Last updated: 11 September 2026
Draft. Not yet in effect.
This page is a draft prepared ahead of the formation of Kirobyte, LLC. The company does not exist yet, so there is nobody for this notice to bind, and it is not in force. It takes effect on a date that will be published here once formation completes. Until then, read it as a description of how the site is built, not as the operator's published privacy notice.
xerobytes.net is operated under the name Kirobyte, LLC (in formation). Once the company is formed, it will be the data controller for the personal data described on this page.
The company has not been filed yet. It will be a limited liability company organised under the law of Texas. Kirobyte, LLC's registered office address will be on public record with the Texas Secretary of State once the company is filed. For anything to do with privacy or your data, write to privacy@kirobyte.com. Mail sent to that address is forwarded through Cloudflare Email Routing to the inbox we read.
The site collects as little as it can function with. You can create an account with an email address, a password and a username you choose, or by signing in with a Google account. An administrator can also create an account for you, with your email address, a password they choose and, optionally, a username. There is no phone number, no address, and no profile questionnaire. Google is the only outside sign-in provider the site offers; there is no sign-in through Discord or any other service.
Creating an account yourself needs either an email address, a password and a username, or a Google account. An account an administrator creates for you needs an email address and a password. Without an account you cannot sign in, publish a build, or heart one. Everything else on the list above is generated by the site, recorded by an administrator, supplied by you when you choose to use a particular feature, or sent by Google because you asked it to sign you in.
There is no automated decision-making and no profiling. Nothing here evaluates you by automated means in a way that produces a legal effect or similarly significant effect. Roles are granted by administrators and super administrators. Administrator access needs a second administrator to approve it, unless a super administrator grants or approves it. The cartographer, enumerator and Enumerator+ roles take effect as soon as they are granted, and can also be granted through an invite link an administrator issues: anyone who redeems a live link while signed in receives the role it carries.
Consent is the legal basis for one thing only: event notices by email. Nothing else on this site asks for your consent, and nothing else relies on it. That box is off until you turn it on, ticking it is the whole of the asking, and you can untick it whenever you like under Settings, then Notifications. Withdrawing is as easy as giving, it takes effect from the moment you save, and it does not affect anything we did while it was on.
No IP address and no user-agent string is recorded by this site's own code. Our hosting and database providers see them as an unavoidable part of serving requests, which is covered further down. One such record is kept with your account: Supabase Auth stores the IP address and browser user-agent string of each signed-in session. Those records are kept until the session ends and is cleaned up, or until your account is deleted. How long a session can last depends on our Supabase session settings. Supabase Auth can also keep an audit log of sign-ups, sign-ins and linked sign-in methods, and some of its entries can include an IP address.
If you sign up with an email address, your display name is the username you type on the sign-up form. If an administrator creates your account, it is the name they entered. If your account is created by signing in with Google, a database trigger sets it to the name on your Google account, which is often a real full name, and the site does not ask you to choose another. If the Google name, or the name an administrator entered, is blank or contains an at sign, the trigger uses the part of your email address before the at sign instead, and the site asks you to choose a username when you next use it signed in. Adding Google sign-in to an account you already have leaves its display name as it was. Accounts created before the sign-up form asked for a name also started with the part of the email address before the at sign, and are asked the same question.
That name becomes public as soon as you create a build. It appears as the author byline on every build you publish, and the public profile view that serves those bylines covers you from the moment you save your first build, whether or not you publish it. Until then, nobody who is not signed in can read your display name at all. The name is also attached to map sightings you submit by hand and to nodes you mark as cleared, though those are visible to a narrower audience, described under Who can see map data. Your email address itself is never published. For an account that still carries the name taken from its email address, the part before the at sign is.
If your username is your real name, your real name is what other people will see. You can change it yourself at any time: sign in, open your account settings, and edit it under Your Name. Change it before you post anything if you would rather not show it. If your account was created by signing in with Google and you would rather not publish the name on your Google account, change it before you write your first build. Changing it here does not change your Google account, and signing in with Google again does not change it back. If you would prefer us to correct it for you, that is the right of rectification, covered under Your rights below.
Signing in with Google is optional. When you choose it, your browser goes to Google, you sign in there, and Google sends you back to this site through Supabase, which runs our sign-in system. We ask Google for its basic email and profile permissions and nothing else. We do not request access to Gmail, Google Drive, Contacts, Calendar or any other Google service, and we do not ask for offline access, so Google gives us no long-lived token for your account.
