Privacy Policy

Last Updated: August 2026

1. Data Controller

Fibonex
Austria
Postal address: to be added before public commercial launch
Email: hello@fibonex.app

2. Data We Collect

2.1 Essential Server Logs

When you visit this website or the game, our servers and hosting infrastructure may create technical logs that are necessary to operate and protect the service.

The legal basis is our legitimate interest in secure, stable operation of the service under Art. 6(1)(f) GDPR. These logs are not used for advertising profiles.

2.2 Optional Website Analytics

If you choose "Accept Analytics" on the website, we store one minimal aggregated analytics event for the visit.

We do not store raw IP addresses or raw user agent strings in the analytics database. We do not use browser fingerprinting, canvas/WebGL/audio probes, plugin scans, advertising trackers, third-party analytics scripts, or IP geolocation services. If you decline analytics, the browser sends no analytics request.

The legal basis for optional analytics is your consent under Art. 6(1)(a) GDPR and, where access to information on your device is relevant, your consent under Section 165(3) TKG 2021.

2.3 Game, Account, Entitlement, and Online World Data

When you use the online game features on play.fibonex.app, we process the data needed to provide those features.

Play stats use the same rotating daily visitor hash and coarse browser family approach as website analytics. Raw IP addresses and raw user agent strings are not stored in the webstats database.

The legal basis is contract performance under Art. 6(1)(b) GDPR and our legitimate interest in preventing abuse, protecting shared worlds, and operating the service under Art. 6(1)(f) GDPR.

2.4 Optional Patreon Sign-in and Account Connection

You can use local Fibonex play as a Guest without Patreon or any account. If you choose Continue with Patreon, your browser is redirected to Patreon and we use Patreon's OAuth API to create or reopen one permanent Fibonex account for that Patreon identity. A player who already uses email and password can instead connect Patreon while signed in. In both cases, Patreon sign-in identity and Patreon membership status are handled separately: the Patreon identity can sign in even without an active paid membership. The configured active recurring Pro tier grants time-limited Patreon-derived Pro access, while a separately configured Founder lifetime tier can grant a permanent account-bound full-version license after successful paid, non-trial, non-gift creator-API verification.

For a linked account, we store:

During the OAuth request, Patreon may return basic identity and membership response data under the identity and identity.memberships scopes. We select the membership for the configured Fibonex campaign and retain only the identifiers and membership fields listed above. We do not request Patreon email access and do not retain the Patreon display name, memberships for other campaigns, your Patreon password, the OAuth authorization code, or any user OAuth access token. The authorization code and access token are used transiently to complete sign-in or linking and the membership check. For a potential Founder lifetime grant, we also transiently evaluate the creator-API free-trial and gifted-membership flags and whether Patreon reports positive campaign lifetime support; the configured tier ID, not its display name or browser-provided price text, identifies the offer. One-time OAuth state is stored only as a hash and remains valid for no more than ten minutes: an existing-account link is bound to the active Fibonex session, while a new Patreon sign-in is bound to a random browser nonce. Patreon sign-in then uses a separate browser-bound, short-lived, single-use completion handle to issue the normal Fibonex session; the session token itself is never placed in the callback URL.

Patreon may send signed membership webhooks for the Fibonex creator campaign. Before applying a recognized event, we retrieve the current linked membership through Patreon's creator API, and we also reconcile linked memberships periodically. When you reopen a stored signed-in Fibonex session or refresh Account & Pro, we may also perform a throttled creator-API membership check for the connected account. An active recurring Patreon entitlement is time-limited and expires if successful verification stops. A successfully creator-verified Founder lifetime grant is stored without an expiry and remains attached to the purchasing Fibonex account after cancellation or Patreon unlink. Webhook deduplication records may also be created for valid campaign events that do not match a linked Fibonex account; those events are marked as ignored. This prevents the same event from changing an entitlement more than once and helps keep membership status accurate.

The legal basis for requested Patreon sign-in, account connection, and the requested Pro benefit is contract performance under Art. 6(1)(b) GDPR. Entitlement integrity, signed-webhook verification, duplicate-event prevention, fraud prevention, and limited auditing are based on our legitimate interests under Art. 6(1)(f) GDPR.

2.5 Local Browser Storage

The browser game stores some data locally on your device, for example offline sandbox saves, blueprint libraries, language selection, login session tokens, and the website analytics consent choice. Offline saves and local blueprints stay on your device unless you actively share them or explicitly enable the optional Pro cloud backup for local Standard World Slot 1.

2.6 Optional Pro Cloud Backup

If you are signed in and enable or request Pro cloud backup, Fibonex uploads one owner-scoped copy of your current local Standard World Slot 1. An active Pro entitlement is required to create or replace that backup. Retrieving an existing backup requires authentication as its Fibonex account owner.

