RoC Command

Privacy Notice

Last updated 1 September 2026

The short version. We store what you type in, so the tool can show it back to you and to your alliance. We do not sell anything to anyone, there is no advertising and no third-party tracking. Everything runs on servers in the EU. You can download all of your data or delete your account yourself, at any time, from your account page.

Who is responsible

RoC Command is a trade name of Sannverk, Molenstraat 49, 6442 XV Brunssum, Netherlands. Sannverk is the data controller for the personal data described here. For anything about your data, write to support@roc-command.com.

What we collect, and why

Your account

A login name generated from the in-game name you give, a password (stored only as a bcrypt hash, never in readable form), and optionally an email address, a timezone and a language. We need this to let you sign in and to show the app in your language and time.

An email address is required only if you create an alliance, because it is the one way to reach the person who owns it and to get them back in if they lose their password. Members who join through an invite link are never asked for one.

What you record about your castle

Your research levels, hero roster and skills, spec allocation, virtue, buildings, dragon progress, Eden planning, castle coordinates, castle type and the hours you are usually online. This is the point of the tool. It is visible to you, and the parts described in the terms are visible to the leaders of your alliance.

Security records

Sign-ins, failed sign-ins, password resets, and member management actions are recorded with a timestamp so that account misuse can be investigated. Server logs record request addresses. Both are kept for about 31 days and then deleted.

Payment

If you buy a plan, Paddle handles the payment as merchant of record. They collect your billing details and card information. We never see or store your card number. We store only which plan you have, when the period ends, and identifiers that let us match your subscription to your account.

Notifications

If you turn on push notifications, your browser gives us a subscription endpoint so we can deliver them. It is removed when you turn them off. Notifications are off by default and we never send marketing through them.

What we do not do

  • No advertising, and no advertising identifiers.
  • No analytics that profile you, and no third-party trackers or social media pixels.
  • We do not sell or rent personal data, ever.
  • No automated decision-making that has legal or similarly significant effects on you.

Why we are allowed to hold it

  • To perform our contract with you: your account, what you record in the tool, and your subscription.
  • Our legitimate interest in keeping the service secure and working: security logs, error reports and capacity measurements.
  • Your consent: push notifications, which you turn on and can turn off at any time.
  • Legal obligation: our payment provider keeps invoice records for as long as tax law requires.

Who else processes it

We use a small number of providers, all of whom act on our instructions under a data processing agreement:

  • Microsoft Azure (Germany) hosts the application and the database.
  • Brevo (France) sends account emails such as password resets.
  • Migadu (Switzerland) hosts the support mailbox.
  • Sentry receives error reports, with personal data scrubbed before sending.
  • Paddle processes payments as merchant of record.

The application and its database are hosted in Germany. Your data is not transferred outside the European Economic Area except where a provider above requires it, in which case it is covered by an adequacy decision or standard contractual clauses.

How long we keep it

  • Your account and what you recorded: until you delete your account, or a leader removes you from their alliance and you have no other alliance.
  • Sign-in sessions: 8 hours, or 7 days if you asked to stay signed in.
  • Password reset links: 1 hour. Email confirmation links: 24 hours.
  • Server logs and security records: about 31 days.
  • Invoices: held by our payment provider for as long as tax law requires, typically 7 to 10 years.

Your rights

Under the GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, and take it elsewhere. Two of these are built into the app and need no request:

  • Download everything we hold about you as a JSON file, from your account page.
  • Delete your account, from your account page. This permanently removes your account and everything personal attached to it. Content you contributed to an alliance, such as newsfeed posts, stays but is no longer attributed to you.

For anything else, write to support@roc-command.com and we will respond within one month. If you are not satisfied, you can complain to your national data protection authority.

Cookies

We use cookies that are strictly necessary and nothing else, so there is no cookie banner to click away:

  • A sign-in cookie that keeps you logged in.
  • A short-lived cookie during two-factor sign-in.
  • A cookie remembering your chosen language.

Children

RoC Command is not intended for children under 16. If you believe a child has given us personal data, contact us and we will delete it.

Changes

If we change this notice in a way that materially affects you, we will tell you by email or in the app before it takes effect.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.