Privacy
The currently published games, Flight64 and Knight, are run by authoritative game servers. They do not use browser analytics.
Data needed to run a game
When you open a game or join multiplayer, the network and game servers process the request, connection status, game session, protocol messages, player actions, and resulting game state. This is limited to delivering the game, keeping players in sync, saving supported progress, preventing abuse, and diagnosing reliability or security problems. It is not used for advertising, marketing profiles, or cross-game tracking.
Server-side service metrics
The authoritative game server sends Adventure.io a random connection-session identifier, the game and server instance, session start, heartbeat and end times, and cumulative counts of accepted inputs and actions. It does not send a player or character name, email, resume token, IP address, location, device, browser, position, input content, or action name. The random identifier is cryptographically pseudonymized before storage. These minimized records are used to measure live service use, capacity and reliability; they are not browser analytics.
Browser storage and identity
Published game pages do not load the Adventure.io analytics SDK, create an analytics session in browser storage, or set a persistent cross-game analytics visitor identifier. If you are signed in, the page can request a random one-use ticket for the game so the owner dashboard can show that connection under your existing Adventure.io account. The ticket can authorize only a connection started within 60 seconds and is stored only as a cryptographic hash. An unused hash may remain for up to 30 minutes and five seconds after expiry solely so the authenticated game server can retry a start recorded while the ticket was valid; it is deleted when used or when that grace period ends. The game server receives neither your account ID, email, nor display name. Without a valid ticket, the connection remains a private player in analytics.
Knight stores a game-specific resume token in local storage so the same browser can return to its character on that Knight shard. That token is not shared with Flight64 or used as the Adventure.io account ticket. Dashboard session and passkey cookies protect account access, while Forget account clears the separate remembered-account hint.
Network address and location
Network systems necessarily process a connection IP address to route traffic and protect the service. Published-game servers do not turn it into geographic coordinates or use it for a player-location map. They do not request browser GPS, city, or postal data. A future location feature would require its own documented purpose and assessment before it is enabled.
Retention
- Live connection and session state is held only while the game server needs it to run the connection.
- Minimized server-side session detail expires after 30 days. Non-identifying daily totals by game are retained for long-term service planning.
- A signed-in account link, when present, expires with that 30-day session detail. Deleting the account removes unused tickets and detaches retained sessions.
- Flight64 does not persist a player profile or gameplay history on its game server.
- Knight persists the character, credentials, inventory, quests, and resulting save state so the player can return. It does not keep a separate action-by-action analytics history. A fixed inactive-character expiry and self-service deletion path are not yet available.
- A fixed retention schedule for any infrastructure security logs still needs to be documented and enforced.
Historical browser analytics
Earlier builds used a browser analytics SDK. The published games no longer add to that dataset. Historical location and latency observations expire after 24 hours, raw events after 90 days, and detailed sessions after 365 days. A legacy visitor cookie or telemetry-scoped signed-account link may remain in a browser until its one-year expiry, but published gameplay paths do not read or refresh either value.
Legacy aggregate rows can still contain a pseudonymous visitor key after detailed sessions expire. Those rows must be deleted or anonymized before Adventure.io can claim that no historical cross-game identifier remains in storage.
Future analytics
No optional browser analytics or player geolocation is active on the published games. If either is introduced later, Adventure.io must explain it before collection and provide a separate clear choice where consent is required. Simply continuing to play is not an analytics choice.
Updated August 28, 2026