← Moonforge Moonforge

Moonforge Privacy Policy

Version 1.4 · last updated

This is the privacy policy for Moonforge, an Android game published by Pannotia Studios. It covers the Moonforge app and the Moonforge website.

It describes what Moonforge collects about you, why, who else touches it, how long we keep it, and how to get rid of it. Every sentence here was checked against what the game actually does, not against what we intended it to do. Where something is not settled, this page says so instead of guessing.

1. Who we are, and how to reach us

Moonforge is made and run by Pannotia Studios.

Write to us at support@moonforge.co.za

That address is the contact point for anything on this page: a question, a request for a copy of your data, a correction, or deleting your account. It is read by a person, not a helpdesk.

Postal address: 630 Smook Ave, Pretoria 0084, South Africa.

Who can see your data on our side

Five people can sign in to Moonforge's admin panel, and we would rather spell out what each of them can see than leave you to assume.

Everyone with that access is also a player in the game. The three moderators are ordinary commanders who play in the same round as you, in their own alliances, and one of them plays in the same alliance as the developers. What they can see about your account, they can see about a commander they may be at war with. We think you should know that rather than picture a neutral support desk.

Beyond those five, outside access includes the technical kind that every hosted service has: the data sits on our hosting providers' machines, and their systems and staff can reach it. It also includes ForgeBuddy, the in-game helper: when a commander sends it a question, the question and a snapshot of that commander's game go to the company that writes the answer (see ForgeBuddy in section 2). The companies are named in section 4.

2. What we collect, and why

Signing in with Google

Google Sign-In is the only way into Moonforge. There is no password, so we never see, store or reset one.

When you sign in, the app asks Google for an ID token and nothing else. Moonforge reads no Google service — not your Gmail, not your Drive, not your contacts — and never writes anything back to your Google account.

Google gives us, and our sign-in service stores: your name, your email address, whether that email is verified, a link to your Google profile picture, and your Google account identifier. We use them to know which account is yours, to keep it yours when you reinstall, and to be able to contact you about it.

Your email address is never copied into game data, and no other player can ever see it. Your Google name and your Google profile picture are never shown anywhere in the game either — the link arrives with the sign-in and sits unused in the account record.

The commander name you choose

You choose the commander name other players see, and you can name your alliance, your planets and your fleets. Nothing is prefilled from your Google account. That name is shown to every other player — on the leaderboard, in chat, on radar and in battle reports. If you type your real name, other players will see your real name. That choice is yours.

The game itself

Moonforge is a game with a server, so the game is stored on that server: your planets, fleets, buildings, research, resources, scores, medals, battle reports, alliance membership and rank, your Moon Credit balance, your class and level, and the times you first attacked someone and last signed in. We need all of it to run the game, settle the week and rank the round.

Moon Credits and the Forge Pass are sold through Google Play's billing system, which handles the payment itself — your card details go to Google, never to us. We keep a record of each order, and we keep it after the account is deleted, unlinked from your name (see section 7).

What you write and send

Everything you type in global chat, in alliance chat, and in a direct message to another commander is stored on our server so it can be delivered and shown. So are your reactions, your alliance, planet and fleet names, and the cosmetics you equip. We store them to run those features, and so that a message can be reported and acted on.

Pictures you upload

When you set a profile or alliance picture you pick one image from your gallery and hand it to the app. The app never opens your camera, never records video, and never browses your photo library — you choose one file and only that file is read.

That file goes to our own image worker, which decodes it to pixels, turns it upright, crops it and re-encodes a 256×256 image from those pixels. Everything the original carried — GPS coordinates, camera model, timestamps, colour profiles, embedded thumbnails — does not survive being redrawn, so none of it reaches storage. The original file you picked is never stored.

Voice notes

Alliance Chat can record a voice note, up to 30 seconds long, and send it to your alliance. It has a section of its own — see 6. Voice notes.

