⚒ Forge & Pray
Home Game News Rankings Game Guide Contact
Portal Login Register

Privacy Policy

GDPR information about Forge & Pray accounts, gameplay, multiplayer presence, support, security, and analytics.

Updated 26 July 2026

1. Controller and scope

Version 2026-07-26, effective 26 July 2026.

At a glance: Forge & Pray processes the information required for accounts, gameplay, security, support, and optional analytics. In persistent shared worlds, your player presence and visible actions may be shown to other players.

The controller for Forge & Pray is Georg Dehling, Frühlingstr. 12, Sulzbach-Rosenberg, Deutschland. Email: contact@forgeandpray.com. Telephone: (+49) 178 7322481.

This policy explains the processing of personal data when you visit the website, play as a guest, create or use an account, enter a multiplayer world, contact the operator, or use administrative or creator features.

On this page:

  • Data categories and legal bases
  • Gameplay and multiplayer visibility
  • Analytics
  • Retention
  • Your rights

2. Data categories

Depending on how you use the service, the following categories may be processed:

  • Account and profile data: email address, chosen or generated identifiers, display name, password hash, avatar path, language or locale, account status, creation time, and last-login information.
  • Game and world data: progress, inventory, virtual balances, quests, map instances, terrain and crop state, position, movement, interactions, player presence, and other server-authoritative game events.
  • Agreement and security data: accepted document version, acceptance time, guest or account reference, IP address, authentication events, audit records, rate-limit data, error and request metadata, and moderation records.
  • Contact data: name or alias, email address, topic, subject, message, handling status, staff notes, response drafts, and activity history.
  • Analytics data: the limited anonymous measurements and optional consented visit data described below.

3. Purposes and legal bases

PurposeLegal basis
Provide guest access, accounts, persistent progress, gameplay, and requested featuresArticle 6(1)(b) GDPR
Record legally relevant acceptance or comply with statutory dutiesArticle 6(1)(c) GDPR where a duty applies
Secure the service, prevent abuse, diagnose faults, moderate shared worlds, and establish or defend legal claimsArticle 6(1)(f) GDPR; legitimate interests in a secure, reliable, and fair service
Answer contract-related requestsArticle 6(1)(b) GDPR
Answer other messages and manage the support workflowArticle 6(1)(f) GDPR; legitimate interests in communication and orderly support
Operate optional identified or session-based analyticsArticle 6(1)(a) GDPR and section 25(1) TDDDG

Where legitimate interests are used, the operator considers the nature of the data, the user's reasonable expectations, the security benefit, and the effect on the individual. Particular care is required where a child may be affected.

4. Accounts, gameplay, and multiplayer visibility

Account and game data is processed to maintain the player's authoritative state. Forge is created as an account-linked instance from the game's curated starter template. Other maps are persistent shared worlds whose state and time are maintained by the server.

In shared worlds, your display name, avatar, presence, position, movement, and visible interactions may be shown to other players. Terrain work, planting, harvesting, dropped or collected resources, and similar world changes may be visible in real time and can persist for later visitors.

Do not use a display name or other visible content that reveals personal information you do not want other players to see.

5. Contact, agreements, security, and moderation

Contact submissions are stored so the request can be routed, answered, and documented. Please do not send passwords or special-category personal data unless the latter is genuinely necessary for the request.

Terms-acceptance records help demonstrate which document version was accepted and when. Security and moderation records help protect accounts, shared maps, the game economy, and the service from fraud, cheating, attacks, and technical abuse.

Passwords are stored as hashes, not as readable passwords. No internet service can promise absolute security, but technical and organisational measures are used in proportion to the project's nature and risk.

6. Analytics

Anonymous aggregate measurement without consent: for ordinary HTML page requests, the service may record the page path without its query string, request method, response status, response time, site identifier, and timestamp. This record does not include a user ID, analytics session ID, IP address, referrer, or user agent and does not set an analytics cookie. It is used to understand aggregate reliability and traffic patterns.

Optional analytics after consent: after an affirmative choice, the service may additionally record the full path including query string, referrer, user agent, IP address, a random first-party analytics session identifier, and—if signed in—the user ID. Registration or contact events may include the relevant user or session reference, IP address, page, and event topic.

Optional consent can be refused or withdrawn at any time through Privacy Settings. Refusal does not prevent core account or game use. Avoid placing personal or confidential information in page URLs because consented analytics may include the query string.

7. Recipients and international transfers

Data may be accessed by the operator and by necessary hosting, infrastructure, database, email, backup, or security providers. They act as processors or independent recipients according to their role and applicable law. Personal data is not sold.

If a provider processes personal data outside the European Economic Area, a lawful transfer mechanism and required safeguards must be used, such as an adequacy decision or standard contractual clauses. You may ask the controller which providers and safeguards apply to the live deployment.

8. Retention

  • Anonymous aggregate visit records are normally retained for up to 90 days.
  • Consented visit and analytics-event records are normally retained for up to 365 days.
  • Account and game data is generally kept while the account is active and is then deleted or anonymised when it is no longer required, subject to technical processing time and overriding legal, security, fraud-prevention, or dispute needs.
  • Contact records are reviewed after the request is resolved and retained only while follow-up, documentation, or legal claims reasonably require them.
  • Security, moderation, and audit data is retained for a period proportionate to the incident, risk, and possible claims.
  • Backups expire according to their operational rotation and are not used as an archive for ordinary access.

Statutory retention duties and the need to preserve evidence can require a longer period in individual cases. Data may be anonymised instead of deleted where it can no longer be linked to a person.

9. Your rights

Subject to the statutory conditions, you may request access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), or object to processing based on legitimate interests (Article 21).

You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. You also have the right to complain to a competent data-protection supervisory authority, including the authority responsible for the controller's German place of residence.

Send requests to contact@forgeandpray.com. Reasonable identity verification may be required to protect your account and other people.

10. Required data and automated decisions

Providing data is voluntary unless a field is required for an account, requested feature, security check, or legal duty. Without required account, agreement, or session information, the corresponding feature cannot be supplied.

Forge & Pray does not use solely automated decision-making that produces legal or similarly significant effects within Article 22 GDPR.

11. Policy changes

This policy will be updated when purposes, providers, recipients, international transfers, retention settings, or material game features change. The effective date at the top identifies the current published version.

Device storage is described separately in the Cookie Policy. Provider details are available in the Legal Notice.

F&P

Project & policies

Learn how the world works, what rules apply, and how your data is handled.

About Forge & Pray Terms and Conditions Privacy Policy Cookie Policy Legal Notice Software Notices

Questions about these pages?

Contact Forge & Pray for a clear answer.

Ask a question
Forge Network Forge & Pray Tend the forge. Pray for the gods' favour.
About the Project Contact Terms Privacy Policy Cookie Policy Legal Notice Software Notices

Copyright 2026 Forge & Pray. All rights reserved.

Privacy settings

We use essential cookies for login, session security, gameplay or legal-consent state, and core site functionality. With your consent, we also use first-party analytics cookies to understand page visits and improve Forge & Pray. Read our Privacy Policy, Cookie Policy, and Legal Notice.

Essential cookies Login, session security, and core site functionality.
Always on
Analytics cookies First-party page-visit analytics — no third parties.