Skip to content
Game data: patch 1.0.0.32 updated 2026-05-31 what changed →

Legal · Privacy Policy

Privacy Policy

What we collect, why we collect it, who processes it, and the control you have over it.

Last updated: 2026-06-26

Who this applies to

This policy covers Quinfall Codex (“the Codex”, “we”, “us”), an unofficial, community-made fan website for The Quinfall, operated by VDecron. You can browse most of the Codex without an account; the data below is collected only as needed for the features you use.

Data we collect

Account & sign-in

  • Email address — if you sign in with an email magic link. We store your email to identify your account and send you the one-time sign-in link. The link itself is stored only as a hashed, single-use token that expires after 15 minutes.
  • Discord account data — if you sign in or link with Discord, we receive and store your Discord user ID and username (display name). We also read your Discord email only when Discord reports it as verified, and use it solely to match or merge your account; an unverified Discord email is discarded.
  • Public name — a nickname / display name shown alongside your contributions. You choose this; it is public by design.

Security & session data

  • Hashed IP address — when you sign in or request a sign-in link, we store a one-way, salted SHA-256 hash of your IP address for security and abuse-prevention auditing. We do not store your raw IP address.
  • Browser user-agent — stored with your session record to help detect suspicious activity.
  • Session token (hashed) — only a hash of your session token is stored server-side; the token itself lives in your first-party session cookie (see Cookies below).
  • Server logs — our host keeps standard request logs. When a sign-in email fails to send, we log only the email domain (e.g. “gmail.com”), never the full address.

Content you create

  • Builds, market listings, guild advertisements, inventory data, watchlists, codex lists, alert rules, shop settings, and feedback you submit. Some of this (e.g. market listings, map nodes, public builds) is shown to other users by design; the rest is tied to your account.

Premium subscription

  • If you buy Premium, we store a record linking your account to your subscription — the payment provider's subscription identifier, the subscription status, the date your access runs until, and any premium redemption code. Your payment-card details are handled by our payment provider, not by us (see Third parties below).

Why we collect it (legal basis)

Where data-protection law (such as the GDPR) applies, we rely on the following bases:

  • Performance of a contract — to create and run your account, deliver features you use, and provide the Premium subscription you purchase.
  • Legitimate interests — to keep the service secure and prevent abuse (hashed IP, user-agent, logs), and to operate community features.
  • Consent — where you actively choose an optional action, such as linking Discord or submitting content.

Third parties who process data for us

We use a small number of service providers to run the Codex. We share only the data each one needs for its function:

  • Lemon Squeezy — payments. Acts as Merchant of Record for Premium. It processes your payment and receives the billing details and email you provide at checkout; we pass it your account identifier (and Discord ID, if linked) so your purchase maps to your account. We do not receive or store your card number.
  • Resend — transactional email. Sends your one-time sign-in links; it receives the recipient email address.
  • Discord — identity provider, only if you choose to sign in or link with Discord. Governed by Discord's own privacy policy.
  • Vercel — hosting. Serves the site and runs our server functions; processes requests and keeps standard server logs.
  • Neon — managed PostgreSQL database where the account and content data described above is stored.
  • PayPal — only if you choose to make a one-off donation from our Support page. The donation happens entirely on PayPal; we do not receive or store your donation payment details.

We also display the public, aggregate live-player count for The Quinfall, which our server fetches from Steam's public statistics API. No personal data is sent to Steam, and that feature sets no cookies in your browser.

We do not sell your personal data.

Cookies & local storage

  • Essential session cookie — when you sign in we set a first-party cookie (qfc_session). It is HttpOnly, Secure, and SameSite=Lax, and expires after about 30 days. It keeps you signed in and is required for account features; it is not used for advertising or cross-site tracking.
  • Browser local storage — we store a few interface preferences (such as a one-time search hint and your high-performance-mode toggle) locally in your browser. This stays on your device and is not sent to us.
  • Third-party embedded content — our Support page loads PayPal's donate button from PayPal, which may set PayPal's own cookies. If the Codex embeds a third-party Twitch stream player, that embed sets Twitch's own cookies; the site-wide stream embed is currently disabled. Any such cookies are governed by those providers' policies.

How long we keep it

  • One-time sign-in tokens expire 15 minutes after they are issued.
  • Sessions expire about 30 days after sign-in.
  • Account data and the content you create are kept while your account exists, and are removed when your account is deleted — either by you from your account page or at your request (subject to short-lived backups and any retention the law requires).

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. You can export a copy of your data or delete your account yourself from your account page. For any other request — or if you cannot sign in — contact us at verywelldecron@gmail.com and we will action your request.

Changes & contact

We may update this policy from time to time; when we do, we will update the “Last updated” date above. For any privacy question, or to make a data request, contact verywelldecron@gmail.com or use the community channels linked in the site footer. See also our Terms of Service.