The Lantern Tower (“we”) collects only the minimum information needed to run the beta, and tells you here what we collect, why, and for how long.
1. What we collect
- Required: email address and nickname. If you set a password, we store only an irreversible hash (argon2id), never the password itself.
- Usage records: sign-up and last sign-in time, game link records (hashes of sign-in tokens), beta download records (when and which version), co-op party and badge records.
- Bug reports: the report bundle (zip) you send — game logs, settings, game version, operating system and graphics card, and, if you choose, a screenshot and save files. The game masks your user folder path before sending.
- Connection data: to limit repeated attempts (brute-force sign-ins) we keep an irreversible hash of your IP address for up to one day. Server access logs are kept for up to 30 days for security and then deleted.
- We do not collect payment details, real names, phone numbers, postal addresses or location data.
2. Why we use it
- To identify your account, keep you signed in, confirm your email, and send password reset or sign-in code emails
- To provide beta downloads and prevent abuse (daily limit)
- To verify you in the co-op lobby and record badges and server-first records
- To handle bug reports and improve the game
- To send service notices (maintenance, important changes). We do not send marketing email.
3. How long we keep it
- When you delete your account, your account, nickname, email, badges and party records are deleted immediately.
- Bug reports and download records are unlinked from your account when you delete it, so they can no longer be tied to you. Report bundles (zip files) are deleted automatically 180 days after we receive them.
- Server-first records (the party that first defeated a boss) remain, but a deleted player’s nickname is removed from the list.
- Database backups kept for disaster recovery may hold deleted data for up to 14 days before they expire.
- Accounts whose email is never confirmed may be deleted after [to be decided: e.g. 30 days].
4. Sharing and processors
We do not sell or give your personal information to anyone. We may comply with lawful requests from authorities as required by law.
We use the following processor to run the service: Amazon Web Services (servers, database, file storage, email delivery · Asia Pacific (Seoul) region). [to be added if the email provider changes]
5. Cookies
We use a single cookie to keep you signed in (up to 30 days). We use no analytics or advertising cookies and no trackers.
6. Your rights
- On the account page you can view your details, change your nickname or password, and delete your account (immediately).
- For any other request to access, correct, delete or stop processing your data, contact us below. We reply within 10 days.
7. Children under 14
Children under 14 may not create an account. If we learn that we hold information from a child under 14, we delete it promptly.
8. How we protect it
- All traffic is encrypted with HTTPS.
- Passwords, sign-in tokens, email links and codes are stored only as hashes.
- The admin console is limited to administrator accounts. Bug report files and game builds are kept in private storage and handed out only through short-lived links.
9. Contact
Data protection officer: Park Suk-yang (creator of The Lantern Tower)
Contact: [to be added]
You can also contact the Korea Internet & Security Agency privacy center (privacy.kisa.or.kr, 118).
10. Changes
If we change this policy, we will announce it in the news section 7 days before it takes effect. Effective date: [to be decided] (draft)