Your device and your connection

Every time the app checks in with the server it sends a device identifier that Android gives it — the same value for this phone and this app until the phone is factory reset. We record it, with your IP address, to stop a removed beta account from coming straight back on the same handset under a new name, to apply the game's screenshot rule, and to see when two accounts are being played on one phone.

That last one has a consequence worth spelling out. Moonforge is one account per person. If we judge that two accounts belong to the same person, we flag the second one: it shows a notice that cannot be closed, and cannot be played until the flag is lifted, while the first account is left alone and nothing on the flagged account is taken or deleted. A shared IP address on its own is never enough, and two phones are two devices — a household on separate phones is not affected. No moderator can do this: moderators cannot see a device identifier at all, and only the two developers can set or lift a flag. Every flag and every lift is recorded. If you think we got it wrong, write to support@moonforge.co.za and a person will read it.

Your IP address is recorded in three places: with that device identifier each time the app checks in, with each login session, and in our hosting providers' request logs. The edge network in front of our server also works out, from that IP address, an approximate country, region, city, postal area and timezone, together with the name of your network operator, and records them in those same logs. Those logs exist so that the service can be run and abuse investigated; we do not use the location they work out for anything else, and the app never asks Android for your location.

The app also sends your device's CPU architecture and the app's version number, so the server knows which build your phone can install. Releases ship as separate 64-bit and 32-bit files, and the wrong one will not install.

If you have notifications on, the app registers a delivery token with Google's push service and sends us that token together with your notification settings — whether notifications are on, and which sound pack you picked.

When the app breaks

When the app crashes or hits an error it can report, it sends us an error code, an error message, the name of the screen you were on or of the server call that failed, the app version, and the head of the technical stack trace — about fourteen lines for an error inside the game, and a longer extract for a crash at the Android level, which also names your device's make, model and Android version. We use these to find and fix bugs, and to see what is breaking most. They go to our own database — there is no crash-reporting company involved. There is no switch to turn this off.

How you move around the app

The app records which screen you are on, how many seconds it was on your screen, how many times you tapped, and the names of a few actions you took there, and sends that to our server about once a minute and again when you leave the app. It also sends a short "still here" beat while you are playing.

It does not record what you typed, what you read, or what you looked at — only screen names, timings and counts. We use it to see which screens are actually used and to find the ones that are slow. There is no in-app switch to turn this off today.

Feedback and reports

If you send feedback from inside the app, we get your message, the category you picked, the screen you sent it from and the app version, tied to your account. If you report another player's message, voice note or picture, we record who reported it, the category and any note you wrote, and we take a copy of the thing you reported so the report still makes sense later.

ForgeBuddy

ForgeBuddy is the in-game helper whose face floats over the game's screens. It answers in two ways, and they are not the same for your data.

Written answers are built into the app. Reading them sends no question anywhere.

Answers to your own questions are written by Claude, an AI model made by a company called Anthropic (see section 4). Using ForgeBuddy sends nothing to Anthropic until you send a question, whether you type it or tap one that ForgeBuddy suggests. Opening ForgeBuddy only asks our own server how many questions you have left today. When you do send one, our server sends Anthropic the game's own rules, and with them:

That is all it sends. The snapshot holds nothing your own screens do not already show you, and none of your chat, your direct messages or your voice notes. Your email address, your Google account and your device identifier are not in it. The request to Anthropic is made by our server, not by your phone, so it does not carry your IP address either.

What we keep. Neither your question nor ForgeBuddy's answer is saved in our database. The conversation lives in the app while ForgeBuddy is open, and it is gone when you close it. What we do keep is a tally, so that we can hold the daily limit and know what ForgeBuddy costs to run: for each day, how many of your questions counted towards the daily limit and how many were answered, how much text went to Anthropic and back (counted in the units Anthropic bills by), and what we estimate that cost us. For each question we also keep a random request number, the day, when it was asked and whether it was answered, with none of its words. If an answer fails, our server's error log can keep a short extract of what came back, at most 200 characters, so that we can see what went wrong.

