Privacy Policy
Last updated: 3 August 2026 · applies to crawlcore.it
1. Who we are
CrawlCore is operated by Stefano Alberti Perdicchia and Marco Savoldelli, together the Mini Muuu team. Privacy contact: info@crawlcore.it.
2. What we collect
Account data: email address, username, a cryptographic hash of your password (never the password itself), your subscription plan, account creation date and account status. Security data: short-lived email verification / password-reset codes (deleted on use, expired after 15 minutes), failed-login counters (kept at most 30 minutes), and — only if you enable 2FA — a TOTP secret used to check your authenticator codes. Game data: run history (scores, heroes used, outcomes), saved dungeons and saved custom heroes, linked to your account. Technical data: a connection identity token stored in your browser to keep you signed in. Analytics: aggregate, anonymous page-view counts and referrers via Plausible (see section 4), never tied to your account or any individual visitor. Crash reports: if the site errors out, a technical report (error message, stack trace, browser/OS) is sent to Sentry (EU-hosted, Germany) to help us fix the bug; not linked to your account.
3. Where it is stored
Account and game data are stored in a SpacetimeDB database hosted on SpacetimeDB Maincloud (Clockwork Labs). Preferences (team colour, notices you dismissed) and guest play counters live only in your browser's local storage. The website itself is static hosting (Hostinger) and sets no tracking cookies.
Clockwork Labs does not publish which country or region Maincloud infrastructure runs in, so we cannot currently confirm whether your data is processed inside or outside the EU/EEA. If it is processed outside the EU/EEA, this counts as an international transfer under the GDPR; we are seeking written confirmation of the hosting region and appropriate safeguards from Clockwork Labs and will update this section once received.
Our providers, at a glance: SpacetimeDB Maincloud / Clockwork Labs (game and account database — region pending confirmation, see above); Hostinger (static website hosting); Resend (transactional email — EU, Ireland); Sentry (crash reports — EU, Germany); Plausible (cookie-less analytics — EU). Each provider receives only the data strictly needed for its role.
4. What we do NOT do
No advertising trackers, no cross-site tracking, no profiling of individual visitors, no sale or sharing of personal data with third parties beyond the hosting/analytics/error- tracking providers named on this page. We use Plausible for site analytics: it sets no cookies, assigns no persistent identifier to your device, and only reports aggregate numbers (page views, referrers, country, device type). For crash reports we use Sentry (EU data region, Germany), only when the site errors, never for tracking normal use. Transactional emails (account verification codes, password resets) are delivered through Resend (EU region, Ireland), which processes the recipient address solely for delivery. Passwords are hashed in your browser (PBKDF2) before they ever leave it.
5. Legal basis and retention
We process account data to provide the service you signed up for (contract, GDPR art. 6.1.b) and security data to keep accounts safe (legitimate interest, art. 6.1.f). Data is kept while your account exists; run history is capped (oldest entries are deleted automatically); verification and reset codes expire after 15 minutes and are deleted on use; failed-login counters clear themselves within 30 minutes. Deleting your account removes account, security and game data.
6. Your rights
Under the GDPR you can request access, correction, export or deletion of your data at any time: email info@crawlcore.it from your account address. You can also lodge a complaint with your local data protection authority (in Italy, the Garante per la Protezione dei Dati Personali).
7. Children
The service is not directed at children under 14. If you believe a minor registered without consent, contact us and we will remove the account.
8. Changes
We will update this page when the service changes (for example when payments or email features launch) and adjust the "last updated" date above.

