PUBLIC SERVICE INFORMATION
Privacy Policy
Effective 17 July 2026
Who operates this service
mig5 system administration operates this deployment of SYN City: Explorer and is responsible for the personal data described in this policy.
Privacy contact: mig@mig5.net.
What we collect
The only real-world identity information required to create an account is your email address. The application also stores information generated when you use it:
- Your display name, optional avatar colour, selected runtime form, allegiance and account role.
- Your messages, faction messages, blocks, reports and moderation history.
- Your gameplay history, including discoveries, Packet Passport data, incident participation, combat events, archaeology, NPC relationships, safehouse status and last saved world position.
- Technical security information such as session records and short-lived rate-limit records. The web server or reverse proxy may also record ordinary request-log information such as IP address, time, requested path, status code and browser user-agent.
We do not request your real name, postal address, telephone number, precise physical location, contacts, camera, microphone or payment information.
Why we use it
We use this information only to provide and secure the game: authenticate your account, preserve your identity and world state, deliver messages, operate multiplayer features, prevent abuse, investigate reports, and maintain the safety and reliability of the service.
We do not use your data for advertising, behavioural profiling, marketing, credit decisions or automated decisions with legal or similarly significant effects.
Legal basis
Where data-protection law requires a legal basis, core account, messaging and gameplay processing is necessary to provide the service you ask to use. Security, abuse prevention, moderation and service reliability are carried out for the operator's legitimate interests in running a safe and dependable multiplayer service. Information is used to meet a legal obligation only where the operator is required to do so.
The current service does not rely on consent for advertising, analytics or tracking because those activities are not performed. A materially different optional use would require an updated notice and, where applicable, a separate choice before it begins.
Cookies and browser storage
After you use a magic link, the application sets one strictly necessary session cookie named syncity_session. It keeps you signed in and authenticates the multiplayer WebSocket. It is HttpOnly, SameSite=Strict, sent only over HTTPS in production, and normally expires after 30 days. Signing out or deleting your account removes it from the browser.
The renderer stores your selected quality mode in local browser storage under syncity.render-quality. This preference stays on your device and is not used for tracking. Old versions may briefly read and immediately delete a legacy local sign-in token during migration.
There are no analytics, advertising, cross-site tracking, fingerprinting or third-party marketing cookies. Because the session cookie is necessary to provide the signed-in service, the application does not display a consent banner for it.
Sharing and external services
We do not sell personal data and do not integrate advertising networks, analytics platforms, social-login providers, tracking services or even CDNs.
The service may rely on infrastructure providers chosen by the operator, such as hosting, database, backup and email-delivery services (Akamai (Linode) and Fastmail, respectively). The email provider necessarily receives your email address and the transactional message needed to deliver magic links, account-change notices or deletion confirmations. Those providers act only to operate the service under the operator's arrangements.
Moderators and administrators can access reports and chat messages when necessary to investigate safety or abuse. Information may also be disclosed where the operator is legally required to do so.
How long we keep information
- Account, profile, message and gameplay data are kept while the account exists.
- Magic links normally expire after 15 minutes. Used and expired link records are removed by the authentication cleanup process after a short security-retention period, normally seven days.
- Session records normally expire after 30 days and are revoked when you sign out, change your email or delete your account.
- Rate-limit records expire automatically after their security window. Web-server log retention is controlled by this deployment's operating configuration; contact the operator for the current period.
Deleting your account
You can request permanent deletion from Account → Delete account. We send a one-time confirmation link to the verified email address so that a stolen browser session cannot silently erase the account.
Using that link removes the live account, verified email, sessions, direct and faction messages associated with the account, blocks, reports and moderation records, profile, gameplay history, discoveries, capabilities, routes and operational nodes. Shared facts about the city—such as the existence of a sector or landmark—may remain, but the link to your account is removed.
Copies contained in infrastructure backups may remain until those backups reach their normal rotation date. They are not used for ordinary operation and would only be restored for disaster recovery.
Your choices and rights
You can change your display name, avatar colour, runtime form and verified email in the Account panel, sign out at any time, or permanently delete the account. You may also contact the operator to ask for access to, correction of, or a copy of your personal data, or to raise a privacy concern.
Depending on where you live, data-protection law may give you additional rights, including restriction, objection and the right to complain to your local data-protection authority.
Security
The application uses one-time expiring magic links, HttpOnly session cookies, encrypted HTTPS deployment requirements, same-origin protections, request and WebSocket limits, non-root containers and restricted database/network access. No internet service can guarantee absolute security, but the service is designed to minimise the data collected and to keep authentication credentials out of browser-readable storage.
Changes to this policy
Material changes will be reflected on this public page by updating the effective date. The policy remains available without logging in.