CAPITAL RIFT

Privacy Policy

What we store, who can see it, and what we send to anyone else.

Last updated 30 August 2026 · NIKS GAMES LLC

We do not run analytics. We do not use advertising or tracking cookies. We load no third-party JavaScript. We never see your card number. We never ask for your location.

Two things worth saying up front: performance telemetry is on by default outside the EU, EEA and UK, and inside them the game asks you first (section 7). And if you ever buy the Player Pass, deleting your account does not delete your email from the purchase record (section 10).

1Who we are

Capital Rift is operated by NIKS GAMES LLC, a Nebraska limited liability company based in Omaha, Nebraska, United States. For anything in this policy, including any request about your data, write to support@capitalrift.com.

Under the UK and EU GDPR, NIKS GAMES LLC is the data controller for everything described here.

2Your account

You sign in with Google. Your email address is the only thing that identifies you to us. We ask Google for the openid email scope, so what comes back is your email address and nothing else: no name, no profile picture, no Google account id.

Correction, 2 August 2026: that was not true until today. The sign-in software we run had never been told which scope to ask for, so it used its own default, profile email, and asked Google for your basic profile as well. That meant your name, your profile picture and your Google account id came back to our sign-in layer and sat in your encrypted session cookie for up to 24 hours. None of it was ever written to our database, shown to anyone, or used for anything: the game only ever reads your email address. We found it while auditing this page against what the code actually does, and we have now pinned the scope to email only. Sessions created before today expire within 24 hours and the extra fields go with them.

Your account row holds:

WhatWhere it comes from
Email addressGoogle sign-in. This is your identifier.
Display nameDefaults to the part of your email before the @. You can change it.
Player number, title, avatarSet when you buy a Player Pass, or chosen by you.
Referral code, who referred youGenerated for you; recorded if you arrived via someone's link.
Created date, last seenSet by us. Last seen updates when you connect and disconnect.
Email preferencesYours. Every notification is off unless you turn it on.

There is no game password to store. Sign-in runs entirely through Google.

3Payment

Your card number, security code, expiry date and billing address never reach our servers. We could not leak them if we tried, because we never receive them.

Payments run on Stripe. When you buy a Player Pass we hand you off to a page hosted by Stripe, and you type your card details there, into Stripe, not into us.

What we send to Stripe

What we keep afterwards

When a payment succeeds, we write one purchase record: your email address, what you bought, Stripe's session and payment identifiers, the amount, the currency, the status (paid or refunded), and the date. Your receipt number is worked out from that record rather than stored.

If you withdraw from a purchase, four more things join that record: the date you withdrew, Stripe's identifier for the refund, which version of our checkout wording you originally bought under, and the fact that you declared you live in the EU, the EEA or the UK. That last one is the only place we hold anything about where you live, and it is there because it is the declaration that entitled you to withdraw. We do not send it to Stripe, we do not use it for anything else, and we do not try to check it against your address or your IP.

We keep that record permanently. See section 10, because this is the one thing that survives deleting your account.

4Game data

Your save: money, cart, staff, buildings, leases, market orders, and where your character is standing.

We also keep a day-by-day record of how you play: which game actions you used, which in-game refusals you hit (for example "too far away"), when you signed in, and the first time you reached each part of the game. We use it to find where players get stuck or give up so we can make the game easier to learn. It is counts per day, not a keystroke log: no chat, no message content, no IP address. The day-by-day detail is deleted automatically on the schedule in section 9.

The game world is built from real-world map data, so your character has real-looking coordinates. Those are your position in a simulation, not your position on Earth. We never call your browser's location API, and the site actively blocks it with a Permissions-Policy header.

Two parts of your game data are visible to other players by design:

5Community

Chat messages, forum posts, bug reports, suggestions, votes, and any screenshots you attach are stored on our server.