Who has it. Answers to your own questions are switched off for players today. They are switched on for one account, which is one of our own, and our records show that every ForgeBuddy question sent to Anthropic so far came from that account. Everyone else gets the written answers only. When that changes, this section changes with it.

Chat translation

Chat translation is switched on from 25 September 2026, in the version of the app released that week and later. A message is sent to be translated only when a reader asks for it: by picking a chat language in Settings, or by tapping Translate on one message.

A reader can pick a chat language in Settings: English or Afrikaans to start with. It is off until they choose one. Messages in Global Chat and Alliance Chat written in another language are then translated for them, and a reader can also translate a single message by hand. The language a reader picks is kept with their account on our server. Direct messages and voice notes are not translated.

The translations are written by Claude, the same Anthropic AI model that answers ForgeBuddy questions (see section 4). To translate a message, our server sends Anthropic:

That is all it sends. It never sends who wrote the message, or anything about the writer's account or the reader's. A deleted message is never sent, and neither is a message that is only an emote. To learn which language a message is in, the game can send it even when it turns out to be in the reader's own language; the reader then sees it as written. The request to Anthropic is made by our server, not by a phone, so it carries nobody's IP address.

If you write in chat, this part is about you. A message you write in Global Chat or Alliance Chat can be sent to Anthropic to be translated for another reader who has chosen a chat language or who asks for a translation, whether or not you use translation yourself. Nothing in the chat rooms tells you this as you write, so this page does. Translation never changes your message: a reader who sees it translated can always open your original.

What we keep. A translation is kept with the message it translates, together with the language the message was written in and any notes on its slang, so that the next reader of that language does not need a new one. It is removed when the message is edited or deleted, and otherwise kept as long as the message is. We also keep a daily tally for each reader: how many of their translations counted towards the daily limit (ten a day to start with), how much text went to Anthropic and back, and what we estimate that cost us. A message already translated into the same language for someone else is shown from what we kept, and does not count.

3. What we do not collect

Each of these was checked against the app that actually ships, not just against the source code.

4. Who else sees it

These are the companies that handle Moonforge data. They are named, not described as "trusted partners".

Supabase hosts the database, the sign-in service, the picture storage and the server code. Everything in section 2 that we keep is stored there, on Supabase's machines, and processed on our instructions.

Cloudflare sits in front of that server, so every request from the app passes through it. It sees your IP address, your app's user agent, and the approximate location it derives from the IP, and it records them in its logs.

Google appears in three roles:

You can stop all of that notification text going to Google by turning notifications off, in the app or in Android's own settings.

Netlify hosts the Moonforge website and the app download. It never receives any game data. As the website's host it does see the IP address and browser of anyone who visits the site or downloads the app, in its own server logs. We only pull back daily totals — how many page views and how many visitors — with nothing about any individual visitor. The download button also tells our own server that a download started: one request carrying no identity, no arguments and nothing about you, so that we can count them. The website loads no tracking script, no third-party font and no advertising pixel.

Anthropic writes ForgeBuddy's answers to the questions commanders send it, using its Claude models. When you send one, our server sends Anthropic your question, the recent messages of that conversation and a snapshot of your own game, exactly as section 2 lists them, and Anthropic sends the answer back. ForgeBuddy sends no snapshot of your game to Anthropic until you ask, and the snapshot sent with a question never carries another commander's name or their fleets' names. ForgeBuddy never sends your email address, your IP address or your device identifier. Today only one account, one of our own, can ask.

Anthropic also translates chat. For each message, our server sends Anthropic the text of the message, the reader's chosen language and the game's own translation instructions and slang list, exactly as section 2 lists them, and Anthropic sends the translation back. Translation never sends who wrote the message or anything about the writer's account or the reader's, and never sends a deleted message or one that is only an emote. Because a message is sent for its reader, a message you write can go to Anthropic whether or not you use translation yourself.

