Hytale Magazine — Privacy Policy

Version 2026.08.1 · effective 2026-08-01

Effective Date: 1 August 2026

Last Updated: 1 August 2026

This Privacy Policy explains what personal data we collect, why we collect it, and how we handle it when you use the Hytale Magazine website at hytalemagazine.com and the Hytale Magazine mobile application (together, the "Service").

We keep this policy in plain language because many of our users are young. If anything is unclear, contact us at legal@hytalemagazine.com.

1. Who We Are

The data controller is SIA "Synchron", a limited liability company registered in Latvia under registration number 40203436468, with its registered address at Ūnijas iela 74A-45, Rīga, Latvia, LV-1084.

You can reach us by telephone on +371 66077707, by e-mail at contact@hytalemagazine.com for general enquiries, and at legal@hytalemagazine.com for anything concerning your personal data — which is the address to use for every request described in Section 11.

2. What We Collect and Why

The table below lists every category of personal data we collect. We do not collect anything beyond what is listed here. There are no advertising trackers, no analytics services from third parties, no data sales, and no profiling for marketing purposes.

Category Examples Purpose Legal Basis (GDPR Art. 6) Retention
Account credentials Email address, password (stored only as a cryptographic hash) Creating and authenticating your account Art. 6(1)(b): necessary to perform our contract with you (Terms of Use) Until account deletion (see Section 8), plus the 14-day cancellation window
Profile information Nickname, avatar image, optional profile fields Displaying your public profile on the Service Art. 6(1)(b): necessary to perform our contract with you Until account deletion
User content Posts, text, uploaded images Publishing your contributions in the community feed and, where applicable, in editorial materials Art. 6(1)(b): necessary to perform our contract with you Until you delete the content or your account. Upon account deletion, the link between the content and your account is irreversibly broken, and authorship is replaced by "Deleted User." You may request full removal by contacting legal@hytalemagazine.com. The text or images within your posts may still contain information that identifies you regardless of authorship removal. Content already incorporated into published editorial materials is retained as described in the Terms of Use, Section 3.3
Verification requests The handle you submit with your verification application Processing your request for a verified account badge Art. 6(1)(b): necessary to provide the verification feature you requested 90 days after the request is approved or denied. Only the verified or denied status is retained on the account
Support tickets Text of your ticket and the conversation with our team Responding to your request and improving the Service Art. 6(1)(b): necessary to provide support you requested 12 months after ticket closure, or upon account deletion, whichever occurs first
Product analytics Page views and shares of articles, linked to your account Understanding which content is useful and improving the Service Art. 6(1)(f): our legitimate interest in improving the Service 12 months rolling, then aggregated and anonymized
IP address Your IP address at the time of a request Rate limiting and protection against abuse (e.g., brute-force attacks, spam) Art. 6(1)(f): our legitimate interest in protecting the Service and its users 7 days in rate-limiting logs, then deleted
Session cookie A session identifier stored in your browser Keeping you logged in during your visit Art. 6(1)(b): necessary to perform our contract with you (you cannot use an account without a session) Expires when the session ends or after 7 days of inactivity

A note on product analytics: views and shares are linked to your account, not anonymized. We use this data to understand what content resonates with the community. We do not use it to build advertising profiles, sell it to third parties, or make automated decisions about you.

Legitimate interest balancing (Art. 6(1)(f)): for product analytics, IP-based rate limiting, and service improvement, we have assessed that our interest in maintaining a functional, safe service does not override your rights, given that (a) the data is minimal, (b) no profiling for advertising occurs, (c) the Service is free, and (d) you can object at any time (see Section 7).

3. Cookies

We use a single, strictly necessary session cookie to keep you logged in. This cookie is:

httpOnly: it cannot be read by JavaScript running on the page, which protects against cross-site scripting attacks.

First-party only: it is set by our server, not by any third party.

Not used for tracking or analytics.

We do not use advertising cookies, tracking pixels, third-party analytics cookies, or any other non-essential cookies. Because we only use a strictly necessary cookie, a cookie consent banner is not required under the ePrivacy Directive (Art. 5(3)).

4. Children

Minimum age. You must be at least 13 years old to create an account. If you live in the European Economic Area, the minimum age is the age of digital consent set by your country under Article 8 of the GDPR — 16 by default, lower where your country has legislated a lower age, and never below 13.

Why it is written as a rule rather than a number. Article 8 lets each member state choose its own threshold between 13 and 16. By setting ours to whichever is higher — 13, or the one where you live — every account holder is old enough to consent to the processing of their own data, and we never need a parent or guardian to consent on someone's behalf.

How we ask, and what we do not keep. Signing up begins with a date-of-birth screen. It does not tell you which answer passes, and the registration form does not appear until an answer old enough for your country is given. We do not store the date. It decides whether the form opens and is then discarded: keeping a child's date of birth when nothing in the Service needs it would be data we would have to protect, disclose and delete for no purpose, which is the opposite of data minimisation.

What happens if we discover an underage account. If we learn that a user is below the minimum age, we will:

Immediately restrict the account.

Delete the account, all associated personal data, and all user content within 72 hours. The anonymization option described in Section 8 does not apply to underage accounts; all content is permanently deleted.

Where technically feasible, notify the email address on file explaining the reason.

Parents and guardians. If you believe your child has created an account on the Service, contact us at legal@hytalemagazine.com and we will delete the account and data promptly.

5. Who We Share Data With

We do not sell personal data. We do not share it with advertisers. We share data only with the following processors, which act on our instructions under a data processing agreement:

5.1 Resend (active)

What they do: deliver transactional emails (account confirmation, password reset, notifications).