When you file a bug report, we automatically attach up to 100 lines of your browser's recent console output, plus your graphics and performance figures, so we can actually diagnose it. That is technical logging the game itself printed. It is visible only to staff, never to other players, and it is capped in size. As of 25 July 2026 the report window says this too, which it previously did not.

We filter slurs in display names, titles and channel names. Ordinary swearing is left alone.

6Reporting illegal content

There is a form at capitalrift.com/report for telling us that something here is illegal, as opposed to merely against the rules. The Digital Services Act requires us to have one, to let you use it without an account, and to let you use it without giving your name. This section is what happens to the data in it, and it was missing from this page until 2 August 2026.

When you send a notice we store what you typed: the category, the exact location of the thing you are reporting, and your explanation of why you believe it is illegal. If you filled them in, we also store your name and your email address. Both are optional and the form says so, because for some kinds of report you should be able to stay anonymous. If you give us an email we use it for exactly two things: sending you the reference number, and telling you what we decided.

We also record the IP address the notice came from. That is there to stop somebody flooding the form, it is never shown to anyone, and we delete it after 30 days while keeping the notice itself.

Who can read it: only us. A notice is never shown to other players, and neither is your name. It is deliberately not stored alongside the public bug and suggestion boards, because an allegation that somebody posted something illegal must not be a thing other players can browse.

If you are the person being reported: a notice about you is personal data about you, and you can ask us for it under section 11 like anything else. What we will not hand over is the reporter's identity, because doing so would make the reporting channel unusable for exactly the people who need it most. If we act on a notice, we tell you what we did and why, which the Digital Services Act requires of us separately.

How long: we keep a notice and our decision for 12 months after we close it, so that we can show our working if the decision is challenged, and then we delete it. The IP address goes at 30 days, as above.

Our legal basis for all of this is the legal obligation the Digital Services Act puts on us to run the mechanism at all.

7Performance telemetry

The game measures its own rendering speed so we can find stutters, and sends those measurements to our own server. Nobody else receives them.

FieldExampleIn there?
Random per-load ida fresh id each page loadyes
Graphics cardNVIDIA GeForce RTX 4070yes
Screen size, pixel ratio3840x2160yes
Browser User-AgentChrome 125 on Windowsyes
Frame timingsabout one sample per secondyes
Your emailno
Your player idno
Your IP addressno

There is no identifier in it linking a sample back to your account. But we are not going to claim it is anonymous: your graphics card, screen size and browser together are reasonably distinctive, and it is sent from your connection.

Whether it runs at all

In the EU, the EEA and the UK, telemetry is off until you say yes. The first time you play, the game asks whether you are happy to help; nothing is read from your device and nothing is sent until you answer, saying no costs you nothing, and once you have answered either way you are not asked again. The law there says measuring your device for our own benefit needs your consent rather than our judgement, and we agree with it. Where you are is judged from the country your connection comes from, request by request, and it is not stored.

Everywhere else it is on by default.

Wherever you are, the switch in your account under Privacy and data is the master control, and because it is stored against your account rather than in your browser it applies on every device you sign in from. Flipping it counts as your answer, so the ask will not second-guess it. ?notelemetry on the game URL and cr_no_telemetry in localStorage still work too, for a single browser.

The ask is new on 25 August 2026 and reaches you with the game update rolling out now. Until your client has that update, the older build still measures by default the way this section used to describe, and the switch above already works everywhere. If that gap bothers you, flip the switch off today and there will be nothing left to ask about.

That switch is live now. This page said on 25 July 2026 that it was "rolling out with the current build", and before that it said a proper setting was "on the list", so if you looked for it and could not find it, that is why. It is there, under Privacy and data, along with the data download and account deletion.

8Who else gets your data

The complete list. There is nothing else.

