A Short Stay in Hell · The Great Library

Privacy Policy

Last updated: 5 October 2026

Operator: Indefatigable ICU

This is a fan-made, non-commercial game. We do not run advertisements, do not sell data, and do not use analytics or session-replay tools. This policy describes exactly what the game collects — nothing more.

1. Who we are

This website and game (the “Service”) is operated by Indefatigable ICU (“we”, “us”). This policy explains what information the Service collects, how it is used, and what choices you have.

2. Information we collect

Information you provide through Google Sign-In (optional). If you choose “Sign in with Google”, Google shares your name, email address, and profile picture with us. We store your display name, Google account identifier, and a masked email (for example j***@example.com) in your browser’s local storage. We never see or store your Google password.

Guest mode. You can play without signing in. We generate a random guest identifier and a soul name that stay on your device only.

Gameplay saves. Your position, settings, and progress are saved in your browser’s local storage on your device. Saves are not uploaded to our servers unless you are signed in and the game synchronises presence (see below).

Book submissions. When you submit a book at the slot, we record: your user identifier, soul name, the book’s location (floor, node, shelf, book number), a short excerpt (up to 300 characters) of the game-generated page text, the result, and a timestamp. These records exist only so the operator can see game activity in the admin console; they are capped at the 500 most recent entries.

Feedback. If you send feedback through the game (bug reports, feature requests, canon complaints), we store the category, title, description, your optional contact address, and technical context (page URL, viewport, and browser string), capped at the 500 most recent entries. Your contact address is never included in a GitHub issue.

Multiplayer presence. While playing online, your identifier, display name, and animated position/state are broadcast in real time to other players over an encrypted-in-transit WebSocket connection. This is how your avatar appears in other players’ worlds.

Kiosk AI requests. When you order food at the kiosk, your text request is forwarded to Google’s Gemini API to generate a 3D recipe. Your request and Google’s response pass through our server; we do not keep a history of your orders.

Server logs. Our servers log IP addresses, connection events, rate-limit hits, and error messages for security and abuse prevention. Logs are visible only to the operator and are periodically cleared.

3. How we use information

We do not use your information for advertising, profiling, or tracking, and we do not sell or rent it to anyone.

4. Legal bases (GDPR)

5. Third parties

No trackers: the site loads no analytics, advertising, or session-replay scripts. Fonts are hosted on our own server (public/fonts), so page loads make no requests to Google Fonts and do not disclose your IP address to Google. The only external requests are the ones you trigger yourself by signing in or ordering at the kiosk.

6. Data retention

7. Children’s privacy (COPPA)

The Service is intended for people aged 13 and older. Before entering the game or using sign-in, you must confirm you are 13 or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact us and we will delete it promptly.

8. Your rights

Depending on your location, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing (for example under the GDPR or CCPA/CPRA). Because guest data lives in your browser, most profile data can be erased immediately by clearing site data. For anything held on our servers, contact us and we will respond within the time required by applicable law.

9. Security

We use reasonable technical measures — rate limiting, input validation, least-privilege admin access, and a Content Security Policy — but no system is perfectly secure, and we cannot guarantee absolute security.

10. Changes to this policy

We may update this policy from time to time. The “Last updated” date above will change when we do, and material changes will be announced on the title screen.

11. Contact

Privacy questions and data requests: privacy@indefatigable.icu
General enquiries: info@indefatigable.icu