game or the test build, and the start of your message (up to 300 characters). Your contact line and the technical details are not included in that post. Discord stores that copy under Discord’s privacy policy. Please do not put private details in the message text.

Storage on your own device

Riftborn keeps its data in your browser’s local storage. It holds: your settings, your saved progress on this device, scores and boards saved on this device, scores or feedback waiting to be sent, the last name you used, your sign-in token if you are signed in, a random one-time check value while a sign-in is in progress (it stops working after 10 minutes, and is deleted when the sign-in finishes or is cancelled, or replaced when the next one starts), and small flags such as which intro or notes you have seen. It stays on your device until you clear this site’s data in your browser settings.

Moving from the old address: when you open the old address (chancrisp.github.io/riftborn), it moves the game data saved there in your browser to riftborn.us in the same browser: your saved progress, settings, scores and boards saved on the device, and anything waiting to be sent. Sign-in details are never moved. The data travels in the part of the web address after the # sign, which browsers do not send to any server, and riftborn.us removes it from the address as soon as the page opens. The copy at the old address stays as it was.

Cookies: no tracking or advertising cookies, and the game itself sets none. The only cookie is a sign-in security cookie: when you press Continue with Google, Discord or GitHub, the Riftborn sign-in server sets one short-lived cookie (10 minutes) on its own address (api.riftborn.us). It holds a random value and nothing about you, and makes sure the sign-in finishes in the same browser that started it.

Deleting your data

Children

Riftborn is not aimed at children under 13. Google, Discord and GitHub set their own minimum ages for their accounts. Guests provide no personal information. If you think a child has made a Riftborn account, tell us through FEEDBACK and we will delete it.

Changes to this policy

If this policy changes, the “Last updated” date above changes with it, and significant changes will also be mentioned in the game’s patch notes.

Contact

Open Riftborn and press the FEEDBACK button on the main menu. Guests and signed-in players can both use it.