Effective 22 August 2026
Privacy, without the fog.
Rocket Foundry is local-first. We use narrowly scoped first-party analytics to improve the game and site, and we do not build advertising profiles.
No advertising IDs, behavioural ads, or sale/share of personal data.
Analytics events do not contain a persistent player, device, account, or save identifier.
Analytics is off until you allow it. Permission can be changed on this page or in game Settings.
1. Controller and scope
This policy covers the Rocket Foundry game, rocketfoundry.net, the Community Hangar, and related support. Paolo Arnolfo, trading as Rocket Foundry, is the developer, service operator, and data controller. Privacy contact: [email protected].
2. Data that stays on your device
Saves, blueprints, settings, mods, Mission Lab scripts, and the Community private signing key stay on your device unless you deliberately publish, report, or contact support. Local game data can be removed through the game data folder or operating-system app controls.
3. Privacy-minimised product analytics
Product analytics is optional and remains off unless you affirmatively allow it. A first-use notice explains the processing before any telemetry request. You can decline without losing functionality and withdraw later. Withdrawing game analytics clears any unsent in-memory batch. Consent is the intended legal basis for this optional collection where applicable.
Checking this browser…
Allowed fields are limited to an event name, broad screen or feature category, broad outcome, app version, platform family, release channel, count, and bounded numeric measurement such as average frame rate. We do not send player or device IDs, advertising IDs, account IDs, IP-derived location, exact device model, save or blueprint names, mods, scripts, coordinates, exception messages, file paths, or other free text.
The website also honors Global Privacy Control and Do Not Track for custom analytics. It uses no analytics cookies and no analytics identifier in local or session storage. A local preference stores only whether you allowed or declined analytics and whether the notice was shown.
Cloudflare necessarily processes network information such as IP address and user agent to deliver and secure requests. We do not copy raw IP addresses into the analytics dataset. The payload is designed not to identify a person or be linkable by Rocket Foundry, but small-beta aggregates can still be distinctive. Client analytics are untrusted estimates and are not used for decisions about a person.
4. Community Hangar and support
Browsing is public. Registering to publish creates a pseudonymous creator ID and stores your chosen display name, public signing key, acceptance status and version of the Community terms, app version, operating-system family, country reported by Cloudflare, creation time, and account status. Publishing also processes the rocket title, author name, blueprint, generated preview, tags, compatibility metadata, submission time, review status, moderation history, and download/view counters. Approved titles, author names, blueprints, previews, tags, and download counts become public.
Reports contain the rocket and version IDs, an enum reason, optional details, status, resolution, and a short-lived keyed anti-abuse token. Do not include personal information. Cloudflare Turnstile may process network and interaction signals for human verification. Administrator actions are recorded in an access-restricted audit log.
If you email support, we process your email address, message, attachments, and the records needed to answer, investigate abuse, or meet legal obligations. We keep ordinary support correspondence only as long as needed for those purposes and applicable limitation periods.
5. Why we process data
- Provide pages, downloads, publishing, moderation, and support.
- Secure the service, authenticate creator actions, rate-limit abuse, and investigate reports.
- Measure broad aggregate usage and performance when you allow analytics.
- Comply with legal obligations and defend legal claims.
Publishing is your deliberate request. Optional product analytics relies on your permission. Security and abuse prevention rely on legitimate interests where applicable.
6. Providers and transfers
Cloudflare provides website and API delivery, Workers, D1 storage, R2 object storage, security, and Turnstile. It acts as a service provider/processor under applicable terms. Data may be processed internationally using applicable transfer safeguards. Discord, app stores, and links you choose to visit have their own policies.
7. Retention and disclosure
- Daily product-analytics aggregates: up to 730 days; no raw analytics event store is retained.
- Community daily rocket statistics: up to 400 days.
- Authentication nonces and idempotency records: about 24 hours; keyed quotas: up to 30 days.
- Resolved reports: up to 180 days; open reports while review is required.
- Rejected, removed, or unpublished objects: normally purged within 30 days.
- Creator, published-content, moderation, and audit records: while the Community account or content is active and afterwards where reasonably needed for safety, disputes, legal claims, or compliance.
Backups and provider replicas may take additional time to expire. We may preserve or disclose records when legally required, to investigate security or abuse, to protect rights and safety, or as part of a merger, acquisition, financing, or transfer of the service subject to applicable safeguards. Aggregates designed not to identify a person generally cannot be linked back for access or deletion, and we do not create an identifier merely to make that link possible.
8. Your choices and rights
You can disable analytics, use the single-player game without Community publishing, unpublish your rockets, and request access, correction, deletion, restriction, objection, or portability where applicable. Email [email protected] from the address you want us to use for the request and identify the relevant creator or rocket IDs. Because Community access uses an on-device signing key rather than an email account, we may ask you to sign a one-time verification request or provide other proportionate evidence before changing private creator records. We will acknowledge and respond within the period required by applicable law; if we cannot verify or fulfil a request, we will explain why and how to appeal where required.
You may complain to your local data-protection authority. We honor legally applicable Global Privacy Control requests; we do not sell or share data for cross-context advertising.
9. Children
Rocket Foundry is intended for players aged 13 and older and is not directed to children under 13. Optional analytics is off until the player allows it and uses no persistent player or device identity. Community users must not put personal information in public fields or content. Parents or guardians can contact us to report personal information so we can investigate and delete it where appropriate.
10. Security and changes
Safeguards include HTTPS, signed creator requests, replay protection, rate limits, strict telemetry allowlists, restricted administrator access, and separation of private signing keys. No system is perfectly secure. Material policy changes will be shown in-game or on the site before changed processing begins where reasonably practicable.