Data they receive: your email address and the content of the email being sent.

Location: United States.

5.2 Anthropic (planned, not yet active)

What they will do when enabled: assist in processing support tickets using AI, to help us respond faster and more consistently.

Data they will receive: the text of support tickets and associated conversation.

Location: United States.

This feature is currently disabled. When we enable it, we will update this Privacy Policy and notify you in advance through the process described in Section 11. We will also display a notice in the support ticket interface informing you that AI processing is active for your conversation.

5.3 No other third parties

Beyond Resend and Anthropic (when enabled), we do not share your personal data with any other third party, processor, or partner.

6. International Data Transfers

Your data is stored on a dedicated server in Latvia.

Both Resend and Anthropic (when enabled) are based in the United States. We rely on the following transfer mechanisms:

Resend: Resend is certified under the EU-U.S. Data Privacy Framework (DPF), including the UK Extension, as listed on dataprivacyframework.gov. No separate Standard Contractual Clauses are required for transfers to Resend.

Anthropic (when enabled): As of the Effective Date, Anthropic is not certified under the DPF. Transfers to Anthropic are governed by Standard Contractual Clauses (Modules 2 and 3) as incorporated in Anthropic's Data Processing Addendum.

We verify the DPF certification status of our processors on the official registry at dataprivacyframework.gov before publication and periodically thereafter. If a processor's certification lapses, we will transition to Standard Contractual Clauses or an equivalent transfer mechanism.

You may request a copy of the applicable transfer safeguards by contacting legal@hytalemagazine.com.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data. We will respond to any request within 30 days.

Right What It Means How to Exercise It
Access (Art. 15) You can ask for a copy of all personal data we hold about you Use the data export feature in your account settings, or email legal@hytalemagazine.com
Rectification (Art. 16) You can correct inaccurate data Edit your profile directly in the Service, or email us for data you cannot edit yourself
Erasure (Art. 17) You can ask us to delete your data Use the account deletion feature in your account settings (see Section 8), or email legal@hytalemagazine.com
Data portability (Art. 20) You can receive your data in a structured, machine-readable format Use the data export feature in your account settings; the export is provided in JSON
Objection (Art. 21) You can object to processing based on legitimate interest (product analytics, rate limiting) Email legal@hytalemagazine.com with the subject "Data Objection." We will stop the processing unless we demonstrate compelling legitimate grounds
Restriction (Art. 18) You can ask us to limit how we use your data while a dispute is resolved Email legal@hytalemagazine.com
Withdraw consent Where processing is based on consent, you can withdraw it at any time Not currently applicable — we do not rely on consent as a legal basis for any processing listed above. If this changes (e.g., when Anthropic processing is enabled, if consent is chosen as the legal basis), we will provide a clear withdrawal mechanism
Lodge a complaint You can file a complaint with a data protection authority Contact the supervisory authority in your country of residence. In Latvia, where we are established, this is the Data State Inspectorate (Datu valsts inspekcija), https://www.dvi.gov.lv.

8. Account Deletion

You can delete your account at any time through the account settings.

14-day cancellation window. When you request deletion, your account is immediately deactivated (you are logged out and your content is hidden from other users). The account and all associated data are permanently deleted 14 days after your request. During this window, you can cancel the deletion and restore your account by logging back in.

Why 14 days? This grace period protects you from accidental deletion and from unauthorized deletion if someone gains access to your account. After the 14 days pass, deletion is irreversible.

What is deleted: your email, password hash, profile information, support tickets, and verification request data.

What is anonymized: your user content (the link between the content and your account is irreversibly broken, and authorship is replaced by "Deleted User"; you may request full removal by contacting legal@hytalemagazine.com). Note that the text or images within your posts may still contain information that identifies you regardless of authorship removal. Product analytics data (the link between the data and your account is removed; aggregate statistics are retained).

What may survive: user content that was already incorporated into published editorial materials before the deletion date, as described in the Terms of Use, Section 3.3. Retention of such content is based on Article 17(3)(a) GDPR: the processing is necessary for exercising the right to freedom of expression and information.

For full details, see our Data Deletion Policy.

9. Data Security

We protect your data with the following measures:

Password hashing: your password is never stored in plain text. It is processed through a cryptographic hash function before storage (via GoTrue/Supabase Auth, self-hosted on our server).

httpOnly session cookies: session tokens cannot be accessed by client-side scripts, reducing the risk of session hijacking.

Rate limiting: IP-based rate limiting protects against brute-force login attempts and automated abuse.

We do not claim to use security measures that we do not have in place. We take reasonable steps to protect your data, but no system is completely secure. If we discover a data breach that poses a risk to your rights, we will notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and, where required, inform affected users (Art. 34 GDPR).

10. Public Nature of Your Content

Your profile and posts are public. Your nickname, avatar, and any content you post are visible to everyone, including people who do not have an account. Public content may be indexed by search engines (such as Google) and cached by third parties beyond our control.

Think carefully about what you share before posting. Once content is public, we cannot guarantee its complete removal from third-party caches or archives even after you delete it from the Service.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

We will post the updated version on the Service with a new "Last Updated" date.

For material changes (such as adding a new data processor or changing a legal basis), we will notify registered users by email or by a prominent notice on the Service at least 14 days before the changes take effect.

If a change materially expands the processing of your data and we rely on consent for that processing, we will ask for your consent before proceeding.

12. Contact

For any questions, requests, or complaints about this Privacy Policy or your personal data:

Email: legal@hytalemagazine.com

You may also reach us through the in-app support ticket system.

Hytale Magazine — Privacy Policy · Hytale Magazine