Ash Atlas Pangolyn Studios LLC

Privacy / Ash Atlas

Privacy Policy

Effective September 15, 2026

This policy explains how Pangolyn Studios LLC (“Pangolyn,” “we,” or “us”) handles information for Ash Atlas, including its website, web game, and supported native app builds. It describes the current implementation and configuration documented in the Ash Atlas repository. Some optional services depend on the deployment environment; we identify those cases below.

1. Information we handle

Ash Atlas handles the following information when the related feature is used:

  • Account and identity: a verified Google account subject and email address, an Ash Atlas account and player identifier, and the public display name and personal flag color chosen during onboarding.
  • Gameplay: player position and region, movement, progression, inventory, equipment, gold balance, flags, affiliations, market activity, and other state needed to run and secure the game.
  • Location: if you explicitly choose World Map relocation, the browser or app can provide a precise device location. The coordinates are sent to Ash Atlas and become the player’s gameplay position; nearby authenticated players can receive position updates through the gameplay view needed to play together.
  • Player content: public, local, city, kingdom, party, and direct messages, plus text and bounded game state included in a bug report when that optional feature is enabled.
  • Security and device data: HttpOnly session and device cookies, server-side token hashes, broad browser and operating-system families, request metadata, and HMAC-derived network values used for authentication, rate limiting, and abuse prevention. The application does not use hardware serials, MAC addresses, advertising IDs, or fingerprinting signals.
  • Diagnostics: the repository contains an optional closed-test telemetry path for performance, connection, gameplay, progression, and inventory measurements. Its documented defaults are off. When enabled by deployment configuration, the data is linked to the authenticated player/session for private operations and is retained under the configured telemetry policy.

We do not find current Ash Atlas code for contacts, photos, files, microphone, camera, push-notification tokens, health data, or real-money payment information. In-game gold and purchases are gameplay state, not a payment processor. No advertising SDK or advertising identifier is present in the repository, and the current implementation does not use Ash Atlas data for targeted advertising or sell it.

2. How we collect and use information

We receive information directly from your sign-in, onboarding choices, messages, support submissions, and optional location action. The game also creates gameplay and security records as you connect, move, trade, fight, build, socialize, and use account controls. We use this information to authenticate you, provide and synchronize Ash Atlas, save gameplay state, show permitted player views, prevent abuse, moderate player content, investigate faults, and maintain the service.

The browser may keep Ash Atlas preferences, chat selection, pinned items, diagnostics, and cached assets in local storage, session storage, Cache Storage, or the app’s web view. Authentication tokens are not intentionally stored in local storage or session storage; web authentication uses cookies managed by the browser or app.

3. Location data

Location is optional. Ash Atlas requests the browser geolocation permission only after you select the World Map relocation action. The request asks for a fresh, high-accuracy fix and sends latitude, longitude, and any reported accuracy to the authenticated game server over HTTPS/WSS. The server validates and stores the resulting coordinates as the player’s current and movement-anchor position, with a 24-hour relocation cooldown.

Exact coordinates are used for gameplay and are available to the server and the interest-managed gameplay connection. Nearby authenticated players may receive exact movement coordinates needed for live world play. Public player HTTP listings expose identity, region, and coarse zone rather than global exact coordinates. Location may also appear in security or relocation diagnostics. You can deny the permission and can continue using non-location parts of the game, subject to gameplay rules.

4. Accounts, authentication, cookies, and sessions

Web sign-in uses Google Identity Services. Ash Atlas requests OpenID identity, email, and profile claims only; it does not request Google contacts, Drive, Calendar, Gmail, Google access tokens, or Google refresh tokens. The browser sends the short-lived Google credential to Ash Atlas for verification, and Ash Atlas stores the verified provider subject and email needed to identify the account.

Production session and device cookies are HttpOnly, Secure, SameSite=Lax, host-only, and scoped to /. Ash Atlas stores HMACs of session and device tokens rather than the raw values. Production sessions are configured for 30 days absolute and 14 days of inactivity; the installation device cookie is configured for up to one year. Native Capacitor sign-in uses a short-lived PKCE authorization code and an in-memory WebSocket ticket before using the same Ash Atlas session model.

Ash Atlas receives the request IP and ordinary user-agent while handling a request. Long-lived security records store HMAC-derived IP and network-prefix values and broad browser/OS families, not a raw IP address or complete user-agent string. Server logs record operational request and error information and redact cookies, credentials, tokens, CSRF values, and email fields where configured.

