SneakBit — Privacy Policy
Effective date: 2026-06-01
TLDR
- You can play SneakBit with no account at all — progress is saved in your browser.
- An account is optional. If you create one, we store your email, a one-way hash of your password, an optional display name, and your saved game progress (a cloud save).
- We don't run ads, trackers, or third-party analytics on the web game.
- We never sell your data, and you can delete your account and cloud save at any time.
Who we are
SneakBit is a game developed by Federico Curzel (operating as Hidden Mugs). This policy covers the web version of SneakBit at sneakbit.curzel.it and its optional online account and multiplayer features. Questions: federico@curzel.it.
Playing without an account
By default SneakBit stores your game progress (current zone, position, dialogue progress, unlocked skills, inventory, and your settings/key bindings) locally in your browser's localStorage on your device. This data never leaves your device and is not sent to us. Clearing your browser data removes it.
Optional accounts & cloud saves
If you choose to create an account, we collect and store on our server:
- Email address — used to identify your account, sign you in, and send password-reset emails.
- Password — stored only as a salted one-way hash (scrypt). We never store or can see your actual password.
- Display name — optional, shown to you (and to other players in multiplayer if set).
- Cloud save — a copy of your game progress, key/gamepad bindings, and language preference, so you can continue on another device. Per-device settings such as audio volume are not uploaded.
This data is used solely to provide the account and cloud-save features. We do not use it for advertising or profiling, and we do not share it with third parties except the infrastructure providers below.
Multiplayer
When you host or join an online session, our relay server temporarily processes connection data (including your IP address and a randomly generated session/connection identifier) to route messages between players in real time. This data is held in memory only for the duration of the session and is not stored after the session ends. Where possible, gameplay traffic is sent peer-to-peer (WebRTC), which may expose your IP address to the other player(s) in your session, as is standard for peer-to-peer connections.
Server logs
Our server keeps minimal operational logs (for example, error and performance information, which may include IP addresses and timestamps) to keep the service running and secure. These logs are kept only as long as needed for operations and security and are not used to track you across other sites.
Password-reset emails are sent through a third-party email provider (SMTP2GO) solely to deliver the message you requested. Reset links are single-use and expire after about one hour.
Cookies & tracking
The web game does not use advertising or analytics cookies and does not track you across other websites. Your sign-in token and local game data are kept in your browser's local storage on your own device, not in cookies sent to third parties.
Service providers
- Hosting — a virtual private server that runs the game server and database.
- Email delivery — SMTP2GO, for password-reset emails only.
These providers process data only to perform their function and are not permitted to use it for their own purposes.
Data retention & deletion
Account data and cloud saves are kept until you delete them. You can delete your account at any time from Menu → Account → Delete account in the game; this permanently removes your account, cloud save, and any pending reset tokens from our server. You can also email federico@curzel.it to request deletion or a copy of your data.
Security
Connections use HTTPS/WSS, passwords are stored only as salted hashes, and sign-in uses signed tokens. No method of storage or transmission is 100% secure, so we cannot guarantee absolute security, but we follow industry-standard practices.
Children's privacy
SneakBit is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised effective date.
Contact
For any question about this policy or your data: federico@curzel.it