Privacy Notice
What C12 AI Gaming collects, why, how long it is kept, and how to get it back or deleted.
Draft — not in force
This document is awaiting review by counsel and does not yet bind you or C12 AI Gaming. It is published so that what we intend to agree to is visible before it is agreed to.
- Party
- C12 AI Gaming
- Version
- 0.1
- Drafted
- 2026-08-16
Controller
C12 AI Gaming is the data controller for personal data processed through ironics.org, the portal and the game. Data protection enquiries go to privacy@ironics.org.
What we collect, and why
| Data | Why we hold it |
|---|---|
| Email address | It is how you sign in, and how we tell you a cohort decision. Without it there is no account. |
| Date of birth | The 13+ eligibility check. We store it for accounts we accept, so that the check is auditable. |
| Epic account identifier | Only if you choose to sign in with Epic. We store the identifier, not your Epic password. |
| Platform, region, hardware, hours | Cohort planning — deciding which builds go to whom. Never used to accept or reject. |
| Application and account status | Running the beta queue and knowing what you are entitled to. |
| Founder tier and number | Your place in the ladder, which is permanent once issued. |
| Server and access logs | Security, abuse investigation and debugging. |
What we do not collect
If the age check fails, nothing is written. There is no record of the attempt, no email address taken from someone we turned away, and no list of rejected applicants — the check runs before the address is read.
We do not run advertising or analytics trackers, we do not buy data about you from anyone, and we do not build a profile of you across other sites.
Legal bases
- —Contract — running your account, the beta queue, and anything you are entitled to.
- —Legitimate interests — security, abuse prevention, and keeping the service working. We have balanced these against your interests and can explain how on request.
- —Legal obligation — the age check, and anything we are required to retain.
- —Consent — optional marketing email only, withdrawable at any time without affecting your account.
How long we keep it
| Data | Retention |
|---|---|
| Account and entitlements | For as long as the account is open, then 30 days after closure. |
| Sign-in links | 15 minutes, single use. Only a hash is stored, never the link itself. |
| Refresh tokens | Until they expire or are revoked. Only a hash is stored. |
| Server and access logs | 30 days. |
| Audit log of administrative actions | Retained. It is append-only and cannot be edited or deleted by anyone, including us. |
| Rejected applications | Not stored at all. |
Who else sees it
We do not sell personal data and we do not share it for advertising. It reaches these processors because the service could not run otherwise:
- —Amazon Web Services — hosting and storage, in the US East region.
- —Cloudflare — content delivery, DNS, and the bot check on the application form.
- —Resend — delivery of sign-in and decision emails.
- —Epic Games — only if you choose to sign in with Epic, and only the identifier that sign-in returns.
Where it goes
Data is processed in the United States. For transfers out of the UK and EEA we rely on the UK IDTA and the EU Standard Contractual Clauses with each processor above.
Your rights
Where UK or EU data protection law applies you have the right to access your data, correct it, delete it, restrict or object to processing, and receive it in a portable form. Where US state privacy law applies you have comparable rights to know, delete, correct and opt out, and we will not treat you differently for exercising them.
Write to privacy@ironics.org. We answer within 30 days. If you are not satisfied you can complain to your supervisory authority — in the UK, the Information Commissioner's Office.
Children
IRONICS is not for under-13s. We do not knowingly collect their data, the application form refuses them, and where we learn we hold such data we delete it.
Cookies
We set a session cookie when you are signed in, and Cloudflare sets one for the bot check on the application form. Both are strictly necessary — there is no advertising or analytics cookie, and so there is no cookie wall.
Security
Sign-in links and refresh tokens are stored as hashes, never as values. Sessions are signed with a key held in a hardware security module that never exports it. Administrative actions are written to an append-only log that no operator — including us — can alter.
If a breach affects you we will tell you and the relevant regulator within the time the law requires.