1. Who controls your data
The data controller is:
- Name
- Calogero Nicosia, sole trader
- Trading name
- Mythic Harmonies
- Business number
- 0762.947.956
- VAT number
- BE0762947956
- Address
- Rue de Stembert 264, box B314, 4800 Verviers, Belgium
- Privacy contact
- contact@mythic-harmonies.com
- Telephone
- +32 455 17 90 00
No data protection officer is appointed at the current scale. The email above is the privacy contact.
Effective date: 25 August 2026.
2. The short version
- We use account and story data to provide the game you request.
- Stripe handles payment details. Complete card details never pass through Viking Saga.
- Google Analytics is off until you actively accept it. Refusal does not reduce access to the game.
- Push notifications are optional and controlled separately.
- Your Oracle question and recent saga context are sent to Anthropic only when you use that feature.
- You can withdraw consent, access your data or request account deletion.
3. Data we use
| Category | Examples |
|---|---|
| Account | Email address, Firebase user ID, authentication provider, account timestamps. |
| Player profile | Chosen pseudonym, age range, gender, declared country, birth month, clan, origin, intention and animal. |
| Game and story | Choices, rune draws, statistics, referral data, community actions and the complete saga stored in your account. |
| Oracle and generated content | Your free-form question, chosen action, mood, rune, pseudonym and the three most recent saga chapters sent to generate the requested response. |
| Subscription | Stripe customer identifiers, subscription status, trial history, invoice and payment state. Complete card data stays with Stripe. |
| Optional analytics | After consent: a Google Analytics client identifier linked to your Firebase user ID, clan and Premium status, plus product events. |
| Optional push | The browser push subscription endpoint and delivery status. |
| Security and diagnostics | Reduced server log labels, HTTP status categories and minimized Sentry error events. Free-form error messages, user IDs, emails and Stripe IDs are excluded from application logs by construction. |
A pseudonym or Oracle question can still contain personal or sensitive information if you type it. Do not enter information that is not needed for the experience.
4. Why we use it and our legal bases
| Purpose | Legal basis |
|---|---|
| Create your account, provide the game, save your saga, generate requested text and operate chosen community features. | Performance of our contract with you. |
| Create, bill, manage and cancel Premium. | Performance of our contract with you. |
| Keep invoices, tax records and legally required evidence. | Compliance with a legal obligation. |
| Measure product use through Google Analytics. | Your consent. No analytics storage or server analytics event is authorized by the mere presence of an identifier. |
| Send browser push notifications. | Your consent. |
| Secure the service, prevent abuse and fraud, diagnose faults and defend legal claims. | Our legitimate interests, balanced against your rights and limited through data minimization. |
5. Service providers and recipients
| Provider | Role and data |
|---|---|
| Google Firebase Authentication | Authenticates accounts using email/password or Google sign-in. The service operates from US data centres. |
| Google Cloud Firestore | Stores account, profile, story, game, consent and limited server workflow data. The production database is in europe-west1 in the European Union. |
| Stripe | Processes payment methods, subscriptions, invoices, billing portal sessions and payment-related country evidence. |
| Vercel | Hosts the application and server functions. Application log values are restricted to closed, non-personal sets. |
| Sentry | Receives reconstructed, minimized server error events. User, request, header, body, breadcrumb, machine name and unrestricted source fields are removed. |
| Google Analytics | Receives data only after per-account opt-in consent. Advertising storage, advertising user data and ad personalization remain denied even when product measurement is accepted. |
| Anthropic | Generates story and Oracle content from the context required for the request. |
| Browser push provider | Google, Mozilla, Apple or another provider chosen by your browser routes encrypted push messages and sees the endpoint and delivery volume. |
We do not sell personal data.
6. International transfers
Some providers process data outside the European Economic Area. This includes Firebase Authentication in the United States and may include other global provider operations. Where required, transfers are governed by the provider's data-processing terms and recognized safeguards such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or Standard Contractual Clauses.
You may contact us for more information about the safeguard relevant to a particular provider.
7. Analytics and cookies
Google Analytics is closed by default. It starts only after you choose Accept for the signed-in account. Declining analytics leaves the full game usable.
When accepted, Viking Saga sets Google Analytics cookies named _ga and _ga_*, sends the Firebase user ID as a Google Analytics User-ID, and sends clan and Premium status as user properties. Cookies and consent expire after 183 days without rolling extension. GA4 user-linked event data is configured for two months; aggregate figures may remain in standard reports.
You can change your choice in Privacy settings. Refusal immediately disables collection, removes the active User-ID, deletes the analytics cookies and starts a retryable server deletion if the consent projection cannot be removed immediately. Advertising storage and personalization stay denied in every case.
8. How long data is kept
| Data | Current retention |
|---|---|
| Account, profile, saga and game statistics | While the account relationship remains open, until you delete the account or ask us to delete it. A 24-month inactivity routine exists only in simulation and is not currently used to delete accounts. Accounts without a notification channel are not automatically deleted under the current design. |
| Payment service data | During the subscription and until account deletion, subject to Stripe's own legal retention obligations. |
| Invoices and tax or accounting records | Ten years from 1 January following the relevant period where Belgian law requires it. |
| Analytics consent and server projection | 183 days without rolling renewal; deleted immediately on refusal. |
| Google Analytics user-linked data | Two months. Aggregated reports may persist. |
| Server analytics deduplication records | 31 days. |
| Push subscription | Until withdrawal, technical invalidation or account deletion. |
| Sentry error events | Up to 30 days under the current plan. Events are minimized and tracing and profiling are disabled. |
| Vercel function logs | One day under the active Pro plan. |
| Anthropic inputs and outputs | Normally deleted by the provider within 30 days. Security, abuse or legal exceptions may require longer retention. Provider trust and safety systems may retain flagged content or related safety scores for longer periods. |
| Closed support requests | 24 months, unless a legal dispute or obligation requires longer retention. |
9. Your rights
Depending on the circumstances, you may have the right to:
- receive information and access a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- object to processing based on legitimate interests;
- receive portable data where the legal conditions apply;
- withdraw consent at any time, without affecting earlier lawful processing;
- complain to a data protection authority.
Send a request to contact@mythic-harmonies.com. We may ask for proportionate proof that you control the account. We will not ask for your password or complete card details.
You can delete your account from the application after any billable subscription has ended. This removes the active account and game data through a server-controlled process. Legally required accounting records and provider records subject to independent legal obligations may remain for their required periods.
You may also complain to the Belgian Data Protection Authority: autoriteprotectiondonnees.be.
10. Generated content and automated decisions
Viking Saga uses automated generation to create narrative content you request. Rune draws and generated text do not make decisions that produce legal or similarly significant effects about you. They are part of the creative experience and should not be treated as professional advice or factual prediction.
11. Minors
The service records an age range and does not ask for an exact date of birth. If you are a minor under applicable law, use Viking Saga with the involvement of a parent or legal guardian and do not purchase Premium without their authorization. A parent or guardian may contact us about a minor's data.
12. Changes and contact
We may update this policy when the service, providers, retention periods or legal requirements change. Material changes will be brought to your attention where required. The current version will show its effective date.
Questions and requests: contact@mythic-harmonies.com.