Privacy Policy
What we collect, why we collect it, and why the Hall of Fallen Kings never forgets.
Last updated 23 August 2026
The short version
- We collect what we need to run the game: your display name, your photo, optional links or a decree, what you paid, when, and a random id in a cookie so we can tell it's the same browser.
- On takeover attempts only, we also log your IP address and browser string — for fraud prevention and rate-limiting, never shown publicly.
- Your uploaded photo is re-processed on our server and the original file is discarded; EXIF, GPS and device metadata never reach our database.
- We use NOWPayments to take crypto payments. We never see your wallet address or card details — only whether an invoice was paid.
- Reign records are permanent by design. That's the product, not an oversight — see below for what that actually means and how to request a redaction.
- We host on Hostinger and store data with Supabase. We do not sell your data. Optional analytics tools only run if the operator has actually turned them on.
This summary is for orientation only. Where it conflicts with the full sections below, the sections below are what actually governs.
1. What we collect, and why
- Display name, uploaded photo, optional decree, optional Instagram / X / website links — this is the content of your reign, the actual product. It is displayed publicly the moment you are crowned.
- Your display name, briefly, while you are paying — opening checkout reserves the crown for you, and for that short window the site tells everyone else that it is being taken and by which name, so they know not to pay. That means the name you choose is shown publicly from the moment you open checkout, before you have paid and even if you never do. Nothing else about the attempt is shown: not your photo, not your links, not your IP. If you would rather not be named at that moment, choose a name you are happy to be seen with.
- Crown value paid and timestamps (crowned at, defeated at) — the historical record, and also used to calculate the next price.
- A random identity key, in an httpOnly cookie — lets us show "this browser has been king N times" on the leaderboards without asking anyone to create an account. It identifies a browser, not a legal identity, and is never displayed in readable form.
- Client IP address and browser user-agent, logged on takeover attempts only — used for fraud prevention and rate-limiting, i.e. stopping one browser or network from spamming attempts. Never shown publicly and never linked to your public profile.
- Analytics events (page views, button clicks, funnel steps) — used to understand how people move through the site. Always written to our own database; see Section 5 for the optional third-party sinks.
- An admin session cookie — set only for the site operator when logging into the moderation panel. Ordinary visitors never receive it.
2. Your photo, specifically
When you upload a photo, we verify it is actually an image and then re-encode it on our own server into a fresh 512x512 WebP file. That process strips EXIF data, ICC colour profiles, GPS location, camera and device information, and anything else embedded in the original file — none of that metadata is ever stored or displayed. The original file you uploaded is not kept; only the re-encoded version is. The processed image is stored under a filename derived from its own content, not from anything that identifies you.
4. Payments
Payment happens on a hosted invoice page run by NOWPayments, not on takethecrown.lol. We send NOWPayments the price and a reference id for your attempt; we never handle, see, or store your wallet address, seed phrase, or any card details, because we do not accept card payments at all. What comes back to us is limited to payment status — paid, failed, refunded — and the amount, which is what tells us to crown you.
5. Third parties we actually use
- Hostinger — hosts the application itself.
- Supabase — hosts the PostgreSQL database (kings, reigns, attempts, analytics events), in the EU (Frankfurt, Germany).
- NOWPayments — processes cryptocurrency payments, as described in Section 4.
We do not sell your data to anyone, for any reason.
Optional, and only if the operator has configured it: event data may also flow to Google Analytics (GA4), PostHog, or a generic webhook, for product analytics. These sinks are off by default and only activate if the corresponding API keys are set — email hello@takethecrown.lol if you want to know whether any are currently active.
6. How long we keep things
This is the section that matters most, because it is unusual: reign records — your display name (unless redacted), your photo (unless redacted), your decree and links, the price you paid, and the dates — are kept permanently. Not "until you ask us to delete it." Not "for a set number of years." Permanently. The Hall of Fallen Kings staying complete and unedited is the actual product; a version of this site that quietly deletes old kings is a different, lesser product.
Things that are not permanent:
- the identity cookie expires after about two years of inactivity, after which that browser simply starts fresh as a new anonymous visitor
- fraud-prevention logs (IP address, user agent) are kept only as long as useful for rate-limiting and abuse investigation — they are never part of the public archive
- admin sessions expire after 12 hours
7. Your rights, and redaction requests
Depending on where you live, you may have legal rights over your personal data — to see what we hold, correct it, or ask us to delete it. We honour these to the extent the law requires and to the extent they do not conflict with the permanent-record nature of the product described in Section 6.
In practice, what we can do: email hello@takethecrown.lol from an address, or with details, that let us confirm it is actually you — or, for someone else's photo used without consent, that you are the person in it — and we will redact the image and/or name on that reign, replacing them with a placeholder.
What we cannot do is delete the reign itself: the fact that King #N existed, held the crown from one date to another, and paid a given amount. That would mean rewriting a historical record that is not supposed to change, and other kings' recorded reigns (who they defeated, who defeated them) reference it. If that is a dealbreaker, it is worth knowing before you take the crown, not after — see also the Terms of Service.
8. Children
Take the Crown is not directed at anyone under 18 (or the age of majority where they live), and we do not knowingly collect data from anyone below that age. If you believe a minor has taken the crown, tell us at hello@takethecrown.lol and we will investigate and redact.
9. Security
We take reasonable technical measures to protect the data we hold — encrypted connections, a database that is not directly reachable from the public internet, secrets kept out of source control — but no system is unbreakable and we cannot guarantee absolute security. If a breach occurs that affects your data, we will disclose it as required by law.
10. International data
Our database is hosted in the EU (Frankfurt, via Supabase). The hosting and payment infrastructure we rely on may process data in other countries depending on where Hostinger and NOWPayments run their own systems. By using the site, you consent to your data being processed in these locations.
11. Changes to this policy
We will post updates here and move the "last updated" date at the top of this page. It is on you to check back occasionally; we will not email you about a change unless we judge it significant enough that you would want to know.
12. Contact
Take the Crown is operated by Branda Stock Ltd, an Israeli company, registration number 516304516, at Hadvir 18, Hadera, Israel. Branda Stock Ltd is the data controller for the information described here. For anything in this policy — access requests, redaction, questions, complaints — hello@takethecrown.lol.
See also the Terms of Service.