What we keep from what Google sends:
Google also issues a short-lived access token at sign-in, described below. Anything else Google sends is discarded.
What we use it for. Creating your account and signing you in; linking Google sign-in to an existing account that has the same email address; keeping your email address on your account and sending you account emails; and setting your starting username and profile picture. We do not use it for advertising, we do not sell it, and we do not use it to build a profile of you. Apart from completing sign-in, nothing on this site calls a Google service or reads anything else from your Google account. Our use of information received from Google follows the Google API Services User Data Policy.
Who else sees it. Supabase stores it and runs our sign-in system. Cloudflare hosts the site, so the session cookie that carries a copy of these details passes through Cloudflare with each request your browser makes, and Cloudflare Email Service delivers our account emails to your address. Neither uses it for purposes of its own. Your username and the address of your profile picture become public once you write a build, as described under What becomes public. Administrators can see the account details listed under How your data is protected, people holding the census or map roles can see your username where those sections say so, and members of an organisation you belong to can see that your account belongs to it. It is not passed to anyone else for purposes of their own.
Where it is kept. Supabase Auth keeps a copy of everything in the list above, in the user and identity records for your account, and refreshes that copy each time you sign in with Google. That copy stays until your account is deleted, even if you change your username or remove your profile picture here. When an account is created by signing in with Google, your Google name, picture address and email address are also copied once into your profile; changes you later make to your Google account do not reach your profile here.
The access token. Google issues a short-lived access token at sign-in. Supabase holds it until sign-in finishes, then returns it to this site's server along with your new session. If sign-in is abandoned part-way, Supabase deletes it in routine cleanup, which removes sign-in attempts once they are more than 24 hours old. The server does not use it, but it can be stored with the rest of your session in the session cookie described under Cookies, which your browser sends back to the site with each request until the session next refreshes. Nothing on this site reads it or uses it.
If you already have an account. Signing in with Google, when Google reports your email address as verified and that address already has an account here, adds Google sign-in to that account instead of creating a second one. If you had confirmed that email address, your password keeps working too. An account an administrator created for you counts as confirmed, so the password they set keeps working until you change it. If you had never confirmed it, the password can be removed, because nobody had yet proved they controlled the address. The username and profile picture already on your account stay as they are.
How it is protected. Sign-in happens over HTTPS between your browser, Google, Supabase and this site, and Supabase states that it encrypts stored data at rest. Other people can see only the parts described under Who else sees it, above. A copy of the same details is also in the session cookie described under Cookies, which JavaScript served by this site can read and which is not currently marked Secure. The safeguards that apply to all account data are described under How your data is protected.
Stopping and deleting. You can stop using Google sign-in for this site at any time from your Google account: go to myaccount.google.com/linkedapps, choose Sign in with Google, choose this site, and select Stop using Sign in with Google. That stops Google signing you in here. It does not delete your account on this site or the Google details stored with it; to remove those, delete your account as described under Deleting your account. Deleting your account here does not remove the connection from your Google account, so remove it there too if you want it gone.
Public here means readable by anyone on the internet, including people who are not signed in and people who are not using the site through a browser.
Kingdom leadership can issue a census link. Anyone holding that link can fill in a form describing a governor: in-game name and governor ID, alliance, city hall and VIP level, power, kill points, troop counts by tier, march and commander setup, battle role, time zone, the in-game hours they are usually active, their Discord handle, their language, and free-text notes. Every one of those is typed in by whoever fills the form.
One thing is recorded that is not typed in. When the person filling the form is signed in to a leadership account here, the submission also records which account entered it, and the census roll shows that entry as submitted by that person. This exists so that an answer entered on a governor’s behalf is never presented as the governor’s own words. The same applies when leadership corrects an alliance tag on a submission: the correction records which account made it. Submissions made by governors themselves, who do not have accounts, record no submitter.
This, and the kingdom forms described next, are where we hold information about people who may never have visited the site. A governor described in a census does not need an account here, may not know the form exists, and cannot sign in to see or remove what was submitted about them. We are recording that plainly because it is unusual and because it changes what you should expect: if you fill in a census about somebody else, you are the person who decided to give us their details.
