1. Scope and operator status
This policy applies to the Xaldia public website, browser game, account system, multiplayer services, public community pages and web Shop available through xaldia.com.
Xaldia is operated by Charles Legault as a Québec sole proprietor trading as Xaldia. Privacy questions and rights requests can be sent to [email protected]; account, purchase and general support can be sent to [email protected].
2. Information Xaldia collects or generates
Account information
- For a Xaldia account: account identifier, email address, password hash and account creation timestamp.
- For Google sign-in: Google account subject identifier, email address when provided by Google, display name when provided by Google, and timestamps associated with the linked identity.
- Authentication/session information, including signed access and refresh tokens and the account identifier associated with them.
Browser session information
The current browser client stores an access token and account identifier in sessionStorage. It stores the refresh token, account identifier, selected character information and last-login timestamp in localStorage so the account session can be restored. These values can be removed by signing out or clearing site data in the browser.
Game and community information
Xaldia maintains information needed for a persistent MMORPG, such as characters, character names and appearance, class and skills, progression, inventory and equipment, game economy, deaths and prison state, housing, guild membership and invitations, gameplay state and other character snapshot data. Some information, such as character profiles, rankings, guild information, housing information and selected activity records, can be displayed publicly as part of the game community.
Moderation data can include account mutes, the reason for a mute, the moderator account involved and related timestamps. The audited PostgreSQL schema does not contain a table that archives ordinary live chat messages.
Commerce information
For real-money purchases Xaldia creates and keeps an internal commerce record that can include an order identifier, checkout request identifier, account or character identifier where relevant, product, amount, currency, fulfillment type and quantity, order status, Stripe Checkout Session identifier, Stripe PaymentIntent identifier, checkout expiry and payment/refund/dispute/cancellation timestamps. Xaldia also keeps entitlement and event-reconciliation records needed to deliver, restore or revoke purchased digital entitlements.
Technical and security information
The game server uses the connection address, including a trusted reverse-proxy forwarded address where applicable, as an in-memory key for authentication rate limiting. Hosting, network and third-party providers may also process ordinary request metadata such as IP address, timestamps, device/browser information and network diagnostics according to their own services and configurations.
3. Why Xaldia uses this information
- create and authenticate accounts and maintain signed-in sessions;
- link a Google identity to the correct Xaldia account;
- save characters and the persistent game world;
- operate rankings, public profiles, guilds, houses and multiplayer features;
- provide moderation, security, fraud prevention and rate limiting;
- create purchases, verify payment status, deliver digital goods and reconcile refunds or disputes;
- diagnose reliability and understand public-site usage when analytics is active;
- comply with legal obligations and establish, exercise or defend legal rights when necessary.
Xaldia should only collect information that is necessary for identified purposes. Where consent is required by applicable law, the service must obtain valid consent before the relevant collection, use or disclosure.
4. Google sign-in and Google user data
Xaldia uses Google Identity Services for sign-in. The browser receives a Google ID token and sends that credential to the Xaldia game server. The server validates the token for Xaldia's configured Google client ID.
After verification, Xaldia uses the Google subject identifier to recognize the linked account and stores the email address and display name supplied in the verified token when those claims are present. The audited application code does not persist the raw Google ID token after verification.
Xaldia does not request access to Google Drive, Gmail, Google Contacts or a user's files through this sign-in flow. Google identity data is used for authentication and account linking, not for advertising profiles.
Google user data can be shared with the Xaldia server and database only as necessary to provide the sign-in/account function, and with service providers that operate the underlying hosting or infrastructure. Privacy, access, correction and deletion requests can be sent to [email protected].
5. Browser storage, analytics and similar technologies
Xaldia uses browser localStorage and sessionStorage for account/session state as described above. These technologies are necessary for the current sign-in experience and are separate from advertising cookies.
The public site uses Cloudflare Web Analytics for aggregate website measurement and performance information. Xaldia does not load Google Analytics 4 on the public landing pages after this policy update and does not use the public-site analytics layer to build advertising profiles.
If Xaldia later adds optional analytics, advertising, identification or profiling technologies that require consent or prior activation under applicable law, they will not be treated as strictly necessary merely to avoid asking for consent.
6. Payments, Stripe and digital purchases
Xaldia uses Stripe Checkout in hosted-page mode for supported real-money purchases. The audited Shop offers diamond packs priced in Canadian dollars. The Xaldia server creates a server-authoritative order and sends Stripe the product name and description, amount, currency, Xaldia order identifier and product identifier needed to create the Checkout Session.
Payment-card details are entered on Stripe's hosted payment page. The audited Xaldia application code does not receive or store a full card number or card security code. Xaldia receives and stores payment-related identifiers and status information needed to verify the transaction and deliver the digital entitlement.
Stripe may collect additional customer and payment information directly in its checkout, including an email address and payment method data. Stripe processes that information under its own legal and privacy responsibilities.
