Privacy Policy
Updated September 27, 2026
Draft. A lawyer has not reviewed this document yet, so the wording may change.
In short and without fine print: what data this website collects, why, where it is stored, who else sees it and how to delete it.
Who is responsible for your data
The The Priest: Echoes of the Path website is run by Ateret Games, which is also responsible for the data you leave here.
We will add the legal entity’s details here once they are finalised.
For any questions about your data, email ateretgamesofficial@gmail.com.
What data we collect and why
Only what a specific action on the site needs. There are no advertising trackers here and no scripts that follow you across other websites.
The “I want this game” button
To add you to the list of people waiting for the game, we store:
- your email — from your Google or Discord account, or the one you type in;
- the language of the page;
- channel tags from the page address (
utm_source,utm_medium,utm_campaign) and the domain of the website you came from — so we know which channels work; - when you joined;
- your consent to news and when you gave it — only if you tick the separate box.
From your Google or Discord account we take only your email and the internal account ID we use to recognise you the next time you sign in. We do not store your name, profile picture or account access tokens.
After you sign in, a session is stored in the database so the button can show straight away that you’re already on the list. We do not record your IP address or browser details in the session. For email sign-in we store only a hash of the one-time link: the link itself exists only in the email.
Pitch deck requests
When an investor or publisher requests the pitch deck, we store their name, email, company, role, message, page language and channel tags, and a copy of the request goes to the studio’s inbox. We need this to reply.
Supporting development
Payments are handled by Ko-fi — we never see your card details. After each payment Ko-fi sends us your email, the name shown on Ko-fi, the amount, currency, payment type (one-off or monthly), tier name, transaction ID and time. We need this to count your total support and send rewards. We do not store the message you leave on Ko-fi.
Abuse protection
To stop anyone sending hundreds of requests in a row, the site counts attempts per IP address and per email. We do not store the addresses themselves — only an irreversible hash that cannot be turned back without a secret key. Each record is needed for an hour at most. The site automatically deletes records older than a day the next time it checks attempts, so occasionally they are kept a little longer.
Visit statistics
To see the overall picture — how many visits, from which countries, websites and devices — we use Cloudflare Web Analytics. For this, the page loads a small Cloudflare script. It sets no cookies, stores nothing in your browser and does not recognise you on later visits or on other websites: we only see overall numbers, not individual people.
Technical logs
Cloudflare keeps technical logs of requests to the site, which may include your IP address and browser details, and stores them for a few days so we can find and fix errors.
Cookies and browser storage
The site sets only the cookies a feature needs to work, and only when you use that feature. There are no advertising or analytics cookies.
-
lang - The language you pick with the language switch. Set only after you use the switch. Kept for a year.
-
better-auth.session_token - Your sign-in session: it lets the site recognise that you’re already on the list. Lasts up to 180 days; the “Sign out” button deletes it at once.
-
better-auth.session_data - A short signed copy of the session, so the page doesn’t query the database on every view. 5 minutes.
-
better-auth.state - Protects sign-in through Google or Discord from forgery. 5 minutes.
-
want_nonce - Ties sign-in through Google or Discord to the browser where it started. 30 minutes.
-
want_flash - A one-time “just added” or “already on the list” note. Up to 2 minutes, deleted as soon as it is shown.
On a secure (https) connection, the names of the sign-in cookies start with __Secure-.
Apart from cookies, the language switch saves which part of the page was on screen to the tab’s memory (sessionStorage) for 30 seconds, so the other language opens at the same place. This record never leaves your browser.
Where data is stored and who else sees it
Data is stored in a Cloudflare D1 database. We do not sell it or pass it to anyone except the services the site cannot work without:
- Cloudflare (USA) — website hosting, the database and visit statistics. It processes IP addresses to deliver pages and protect the site from attacks. Cloudflare’s policy
- Brevo (France) — sends emails: sign-in links, notifications to the studio about pitch deck requests, and news to those who agreed to receive it. Brevo’s policy
- Google and Discord — only if you sign in through them. They learn that you are signing in to this site and pass us your email. Google’s policy, Discord’s policy
- Ko-fi (United Kingdom) — handles payments and passes us the payment details. Ko-fi’s policy
Some of these companies process data outside Ukraine and the European Union.
How long we keep data
- Your place on the “I want this game” list — for as long as the game’s waiting list exists, or until you ask us to delete it.
- Your sign-in session — up to 180 days; signing out deletes it at once.
- Pitch deck requests — up to three years after the last correspondence.
- Payment details — for as long as accounting and tax rules require.
- Hashes for the attempt counter — about a day; they are deleted automatically, so occasionally a little longer.
Your rights and how to delete your data
At any time you can:
- find out what data we hold about you;
- correct it;
- ask us to delete all of it;
- receive your data in a machine-readable format;
- object to processing we carry out on the basis of legitimate interest (for example, abuse protection);
- withdraw your consent to news — with the unsubscribe link in any email or by writing to us. This does not affect your place on the “I want this game” list.
To delete your data, email ateretgamesofficial@gmail.com from the address that is on our list. We will delete your list entry, sessions and sign-in data, remove your email from the mailing list and confirm by email within 30 days. If you write from a different address, we may ask you to confirm that the email is yours.
We may be required to keep payment details for longer under accounting rules.
If you believe we are violating your rights, you can contact the Ukrainian Parliament Commissioner for Human Rights or the data protection authority in your country.
Legal bases
- news — only with your consent;
- the “I want this game” list and replies to pitch deck requests — at your request;
- records of payments and rewards — fulfilling the support arrangement and accounting requirements;
- abuse protection and technical logs — legitimate interest: keeping the site secure.
Children
If you are under 16, please don’t leave your data with us without a parent’s consent.
Changes to this policy
If this policy changes, we will update it here and change the date at the top of the page.