Census submissions are not public. The table is restricted at the database level to signed-in administrators and the census enumerators leadership appoints, no anonymous access is granted to it at all, and there is no page on this site that renders a census entry to anyone else. Submissions are append-only: a new submission never overwrites an earlier one, so a correction adds a row rather than replacing it, and the older row remains until the data is deleted.
A census link can be revoked, which closes the form immediately for everyone holding it. If you are named in a census and want the entries about you removed, write to us using the contact address above and say which governor you are; you do not need an account to ask, and we will not require you to make one.
Administrators and holders of the Enumerator+ role can build forms in the kingdom tools and issue a link to each one. Anyone holding a link can answer the form without an account. A form can ask free-text questions, so an answer can contain whatever the person filling it in chooses to type, including details about somebody else.
Answers are not public. Only administrators and Enumerator+ holders can read them, and no anonymous access is granted to them. The site stores the answers, the link they came through and the time they were sent; it does not attach an account or an IP address to them. Answers are append-only: they cannot be edited or deleted through the site, and a form that has been answered cannot be deleted.
If you answered a form, or are named in an answer, and want it removed, write to us using the contact address above and say which form and roughly when. You do not need an account to ask. We remove answers directly in the database.
Map sightings and node status are not public. Both tables are restricted at the database level to signed-in accounts holding the admin or cartographer role, and the live map itself returns a not-found response to anyone else. Visitors who are not signed in receive no sighting or node status content from either table. A client that subscribes to the live feed by hand, signed in or not, is still told when a row is deleted, with that row's internal id and nothing else.
Inside that group, your display name is visible as the reporter on sightings you submit by hand, and as the last person to update any node you mark as cleared. Sightings uploaded by the scanner instead carry whatever reporter string was configured on the machine that sent them.
An administrator can also switch the live map so that each cartographer sees sightings and node status only for the kingdoms they are assigned to, or belong to through an organisation. Administrators still see every kingdom. A home kingdom you set decides only where the map opens, and only you can see it.
You must be at least 13 years old to create an account. The Rise of Kingdoms tools published here are companions to a game with a large younger player base, but the site is not directed at children under 13 and accounts are not knowingly created for them. Where the law where you live sets a higher age for using an online service without a parent's authorisation, that higher age applies instead.
If we learn that an account belongs to someone below the minimum age, we delete the account and the data attached to it, and we will not ask for more identifying information than is needed to find the account. If you are a parent or guardian and believe your child has created an account here, write to privacy@kirobyte.com.
One point matters more for younger account holders than for anyone else. Your username is published as the byline on anything you post. If your account was created by signing in with Google, it starts as the name on your Google account, which is often a real full name. Change it in account settings before posting.
The site sets three cookies, one of which the browser may split across numbered chunks. All three are strictly necessary. There are no analytics cookies, no advertising cookies, and no tracking or cross-site identifiers of any kind.
There is no cookie banner on this site and no consent is collected, because all three cookies are strictly necessary: without them you cannot sign in, stay signed in, or submit a form safely. An earlier build also set a sidebar:state cookie, which was an interface preference rather than a necessity and so would have needed consent. Nothing ever read it back, so it was removed instead.
Three cookie names inherited from the underlying starter kit (layout-style, lang, theme) are read if they happen to be present, but this build never sets them. If your browser still holds one from an earlier version of the site, it will not be recreated once it expires or you delete it.
Browser storage is not used to hold personal data. The in-browser inventory scanner is the one place it might otherwise be: its text recognition runs entirely in your browser against files served from this domain, and it deliberately disables the recognition engine's own cache so that nothing is written to IndexedDB.
There is no analytics on this site. No telemetry, no error reporting, no session replay, no heatmaps, no advertising or conversion pixel, no fingerprinting, and no third-party tracker of any kind. The codebase contains no Google Analytics, Tag Manager, PostHog, Plausible, Umami, Fathom, Mixpanel, Amplitude, Segment, Hotjar, Clarity, Sentry, or Vercel Analytics.
The one activity record the site keeps for itself is the last-active time described under What we collect. It is for administrators running the kingdom tools, is not analytics, and is not passed to anyone else.
The Inter typeface is bundled into the site at build time, so your browser makes no request to Google to load fonts. Your browser only goes to Google from this site if you choose to sign in with Google or follow a link to one of Google's pages, and, after you have signed in with Google, when it shows your own Google profile picture in your account menu and account settings. Other visitors' browsers never load it.
