Riverhold — Privacy Policy

Effective 1 July 2026. Publisher: Zodiverse Publishing OÜ.

This policy explains what information the Riverhold app ("the App", published on Google Play as co.zodiverse.riverhold) collects, why it is collected, and how it is handled. The App is a role-playing game connected to a shared game server operated by Zodiverse Publishing OÜ.

1. Who we are

Riverhold is developed and operated by Zodiverse Publishing OÜ, incorporated in Estonia. Contact: apps@thezodiverse.com.

2. What we collect

The App collects only the minimum information required to run your character and keep your account secure:

The App does not collect: precise location, contacts, calendar, camera, microphone, health data, financial-account numbers, advertising IDs, browsing history, or any content outside the App itself.

3. Why we collect it

4. Third parties

We share information with:

We do not sell, rent, or share your data with advertisers, data brokers, or unrelated third parties.

5. Where your data is stored

Game data is stored on servers located in Germany (Hetzner Cloud), operated by Zodiverse Publishing OÜ. All connections between the App and the server use HTTPS with strong encryption. At rest, sensitive fields are protected inside our database with standard database access controls.

6. How long we keep it

We keep your account and game state for as long as you continue to use Riverhold. If you delete your character in-game (Settings → Delete Character), your character, inventory, quest progress, and all associated game data are permanently removed from our database within 30 days, and the corresponding avatar file is deleted. Sign-in identifiers linking your Google account to a deleted character are also removed.

7. Your rights

You can:

Requests are answered within 30 days.

8. Children

Riverhold is not intended for children under 13 and is rated for teens and adults. We do not knowingly collect data from users under 13. If we learn a user under 13 has created an account, we delete the account and all associated data.

9. Security

We follow common industry practice: HTTPS everywhere, short-lived session tokens, secure Google-verified sign-in, and no storage of user passwords (we never see them). No system is perfectly secure — if we discover a breach affecting your data, we will notify you at the email address on file within 72 hours where legally required.

10. Changes to this policy

We may update this policy. Material changes will be announced inside the App and via the "Effective" date at the top of this page. Continued use of the App after an update means acceptance of the new policy.

11. Contact

Questions, corrections, or deletion requests: apps@thezodiverse.com.