7. Game Camera, television and WebRTC
Xaldia includes an in-game Camera/television feature. Despite its name, the audited capture code records a live stream of the rendered game canvas. It does not call the browser device-camera or microphone capture API.
The feature uses WebRTC video connections. The Xaldia game server relays signaling information such as broadcast identifiers, player identifiers, SDP offers/answers and ICE candidates so authorized peers can connect. Video is sent peer-to-peer when possible. A TURN service, if configured, can relay the video when a direct connection is not possible.
The default WebRTC configuration uses Cloudflare's public STUN endpoint. The audited code contains no MediaRecorder-based recording or database persistence of the video stream. Active broadcast/viewer state is maintained in server memory for the live session.
8. Service providers and infrastructure
| Provider / technology | Role | Information that may be involved |
|---|---|---|
| Google Identity Services | Account sign-in | Google subject identifier, email/display name when supplied, ID-token verification data. |
| Cloudflare Web Analytics | Aggregate public-site analytics and performance measurement | Website usage and performance information processed through Cloudflare's analytics service. |
| Stripe | Hosted payment processing | Checkout/customer/payment information and transaction identifiers/statuses. |
| Cloudflare Pages | Public website hosting and delivery for xaldia.com | Ordinary web request and hosting metadata processed to serve the public site. |
| OVH infrastructure | Authoritative game server identified in the project deployment documentation | Account, game, commerce, network and server data handled by the backend. |
| PostgreSQL | Application database technology | Persistent account, identity, character, community, moderation and commerce records. |
| Cloudflare STUN | WebRTC network discovery | Network connection metadata needed to establish a WebRTC route. |
| Optional TURN service | WebRTC relay when configured | Network metadata and relayed game-video traffic. The actual production TURN provider must be confirmed if enabled. |
9. Processing outside Québec or Canada
Google, Stripe, Cloudflare and infrastructure/network providers are global services and information can be processed outside Québec or Canada depending on the service and configuration. Québec law can require a privacy impact assessment before communicating personal information outside Québec and contractual safeguards appropriate to the assessment.
The source repository does not prove that the required privacy impact assessments and processor agreements have been completed for production. That operational compliance work must be confirmed by the operator before launch.
10. Retention, deletion and anonymization
Authentication credentials use short technical lifetimes (for example, access tokens are issued with a 15-minute lifetime and the legacy refresh-token path uses a 30-day lifetime). Account and persistent game data are kept while needed to operate the account and game, protect the service, resolve disputes and meet applicable legal obligations.
When personal information is no longer required for an identified purpose or legal obligation, Xaldia will destroy it securely or anonymize it where the law permits. Transaction, accounting, fraud-prevention or dispute records can be kept longer when required or reasonably necessary for legal, tax, financial or security obligations.
A player may request access, correction or deletion/anonymization by contacting [email protected]. Requests are handled subject to identity verification and any lawful retention exception.
11. Security
Xaldia uses measures visible in the audited code such as password hashing, signed authentication tokens, server-side validation, authentication rate limits, server-authoritative purchase pricing, verified Stripe webhooks, restricted database roles and an authoritative game server. Stripe live Checkout is restricted by the server code to HTTPS origins.
No Internet service can promise absolute security. Security controls are reviewed and may change as the game evolves. This policy intentionally does not publish secrets, private keys or operational details that could weaken security.
12. Your privacy rights
Subject to applicable law, people can have rights to know what personal information is held about them, obtain access, request correction, withdraw consent where applicable, and in appropriate circumstances request deletion, anonymization or de-indexing.
Charles Legault is Xaldia's person responsible for the protection of personal information. Send privacy and data-rights requests to [email protected]. General account or purchase support can be sent to [email protected].
Mandatory rights available under Québec law and other applicable laws remain available regardless of this policy. Québec privacy information is available from the Commission d'accès à l'information du Québec.
13. Children and teenagers
Xaldia is intended to be capable of serving a broad, family-inclusive audience rather than imposing a blanket 13+ rule. That does not remove age-specific privacy rules. Where applicable law requires parental or guardian authorization below a local age of digital consent, that authorization must be obtained before the relevant personal information is collected or used.
The current account flow does not yet include the verified parental-consent service required for younger users in all launch countries. Xaldia therefore must not knowingly enroll a child who requires verified parental authorization until that production flow is enabled. Real-money purchases by a minor also require the authorization legally required in the minor's jurisdiction.
14. Privacy incidents
Xaldia must maintain operational procedures for confidentiality incidents, including assessment, mitigation, required notices and the legally required incident register. The public repository does not by itself prove that the operator's incident-response register and escalation process exist outside the codebase.
15. Changes, questions and complaints
Material changes to privacy practices should be reflected in an updated version of this policy and communicated in a manner appropriate to the change before new uses that require consent take effect. The effective date and last-updated date appear at the top of this page.
A verified operator address, privacy-responsible-person contact and support channel still need to be supplied and published. Until then, Xaldia should not represent this page as proof of complete legal compliance.