Cloudflare Turnstile protects the sign-in, sign-up, magic link and password reset forms. It is there to tell a person from a script, not to identify you: it receives your IP address and browser characteristics, issues a token that Supabase verifies, and is not used to build a profile or to track you between visits. It runs only on those forms.
A small worker at dl.xerobytes.net keeps one aggregate counter per day of downloads served from origin, held for 48 hours. Repeat downloads are served from the edge cache and are never counted, so it is a cost guardrail rather than a download figure. It records no IP address, no user agent, and no per-download entry, and it sets no cookies.
The inventory scanner on the calculators page reads your screenshots inside the web page itself. The image is never uploaded. Text recognition runs in your browser, against files served from this site, and the picture you select is not sent to us, to Supabase, or to anyone else. Nothing about it reaches a server and nothing about it is stored. Close the tab and it is gone.
eagle-eye is an optional Windows program, downloaded from dl.xerobytes.net and run on your own PC. It is not part of the website, nothing on the site requires it, and it is only relevant if you have chosen to install it. Unlike the in-browser scanner described above, it can send data to this site.
Two limits are worth stating. The session cookie can be read by JavaScript served by this site, because the Supabase browser client needs it, and it is not currently marked Secure, so your browser does not limit it to HTTPS connections. The Cookies section explains both.
That is the entire list. Nothing is sold, rented, or shared with advertisers or data brokers, and no third party receives your data for purposes of its own. Google knows that you signed in with it, under its own privacy policy, and information we receive from Google is used only as described under Signing in with Google. We would disclose data if we were legally compelled to.
Supabase, Cloudflare and Google are United States companies running global infrastructure, so your data may be processed outside the country you are in, including in the United States. Where that involves personal data leaving the United Kingdom or the European Economic Area, transfers to Supabase and Cloudflare rely on the data processing terms and standard contractual clauses those providers make available to their customers. Google handles your Google sign-in under its own privacy policy.
Deleting your account removes the underlying authentication record, and that cascades: your profile row, your builds, your hearts, your role grants and invite redemptions, your event notification preferences, your organisation memberships, kingdom assignments and home kingdom, your Google sign-in link with the Google details stored alongside it, and your session records are all removed. We delete your uploaded avatar file first; if that fails, the account is still deleted and we remove the leftover file by hand. It is a real deletion, not a hidden flag. Copies can remain in database backups until they age out, as set out above. The list does not include Supabase Auth's audit log, if it is kept: nothing on this site deletes its entries.
Three consequences are worth knowing. Builds you published disappear from the site along with the account, so anyone reading them loses them. Map sightings you submitted by hand carry your display name in a free-text field that is not linked to your account, so the cascade does not catch them; they are removed on the 90-day cycle described above, or sooner if you ask us. Node status rows carry your display name the same way; they are removed once the node's status has gone 90 days without an update, or sooner if you ask us.
Deleting your account does not touch your Google account. This site does not tell Google you have left, so it can stay listed among the apps linked to your Google account until you remove it at myaccount.google.com/linkedapps. A profile picture that came from Google was never stored by us, so deletion removes our copy of its address, not the picture.
If you are in the United Kingdom or the European Economic Area, data protection law gives you the rights below. We will honour them for everyone, wherever you are.
To exercise any right you cannot exercise yourself in account settings, write to privacy@kirobyte.com. We will reply within one month. There is no charge, and we will not ask you for more identifying information than we need to be sure the request is yours.
If you think we have handled your personal data badly, write to privacy@kirobyte.com and we will reply within one month. You also have the right to complain to a data protection supervisory authority. In the United Kingdom that is the Information Commissioner's Office. In the European Economic Area it is the authority for the country where you live, where you work, or where the problem happened.
Supporter memberships are not live yet. No payment provider is connected to the site, and no payment or card details are collected or stored today. An administrator can record an account as the payer for an organisation's access to the kingdom tools, as described under What we collect; that record names an account and a number of seats, and no money moves through the site. When memberships launch, payments will be handled by our payment provider, card details will go to them rather than to us, and this policy will be updated to describe that before any payment can be taken.
This policy will be updated as the site changes. The current version is always the one published on this page, and the date at the top tells you when it last changed.