Ironwrought / Privacy
Ironwrought Demo Privacy Notice
This notice applies to optional Ironwrought demo gameplay analytics.
What this optional collection does
If you choose Allow gameplay analytics, Ironwrought measures how players experience the fixed Steam demo so the developer can improve onboarding, pacing, encounter balance, and completion/conversion paths. Collection is optional and is not required to play, save, or finish the demo. Play Demo and Continue Demo remain available after declining.
PostHog Cloud EU processes the consented events as the analytics processor. Players are routed to the EU PostHog ingestion and management region without geolocation. The developer remains the data controller.
What is collected
The typed demo events and compact run summary may contain:
- a random pseudonymous installation identifier, session/run identifiers, and unique event IDs;
- schema/build version, route variant, coarse platform, language, and input method;
- milestone timing and closed result categories for menu actions, tutorial steps, segments, encounters, branches, level-up choices, defeat/retry/resume, completion, and external links;
- stable game-owned encounter, segment, class, ability, and hero IDs; and
- coarse encounter outcome, turn, duration, stamina/damage bands, completion status, and CTA placement/destination.
A CTA records intent to open a store or community link. It does not prove a Steam wishlist, visit, license, or purchase. Steamworks remains the source of truth for Steam impressions, visits, downloads, licenses, and wishlist additions/deletions.
What is not collected
The demo telemetry system does not derive or retain location from network IP addresses;
the hosted transport may process a network address transiently for delivery and
security. The client wire serializer explicitly disables PostHog GeoIP enrichment with
$geoip_disable: true; ds-telemetry serializer tests verify this
invariant, rather than a server project setting. It does not collect Steam IDs, account
names, player names, freeform text, save contents, action-by-action histories, combat
logs, screenshots, replays, precise hardware fingerprints, autocapture, session replay,
heatmaps, surveys, or person profiles. Person processing is disabled with
$process_person_profile: false.
Crash logs remain local and are not sent through gameplay analytics. Any future remote crash reporting would require a separate design and disclosure.
Consent, refusal, and withdrawal
The first Play Demo or Continue Demo action opens this notice before gameplay, identifier creation, telemetry storage, policy requests, or network activity. Allow gameplay analytics and No thanks have equal interaction status. Closing the notice without choosing does not start the requested action.
A refusal is durable and has no gameplay consequence. You can withdraw later in Settings → Privacy & Data. Withdrawal immediately disables collection and transmission, deletes the local telemetry queue, retry/quarantine state, interrupted summary, policy cache, logs, and installation ID, and keeps telemetry disabled if cleanup needs a retry. A later opt-in gets a fresh installation ID; it is not linked to the old one.
Withdrawal does not itself erase events already uploaded to PostHog. To request server-side access or deletion, contact privacy@ironwrought.net and, if available, provide the installation ID shown by the game. The operator validates scope, submits the supported EU PostHog deletion request, verifies completion, records the restricted request log, and responds within the legally applicable deadline. Do not send unnecessary identity documents.
Retention and access
The current PostHog EU project reports raw-event retention of up to 84 months under the selected plan. This replaces the earlier 30-day target because the current plan does not expose an enforceable shorter setting or replacement deletion job. Aggregate reports may be retained for 13 months only when they no longer contain installation-level identifiers or permit practical singling out. The operator runbook records the provider-reported retention and any future verified deletion control; production telemetry stays disabled if the disclosed retention or access controls cannot be verified. Access is restricted to the controller and approved operators who need it for the stated measurement purpose.
The full operational runbook documents PostHog EU controls, deletion verification, access review, incident handling, and retention evidence. DPA execution, legal review, and final publication are release gates; this notice does not claim that software implementation alone constitutes legal approval.
Steam reporting and time conventions
Steamworks reports are separate from consented PostHog cohorts and are never joined to an installation ID. Steam report timezone and availability delay must be recorded by the operator for each export; written runbook analysis uses UTC for telemetry events and labels Steam's own timezone and reporting delay. Steam exports are preserved in the restricted release-operations location with the campaign/release annotation used for that report.