5. Chat, messages, and player content

Messages are user-generated content. Public and scoped chat is stored in PostgreSQL so authorized players can receive history and moderation can operate. Direct messages use the same durable message ledger and are visible to the conversation participants. Messages are transmitted over the authenticated WebSocket, are rendered as plain text, and are not end-to-end encrypted: the Ash Atlas server can read, store, and moderate them. Other players can see content according to the channel’s access rules.

The code uses bounded history windows and channel-specific retention policies, but it does not define one universal expiration period for every durable public or direct message. Player reports are available from message and player actions, blocks hide blocked public/scoped senders, hide blocked direct-message previews/history in the client, and prevent new direct messages. The server applies a bounded first-line text filter before durable storage. Reports are queued for human review; the automated filter is not perfect. Developer-authorized moderation can hide or delete supported durable chat messages. Current Community Rules acceptance is required before posting chat content.

Bug reports are optional and disabled by default in the repository configuration. If enabled, a report may include your written description and bounded recent client/server diagnostics, player state, nearby entity excerpts, and performance history. The configured email delivery path uses Resend; report records are intentionally retained outside routine telemetry-segment deletion.

6. Service providers and sharing

Ash Atlas uses or permits the following external services for the purposes described:

  • Google Identity Services / Google: account sign-in and identity verification. Google receives the sign-in interaction and provides the credential that Ash Atlas verifies.
  • OpenStreetMap tile service: map raster tiles are requested from tile.openstreetmap.org. The tile provider receives normal network and browser request information; Ash Atlas does not intentionally attach account tokens to those tile requests.
  • Resend: if bug reports are enabled, accepted report notifications are sent to the configured support recipient through api.resend.com.
  • Cloudflare Web Analytics: the production hosting configuration permits a deployment-injected analytics beacon. The Ash Atlas application bundle does not inject it directly. Its active status and exact collection must be checked for each public release and reflected in store disclosures.
  • Hosting, database, and network infrastructure: service operators and infrastructure providers process requests and stored data as needed to host Ash Atlas. The repository does not name every provider or data-center region.

We do not share data with advertisers or data brokers in the current implementation. We may disclose information to service providers, moderators, security personnel, or authorities when needed to operate, protect, or legally support the service. We do not claim that every infrastructure provider has the same retention or geographic policy; see the audit gap list for items that must be confirmed before store submission.

7. Security and retention

Authentication and gameplay traffic use HTTPS/WSS in production. Cookies are protected with HttpOnly, Secure, and SameSite settings, raw authentication tokens are not stored in the database, and sensitive log fields are redacted. No Ash Atlas chat, location, or gameplay feature is end-to-end encrypted because the server is authoritative for game state and moderation.

Retention depends on the record. Expired/revoked sessions and ordinary authentication network telemetry are cleaned on an approximately 90-day schedule. The documented optional telemetry defaults are 60 days for server/world samples, 30 days for client samples, and 90 days for gameplay/player/inventory samples, subject to the deployment configuration. Account, gameplay, location, and durable message retention has no single repository-wide period. We keep records only for the operational, security, moderation, and legal purposes for which they are needed, subject to those configured controls.

8. Your choices and deletion

You can sign out of the current session or revoke all active sessions from the account controls. You can refuse or later revoke browser/device location permission through your platform settings. You can clear local browser/app storage to remove local preferences and cached assets; this does not delete server-side account or gameplay records.

Ash Atlas provides an authenticated request from Account settings and a public ownership- verification path at playashatlas.com/delete-account. The request revokes sessions and suspends the account while Pangolyn manually processes it; it is not an instant self-service erasure. Shared-world, security, fraud, moderation, legal, and transaction records may be anonymized or retained only as necessary. Support will confirm the outcome or explain any lawful retention. See the Terms & Community Rules for UGC reporting and appeals.

9. Children and international players

Ash Atlas is not directed to children under 13, and we do not knowingly collect a child’s personal information. If you believe a child has provided information, contact us so we can review it. Ash Atlas may be accessed from different countries; information may be processed where Pangolyn, its providers, or its infrastructure operate.

10. Changes and contact

We may update this policy when Ash Atlas changes. We will update the effective date and publish the revised policy at this URL. Questions about this policy or a privacy request can be sent to [email protected].