WhoWhat they getWhy
GoogleYour email addressSign-in. We request the email scope only.
StripeYour email, our player id, the amount, and the card details you type on their pageTaking the payment.
Google (Gmail)The customer ledger: who owns a Player Pass, their player number, and purchase recordsAn off-site backup of who paid, mailed to a company mailbox so it survives losing the server.
GitHub (Microsoft)The nightly database backup, which includes your email address and any purchase recordAn off-site copy of the whole database, pushed to a private repository, so a dead server does not mean a lost world. Nobody but us can read it.
CloudflareYour IP address, and the traffic between your browser and our server, which passes through their networkThey sit in front of the site to absorb attacks and to cache map data closer to you. They relay traffic and cache what we mark cacheable; they do not receive a copy of the database, they set no cookies here, and they inject nothing into our pages.

Correction, 25 August 2026: the Cloudflare row was missing for twelve days. We put Cloudflare in front of the site on 13 August 2026 and this page kept calling the list complete without naming them. Same mistake as the GitHub row below, found the same way, in an audit of this page against what actually runs. While we were at it we also switched off a Cloudflare feature that would have had your browser send connection-error reports to them, so the paragraph after this table stays true.

Not on this list, because we do not use them: analytics of any kind, advertising networks, tracking pixels, error-reporting services, and third-party JavaScript. Our fonts are served from our own server rather than Google Fonts, so loading a page does not tell Google you visited.

Correction, 25 July 2026: the GitHub row above was missing from this list for eight days. The nightly off-site backup started on 17 July 2026 and this page still said the list was complete. Nothing leaked and the repository is private, but the list was wrong and this is us saying so rather than quietly editing it in.

Cookies

One sign-in session cookie, which is strictly necessary to keep you logged in, plus a couple of short-lived cookies that exist only during the sign-in handshake itself and protect it against cross-site request forgery. Those are all of them. There are no analytics or advertising cookies, and Cloudflare, who relay our traffic (see the table above), set none here either.

We also use your browser's localStorage. The full list, because we would rather write it out than round it off:

Three more entries live in sessionStorage, which your browser empties by itself when the tab closes: a flag that keeps the loading screen up for one navigation while the tutorial moves you into the city, whether you dismissed the low-graphics-mode notice, so it does not nag you twice in one sitting, and, if you clicked the telemetry ask away with its close button, a note not to re-ask this sitting.

One correction to something this page used to say. It said there were four of these and that none of them ever left your device. There are more (the list above is current as of 25 August 2026), and one does leave: your player id is sent to us once when you sign in, so that any progress you made before you had an account gets attached to it. The rest genuinely stay in your browser. Corrected 2 August 2026, and when the game gains a new entry, updating this list is part of shipping it.

9How long we keep it

WhatKept for
Web server access logs (includes your IP address)5 days, then deleted automatically
Database backups14 days here, and the newest 14 nightly copies off-site
Performance telemetryRotates out on size, which at the volume the game currently produces is under a day. Not a fixed period.
Chat, direct messages, forum posts, bug reports, screenshotsIndefinitely. We do not currently delete these on a schedule.
Illegal-content notices (section 6)12 months after we close them. The reporter's IP address goes at 30 days.
How you play, day by day (which game actions you used, and which refusals you hit, behind our admin learning dashboard)45 days, then deleted automatically
Sign-in sessions (when you played, so we can see whether new players come back)90 days, then deleted automatically
Blocks placed by our abuse filter (an IP address, when a connection floods us)Dropped automatically within a day
The off-site copy of who bought a Player Pass (section 8)The last 30 daily copies on our server, and the mailed copies for as long as that mailbox exists
Your account and game saveUntil you delete it
Purchase recordsIndefinitely, see below

Our application logs record player ids for actions like granting access, but contain no email addresses and no IP addresses. They are capped by size rather than by age, which in practice means days.

Two of these numbers were wrong until 25 July 2026. This page said access logs were kept 14 days when we had already cut them to 5, and said telemetry lasted about three weeks when the file it is written to fills up in well under a day. Both errors meant we were keeping less than we told you, not more, but the numbers were still wrong and they are now the real ones.