Anthropic processes that text to write the answer or the translation, and handles it under the commercial terms that cover Moonforge's use of its service, for ForgeBuddy and for chat translation alike. Its privacy policy explains how it treats personal data in its own products, and says that content it processes for its business customers falls under their customer agreement instead. For ForgeBuddy and for chat translation, that agreement is the commercial terms. How long Anthropic keeps the text, and what else it may do with it, are set by those terms and not by us. We would rather send you to Anthropic's own words than paraphrase them here.

That is the whole list. There is no advertising network, no analytics company, no crash-reporting company and no data broker anywhere in Moonforge. If an outside company starts handling Moonforge data for anything new, this page will say so before it is switched on.

5. What other players see

Almost nothing in Moonforge can be seen without signing in: every screen, every profile, every leaderboard and every chat message needs an account. The one exception is pictures, and it is a real one — see the picture links below.

On your profile, another commander sees: your commander name, your class, your level and weekly level, your planet count, your population, your current strength level, your alliance, your battle record, your medals, your ranks and scores, your cosmetics, your profile picture, and your account identifier.

Never on your profile: your email address, your Google name, your ship counts, your fleet breakdown, your attack or defence strength, what you have queued, your level progress, your Moon Credit balance, or what a rename would cost you. Those are stripped by the server before the profile leaves it.

A short public list. Any signed-in commander can read a basic list of every account: the account identifier, the commander name, the class, the alliance and the date the account was created. Nothing else about an account can be read that way.

On the leaderboard, other commanders see your rank, your score, your name, your weekly level and your alliance, and they can search for you by name.

On radar, a commander whose radar reaches you sees a planet's owner name, the name you gave the planet, its level, an estimate of what it would be worth to raid, whether it looks abandoned, whether its owner looks inactive, when it was last raided, and whether an artifact sits on it. A fleet in flight shows as a blip carrying its position, its heading, its speed and a size band — small, medium or large — worked out from how many ships it holds, and whether it can be intercepted, which tells the viewer it is hostile or carrying cargo. A fleet's name, its owner and its exact ship count are shown only for your own fleets and your alliance's. No account identifier appears on radar, and the coordinates are the game map's, not anywhere real.

In chat, a global chat message shows your name, your role colour and what you wrote, to every signed-in commander who has accepted the chat rules. Alliance chat is limited to your alliance. A direct message is visible only to you and the commander you sent it to; if the other commander deletes their account, your copy stays and shows "Departed commander" where their name was.

Translated. A commander who has chosen a chat language, or who asks for a translation, may read your Global or Alliance Chat message translated into their language, and can always open your original; see section 2.

If someone fights you, the battle report they get names you and shows your defending strength at that moment, how many ships you had before and after, and how many were destroyed. That is a real disclosure of your fleet strength at the moment of the fight, to the commander on the other side of it.

Inside an alliance, an officer can see a named member's live attack and defence strength, and every member can see the alliance-wide totals. An officer can also see whether you are online now and how long ago you were last seen. Joining an alliance means sharing that with the people in it.

Friends you have accepted see when you were last online.

No other player ever sees: your email address, your Google profile, your IP address, your device identifier, your device model, your crash reports, your feedback, or which screens you spend time on. Some of those are visible to the people described in section 1: the moderators can see which screens you have been on, and the two developers can see everything else on that list.

6. Voice notes

Alliance Chat can record a voice note, up to 30 seconds long, and send it to your alliance. This is the only place Moonforge uses the microphone, and it is worth being exact about.

When the microphone is on. You start a recording by tapping the microphone button in Alliance Chat. It ends when you send it, when you discard it, or when it reaches 30 seconds — at which point it sends itself. There is no always-listening mode and no service that can start a recording on its own. If you leave the app while a recording is running, the recording keeps running and still sends itself at the 30-second limit. Android asks for microphone permission when you tap that button, and asks again each time you tap it until you allow it or Android stops asking. You can refuse: the rest of the game works normally, you simply cannot send voice notes.

