Data kept for the service
The planned account flow stores the minimum identity, security, game-link and audit data needed to operate and protect an account.
Credentials
Plaintext passwords, session tokens, reset links and authentication codes must never be written to logs. Session tokens are stored server-side only as cryptographic hashes.
Operational security
Limited IP and browser security signals may be retained for rate limiting, fraud prevention and incident investigation under defined retention periods.
Your choices
The final policy will explain access, correction, deletion and contact procedures before any real account data is collected.
Registration remains disabled until the data controller, contact address, retention periods and final jurisdiction-specific text are supplied.