Last updated: 18 September 2026
Who is responsible
Roluva is operated by Roluva, who is responsible for the personal information handled by this service.
For privacy questions or requests, contact [email protected].
Playing on your device
Your browser stores your game progress and preferences locally. Viewing your guest Profile does not create an account or publish your records. Signing in does not automatically upload your game: account-save uploads and restores are actions you choose.
The browser remembers a community profile credential when you create or recover a profile. It remembers an encrypted-backup recovery code only if you select that option. These credentials let whoever holds them access their associated profile or backup, so keep them private.
Optional playtest reports record visits and selected game events on your device after you enable them. They are not automatically sent to Roluva. You can turn reporting off or export a report yourself.
Accounts and sign-in
- Email and password: we store your normalized email address, a salted password hash, an optional account name, creation information and email-verification status. Passwords are not stored as plain text. Email verification is not currently required, and verification or password-reset emails are not currently sent.
- Google: with your permission, Google supplies a stable account identifier and profile information. Roluva keeps the identifier and display name to create or find your account. The requested permissions are
openid profile; we do not request your email address or access to Gmail. - Discord: the
identifypermission supplies your user identifier and profile information. Roluva keeps the identifier and display name. We do not request access to your messages, server list or email address.
Provider access and refresh tokens are not retained after sign-in. Connecting a second provider from Account settings associates that provider with the same Roluva account. We do not combine separate accounts based on a matching name or email address.
We use account information to authenticate you, protect account access and provide the account features you request. A provider account name is private account information unless you separately choose to use it in a public community profile.
Saves and public profiles
Account saves are game data you explicitly upload to your account. They are private to that account, but the Roluva server can read them. The server stores a save revision and update time to help prevent conflicting updates.
Recovery-code cloud backups are separate. Your browser encrypts them before upload using a key derived from the recovery code. The server stores encrypted data and operational metadata; it cannot recover the save without that code. Signing in does not give an account access to an existing encrypted backup.
Community profiles store the display name, selected preset avatar, visibility choice, profile dates and any game totals and records you publish. Profiles start private. Making a profile public allows other people to see its shared information and leaderboard entries. Once published, others may copy that information. Choose a public name that does not reveal details you want to keep private.
Cookies and connection information
Account features use a secure session cookie that browser scripts cannot read. A session expires after 30 days unless you sign out or delete the account sooner. Google and Discord sign-in use a separate, single-use browser flow that expires after ten minutes. These support sign-in and account security.
Requests necessarily pass connection information, such as an IP address, requested URL and browser headers, to the hosting infrastructure and Cloudflare. These services deliver pages, cache public content and protect the site. The application also uses short-lived request counters to limit abuse. This is separate from the optional on-device playtest report.
Clearing browser site data removes local saves, preferences and remembered credentials. It does not delete information already stored on the server.
Why information is used and who receives it
We use information needed to provide the game, accounts, saves and sharing features you request. We also use security information to protect the service and its players, prevent unauthorized access and handle support requests. Where data-protection law requires a lawful basis, providing requested account features supports performance of the service agreement, and protecting and maintaining the service supports our legitimate interests.
The hosting provider processes server data to operate Roluva, and Cloudflare processes traffic to deliver and protect the site. Google or Discord receives the sign-in requests you choose to make; each also handles information under its own privacy policy. Public profile information is shared with visitors only when you choose to publish it. If you contact us, we use your message and contact details to address your request.
See Cloudflare's privacy policy, Google's privacy policy and Discord's privacy policy for those providers' practices.
Optional usage statistics
If you choose Allow statistics, Roluva sends small batches of usage counts to its own server: visits, page views, visible-page time, manual and automatic rolls, offline progress, upgrades, ascensions, activity claims, and sharing actions. Sharing counts distinguish opening the sharing panel, generating an image, requesting a download, copying a link and handing a share to another app. A share handoff does not prove that you published it.
With your permission, the browser stores a random visitor identifier and temporary session counters to recognize return visits and avoid counting the same batch twice. We record a limited source category, such as a search engine or social site, and may receive a short campaign label from the page URL. We do not send full referrer URLs, query strings, passwords, recovery credentials, game saves or generated images as part of usage statistics. Signed-in usage counts can be associated with your Roluva account.
You can decline and keep playing, or change the choice in Settings. Turning statistics off stops new usage batches and removes the remembered statistics identifier and session counters on that browser. Previously accepted counts are not recalled. Daily browser and account analytics records have a 90-day retention window; session records expire 90 days after their last activity. Daily aggregate statistics have a 365-day retention window. Periodic cleanup removes expired records in batches. Account deletion removes the account association and account-specific analytics records; aggregate totals remain.
The operator uses a password-protected administration area to review these statistics and inspect account details and saved-progress summaries for support and service operation. Aggregate account creation and successful sign-in counts are recorded on the server independently of optional browser statistics. These measure account operations; they do not verify that gameplay was earned.
Sharing discovery images
Discovery images are generated on your device. They contain the selected game result and its saved game statistics, with Roluva branding. The image is not automatically uploaded to Roluva. Downloading saves a copy through your browser; choosing your device's share feature passes it to the app or recipient you select, which handles it under its own terms.
Retention and deletion
Accounts, account saves, community profiles and encrypted backups do not currently expire simply because they are inactive. They remain in the active service until you delete the relevant item or ask us to handle a deletion request. Expired sessions and sign-in flows stop working at their expiry time and are cleaned from storage periodically.
- Delete an account in Account settings to remove its account details, linked provider identities, email credentials, sessions and account save.
- Delete a community profile separately. Account deletion does not delete that profile. Delete it first if you want it removed, or retain its original recovery code if you want continued access after deleting the account.
- Delete an encrypted backup separately using its recovery code. This removes the encrypted save. The server retains a hashed credential identifier, revision and deletion time without an automatic expiry to prevent an old upload from restoring a deleted backup.
- Delete an account save separately if you want to keep the account. A revision and deletion marker remain until you upload a replacement save or delete the account, to prevent conflicting saves.
- Clear this browser's site data to remove local game data and remembered credentials. Export a save first if you want to keep your progress.
Signing out does not erase your browser's game. Deletion from the active service does not remove copies you exported or copies other people made of public information. Contact us with questions about retained operational records or backups.
Your choices and rights
You can play without an account, keep a community profile private, export your game save and use the deletion controls described above. Where applicable law provides these rights, you can also ask to access, correct, delete or receive a copy of personal information, or restrict its use. Send requests to [email protected]. We may need information to confirm that the request concerns your account.
You can object to processing based on legitimate interests where applicable law gives you that right. You can also complain to your local data-protection authority; in the UK this is the Information Commissioner's Office.
Changes to this policy
This page will be updated when Roluva's data practices change. The date above identifies this version. The Terms of service explain the rules for using Roluva.