Legal

Privacy Policy

Last updated: July 22, 2026

Felyra is my independent game studio — I build Let It Lie in the open and run this website. This policy explains what personal data I collect, why, how I protect it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Romanian data-protection law. If anything here is unclear, email me at team@felyra.studio.

1. Who I am (data controller)

The data controller for personal data processed through felyra.studio is:

2. Data I collect

I do not collect special-category data, and I don't run advertising or third-party tracking.

3. How I use it (legal bases)

4. Payments

All payments are processed by Stripe Payments Europe, Ltd., a PCI-DSS Level 1 certified payment provider. Your card data is collected and stored by Stripe directly — it never passes through or is stored on my servers. Stripe processes your data as an independent controller for fraud prevention and as my processor for completing the transaction. See Stripe's Privacy Policy.

5. Cookies

I only use cookies that are strictly necessary to operate the site — to keep you logged in, secure your session against forgery, and let Stripe process payments. I don't use analytics, advertising or cross-site tracking cookies. Full details are in my Cookie Policy.

6. Who I share data with

I never sell your data. I share it only with the service providers needed to run Felyra:

My core providers (Hetzner, Stripe Payments Europe, Oblio) process data in the EU. Where a provider (such as Google) may transfer data outside the EU, that transfer is covered by an adequacy decision or Standard Contractual Clauses under the GDPR.

7. How long I keep it

I keep account and contribution data for as long as your account exists. If you delete your account, I erase or anonymise your personal data, except records I'm legally required to keep (for example, payment and invoice records, which tax law requires me to retain for the legally mandated period).

One special case: community art that has already been baked into a released version of the game stays in the game — a shipped game can't be changed retroactively. On request I will remove your name from its public displays (credits, placards), so the art remains but is no longer linked to you.

8. Your rights

Under the GDPR you have the right to:

To exercise any of these, email team@felyra.studio. You also have the right to lodge a complaint with the Romanian supervisory authority, ANSPDCP.

No automated decisions. I don't use your data to make automated decisions that produce legal or similarly significant effects on you (GDPR Article 22), and I don't profile you.

9. Security

Passwords are hashed with Argon2id and never stored in plain text. Connections are encrypted with HTTPS, payment data is handled entirely by Stripe, and access to systems is restricted. No system is perfectly secure, but I work to protect your data using industry-standard measures.

If a breach happens. If a data breach occurs that is likely to affect your rights, I will notify the Romanian supervisory authority (ANSPDCP) within 72 hours where the law requires it, and inform you without undue delay if the breach is likely to present a high risk to you.

10. Children

Felyra is not directed at children under 16. If you are under 16, please do not create an account or make contributions without the consent of a parent or guardian. If I learn I've collected data from a child without proper consent, I'll delete it.

11. Changes to this policy

I may update this policy as the project grows. Material changes will be reflected by the “last updated” date above, and where appropriate I'll let you know directly.

Contact

Questions about your data or this policy? Email team@felyra.studio and I'll get back to you.