CLI-GAMES
ctf/usr/gamesmanual
Enter Terminal

What crosses the wire

Privacy Policy

Last updated: September 7, 2026

September 7 clarification: analytics defaults, pseudonymous linkage, and research boundaries. The previous policy date was August 11, 2026; this clarification does not change the analytics default or enroll anyone in research.

We do not sell personal information, build cross-site advertising profiles, or run session replay. We collect what the product needs, minimize analytics, and put the optional switch here in the open.

01 / Your analytics choice

Optional usage analytics: disabled

Optional product analytics is enabled by default unless you opt out or your browser sends a supported privacy signal. This setting is not research enrollment.

This controls optional browser and account product analytics plus self-hosted Umami. It does not disable essential security, payment, service-integrity, error, or aggregate delivery-performance records.

This controls optional browser and account product analytics plus self-hosted Umami. It does not disable essential security, payment, service-integrity, error, or aggregate delivery-performance records.

CLI-Games honors Global Privacy Control and Do Not Track signals. Terminal users can run privacy analytics off at any time.

02 / Information we collect

  • Account data: email address, username, authentication records, and preferences you choose.
  • Referral data: the issuing account, hashed code, expiration, and the account identifiers and times associated with reservation and redemption. New self-shared codes do not copy the recipient's email into the referral record. A limited set of legacy email-bound invitations may retain their original address for audit and redemption.
  • Game and community data: saves, scores, achievements, messages, friendships, and other features you use.
  • Payment data: subscription or donation status and processor identifiers. Payment processors handle card or wallet details.
  • Usage analytics: page routes, feature and game identifiers, command names without arguments, outcomes, timings, coarse campaign tags, the bounded kind of ad-click parameter present (never its opaque value), a coarse device class derived from (never stored as) the User-Agent header, and referring domain.
  • Ad click data: if you arrive from an ad we placed, the ad platform's opaque click identifier and the time you arrived.
  • Entry surface: a coarse bucket for the kind of page (home, catalog, a specific game, terminal, or other) your session first landed on, recorded on the account at signup.
  • Signup door: a separate coarse bucket for the kind of page where you chose to create an account. It is not used as a substitute for your session's first landing page.
  • Link tag: a short code from the specific link you followed, if one was present (for example, a link posted in a discussion elsewhere), recorded on the account at signup — distinct from Referral data above, which is the Founder program specifically.
  • Operational data: limited request, security, and error information needed to run, protect, and debug the Service.

03 / How product analytics works

  • Anonymous analytics sessions use a random identifier kept in memory for the current page session, not a cookie or browser storage.
  • After a catalog card is opened, that tab temporarily keeps only the requested and launched game identifiers, random view and exposure identifiers, and open time in session storage. This makes a new tab or reload joinable to the same funnel for up to 30 minutes. The URL handoff is immediately removed, and opting out clears the record.
  • Your session's first landing page is bucketed into the small set above and held in session storage the same way — never a cookie, never the raw path — so it can be included with an eventual signup on that same tab. Opting out clears it.
  • When you explicitly create an account, we may include the same coarse bucket for the page where that request began. This is separate from first touch, never stores a raw path, and is collected only while optional analytics is enabled.
  • If the landing URL carried a short link tag, it is held in session storage the same way — never a cookie — so it can be included with an eventual signup. Opting out clears it.
  • Signed-in events use a one-way, keyed pseudonymous identifier rather than storing an account ID in the analytics table.
  • Analytics events do not store IP addresses or full user-agent strings.
  • We do not collect terminal command arguments, message contents, save names, search text, form text, or full referring URLs as analytics.
  • Our self-hosted Umami instance provides cookie-free site measurement. It stores event and session-level route, referrer-domain, coarse device, geography, and performance data; it excludes URL searches and fragments.

Pseudonymous data is not fully anonymous. We minimize it, restrict its use, and apply the retention limit below.

A signed-in account's keyed pseudonym can link its measured activity across visits. It is not an anonymous person count. CTF command analytics uses a fixed input label and can link submission timing to a scenario attempt; it does not store the command text, answers, or password-prompt responses.

