Legal
Privacy Policy
Last updated: 1 September 2026
This policy covers the Embershroud marketing website (embershroud.com). It does not cover the game itself (see the game privacy policy), the Steam store, the Discord server, or the wiki, each of which has its own policy.
Who is responsible
The data controller is Iterative Studios AB, a company registered in Sweden with organisation number 559392-0605. For privacy matters, email [email protected] or use our contact form. We have not appointed a data protection officer.
What we collect
Browsing this site requires no account and no sign-up. We do not ask for your name, email, or any personal information to view it.
Analytics
We use privacy-first, aggregate analytics (Cloudflare Web Analytics) to understand overall traffic and which pages are useful. It uses no cookies, sets no client-side identifiers, does not track you across other sites, and does not build a profile of you.
Contact forms
If you use our general contact form, we collect the details you submit to read and reply to your request. The legal basis is taking steps connected with a contract when your request concerns an account or purchase (GDPR Art. 6(1)(b)); compliance with a legal obligation when you make a privacy or data-rights request (Art. 6(1)(c)); otherwise, it is our legitimate interest in responding to enquiries and operating support (Art. 6(1)(f)). We retain ordinary correspondence while needed to resolve the request, maintain a relevant business record, or handle a dispute, then review it for deletion. Records subject to a legal obligation are retained for the required period.
Illegal-content notices
If you use our illegal-content notice form, we collect the information you submit to identify and assess the reported content, decide whether to act, send receipt and decision information, and handle any request to reconsider the decision. The legal basis is compliance with our legal obligations for the notice process (Art. 6(1)(c)) and our legitimate interests in preventing abuse, making consistent decisions, and establishing or defending legal claims (Art. 6(1)(f)). A human makes the decision; we do not decide whether to act using solely automated means.
We review illegal-content notice records at least once each year and delete closed cases whose last activity was more than 24 months earlier. We retain a record longer only where an investigation, reconsideration, legal claim, regulatory request, or other legal obligation remains open.
Contact messages are delivered through Resend and stored in Google Workspace, which process them for us. We do not add you to a marketing list or use your details for marketing. Where a provider processes data outside the European Economic Area, we use an applicable adequacy decision or contractual safeguards required by EU law.
To protect our contact forms from spam and abuse, they are secured by Cloudflare Turnstile. When you submit, Turnstile checks that you are human, which processes some technical signals (such as browser information) via Cloudflare on our behalf, under Cloudflare's Privacy Policy. It is privacy-preserving and is not used for advertising or cross-site tracking.
Security vulnerability reports
If you use our security vulnerability route, we keep your email address and the information you choose to provide so we can receive, assess, and fix the report and run our product-security process. The legal basis is our legitimate interest in protecting the product and its players (GDPR Art. 6(1)(f)); if the report becomes legally reportable, we also process what is required to meet that obligation (Art. 6(1)(c)). Our email provider processes the message for us. Where the law requires a report, the technical vulnerability or incident information is sent through the EU Single Reporting Platform to the coordinating national CSIRT, ENISA, and other authorities required by law; we do not include the reporter's identity in that filing.
We keep the email thread while we work on the report and for up to 12 months after closure, then delete it. We keep a separate technical case record that does not name the reporter for up to 24 months after closure. The security page explains what not to send and how to exercise your privacy rights.
Your rights
Under the GDPR, you may ask to access, correct, erase, or restrict our use of your personal data, and to receive portable data where that right applies. You may object to processing based on legitimate interests. These rights have legal limits; for example, we may retain information needed for an open notice, legal obligation, or claim. Send a request to [email protected]. You may also complain to your local data protection authority; our authority is the Swedish Authority for Privacy Protection (IMY).
External links
Buttons and links to Steam, Discord, the wiki, and Iterative Studios take you to third-party services governed by their own privacy policies.
Contact
Questions about this policy or a data request? Email [email protected] or use our contact form.