Privacy Policy
Last updated: June 2026
1. Who We Are
We are a UK-based independent game project operating BeyondHuman, an online game in early access. For the purposes of UK GDPR, the project owner is the data controller for personal data processed through this website and game.
2. What Data We Collect
We collect:
- Email address and password (for account creation and authentication);
- Character data and game state (gameplay progress, inventory, position);
- Session data and authentication tokens (to keep you logged in);
- Email communication preferences (including whether you have unsubscribed);
- Public wallet address(es) you connect, and related public on-chain activity (for NFT ownership verification and, when enabled, deposits and withdrawals);
- Limited, privacy-friendly analytics about how the site is used.
3. How We Use Your Data
Your data is used to:
- Authenticate your account and maintain your session;
- Run the game — store and retrieve your characters, progress, and game state;
- Verify NFT ownership and, when enabled, process deposits and withdrawals;
- Send service and account communications, and (with the appropriate basis) project updates;
- Understand general usage patterns to improve the game.
We do not sell or trade your personal data.
4. Legal Basis (UK GDPR)
We process personal data under the following bases:
- Contract — processing necessary to provide the game service you signed up for (account, characters, gameplay, custody and withdrawals);
- Consent — optional marketing or project-update emails, which you can withdraw at any time;
- Legitimate interest — site analytics, security, and service improvement; and, for returning legacy players, a one-off notice that the service they previously used is continuing (the relaunch notification), with an unsubscribe option honoured.
5. Emails & Communications
We may email you about:
- Account security and service essentials (password resets, email changes);
- Major project updates and, for legacy players, account migration;
You can unsubscribe from non-essential emails at any time using the link in our emails. If you previously unsubscribed, we honour that and will not send you marketing or update emails.
6. Blockchain & Wallet Data
Public blockchains are, by design, public and permanent. Wallet addresses, NFT ownership, and on-chain transactions are publicly visible and outside our control, and cannot be deleted or altered by us. When you connect a wallet we may link its public address to your account to verify access and process transactions. We never ask for, and you should never share, your private keys or seed phrase.
7. Third-Party Services
We use trusted third-party providers, which may process limited data on our behalf:
- Supabase — authentication and database (account data, game state);
- Vercel — web application hosting;
- Railway — game server hosting;
- Resend — transactional and update emails;
- WalletConnect — wallet connection;
- Blockchain RPC / node providers — reading public on-chain data (e.g. NFT ownership, token balances);
- Privacy-friendly analytics — aggregate, cookie-less usage statistics.
8. Cookies & Analytics
We use essential cookies needed to keep you logged in and to operate the game. Our analytics are privacy-friendly and aggregate: they do not use tracking cookies and do not identify you personally, so no cookie-consent banner is required for them.
9. Data Retention
We retain your data while your account is active. You may delete your account at any time through the Account settings page, which permanently removes your account data, characters, and game progress. We may retain limited data where required by law or to resolve disputes.
10. Your Rights
Under UK GDPR you have the right to:
- Access your data;
- Correct your data;
- Request deletion (available via Account settings);
- Withdraw consent;
- Lodge a complaint with the Information Commissioner’s Office (ICO).
Please note that public on-chain data (wallet addresses, NFT ownership, transactions) is stored on public blockchains and cannot be deleted or rectified by us.
11. International Users
We primarily expect users from the UK and EU and handle data in accordance with UK GDPR requirements. Where data is processed outside the UK/EU by our providers, appropriate safeguards are in place.
12. Changes to This Policy
We may update this Privacy Policy as the project and our processing evolve. The “last updated” date above shows when it last changed, and we will take reasonable steps to flag significant changes. We encourage you to review this page periodically.
13. Contact
For privacy requests or questions about this Privacy Policy, contact: info@beyondhuman.ai