What is recorded. Compressed audio — AAC in an MP4 container, mono, 24 kHz, around 50 kbps. A clip cannot exceed 30 seconds or 256 KB, and our server re-reads the audio when it arrives to check both, rather than trusting what the app claims.

On your phone. The clip is written to the app's private folder while you are recording, and deleted when you send or discard it. If you leave the screen while a recording is running, or the app crashes mid-send, a copy can be left in that private folder until Android clears it. No other app can read it there.

Where it goes. The audio is uploaded over HTTPS and stored as raw bytes inside our database, on our database provider's servers. It is not put in a file store and it has no web address — there is no link to a voice note that could be shared, guessed or indexed. It is never sent to an advertiser or a data broker, and it is never transcribed. Nothing anywhere converts a voice note to text or analyses what you said; the server only checks the format and the length.

Who can hear it. Members of the alliance it was sent to, who have a Comm Station at level 4 or higher, and who have not blocked you or been blocked by you. An alliance holds at most five commanders, so at most four other people can play a clip at any one time. Nobody else can — not other players, not other alliances, and not anyone without an account.

One thing to be aware of: the check is made when someone presses play, against the alliance they are in then. A commander who joins your alliance later can play a voice note you sent before they joined, and a commander who leaves can no longer play it, though the clips they sent stay in the alliance. Because we keep clips indefinitely, the number of people who can have played one over its life is not limited to five — only the number who can play it at any one time is.

Notifications. When you send a voice note, the other members get a push notification that says who it is from and the words "Voice message". The audio itself never goes to Google.

How long it is kept. Indefinitely. There is no job anywhere that deletes voice notes on a schedule. A voice note is removed when the alliance it was sent to is disbanded, when the sender's account is deleted, or when a round wipe clears alliances at the end of a round. If a voice note has been reported, a copy is kept in the moderation record even after that — see section 8.

7. How long we keep it

Almost nothing in Moonforge is deleted automatically, and the honest answer for most of what you send us is "indefinitely". We would rather say that than print a retention window nothing enforces.

