Privacy Notice
LargeScaleConflict can be played without signing in and has no advertising. Optional Google, Discord, GitHub, Twitch and passkey sign-in, cloud backups, and the market are described below. Usage analytics are off unless you opt in. This notice explains what data is involved. The developer does not publish a name, an email address, or a postal address.
Stored on your device
- Your acceptance of the Terms (the version number and date) and your analytics choice, so you are not asked every time.
- Game preferences; encrypted player records such as your identity, market credentials, stash, progression, friends, unlocks, memorial entries and voice blocks; and local raid/rejoin records. Device encryption keys stay on this device and are not included in cloud backups.
Your date of birth is used only in your browser to check that you are 18 or older. It is not stored or sent anywhere. You can clear local data through your browser's site settings. Clearing local data does not delete server accounts or cloud backups.
Accounts, sign-in and cloud backups (optional)
Account settings show the sign-in providers configured for this site. Choosing Google, Discord, GitHub or Twitch takes you to that provider to authorize sign-in. Your provider password is never collected by the game. The server verifies the response and stores the provider name and stable account identifier, a random game-account identifier, and creation/linking times in Cloudflare D1. Provider responses are processed to verify identity; provider access and refresh tokens are not retained.
For a passkey, D1 stores its credential identifier, public key, algorithm, creation and last-use times, and the player identity/market-key vault it restores. The game does not receive your fingerprint, face data, device PIN or passkey private key. A recovery code contains the player identity and market credentials: anyone with it can use those credentials. Keep it private.
When the optional account service is configured, player identity/market-key vaults and cloud progress records are encrypted before storage in D1 with a server-managed key. The server can decrypt them to provide account access and restoration; this is not encryption that hides backups from the server. Earlier passkey vaults are upgraded when used after this encryption is configured. Provider identifiers, record versions and timestamps, and passkey public-key metadata are stored separately from encrypted vault contents.
Signing in creates an application session. Its random token is kept in a Secure, HttpOnly, SameSite=Lax cookie; D1 holds a hash of that token, its account reference and expiry. A separate short-lived cookie and server record protect the provider sign-in flow. Authentication rate limiting uses temporary counters keyed by a hash of the request IP address.
Connecting a player saves its identity and market credentials. Cloud progress backup is a separate, explicit action: it includes stash and progression, friends, unlocks, memorial entries, voice blocks and the local raid-death note, plus a profile hash, save time and version. It does not include device encryption keys, device settings, live raid checkpoints or rejoin details. Signing in alone does not upload or replace local progress. Restoring a backup replaces local saved progress after confirmation; it does not merge progress from two devices.
Signing out revokes this browser's application session. It does not delete the saved account or backup, clear local progress, sign out other devices, or sign you out of Google, Discord, GitHub or Twitch. Account sign-in and cloud backup are separate from analytics consent; using them does not turn analytics on.
Analytics (optional)
The Google Analytics script is not loaded, and nothing is sent to Google Analytics, unless you opt in. The page only sets Google's Consent Mode defaults to denied. It does not include the Google tag. If you tick allow anonymous usage analytics, the game then loads the Google Analytics tag (Google LLC), grants analytics storage, and Google Analytics collects usage data such as pages viewed, session length, device and browser type and approximate location, and sets cookies or similar identifiers. Advertising signals are never granted. Google processes this data under its own privacy policy. You can change your choice at any time with Privacy settings on the game's start screen. Turning analytics off stops further collection by this game. It does not delete data Google already holds.
Multiplayer
When you choose Enter the strip, your browser connects directly to other players' browsers (WebRTC) and to a signalling server (PeerJS) that introduces players. For this to work:
- Private relay (default). With Hide my IP from other players on (Settings → Online, on by default), every connection goes through a TURN relay (Cloudflare Realtime TURN): other players see only the relay's address, not your IP address. Your IP address is visible to the signalling server and the relay service. If the relay is unavailable, the game asks you before connecting directly and never does so silently;
- with the private relay off, or if you choose Connect anyway, your IP address and connection details are visible to other players in your session (and in your party, and to friends whose presence you check) as well as to the signalling server;
- Squads and friends. Your callsign (a name you choose; no real name is needed), a random key and the friend code derived from it, and your friends list (their callsigns, friend codes and when you last saw them online) are stored in encrypted browser records. The Squad screen also synchronizes friend codes, names and added times to D1 so the list can follow your player identity across devices; an optional cloud backup can include the list as well. While the main menu is open after you open the Squad screen, friends who know your friend code can see that you are online, your callsign and your party code. Party chat goes only to the members of your party and is not stored;
- a random session identifier is created for your browser each time you play;
- game data you generate (your characters' positions and actions) is sent to the other players in the session;
- Voice chat (optional, off until you turn it on). The microphone is used only after you agree to the explanation the game shows and your browser asks you. While you talk (hold the talk key, or with open mic when you speak), your voice is sent as audio to the players who can hear you: players near you in the game, and your party or squad over the radio. Players outside your party are not connected unless you turn on Hear players outside my party (off by default). With Hide my IP on, voice goes through the same private relay as everything else. Voice is streamed live between browsers only: the game does not record or store it, and we have no server that receives it. Other players hear what you say, and anything they do on their own device is outside our control. You can mute or block anyone (Pause menu, Squad screen); blocks are kept in encrypted browser records with a voice identifier and/or friend code, a name and a timestamp. Optional cloud backups include these block records, not voice recordings. Your voice settings (microphone choice, volumes) are stored only in your browser.
