Legal
Privacy Notice
Last updated: 14 August 2026
At a Glance
This overview is provided for convenience only. The numbered sections that follow are the operative text of this Notice and prevail in the event of any inconsistency.
- Who is responsible: Pyrekin OÜ acts as controller of the personal data described here — see section 2.
- What we handle: account and login data, gameplay and run data, purchase and payment records, and — where you request an ember withdrawal — identity verification data.
- Why we handle it: to open and run your account, let you play and save runs, process purchases, review withdrawal requests, keep the platform secure, and meet legal duties.
- Who receives it: our hosting provider, our payment provider, and public authorities where the law compels disclosure. We do not sell your data or share it with third parties for marketing.
- Where it lives: primarily on infrastructure located in the EU.
- How long we keep it: no longer than the purpose and the applicable statutory periods require.
- What you can do: access, correct, erase, port, restrict or object to our use of your data, and complain to a supervisory authority.
Part A — Who We Are and How to Reach Us
1. Scope and Effect of This Notice
This Privacy Notice (the “Notice”) sets out, in a single place, what Pyrekin OÜ(the “Company”, “we”, “our” or “us”) does with information relating to identifiable individuals, and the entitlements you hold in respect of that information.
It applies whenever you visit our website, register or hold an account, make a purchase, request an ember withdrawal, or otherwise deal with us. Using our services signifies that this Notice has been made available to you and that you are aware of its contents; it is not, and does not operate as, your consent to any processing described below, save where a section expressly states that consent is the legal basis relied upon.
References to data protection law mean Regulation (EU) 2016/679 (the “GDPR”) and any national legislation, guidance or successor instrument giving effect to it.
2. The Controller
Pyrekin OÜ, company registration № 17573421, registered office: Tartu mnt 84a, 10112 Tallinn, Estonia, is the controller of the personal data described in this Notice.
No data protection officer has been designated as mandatory under Article 37 of the GDPR; enquiries are handled by the contact route in section 3.
3. How to Reach Us
Any question, request or objection concerning this Notice or your data may be directed to hello@pyrekin.com. Where a request concerns the exercise of a right under section 13, please describe what you are asking for; we may need to satisfy ourselves of your identity before we act.
Part B — The Data We Hold and Where It Comes From
4. Origin of the Data
Information about you reaches us by three routes:
- From you directly. What you provide on registration, at checkout, in your account settings, on a withdrawal request, or in correspondence with our support team.
- From your use of our systems. Data generated as you play — run state, run history, purchases — and basic technical data (HTTP request metadata) captured for security and debugging.
- From third parties. Our payment provider (confirmation of payment, limited payment metadata) and, where you request a withdrawal, the identity-verification process itself.
5. Mandatory and Discretionary Data
Certain items we cannot do without: without them we are unable to open an account, process a purchase, review a withdrawal request, or discharge a duty imposed on us by law. Those items are marked as required at the point of collection, and withholding them will mean the relevant service cannot be supplied.
Everything else — such as an optional display name — is discretionary, and may be supplied, altered or removed at will through your account settings.
6. Categories of Data
Depending on how you interact with us, we may hold and use the following:
- Account data — email address, optional display name, and a hash of your password (we never store your password in plain text).
- Gameplay data — your active run state, run history, achievements, and leaderboard entries.
- Purchase data — records of ember packs, cosmetic items, and other purchases linked to your account.
- Payment data — payment confirmation records from our payment provider; full card details are held by that provider, not by us.
- Verification (KYC) data — where you request an ember withdrawal: a government-issued ID, optionally a selfie holding it, and payout card details (only the last four digits of which are ever displayed to you or to us after processing).
- Device and technical data — IP address and basic HTTP request metadata, logged for security and debugging.
- Support data — the record of your correspondence with us, including how it was resolved.
We do not seek out special category data within the meaning of Article 9, nor criminal offence data under Article 10, and ask that you do not volunteer any.
