Local game data
CreditQuest works without an account. The browser stores save progress and preferences on your device so that you can resume the game and keep settings such as audio, display, tutorial, and control choices. This information stays in browser storage unless you use a network feature described below. Clearing site data removes it from that browser.
Shared relay features
While you are actively playing online, the relay feature may send an automatically generated runner identifier, display name and color, current map, approximate in-game position, facing direction, appearance, weapon, and game state to the CreditQuest server. This allows nearby ghost runners and the online count to appear.
Presence is kept in server memory and expires after roughly 12 seconds without a heartbeat. The server keeps at most 80 recent relay messages in memory. Messages include the runner identifier, display name, color, text, and time, are visible to other connected players, and disappear when the server process restarts. Do not put personal or sensitive information in a relay message.
Hosting and network delivery
The hosting and network providers necessarily process ordinary connection information—such as IP address, request time, requested path, browser headers, and security signals—to deliver and protect the site. The CreditQuest application does not maintain its own persistent access-log database. Provider-level logging and security retention are controlled by the hosting account and infrastructure.
Analytics design
CreditQuest uses PostHog as a product-analytics processor. Events are sent to PostHog's US Cloud capture service through a small first-party adapter. No third-party analytics SDK is loaded. The adapter creates one random identifier in memory for the current page only; it is not written to cookies or browser storage and changes when the page is reloaded.
The event set is limited to game loaded, run started or resumed, tutorial progress, qualified first play, selected progression milestones, chapter completion, game over, and coarse active-play thresholds. Collection runs only on the secure production site and fails closed for Global Privacy Control, Do Not Track, automated testing, local development, or an invalid configuration.
Data that analytics must not receive
- Runner names, relay identifiers, relay messages, or other free text.
- Save files, browser-storage contents, quest objects, or dialog text.
- Exact in-game coordinates or frame-by-frame combat activity.
- Full URLs, raw query strings, advertising click identifiers, email addresses, or full referrers.
- Console logs, arbitrary errors, or automatically captured page content.
Campaign attribution
Approved campaign tags may be read into memory after strict validation and attached to the game-loaded event. The accepted fields are source, medium, campaign, content, and term. An external referrer may be reduced to its hostname. Raw query strings, full referrers, and advertising click identifiers are not analytics properties and approved campaign or click parameters are removed from the visible URL.
Retention and choices
Local saves and preferences remain until you clear them. Relay presence and messages follow the short-lived limits above. Product-analytics events are retained in the PostHog project for no more than 12 months and are then deleted. CreditQuest does not keep a second analytics database.
You can prevent optional analytics collection by enabling Global Privacy Control or Do Not Track in a compatible browser. Network-level blockers may also block PostHog. These choices do not stop necessary local saves or relay requests that you actively use.
For privacy questions, objections, or deletion requests, email ianwalmsley@ianlan.net. Because the analytics identifier is random, page-scoped, and not retained in your browser, CreditQuest may be unable to associate a past event with you; that limitation is intentional and prevents cross-visit profiling.
Changes to this notice
Updated September 6, 2026: coarse active-play checkpoints may include the current Chapter 1 story step for first runs, helping identify where players lose the route. This adds no recordings, coordinates, text input, or persistent identifiers. Material changes to analytics or network behavior will be documented here before those changes are enabled.
Return to CreditQuest