Signalling and relay services may log connection metadata (including how much data a connection used, but not its content, which is encrypted end to end by WebRTC) under their own policies. We do not operate a game server for play sessions, and the game does not store their live position, action or voice streams. D1 stores the account, friends, backup and market records described in this notice. Play alone (offline) makes no peer-to-peer connections.
The market and coin purchases
If you open the market, the server keeps an anonymous market account: a random code (its secret half only as a one-way hash), your coin balance, what you listed, bought and sold, and when. It holds no name, email or device identifier. Your IP address is used for a few minutes to limit how often requests can be made and is not stored with the account. Coin purchases are made on PayPal's site under PayPal's privacy notice; the game only receives the order number, the amount, whether it was paid, and the terms version and immediate-delivery confirmation stored with that order. It never receives your card or PayPal account details. If you save a passkey or connect a player account, its identity vault can associate the market credentials with that saved player.
How long it is kept
The acceptance of the Terms and the choices stored in your browser stay until you clear the site's data or use Privacy settings. A market account, its balance, inventory, listings, ledger, and the record of a coin purchase (including the terms version and the immediate-delivery confirmation) are kept for as long as the market runs, because they are the account. There is no delete button in the game. PayPal keeps its own record of a payment under PayPal's notice. Deleting a market account, once a request can be received, does not delete PayPal's record. Live play-session streams are not stored by the game. Local game records remain until cleared or replaced; Privacy settings resets consent, not player progress.
Saved account/provider links, passkey records, server friends lists, and the latest identity vault and cloud backup have no automatic expiry or in-game account-deletion control. A new successful backup replaces the previous cloud copy. Application sessions expire after seven days, and provider sign-in attempts after ten minutes. Expired session/sign-in records are cleaned during later sign-in requests, rather than on a guaranteed deletion schedule. Rate-limit counters expire after two minutes and are pruned on later authentication requests. Signing out immediately removes the current application session record; it does not remove these saved records.
Access, correction, and deletion
You can clear everything this game stored in your browser through your browser's site settings. For the market account, a request for a copy, a correction, or deletion has to name the account code, because that is the only way to find the record. Clearing browser data or signing out does not delete account/provider links, passkey records, server friends lists or cloud backups; no server-account deletion control is provided. No contact is published, so that request cannot be sent from this page. Where the law gives you other rights (including to object, or to complain to a supervisory authority), those rights are not waived here.
Who else processes data
- Cloudflare serves the website (Cloudflare Pages), holds account, friends, cloud-backup and market records (D1), and provides the private relay (Realtime TURN). It processes standard request data, such as IP address and user agent, to deliver and protect the site, and it sees your IP address when a relayed connection uses the TURN service.
- Google, Discord, GitHub and Twitch process an optional sign-in that you choose under their own privacy notices. Google Analytics receives analytics data only after a separate opt-in.
- PayPal processes a coin purchase on PayPal's own site, and only if you choose to buy coins.
- A PeerJS signalling host introduces players: a server run for this game, and the public PeerJS service if that server is unavailable. It sees connection setup. It does not receive the contents of play, which WebRTC encrypts between browsers.
Transfers to the United States
The developer is in the United States. Cloudflare, Google, Discord, GitHub, Twitch and PayPal may process personal data in the United States, including data of players in the United Kingdom and the European Economic Area. This notice does not add a transfer mechanism of its own beyond what those companies publish for their services.
Children
The Game is for adults (18+) and is not directed to children.
Contact
No name, email address, or postal address is published.