04 / How we use information

  • Operate accounts, games, saves, leaderboards, community features, and payments.
  • Understand visitor intent, feature adoption, reliability, and where the product needs investment.
  • Send authentication and security messages, rare notices about material service changes or durable benefits attached to your account, and marketing messages you explicitly request.
  • Reserve a privately shared referral to the account that enters it and apply the benefit after that account confirms its email.
  • Prevent abuse, investigate failures, and secure the Service.
  • Measure contextual in-terminal advertising without behavioral profiles.

Product analysis can describe observed progression through games. Any public aggregate findings require review to avoid identifying people or sessions; a report without names is not automatically anonymous. Optional analytics, saving a practice record, and sharing an achievement are not study consent. A separately recruited learning study would have its own notice and voluntary participation choice, without restricting ordinary play for declining.

05 / Retention

Raw first-party product analytics and raw Umami events are automatically deleted after 90 days. Aggregate reports that no longer identify a person or session may be retained to compare long-term product health.

Account and game data is retained while needed to provide the Service. Security, payment, and transaction records may be kept longer for fraud prevention, disputes, tax, or legal obligations. Delete your account with deleteaccount.

06 / Advertising and browser storage

Ads are text-based, stored in our database, and selected by game or page context—not a behavioral profile. Anonymous visitors do not receive a durable browser or cross-session advertising identifier. With optional analytics enabled, a random token kept only for one browser tab may assign that tab to an advertising test; the server keeps only a one-way digest, coarse device class, and closed lifecycle facts for up to 90 days—not account identity, IP address, raw browser User-Agent, or input content. We do not share personal information with advertisers.

Browser storage supports features you request, including themes, shell settings, tutorial progress, local game state, offline support, and your analytics preference. The analytics preference is mirrored into a value-only SameSite cookie so server account routes honor the same choice. Optional analytics and anonymous ad frequency do not use cookies or durable identifiers to recognize a visitor. The advertising-test token uses tab-scoped session storage and disappears when the tab closes or optional analytics is disabled.

When you arrive from an ad we placed, the landing URL carries the ad platform's click identifier (such as gclid) or a paid-campaign tag (such as utm_source or a paid utm_medium). We keep the click identifier, a valid source tag, or only a coarse “paid source unknown” marker when no valid source was supplied, in one first-party cookie for up to 90 days. If you then create an account, we record it on the account, and for click identifiers we report the identifier with the signup time back to the ad platform, so the platform can attribute the signup to its ad. Reddit also receives a random unique conversion-event identifier so a retried report is counted only once; it is not derived from your account. This measures our own advertising: it identifies a click, not your browsing, we load no ad-platform scripts, and it is not used for profiling or shared beyond that report.

07 / Service providers

  • Hetzner: application and database hosting.
  • Cloudflare: delivery, DDoS protection, and aggregate web performance measurement.
  • Umami: self-hosted, cookie-free aggregate analytics.
  • Sentry: sampled error and performance monitoring; session replay is disabled.
  • Resend: account, service-notice, and opt-in marketing email delivery.
  • Anthropic: pseudonymous excerpts from invited playtester reports for advisory finding clustering.
  • Stripe and Coinbase Commerce: payment processing when used.
  • Pusher: real-time multiplayer and community updates.
  • Google Ads: measurement of our own ad campaigns — receives only ad click identifiers and signup times; no emails, usernames, or activity.
  • Reddit Ads: measurement of our own ad campaigns — receives only Reddit click identifiers, signup times, and random unique conversion-event identifiers; no emails, usernames, account IDs, or activity.

These providers process information only to supply their services. We do not authorize them to sell it for their own advertising.

08 / Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, and to object to or restrict certain processing. You can opt out of optional analytics above and manage optional marketing email with mailing. Authentication, security, and rare account-relevant notices do not depend on a marketing-list subscription. We keep those notices targeted and send them only when the information materially affects the account or the service it uses.

CLI-Games does not send referral invitations. A Founder receives a code and decides how to share it privately. Entering a code does not subscribe the resulting account to a mailing list.

09 / Children

We do not knowingly collect personal information from children under 13 without parental consent. Contact us if you believe a child has provided personal information.

10 / Contact and changes

We may update this policy as the Service changes. The date above shows the latest revision.

Privacy and data requests: [email protected]

ctf/usr/gamesautomationmanualcommunitymemberssshfaq
creatorswork with usprivacytermsfounder terms

CLI-Games — train, prove, apply, inhabit