Part C — Why We Process Your Data
7. Objectives Pursued and Legal Bases Relied Upon
No processing takes place without a lawful basis. The table below pairs each objective with the categories of data engaged and the ground under Article 6 on which we rely. Where the ground is legitimate interests, we have weighed those interests against your rights and freedoms and concluded that ours do not override yours.
| Objective | Data engaged | Legal basis |
|---|---|---|
| Opening and administering your account | Account data, Support data | Performance of a contract |
| Letting you play and resume runs across devices | Account data, Gameplay data | Performance of a contract |
| Powering the leaderboard and your profile statistics | Gameplay data | Performance of a contract |
| Processing purchases and proving ownership of purchased items | Account data, Purchase data, Payment data | Performance of a contract |
| Reviewing and processing ember withdrawal requests | Account data, Verification (KYC) data, Payment data | Legal obligation; performance of a contract |
| Screening for fraud, abuse, and breach of the Terms | Account data, Device and technical data, Purchase data | Legal obligation; legitimate interests |
| Answering enquiries and providing support | Account data, Support data | Performance of a contract |
| Running the platform and administering IT security | Account data, Device and technical data | Legitimate interests; legal obligation |
| Meeting statutory, tax, and AML/regulatory duties | Purchase data, Payment data, Verification (KYC) data | Legal obligation |
| Establishing, exercising, or defending legal claims | Account data, Purchase data, Payment data, Support data | Legitimate interests; legal obligation |
Part D — Disclosure and Transfers Abroad
8. Recipients
We do not sell personal data and we do not disclose it beyond what the purposes in section 7 require. The recipients fall into three groups:
- Our hosting provider, which stores Pyrekin's data on our behalf.
- Our payment provider, which processes payments and, for withdrawal requests, supports payout to your bank card. Each such supplier is bound by a written processing agreement containing confidentiality and security undertakings and is permitted to use the data only as we direct.
- Public authorities, regulators, courts and law enforcement, where disclosure is compelled by law or is necessary to protect the rights, property or safety of the Company, our players, or others.
If our business or any part of it changes hands, personal data may pass to the acquirer, which will remain bound by protections no less favourable than those set out here.
9. International Transfers
Pyrekin's own infrastructure is located within the EU, so account, gameplay, and purchase data described in section 6 does not routinely leave the EU/EEA on that account. Some of our suppliers and partners — including, potentially, our payment provider and any identity-verification provider we use — may nonetheless operate from, or process data in, a country outside the EEA. The legal regime there may fall short of the standard the GDPR requires.
Where that happens, the transfer is made on one of the following footings:
- the destination is covered by an adequacy decision of the European Commission; or
- the Standard Contractual Clauses adopted by the European Commission are in place; or
- the recipient is certified under an approved framework, such as the EU–U.S. Data Privacy Framework, where that framework covers the transfer in question.
We recognise that contractual protection has limits. Residual exposure may include access to your data by foreign public authorities on terms broader than EU law would permit, practical difficulty in enforcing your rights or obtaining a remedy, or the absence in the destination country of rights and redress mechanisms equivalent to those you enjoy at home. We therefore assess the risk before relying on any of the mechanisms above and apply supplementary measures where warranted, including minimising what is sent, encrypting it in transit and at rest, and confining access to named personnel.
Details of the mechanism used for a particular transfer, and a copy of the safeguards, may be obtained from hello@pyrekin.com.
Part E — Retention and Security
10. Retention
Data is kept for as long as the purpose that justified collecting it subsists, and thereafter only for as long as a statutory, regulatory, tax, or accounting rule requires. In practice this means:
- Account and gameplay data: for as long as your account is active, and deleted immediately upon a confirmed account-deletion request (see section 13), except to the extent retention is separately required below.
- Purchase and payment records: for the period required by applicable accounting and tax law.