The cloud-backup record contains:

Only this one local slot is covered by the initial cloud-backup feature, and no other local save or blueprint library is uploaded automatically. A replacement creates a new revision of the same single backup rather than a separate online-world history.

The local save remains the primary game state. The cloud copy is not a ServerWorld, is never registered with or loaded by the multiplayer world manager, and does not become shared or server-authoritative gameplay. Restoring it is a client-side local-save action. The legal basis is contract performance under Art. 6(1)(b) GDPR because the backup is stored only when you request this account feature.

3. Legal Basis for Processing (GDPR)

Depending on the feature, we rely on:

4. How We Use Your Data

5. Data Retention

Website analytics and routine security logs are kept for up to 90 days unless longer retention is necessary to investigate abuse, security incidents, or legal claims. Account and online world data is kept while your account or world is active, or as long as required for backups, abuse prevention, legal obligations, or dispute resolution.

A live Patreon identity and membership connection is kept while the accounts remain connected. Disconnecting Patreon deletes the live identity and membership connection and revokes only the recurring Patreon-derived Pro entitlement; a previously verified Founder lifetime license and its anti-duplication purchase claim remain attached to the purchasing Fibonex account. Disconnecting does not delete your Fibonex account, local saves, or cloud backup. To prevent account lockout, Patreon cannot be disconnected while it is the account's only sign-in method. Limited entitlement history, audit records, and webhook deduplication records may remain after disconnecting so repeated events cannot restore or change access incorrectly and so billing, security, and legal events can be documented. No automatic fixed deletion interval is currently applied to those entitlement, audit, or deduplication records; they are retained only while needed for those purposes, legal obligations, or claims, and can be addressed as part of an applicable privacy request. OAuth and single-use completion states expire after no more than ten minutes and are cleaned from active use after expiry or consumption.

The single Pro cloud backup is retained until it is replaced or deleted following your request. Cancelling or unlinking Patreon, losing Pro eligibility, logging out, or disabling a Fibonex account does not automatically delete that backup. Account deactivation revokes active sessions and blocks account access, but retains account, entitlement, online-world, audit, and cloud-backup records unless and until the account is reactivated or an applicable erasure request is completed. Contact us if you want account data, Patreon-link history, or the cloud backup reviewed or erased.

6. Your Rights (GDPR)

Under GDPR Articles 15-22, you have the right to:

To exercise these rights, contact: hello@fibonex.app

7. Cookies, Local Storage, and Consent

We use localStorage to remember your privacy choice. This is necessary so the banner does not appear on every page view. You can change your choice through the "Privacy Settings" button in the footer or by deleting site data in your browser.

The game may use IndexedDB, local app save files in the desktop version, and localStorage for offline saves, blueprint libraries, language settings, and local session data. These are necessary or requested by you for the game experience.

Deleting browser or desktop data can remove your local copy but does not delete a cloud backup that you previously requested. Conversely, deleting a cloud backup does not delete the local save on your device. Patreon unlinking and Pro-status changes do not alter local browser or desktop saves.

8. Third-Party Services

We do not use Google Analytics, third-party advertising trackers, browser fingerprinting providers, external IP geolocation, or externally hosted web fonts on the public website or game app. The Roboto Mono font is served locally from Fibonex under the SIL Open Font License 1.1. We may use service providers for hosting, infrastructure, email delivery, payment processing, or support if those services become necessary. Those providers only receive data required for their role.

9. International Data Transfers

If a provider, including Patreon where applicable, processes personal data outside the EU/EEA, we use appropriate safeguards such as EU adequacy decisions or Standard Contractual Clauses where required. The provider's own privacy policy explains its locations and transfer safeguards.

10. Security

We implement industry-standard security measures including encryption, secure connections (HTTPS), and access controls.

11. Updates to This Policy

We may update this policy periodically. Material changes will be notified via email or website notice.

12. Supervisory Authority

You have the right to lodge a complaint with a data protection authority. In Austria, the competent authority is the Austrian Data Protection Authority (Datenschutzbehoerde), Barichgasse 40-42, 1030 Vienna, Austria, https://www.dsb.gv.at/.

13. Contact Us

For privacy inquiries:
Email: hello@fibonex.app

14. Health and Safety Warning

Some individuals may experience adverse physical effects when playing video games, including but not limited to dizziness, nausea, eye strain, headaches, fatigue, motion sickness, or seizures triggered by visual stimuli such as flashing lights or patterns.

If you or any player experiences symptoms such as dizziness, altered vision, eye or muscle twitching, loss of awareness, disorientation, involuntary movements, or convulsions, stop playing immediately and consult a qualified medical professional before resuming play.

To reduce the risk of discomfort or injury:

Parents or guardians should supervise children and ensure appropriate breaks are taken.

This software is provided for entertainment and educational purposes only and is not a medical device. The developer makes no medical claims regarding the safety or health effects of gameplay.