Privacy Policy
Effective date: 2026-05-12 · Version 2026-05-12
MOLVERINE CORP, a Wyoming, USA corporation with its registered office at 30 N Gould St, Sheridan, WY 82801, USA (“we”, “us”), operates the Molverine web service (the “Service”). This Privacy Policy explains what personal data we process, why, and what rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable privacy laws.
Краткая русская сводка доступна по запросу на molverinecorp@gmail.com.
1. Data Controller
- Legal name: MOLVERINE CORP
- Registered office: 30 N Gould St, Sheridan, WY 82801, USA
- Contact for privacy requests: molverinecorp@gmail.com
We do not currently maintain an establishment in the European Union; however we are subject to the GDPR to the extent we offer the Service to data subjects in the EU/EEA (Art. 3(2) GDPR). EU/EEA users may also contact us at the address above for any data-protection matter.
2. What We Collect
- Account data — email, display name, hashed password (bcrypt) or OAuth provider identifier (Google), avatar URL, role, account-status flags.
- Consent records — timestamps and version strings of the Terms / Privacy / marketing consents you gave at signup.
- Game state — cases you activated, evidence-board nodes, theories, chat history with in-game NPCs (AI-generated), lab analyses you submitted.
- Technical data — IP address, user-agent, request timestamps. Used for rate-limiting, abuse detection, and basic operational logs.
- Cookies — see Section 8.
We do not intentionally collect special-category data (health, biometric, political opinions, etc.) and we do not knowingly collect data from children under 16.
3. Why We Process It (Lawful Basis under GDPR)
- Contract (Art. 6(1)(b)) — to deliver the game you signed up for: store progress, run interrogations, accept payment for paid cases.
- Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, rate-limiting, aggregate product analytics.
- Consent (Art. 6(1)(a)) — non-essential cookies, marketing emails. You can withdraw at any time.
- Legal obligation (Art. 6(1)(c)) — responding to lawful requests from authorities.
4. Subprocessors
We share personal data with the following processors strictly to operate the Service:
- Amazon Web Services, Inc. — PostgreSQL hosting (RDS). Region: see status page.
- Vercel, Inc. — application hosting, edge caching, basic request logs.
- OpenAI, L.L.C. — generates NPC dialogue from your interrogation messages. Per OpenAI’s API terms, your prompts are not used to train their models.
- Resend, Inc. (if email features are enabled) — transactional + contact-form emails.
- Google LLC — only if you sign in with Google OAuth.
We do not sell or rent your personal data to third parties for their own marketing.
5. Data Retention
- Account data — for as long as your account exists, plus up to 30 days after deletion (backup rotation).
- Game state — same as account; can be exported on request.
- Contact-form messages — up to 24 months, then purged unless tied to an open support thread.
- Operational logs (IP, request metadata) — up to 90 days.
- Consent timestamps — kept as long as the underlying account, as proof of valid consent (GDPR Art. 7).
6. Your Rights
Under the GDPR / UK GDPR you have the right to:
- Access — get a copy of your data (download via your account settings, or request by email).
- Rectification — correct inaccurate data.
- Erasure (“right to be forgotten”) — delete your account and associated data.
- Restriction and objection to certain processing.
- Portability — receive your data in a structured, machine-readable format (JSON).
- Withdraw consent at any time, without affecting prior lawful processing.
- Lodge a complaint with your local supervisory authority.
Under the CCPA / CPRA, California residents additionally have the right to know what personal information we collect, to delete it, to correct it, and to opt out of any “sale” or “sharing” for cross-context behavioral advertising. We do not currently sell or share your personal information; see Do Not Sell or Share.
To exercise any right, email molverinecorp@gmail.com from the address on file, or use the in-app controls under Account → Privacy. We respond within 30 days (45 days for CCPA requests, with one extension permitted).
7. International Transfers
Our infrastructure may store and process data in the United States and the European Union. Where personal data is transferred outside the EEA / UK, we rely on Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework with the relevant subprocessors.
8. Cookies
We classify cookies and similar technologies into three categories:
- Strictly necessary — session, authentication, CSRF protection. Always on; you cannot opt out without breaking the Service.
- Analytics — only set if you accept the analytics category in our cookie banner.
- Marketing — only set if you accept the marketing category.
You can change your choice any time via the “Cookie settings” link in the footer.
9. AI-Generated Content
In-game NPC interrogations are produced by large language models (currently OpenAI GPT models). The content is fictional and may be inaccurate, offensive, or contradictory. We do not represent NPC dialogue as factual. Your interrogation messages are sent to OpenAI for inference; per OpenAI’s API terms, those messages are not used to train their models. See also Section 10 of our Terms of Service.
10. Security
We use TLS in transit, bcrypt password hashing, role-based access control, IP rate-limiting, and least-privilege database credentials. No system is perfectly secure. If you discover a vulnerability, please email molverinecorp@gmail.com.
11. Children
The Service carries a 16+ content rating and is intended for users aged 16 and older — case content includes depictions of crime and other adult themes typical of the detective genre. We do not knowingly collect personal data from children under 13 (COPPA in the United States) or below the digital-consent age in your jurisdiction (16 in most of the EU). If you believe a minor has created an account, contact us and we will delete it.
12. Changes
We may update this Policy from time to time. Material changes will be announced in-app and the version number at the top of this page will be incremented. Continued use after the new effective date constitutes acceptance of the updated Policy.
13. Contact
Privacy questions and DSARs: molverinecorp@gmail.com.
Postal address: MOLVERINE CORP, 30 N Gould St, Sheridan, WY 82801, USA.