ᛚᛖᚷᚨᛚ
Privacy
Last changed 20 September 2026. This page says what Nornloom keeps about you when you play online, why, for how long, and what you can ask for. It is written under the General Data Protection Regulation (GDPR) and the Polish Personal Data Protection Act.
Who is responsible
The controller is KB Info Krzysztof Bialowas, Poland. Write to privacy@nornloom.com about anything on this page. There is no data protection officer; the operator answers in person.
Playing alone keeps nothing until you sign in
A solo hero is saved on your device, in the browser's storage or the app's data. Nothing about it is sent anywhere until you sign in; from then on a copy is kept for your account, as listed below. Clearing that storage removes the hero from the device. In the browser and in the Android app alike, nothing leaves the device until you sign in.
What the worlds keep when you sign in
᛫
Your sign-in: the site's host (Microsoft Azure Static Web Apps) lets you sign in with GitHub, a Microsoft account or a Google account and sets one cookie for that. The worlds receive an opaque id from the provider and the name it shows for you, which for a Microsoft or Google account is usually its e-mail address. No password or profile is asked for or stored. The name is kept for support only and is never shown to other players.
᛫
In the Android app: the sign-in itself happens on the site, in your phone's browser, with the same cookie. The app is then handed a sign-in token, which it keeps in the device's protected storage for up to 30 days and sends to the worlds in place of the cookie. Signing out in the app deletes it. The token names your account id and the display name above, nothing else.
᛫
Your heroes: name, look, level, gold, gear, cards, decks, quests and where they stand. Other players see a hero's name, level and look. Every change of gold is written to a ledger so the worlds can be checked for cheating.
᛫
Your solo heroes: each one's save (name, look, level, gold, gear, cards, decks, quests and where it stands), kept whole so it follows you between devices. Nobody else sees it and the worlds do not read it. Forgetting the hero removes the copy; deleting the account removes them all.
᛫
Hero names: a name you choose is checked before it is accepted, by the name rules and by Microsoft's Azure AI Content Safety service, which sees the name and nothing else. Refused names are kept so the keepers can tune the rules.
᛫
Parcels between heroes: gold, items, cards and a short note, until claimed or returned.
᛫
Reports: when a player reports another, the report and a short note are kept for the keepers.
᛫
Play days: the days you entered a world or a solo save landed, with the country the connection came from as Cloudflare reads it and nothing finer, so the keepers can see how many people play and from where. Gone with the account.
᛫
Technical logs: the world servers log joins, leaves, fights and errors with hero names, and the hosting keeps connection logs (IP addresses) for a short time for security.
᛫
Chat is not stored. Words the name rules refuse are dotted out as they pass; nothing is kept.
Why, and on what basis
᛫
To run the game you asked for (performance of a contract, GDPR art. 6(1)(b)): your sign-in and your heroes.
᛫
To keep the worlds fair and safe (legitimate interest, art. 6(1)(f)): the ledger, reports, moderation and the technical logs.
᛫
To meet legal duties (art. 6(1)(c)) where the law asks.
᛫
Nothing is sold, no advertising is shown, and no profile is built. There is no analytics or tracking beyond the host's connection logs.
Where, and who else sees it
The worlds and their database run in the European Union (Microsoft Azure, West Europe). Cloudflare stands in front of the worlds' address and serves the site's domain name, so every connection to the worlds passes through it and it sees your IP address on its own terms; it also forwards mail sent to the address above. Microsoft (hosting, the sign-in token service with its request logs, and the Microsoft sign-in), GitHub (the GitHub sign-in) and Google (the Google sign-in) act on their own terms for the sign-in itself. No data is handed to anyone else, unless the law requires it.
How long
᛫
Your account and heroes, solo and on the worlds: while you play. A hero left alone is not deleted by itself; a solo hero you forget is gone from the account at once.
᛫
When you delete your account: the worlds stop your heroes at once; after 7 days every hero is emptied and renamed, parcels waiting for them go back to their senders, and the account keeps only an anonymous row so the ledger still adds up. Signing in again within those days keeps the account.
᛫
Reports: 365 days, then dropped.
᛫
Technical logs: a few weeks, then dropped.
Your rights
You can ask what is kept about you, have it corrected, have it deleted, have its use limited, receive a copy of what you gave, and object to the uses based on legitimate interest. Deleting your account is a button on the title screen; for anything else write to privacy@nornloom.com. If you think your data is handled wrongly you may complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl) or to the authority of the country you live in.
Age
Playing online is for people aged 16 or older, the age at which a person in Poland may agree for themselves. If a younger person has signed in, write and the account is removed.
Changes
When this page changes, the date at the top changes with it and the sign-in box says so.