Privacy Policy

Slopa

Last updated: August 20, 2026

1. Introduction

This Privacy Policy explains how Slopa Limited ("we", "us", "our") collects, uses, and protects your information when you use Slopa, 3D online RPG game at https://slopa.io (the "Service"). We are the data controller for the personal data described here. By using the Service you agree to the practices described in this policy.

2. Information We Collect

We collect only what we need to run the game:

3. How We Use Your Information

We use your data to:

4. Legal Bases for Processing

Where applicable law requires a legal basis, we rely on: performance of our contract with you (to operate your account and the game); our legitimate interests (to secure the Service, prevent cheating, and improve gameplay); your consent (where requested, such as for non-essential cookies); and compliance with legal obligations.

5. Cookies and Local Storage

We use strictly necessary cookies and browser storage to keep you signed in, maintain your session, and remember your preferences. The Service does not use third-party advertising or cross-site tracking cookies. If you play as a guest, the identifier that restores your guest account is stored the same way (see section 6). You can clear storage in your browser, but doing so may sign you out and reset preferences.

6. Guest Accounts

You can start playing without registering. Pressing PLAY NOW creates a guest account, and a random identifier for it is stored in your browser, in local storage and in a cookie named guest_key, and sent to us so the same character comes back on your next visit. A guest account holds no email address and no password: it holds the display name assigned to it and your in-game progression, together with the technical and anti-abuse data described in sections 2 and 7.

A guest account is deleted, with everything in it, 7 days after its last activity; each time you play, that period starts again. Adding an email address and a password to it, through SAVE YOUR ACCOUNT in the game, makes the account permanent, and it is then an ordinary account under this policy.

Because the identifier lives only in your browser, clearing your browser storage, or playing from a different browser or device, leaves the guest account unreachable, and it is deleted once its 7 days run out. We cannot restore it for you: with no credentials on the account, we have no way to establish that it was yours.

7. Fraud and Abuse Prevention

To stop automated mass creation of guest accounts, we count how many guest accounts are created from an IP address and from a browser over a rolling 24-hour window, and show a Cloudflare Turnstile bot check once a count is exceeded. Turnstile receives your IP address and your interaction with the check; Cloudflare processes it as their own privacy policy describes.

The browser in that count is identified by a fingerprint: one irreversible hash, computed in your browser from stable technical characteristics of it, namely canvas and WebGL rendering output, graphics vendor and renderer strings, audio processing output, screen size and pixel ratio, timezone, language, processor cores, memory, and touch points. Only the hash reaches us. It is deliberately not derived from your user agent, plugins, or fonts.

The fingerprint is never a credential: it signs nobody in and unlocks nothing, and two identical devices sharing one hash can at most face a bot check. We use it for fraud and abuse prevention only. It is not used for advertising, profiling, or tracking you across other sites, and it is not shared with anyone.

8. Sharing Your Information

We do not sell your personal data. We share data only with:

9. Data Retention

We keep your personal data for as long as your account is active and as needed to provide the Service. After account deletion we remove or anonymize your data within a reasonable period, except where we must retain certain records to comply with legal, accounting, or security obligations, or to resolve disputes. Guest accounts are deleted 7 days after their last activity (section 6), and the anti-abuse counters of section 7, an IP address or a fingerprint hash per guest account created, are deleted 24 hours after they are written.

10. Your Rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA, UK, and similar regimes have rights under the GDPR; California residents have rights under the CCPA, including the right not to be discriminated against for exercising them. To exercise any right, contact us at privacy@slopa.io. You may also lodge a complaint with your local data protection authority.

11. Data Security

We use technical and organizational measures to protect your data, including encryption in transit, hashed passwords, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to respond promptly to incidents.

12. International Transfers

Your data may be processed in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards, such as standard contractual clauses, to ensure it remains protected in line with this policy.

13. Children's Privacy

The Service is not directed to children under 13, or under the higher minimum age set by your country's law, and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us at privacy@slopa.io and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date and, for material changes, provide additional notice where appropriate. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

15. Contact

For privacy questions or requests, contact us at privacy@slopa.io.