Chat, direct messages and forum posts have no deletion schedule yet, which is the weakest line in this table. We would rather say that than pretend a policy exists. Setting real limits is on the list.

10Deleting your account

You can delete your account from the account screen. Here is exactly what happens, including the parts that are not deletion.

Erased

Your game save, cart, bank accounts and transactions, market orders, friendships and channel memberships, and our day-by-day record of how you played are deleted outright.

Anonymised

Your account row survives with the display name Deleted Player and your email address removed. Your player number stays attached to that row, because that is what stops the number being handed to somebody else.

Released

Buildings and businesses you owned go back to being unowned.

Kept

If you have ever bought a Player Pass, your email address stays in that purchase record after you delete your account. We do not remove it.

We keep it because it is the record of a completed sale: we need it for tax and accounting, and to answer a bank if a payment is ever disputed. Stripe holds its own copy of the same transaction independently of us. This is the one carve-out to an erasure request, and we would rather write it down than let "we delete your data" quietly mean something narrower.

The whole row survives, so if you had already withdrawn, the withdrawal details in section 3 survive with it, including your EU, EEA or UK declaration. Two practical things follow. Your purchase is unhooked from your account when you delete, so the self-serve withdraw button stops working even if your window is still open: withdraw first, then delete. And if you did delete first, the right is still yours and the record is still there, so email us from the address you bought with and we will refund you.

Also kept:

11Your rights

If you are in the UK, the EU or the EEA, you can ask us for a copy of your data, to correct it, to delete it, to take it elsewhere, or to object to how we use it. Email support@capitalrift.com and we will answer within 30 days. It is a small operation, so it will usually be much faster.

Three of those you do not have to ask us for at all, because they are buttons in your account:

The purchase-record carve-out in section 10 is the one limit on erasure, and it rests on our need to keep accounting records and to defend legal claims.

Our lawful bases: performing our contract with you (running your account, delivering what you paid for), our legitimate interests (keeping the game working, preventing abuse, understanding performance problems), your consent where you have opted in (notification emails, which are off by default), and legal obligation (keeping records of sales, and running the illegal-content reporting mechanism in section 6).

Where we rely on your consent you can take it back at any time, without giving a reason and without it affecting anything we did while you had given it. In practice that means the notification toggles in your account, which are the only thing here that runs on consent.

Nothing here makes automated decisions about you. No profiling, no behaviour scoring, no algorithm deciding whether you keep your account. Two filters run automatically as you type, one masking slurs and one refusing links, and both tell you when they act; neither records anything against you. If your account is ever restricted, a person read it and decided.

If you are unhappy with our answer you can complain to your local data protection authority. In the UK that is the ICO.

Sending your data to the United States

We are a US company and our servers are in the United States, so using Capital Rift means your data is transferred there. Under UK and EU data protection law that transfer needs a legal basis, so here is ours.

Every company in section 8 that receives your data is certified under the EU-US Data Privacy Framework, and its UK extension, which the European Commission has formally decided offers adequate protection. That covers Google, Stripe, GitHub and Cloudflare. For our own servers, we are the controller and we are the ones handling it, so what protects you there is this policy plus the rights in section 11, which we honour regardless of where you live.

12Children

Capital Rift is not intended for children under 13, and we do not knowingly collect anything from them. If you are between 13 and 16 and live in the EU or the UK, you need a parent or guardian's permission to use it. If you believe a child has an account, email us and we will remove it.

13Security

Everything runs over HTTPS. Sign-in is Google's, so there is no game password for us to lose. Card details never reach us. The game API is locked to your own account, so one player cannot act as another.

What we will not claim: we are a small operation, not a bank. No service is unbreakable, and we are not going to print a paragraph of security theatre here. If something happens that puts your data at risk, we will tell you.

14Changes

If this policy changes we will update the date at the top, and tell you in the game if the change is significant. The game is in active development, so it will change.

NIKS GAMES LLC support@capitalrift.com Terms of Service · Back to Capital Rift