Privacy Policy
OSADA is a free, browser-based turn-based strategy game served at osada.fun. This policy explains what information the game and its server handle, and why. In short: you can play without an account, the game shows no ads and runs no analytics or tracking, and when you do sign in we keep only what is needed to store your saved games.
1. Playing without an account
Signing in is optional. As a guest, your saved games, settings and progress are kept only in your own browser's storage (localStorage and IndexedDB) on your device. They are not sent to our server. You can export them to a file and import them again at any time. Clearing your browser's site data deletes them.
2. Signing in with Google or GitHub
If you choose to create an account so your saves can follow you between devices, you sign in through Google or GitHub. These services only confirm who you are; they never store your saves.
- Google: we request only the
openidscope. We receive and keep a single opaque account identifier (thesubvalue) issued by Google for OSADA. We do not request or store your email address, name, profile picture, contacts or any other Google data. - GitHub: we request no scopes. We use the one-time access token to read your numeric GitHub user id, keep that id, and discard the token. We do not store your username, email or repositories.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data in detail
- Data accessed: only the OpenID Connect identifier (
sub) for your Google account, received once when you sign in. The ID token that carries it also contains its issuer, audience and expiry time, which we check and then discard. - How it is used: solely to recognise your OSADA account when you sign in again, so that your online saves are returned to you. It is not used for advertising, profiling, analytics, artificial intelligence or machine-learning, image generation, or any other purpose.
- Sharing: the identifier is not sold, transferred or disclosed to anyone. No third party, other than Google itself during sign-in, takes part in processing it.
- Storage and protection: the identifier is stored in the account database on the OSADA server, reachable only over encrypted HTTPS connections and accessible only to the server administrator. Session cookies are stored only as cryptographic hashes; sign-in uses the authorization-code flow with PKCE, a nonce and anti-forgery checks.
- Retention and deletion: the identifier is kept while your account exists and is deleted immediately when you delete the account (see section 9), or when the account is removed after inactivity.
3. What we store for an account
- An internal account id, the provider identifier described above, and the dates the account was created and last used for saving.
- Sign-in sessions: a random session cookie is set in your browser; the server keeps only a cryptographic hash of it, its expiry date (30 days, renewed while you play) and a protection token against cross-site requests. You can sign out on this device or on all devices.
- The saved games you upload: campaign and battle saves, hero records, custom rule sets, together with a short summary (campaign, turn, dates) and the amount of storage used.
- Short-lived technical records needed for sign-in and reliable uploads (sign-in state, request receipts). These expire on their own.
4. Cookies and local storage
We use only cookies that are strictly necessary: a session cookie that keeps you signed in, and a short-lived cookie that protects the sign-in step against forgery. We use no advertising, analytics or third-party cookies. The game also uses your browser's local storage for guest saves, settings, language and music preferences.
5. Multiplayer
Multiplayer rooms exist only in the server's memory while a game is in progress and are discarded when the room closes. The names you enter in a room are shown to the other players in that room.
6. Server logs
Like most websites, our web server writes standard access logs (IP address, time, requested page, browser type) to keep the service secure and working. These logs are rotated and deleted automatically and are not used to build profiles. Requests to the account and save API are not written to the access log.
7. How we use information
Only to let you sign in, store and synchronize your saved games, protect the service against abuse, and keep it running. We do not sell, rent or share your information with anyone, do not use it for advertising, and do not use it to train machine-learning models.
8. Where data is kept
Account data and online saves are stored on a server operated by the OSADA project. No third-party storage service holds your saves.
9. How long we keep it, and deleting it
Account data and online saves are kept while you use your account. After 12 months without playing or signing in, they may be removed. You can delete your account at any time from the game (Save / Load → Online saves → Delete account); this immediately removes the account, its linked sign-in identities, its sessions and all of its online saves. Saves already downloaded to your devices stay there. You can also unlink a provider, or revoke OSADA's access in your Google account or GitHub settings. If you cannot use the in-game option, write to us and we will delete the account for you.
10. Children
OSADA is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will delete it.
11. Your rights
You can see and download your saves in the game, and delete them or your whole account at any time. For any other request about your data, contact us at the address below.
12. Changes
If this policy changes, the new version will be published on this page with a new effective date.
13. Contact
OSADA project — loloped.up4k@gmail.com