How the Command Center uses personal data
Controller and contact
Lucas Bach Boesgaard · lucasboes9@gmail.com
Privacy requests: lucasboes9@gmail.com
Purpose and legal basis
Account access and private workspace administration: Contract (Article 6(1)(b)) — processing is necessary for account authentication and access to the private service.. This covers authentication and the account-bound command data needed to provide the private service.
No-login resource requests and abuse prevention: Legitimate Interests (Article 6(1)(f)) — reviewing and delivering requested in-game resources and preventing abuse, with 30-day retention.. Public submissions remain disabled unless this purpose has its own configured legal basis.
The legitimate interests pursued for public requests are reviewing and delivering requested in-game resources and protecting the form from automated abuse. The controller limits the impact through data minimization, short retention, keyed source hashing, submission limits, owner-only review, and service-only database access.
Data must not be reused for unrelated purposes. The application does not currently offer a separate optional “Remember Me” control.
Data handled
Supabase Auth handles the email address, password verifier, authentication factors, account dates, and session records. The Command Center stores account activation metadata and may store game names, influence and troop statistics, activity and faction roles, resource requests, transaction notes, battle reports, and planning notes. A public resource request stores the submitted in-game name, resource, amount, purpose, privacy-notice version, status, and timestamps without creating a login.
Roster and operational data may be entered by another faction member rather than collected directly from the person concerned. Do not enter real-world identity, contact information, health data, political or religious beliefs, sexuality, government identifiers, payment information, or other sensitive information.
To limit automated abuse, public submissions use a daily rotating keyed hash derived from network and browser signals. The original values are not stored in the request table. The rate-limit record is kept separately, stops affecting submissions after one hour, and is removed by the daily cleanup.
Recipients, hosting, and transfers
Vercel hosts the application and Supabase provides authentication and PostgreSQL. Their authorized subprocessors may process data to provide infrastructure, email delivery, security, backups, and support. Hosting providers may process service logs such as IP address, request time, and browser metadata. The controller must keep the applicable processor agreements and international-transfer safeguards under review.
Retention
Member accounts that have not used an authenticated feature for 30 days are scheduled for deletion. Public resource requests expire after the same period. The owner account remains until manually deleted. Supabase authentication logs, provider backups, and infrastructure logs may remain for the limited periods stated in provider agreements.
Your choices and rights
The account page provides a machine-readable export and permanent account deletion. A person who submitted a public resource request can ask for access, correction, deletion, restriction, or object to the legitimate-interest processing by contacting the controller and identifying the in-game name and request details. Requests are normally answered within one month after identity is reasonably verified. There is no advertising, sale of personal data, or automated decision-making with legal or similarly significant effects.
You may complain to Datatilsynet or another competent supervisory authority.
Browser processing
Screenshot recognition runs locally in the browser; original screenshots are not uploaded by the reader. Values selected from recognition become command data. The browser keeps a local recovery copy, and downloaded backups remain wherever the user saves them. Users must protect and delete those copies separately.
Security and incidents
The service uses encrypted transport, managed Supabase authentication, row-level database policies, same-origin write checks, revision conflict protection, and restricted account access. No security measure eliminates all risk. Suspected unauthorized access or loss should be reported immediately to the privacy contact so the controller can assess containment, notification, and documentation duties.