VELGA / POLICY

Privacy

How the current alpha handles information.

Scope and operator

Velga.io is a multiplayer browser FPS developed by Yimir Games. This page covers the current game and these informational pages. Final operator details, jurisdiction and a privacy contact must be confirmed before publication.

Account information

Registered accounts contain a username, account UUID, creation time, a server-side password hash, Velkie balance, owned and equipped cosmetics, and aggregate spin counts by rarity. Passwords are submitted for registration and login; the current backend stores a bcrypt hash rather than the plaintext password. These records support authentication and persistent progression.

Browser storage

The game uses browser local storage for an authentication token, cached public account profile and device settings. Guest identity is stored for the browser session. Signing out clears the local account token and profile; it does not delete the server account. These information pages do not read or write those game records.

Multiplayer information

Playing sends session and gameplay information to the multiplayer server, including identity, movement, weapon actions and match state. Usernames, visible equipment and match information are shown to other players as part of play. Live round state is held by the server; aggregate cosmetic progression is stored with registered accounts.

Infrastructure and operational logs

The project uses a separate frontend and multiplayer/API backend. Its current architecture supports Vercel frontend hosting, Render backend hosting and server-side Supabase account persistence, with local JSON persistence for development or fallback. Server code logs connection, disconnection and operational errors. Hosting providers may process request and connection information. Actual deployment regions, provider practices, log contents and retention require confirmation.

Retention, access and deletion — unresolved

Account data persists across sessions. A complete retention schedule, backup deletion process and verified account access/deletion request channel have not been finalized. Do not assume that signing out or clearing browser storage deletes server records. These procedures and the applicable rights process require legal and operational review.

Future services — not currently live

Stripe and payment processing, Google advertising, analytics, cookies/consent architecture, branded support email and Velga domain infrastructure remain unresolved future items. This information site adds no analytics, advertising or tracking scripts. This does not establish that hosting never logs requests or that all future services will be cookie-free. Review and update this page before introducing any such service.

Age and youth policy

AGE POLICY REQUIRES FINAL LEGAL REVIEW BEFORE PUBLIC COMMERCIAL LAUNCH. No minimum age, child-directed status, parental consent system or youth-law compliance is established by this page.

Contact and changes

A direct support contact has not been verified for this alpha. A verified privacy contact and a process for policy changes must be in place before the final policy is published. No working email address is represented here.