Privacy Policy

Last updated: 5 July 2026

This Privacy Policy explains what personal data TribalKit ("we") collects when you use tribalkit.com, the TribalKit browser extension and related services, why we collect it, and the rights you have over it.

TribalKit is the controller of this data. For anything privacy-related, contact [email protected].

1. Data we collect

Account data — name, username, email address, avatar and password (stored only as a secure hash). If you sign in with Google, GitHub or Discord, we receive your basic profile (identifier, name, email, avatar) from that provider. If you enable two-factor authentication, we store its configuration.

Security and session data — IP address, approximate country, browser and device information (user agent) and session tokens. The extension additionally computes a device fingerprint and keeps a history of IP addresses per license, used for licensing and abuse prevention.

Game data — your Tribal Wars player name and ID, the servers and worlds you link, your license keys and a log of the actions the extension performs (which scripts ran, when, and on which world).

Technical telemetry — the extension continuously reports diagnostic data: errors, console logs, network request addresses and timings, the address of the game page where they occurred, and the extension version. We use it to detect and fix problems quickly.

Billing data — payments are processed by Stripe. We store your Stripe customer and subscription identifiers and invoice metadata (amount, currency, status). Card details are handled exclusively by Stripe and never reach our servers.

Support and feedback — the content of tickets, messages, feedback and attachments you submit, plus basic browser information captured at the time.

Notifications — if you enable them, the push subscription tokens of your browser.

Integrations — if you link Discord, your Discord ID, username and avatar.

Referrals — referral codes you use or share and the resulting connections between accounts.

2. Why we process it (legal bases)

We process personal data:

  • to provide the Service you signed up for — account, licensing, subscriptions, support (performance of a contract, Art. 6(1)(b) GDPR);
  • to keep the Service secure and prevent fraud and license abuse — session checks, device fingerprinting, IP history — and to diagnose and fix technical problems through telemetry (legitimate interests, Art. 6(1)(f));
  • to send you notifications you opted into (consent, Art. 6(1)(a), withdrawable at any time);
  • to keep billing and tax records (legal obligation, Art. 6(1)(c)).

3. Cookies

We only use cookies that are necessary for the Service or that store your preferences: session cookies (prefixed "tribalkit"), your language choice (NEXT_LOCALE), a temporary referral cookie (tk_ref) when you arrive through a referral link, and a short-lived cookie used during extension sign-in (tk_ext_redirect).

We do not use advertising cookies, third-party analytics or cross-site tracking of any kind.

4. Who we share data with

We do not sell personal data. We share it only with the service providers below, and only to the extent needed:

  • Stripe — payment processing;
  • Resend — transactional email (verification, notifications);
  • Google, GitHub, Discord — only if you sign in or link accounts through them.

Our databases run on our own infrastructure hosted in the EU. Support content may additionally be processed by Google's AI services, as described in the "Artificial intelligence in support" section.

5. International transfers

Our infrastructure is hosted in the European Union. Some providers (such as Stripe, Resend, Google, GitHub and Discord) may process data in the United States; in that case the transfer relies on GDPR safeguards such as the EU–US Data Privacy Framework or Standard Contractual Clauses.

6. Artificial intelligence in support

When you submit a support request, we may use Google's artificial-intelligence services to help us classify tickets, summarise messages, identify relevant technical information and prepare suggested replies for our team.

For that purpose we may send the content of the ticket and, when relevant to solving the problem, attachments, technical information, browser data and logs associated with the request. We aim to limit the data sent to what is strictly necessary and to remove or mask passwords, authentication tokens, cookies and payment data.

Google acts as a service provider for this feature. Data may be processed outside the European Union, including in the United States, subject to the safeguards described in the "International transfers" section.

We use this feature based on our legitimate interest in providing faster, more consistent and more effective support. You can object to this processing on grounds relating to your particular situation, or ask us to restrict it, by contacting [email protected]. We will assess your request and, whenever reasonably possible, handle your support request without the use of AI.

You can ask for information about the data in your tickets that was processed using AI, including the categories of data sent, the purpose of that processing and the recipients involved.

AI does not make solely automated final decisions about your account, license, payments, access to the Service or the application of sanctions. Relevant decisions are made or reviewed by a person on our team.

7. How long we keep data

Account and game data are kept while your account exists. When you delete your account it is deactivated immediately and your data is permanently erased after a retention period of 90 days, except what we must keep for legal reasons (for example invoicing data, kept for the periods required by tax law).

Security logs, telemetry and similar technical records are kept for a maximum of 90 days and then deleted or anonymised.

8. Your rights

Under the GDPR you can ask us for access to your data, correction, deletion, portability and restriction of processing, and you can object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time.

To exercise any right, email [email protected] from the address linked to your account. You can also delete your account directly in the settings.

9. Security

We protect data with measures such as encryption in transit (HTTPS) and encryption at rest: passwords are stored only as secure hashes, and tokens, cookies and other sensitive data are stored encrypted. We also apply scoped access controls, audit logs on administrative actions and optional two-factor authentication on your account.

10. Children

The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a minor has provided us data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the Service evolves. If a change is material, we will notify you by email or in the app. The date of the latest revision is always shown at the top.