WORLD

world.digitalreality.studio

Privacy Policy

How WORLD handles your data

Effective 1 September 2026

This Privacy Policy explains how Digital Reality Studio (“we”) processes personal data in WORLD. It is written for the EU/EEA GDPR and Danish data-protection rules. Controller: Digital Reality Studio, contact world@digitalreality.studio. Production site: https://world.digitalreality.studio.

1. What we collect

  • Account: email address, password hash (we never store the password in clear text), display name, and, if you use Google sign-in, the identifier and email Google shares with us.
  • Citizen file: handle, portrait, chosen avatar or uploaded photo, bio, city, level, inventory, property, firms, loans, energy and similar game state.
  • Ledger: WORLD movements, idempotency keys, cashier tickets, quoted USD, chain asset, amount, and optional transaction hashes you submit or that we observe on public chains.
  • Communications: chat messages, support emails you send us.
  • Technical: session cookie or bearer token, approximate timestamps, security events (failed jobs, rate limits, bans). We do not need your home address to run the game.
  • We do not collect blockchain private keys, seed phrases, or full payment-card data. Never paste those into WORLD.

2. Why we process it (legal bases)

  • Contract (GDPR Art. 6(1)(b)): creating your account, running the game, crediting WORLD, operating the cashier, enforcing caps and bans.
  • Legitimate interests (Art. 6(1)(f)): securing the service, preventing fraud and exploits, economy integrity, aggregated statistics. You may object; we will stop unless we have compelling grounds.
  • Legal obligation (Art. 6(1)(c)): accounting, responding to lawful requests, sanctions compliance.
  • Consent (Art. 6(1)(a)): only if we later add optional marketing email or non-essential cookies. We do not currently send marketing mail or drop advertising cookies.

3. Cookies

We use strictly necessary cookies and similar storage for sign-in (session) and to keep you logged in on this device. These are required to provide the service you request and do not need a marketing-consent banner under ePrivacy rules for essential cookies. Google sign-in is initiated by you and may set cookies on Google’s domain under Google’s policy. We do not use advertising pixels, cross-site trackers, or non-essential analytics cookies today. If that changes, we will update this policy and, where required, ask first.

4. Who we share with

  • Hosting and database providers that run WORLD’s servers and Postgres (processors under contract).
  • Identity providers you choose (e.g. Google) to complete sign-in.
  • Public blockchain infrastructure (explorers and RPC nodes) to verify cashier payments. Transaction hashes and amounts you pay are already public on the chain.
  • Authorities if the law requires it.
  • We do not sell your personal data.

5. Blockchain is public

A payment to a house wallet is a public chain record. We store the hash against your ticket so we can credit you and prevent replay. We cannot erase a blockchain. If you want WORLD without linking a chain payment, do not use the cashier — play with the citizen grant and in-game earnings instead.

6. Retention

  • Account and ledger: for as long as the account exists, then as long as we need backups, dispute handling and legal records (typically up to five years for payment-related entries unless a longer statutory period applies).
  • Chat: recent messages in the live wire; we may keep longer copies for abuse investigations.
  • Session tokens: until they expire or you sign out.
  • Banned accounts: we may keep the ban record and enough data to stop re-entry.

7. International transfers

Infrastructure and RPC providers may process data outside the EU/EEA. Where we do that, we rely on adequacy decisions or Standard Contractual Clauses plus appropriate safeguards.

8. Your rights

If you are in the EU/EEA/UK you may request access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent where processing is based on consent. Write to world@digitalreality.studio with the subject “WORLD privacy”. We will need to verify the account. You also have the right to lodge a complaint with Datatilsynet (Denmark) or your local supervisory authority.

Erasure: we will delete or anonymise game profile data where the law requires. We may retain ledger rows that we must keep for accounting or fraud prevention, and we cannot delete public chain data.

9. Children

WORLD is 18+. We do not knowingly collect data from children. If you believe a minor has an account, email us and we will delete it.

10. Security

We use hashed passwords, session cookies, same-site request checks, parameterised queries, and input sanitisation. No method is perfect. You must keep your email and password to yourself and use a unique password.

11. Changes

Version 2026-09-01, effective 1 September 2026. We will post updates at https://world.digitalreality.studio/legal/privacy.