1. Who we are
Runeword Technology Services ("Runeword", "we", "us" or "our") is the controller of personal data described in this notice when we decide how and why that information is used.
Contact: info@runeword.co.uk
Country: United Kingdom
Postal/legal address: Runeword Technology Services, 802 Kingsbury Road, Birmingham, B24 9PS
2. Scope of this notice
This notice applies to Runeword websites, software, account systems, online communities and services that link to it. A specific product or contracted service may provide additional privacy information where its processing differs materially.
3. Personal data we may collect
Account and identity information
Depending on the Service, this may include your username, display name, email address, date of birth or age-eligibility information, profile information, recovery email, password hash, two-factor authentication configuration and account-security preferences.
Content and community activity
Where relevant, this may include profile information, posts, comments, messages, media, astronomy observations, projects, event participation, communities, reactions, reports, moderation records and other information you choose to submit.
Technical and security information
We may process IP addresses, user-agent/browser information, session identifiers, login history, security-event records, timestamps, rate-limit records, device/session information, audit information and diagnostic logs to operate and protect the Services.
Communications and business enquiries
If you contact us, request support, commission work or enter into a business relationship, we may process your name, business details, contact information, correspondence and information reasonably necessary to provide the requested service.
5. How and why we use personal data
UK data-protection law requires us to have a lawful basis for processing. The basis depends on the purpose:
- Contract / steps at your request: creating and administering your account, authenticating you, delivering features you request, storing and displaying your content according to your settings, providing paid or commissioned services and responding to service requests.
- Legitimate interests: securing accounts and infrastructure, preventing fraud and abuse, enforcing rules, moderating communities, diagnosing faults, maintaining service reliability and protecting Runeword, users and third parties. We consider necessity and the impact on your rights before relying on this basis.
- Legal obligation: where we must retain, disclose or otherwise process information to comply with applicable law, court orders, tax/accounting duties or valid legal requests.
- Consent: where we specifically ask for optional consent, for example certain marketing or non-essential cookies/technologies if introduced. You may withdraw consent where consent is the basis.
6. Who we share personal data with
We may disclose limited personal data where reasonably necessary to:
- hosting, infrastructure, email, backup and technical service providers acting on our behalf;
- Google, Microsoft, Apple or Discord when you choose to use or manage the relevant authentication integration;
- professional advisers, insurers, auditors or contractors where appropriate and subject to confidentiality obligations;
- law-enforcement, regulators, courts or other parties where disclosure is required or permitted by law; and
- a successor organisation in connection with a genuine business restructuring, merger or transfer, subject to appropriate protections.
We do not sell your personal data to advertisers.
7. International data transfers
Some technology and authentication providers operate internationally and may process information outside the United Kingdom. Where Runeword makes a restricted transfer of personal data, we use an applicable lawful transfer mechanism or other safeguard required by UK data-protection law. Third-party providers also process information under their own privacy notices and international arrangements.
8. How long we keep information
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the Service, maintaining account security, resolving disputes, enforcing agreements and meeting legal obligations.
Account and linked-provider records are generally retained while the account remains active or until the link is removed. Short-lived OAuth authorisation state and correlation data expires after the authentication flow. Security and audit information may be retained for a proportionate period where needed to detect abuse or investigate incidents. Backup copies may remain for a limited period after deletion until they rotate out of backup systems.
Where a Service supports account deletion or anonymisation, some records may be removed, anonymised or retained only where a lawful reason requires it.
9. Security
We use technical and organisational measures designed to protect personal data, including access controls, prepared database access, password hashing, session controls, CSRF protection, rate limiting, encryption where appropriate, two-factor authentication features and restricted handling of provider credentials and tokens.
No online service can guarantee absolute security. You should use a strong unique password where a password is enabled, protect your third-party sign-in accounts and enable two-factor authentication where available.
10. Cookies and similar technologies
Our account-based Services use cookies or similar browser storage that are necessary for functions such as authenticated sessions, security, CSRF protection, OAuth state/browser correlation, preferences and sign-in continuity. These technologies are used to provide or secure features you request.
If we introduce analytics, advertising or other non-essential storage/access technologies that require consent, we will provide the appropriate information and consent controls before using them where required by law.
11. Your data-protection rights
Depending on the circumstances and lawful basis, UK data-protection law may give you rights to:
- request access to personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- ask us to erase data in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing based on legitimate interests;
- receive certain data in a portable format;
- withdraw consent where consent is our lawful basis; and
- raise a complaint about our use of your data.
Your right to object: where we rely on legitimate interests, you may object to that processing. We will consider your objection and stop the processing unless we have compelling legitimate grounds to continue or the processing is needed for legal claims.
To exercise a right, contact info@runeword.co.uk. We may need to verify your identity before acting on a request.
12. Children and age restrictions
Some Runeword Services may have specific age requirements. Astro Corner is currently available only to adults aged 18 or over and requests date of birth privately for age eligibility. We do not knowingly permit under-18 accounts on Astro Corner under the current eligibility rules.
13. Disconnecting third-party sign-in providers
Where the Service supports connected accounts, you can review and disconnect Google, Microsoft, Apple or Discord through Account Security, provided the account retains another usable sign-in method where required for lockout protection.
You can also manage or revoke access from the relevant provider's own account/security settings. Revoking a provider does not automatically delete the underlying Runeword account or content; account deletion is a separate process.
Google, Microsoft, Apple and Discord are independent controllers for their own services and publish their own privacy information. Their privacy practices are not controlled by Runeword.
14. Questions and complaints
Please contact us first at info@runeword.co.uk if you have a concern about our use of your personal data.
You also have the right to complain to the UK Information Commissioner's Office (ICO), the UK's data-protection regulator. Information about complaints and your rights is available from the ICO.
15. Changes to this notice
We may update this notice when our Services, authentication providers, legal obligations or processing activities change. We will publish the current version here with its effective date and may provide additional notice for material changes where appropriate.
16. Contact us
For privacy questions or rights requests:
Runeword Technology Services
United Kingdom
info@runeword.co.uk
Postal/legal address: Runeword Technology Services, 802 Kingsbury Road, Birmingham, B24 9PS
4. Google, Microsoft, Apple and Discord sign-in
If you choose a third-party sign-in option, we redirect you to that provider. You authenticate directly with them. Runeword does not receive your Google, Microsoft, Apple or Discord password.
Our current account integration requests only the identity scopes needed to sign you in and link the provider to your Runeword account:
We use the provider's stable account identifier to link the identity to your Runeword account. We do not use email address alone to silently merge accounts.
These login integrations do not request access to Gmail, Google Drive, Outlook mail, OneDrive, Microsoft files, iCloud content, Discord messages, Discord servers/guild administration, friend lists or other unrelated provider content.
For Google, Microsoft and Discord, temporary access tokens used during sign-in are not retained after identity verification. Apple may issue a refresh token that we retain in encrypted form where needed to support revoking the Sign in with Apple authorisation if you later disconnect Apple.
We use social-login information to authenticate you, protect account security, pre-fill limited registration details when appropriate, maintain an explicit provider link you requested and investigate authentication abuse. We do not use provider login data for targeted advertising.