- Verification (KYC) data and withdrawal records: for the period required by applicable anti-money-laundering and counter-terrorist-financing law, running from the date of the relevant withdrawal request. This may mean that, unlike other account data, KYC documentation is not deleted immediately upon review or account deletion, but is retained for the legally mandated period and then deleted.
- Security and technical logs: for a limited period appropriate to their security and debugging purpose.
- Material relevant to actual or anticipated legal claims: until the relevant limitation period has run.
Once no basis for retention remains, the data is deleted or irreversibly anonymised so that it can no longer be associated with you.
11. Security Measures
We treat the integrity and confidentiality of your data as an obligation, not an aspiration, and maintain technical and organisational measures proportionate to the risk, including:
- encryption of stored verification (KYC) data and payout card details, both in transit and at rest;
- displaying only the last four digits of payout card details, ever;
- access to verification data limited to personnel who need it to review a request;
- role-based access control for internal systems;
- a documented incident response procedure, including assessment of any personal data breach and notification to the competent supervisory authority and, where required, to you.
12. What You Can Do
Security is shared. You can materially reduce the risk to your own data by:
- using a long, unique password for your account and changing it if you suspect compromise;
- treating unexpected messages asking for credentials or payment as suspect until verified independently;
- keeping your device and browser patched and running reputable security software;
- reviewing your account activity periodically and telling us at once about anything you do not recognise.
Part F — Your Rights and How to Enforce Them
13. Rights Available to You
Subject to the conditions and exceptions the legislation itself imposes, you are entitled to:
- be told what data we hold about you and receive a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have data erased where it is no longer needed for the purpose, where consent has been withdrawn and no other basis applies, or where it has been processed unlawfully;
- have processing restricted while a dispute about accuracy or lawfulness is resolved;
- object to processing founded on our legitimate interests;
- receive data you have provided in a structured, commonly used and machine-readable form, where the processing rests on consent or contract and is carried out by automated means;
- withdraw consent at any time where consent is the basis on which we act.
You can exercise the right to erasure directly at any time using the “Delete my account” button in your profile, which erases your account, run history, cloud save, and purchase records immediately and irreversibly — except for records we are required by law to retain, such as verification (KYC) data during the period described in section 10.
For any other request, write to hello@pyrekin.com. We reply within one month of receipt, extendable by two further months for requests that are complex or numerous, in which case we will tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive. We may ask for information reasonably needed to confirm that you are who you say you are, and will not act until we are satisfied on that point.
14. Automated Decisions and Profiling
No decision producing legal effects for you, or otherwise significantly affecting you — including the review of a withdrawal request — is taken by automated means alone; withdrawal requests are reviewed manually. We do not use your data for automated profiling for marketing purposes.
15. Age Limits
The services are directed at adults. We neither seek nor knowingly process data relating to anyone under 18 (a “Minor”), and by using the services you confirm that you are not one. If you have reason to think a Minor's data has reached us, write to hello@pyrekin.com and we will investigate and delete what should not be held.
16. Complaints and Supervisory Authority
If something about our handling of your data troubles you, raise it with us first at hello@pyrekin.com; we would rather resolve it directly. That route does not displace your statutory right to complain to a supervisory authority.
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
Telephone: +372 6828 712 · Email: info@aki.ee
Website: https://www.aki.ee/en
If you live in another EEA country, you may also complain to the supervisory authority of the Member State in which you live or work. A list of the national authorities is maintained by the European Data Protection Board at edpb.europa.eu.
17. Amendments to This Notice
This Notice will be revised as our processing, our suppliers, or the law change. The date at the head of the document always identifies the current version. Where a revision is material — a new purpose, a new legal basis, a new category of recipient — we will draw it to your attention before it takes effect, by notice on the website or by writing to you directly. Continuing to use the services after a revision has taken effect means the revised Notice governs our relationship; it does not, of itself, constitute consent to any processing for which consent is legally required.
For the cookies and localStorage entries we set, see our Cookie Notice.