◬ Privacy

Privacy Policy

Last updated · 2026-05-25

Who we are

Drobia is operated by Brad Carvalho. Questions go to support@drobia.com.

What we collect

  • Account data: email address (for sign-in via magic link), display name you choose, coalition pick.
  • Gameplay data: survivor progression, materials, expedition history, chat messages, market listings, trade history, contracts completed.
  • Operational data: sign-in timestamps, IP address for anti-spam, basic page-view + action telemetry (no third-party trackers).
  • Payment data: when subscription billing is enabled, Stripe handles payment information. We see the subscription tier and the fact you paid — never the card.

How we use it

  • Run the game: deliver gameplay, sync chat, settle trades, etc.
  • Improve the game: aggregate which features get used, where new players fall off, what breaks. Aggregate only — no individual session replays.
  • Reach you: transactional emails (sign-in link, important account events).
  • Stop abuse: rate limit, block spam signups, enforce the chat blocklist.

Who we share with

  • Supabase — auth + database hosting (US-West).
  • Resend — transactional email delivery.
  • Cloudflare Turnstile — anti-spam on signup.
  • Anthropic — the in-game Operator chat sends your current survivor state + your question to Claude when you call the radio. Your email is never sent; the conversation is not retained beyond the response.
  • Stripe — payment processing if you subscribe.
  • DigitalOcean — server hosting.

We do not sell your data, run ads, or share with analytics ad networks.

Your rights

You can ask for a copy of everything we have on you, correct it, or delete the account entirely. Deletion is self-serve in your settings — there's a 30-day grace where signing back in cancels the request. After 30 days, the account and every row tied to it are hard-deleted. Survivor display name stays attributed to the prior strikes / market listings for game-history integrity, but the account itself is gone.

If you're in the EU/UK, this satisfies your GDPR right to erasure. If you're in California, this satisfies CCPA. Outside both: same rights, same process.

Data retention

Active accounts: as long as the account exists. Deleted accounts: 30-day grace, then removed. Anti-spam logs: 90 days. Chat messages: visible while the account is active.

Cookies + similar

We use a single first-party cookie (your Supabase session) to keep you signed in. No third-party tracking cookies, no advertising IDs.

Children

Drobia is not directed at children under 13. We don't knowingly collect personal information from anyone under 13.

Changes

If we change this policy in a way that materially affects you, we'll notify account holders by email at least 14 days before the change takes effect.

Contact

support@drobia.com — privacy questions, deletion requests, anything else.

← Back to Drobia · Terms of Service