WhatHow long
Global chatIndefinitely. Chat shows you roughly the last 24 hours, but that is what is displayed, not what is kept. Nothing deletes an old message on a schedule. When your account is deleted your messages are replaced with "This message was deleted"; the original is kept where only a moderator can read it, for moderation.
Alliance chat and voice notesIndefinitely, until the alliance is disbanded, a round wipe clears alliances, or your account is deleted — your messages and voice notes are deleted with the account. See section 6.
Direct messagesIndefinitely. A direct message is one record shared by both commanders. When your account is deleted the other commander keeps their copy, shown under a placeholder name.
Your in-app mailbox and notification historyIndefinitely, until your account is deleted.
Battle reportsIndefinitely, with the names in them. Your inbox shows about 30 days of the current round, but reports from earlier rounds are still on the server. A report is one record shared by both commanders in it and is kept, with your name, after either account is deleted.
Your profile pictureUntil you replace or remove it, or the account is deleted — at which point the stored image is deleted too. A signed link already handed out stays valid for a year but stops working once the image is gone; see section 5.
Alliance picturesAn alliance picture belongs to the alliance, not to whoever set it, so it is not deleted with a member's account — the Commander's included — because the alliance carries on. It goes when the alliance replaces or removes it, or when the alliance is disbanded.
Feedback you sent usIndefinitely, until the account is deleted.
Crash and error reportsIndefinitely, until the account is deleted.
ForgeBuddy questions and answersNot kept by us. The conversation is gone when you close ForgeBuddy. If an answer fails, a short extract of what came back, at most 200 characters, can sit in the server's error log, which, like the server request logs below, is kept for a window set by our hosting plan. What Anthropic keeps is set by its terms, not by us; see section 4.
ForgeBuddy talliesIndefinitely, until the account is deleted. These are the daily counts of questions that counted towards the limit and of answers, how much text went back and forth, what we estimate it cost, and a record of each question with none of its words; see section 2.
Chat translationsAs long as the message they translate. A translation is kept with its message so that the next reader of that language does not need a new one, and it is removed when the message is edited or deleted. Nothing is kept until chat translation is switched on; see section 2.
Chat translation talliesIndefinitely, until the account is deleted. These are each reader's daily counts of the translations that counted towards the daily limit, how much text went back and forth, and what we estimate it cost; see section 2. Nothing is kept until chat translation is switched on.
Device identifier and IP address sightingsIndefinitely, until the account is deleted.
Your account record and game stateGame state until the account is deleted or the round data is wiped. When the account is deleted, a nameless placeholder record — "Departed commander" with a number, every profile field cleared — is kept indefinitely so that shared records still point at something.
Purchase recordsIndefinitely, and kept after the account is deleted, unlinked from your name: an order can be disputed or refunded through Google Play long after the account is gone. The Forge Pass records that go with an order — what was granted, how far it got, what was claimed — are kept with them for the same reason.
Reserved commander nameWhen your account is deleted your commander name is held, shown nowhere, until the round that is running ends, so nobody can take it over in that round; after that it is released. Deleted in the gap between one round and the next, the hold runs to the latest round end the server knows of — which may already have passed, in which case the name is free at once. A name made only of emoji has nothing to hold and is not reserved; a server with no round at all holds the name with no end date.
Past namesIndefinitely. Every rename is kept as a moderation record, after deletion too.
Scouting and intel reportsDeleted when the round ends, and with the account before that if you delete it.
Screen-time and tap telemetryAbout 30 days for the detailed rows and about 400 days for the daily summaries, cleaned up by a nightly job. Both are deleted with the account.
Queued game orders once they have resolvedDeleted 48 hours after they resolve.
Push delivery recordsUsually deleted within 14 days. That cleanup runs on the back of ordinary push traffic rather than on a clock, so it is a normal outcome rather than a guarantee. They are also deleted with the account.
Login sessionsEach session record keeps the IP address and browser agent it was created with, and is kept until it is replaced or the account is deleted — seven days after you ask. A session that was already open at that moment can last up to an hour more and can do nothing.
Server request logsA rolling window set by our hosting plan rather than by us. Moonforge's server is about a month old and none of its logs have aged out yet, so we cannot honestly print a number we have not seen happen.
BackupsOur hosting provider backs the database up automatically and copies its transaction log off the server continuously, so data you delete can survive in a backup for a while after it leaves the live game. The window is set by our hosting plan.
Moderation recordsIndefinitely, by design. See section 8.

The windows above that are set in the game's configuration — 30 days, 400 days, 48 hours — describe how the game behaves today and can be changed. If we change one materially, we will change this page too.

8. Deleting your account

There are two different things you can ask for, and they are not the same. There is a page of its own for this — how to delete your Moonforge account — and this is the short version.

Both doors are in the app, under Settings › Account › Leaving. Delete my game on this server acts at once. Delete account closes your account for seven days — you can sign in and tap Keep my account at any time in those seven days while a round is running — and on the seventh day the account is emptied and your sign-in is deleted. In the short settlement gap between one round and the next the game refuses both asking and keeping, and the seven days keep counting. If you cannot sign in, email support@moonforge.co.za from the Google address you play with and we will do it from our side within 30 days.

Delete my game on this server

This clears your game at once — your planets, fleets, artifacts, buildings, research, resources, queues, intel and alliance membership on the server you are playing on. Your Moon Credits stay with your account. Your level starts again; points already on the board stay. Your account itself survives, and you pick a new starting location without signing up afresh. It is a convenience for leaving a round, not a deletion: your account record, your email address, your chat history and the battle reports you appear in are not removed by it.

Delete account

This closes your account for seven days, during which nothing is taken and you can sign in and keep it. On the seventh day it removes your sign-in record — your email address and your Google identity — and empties your commander record: your commander name, your game state, your Moon Credits (set to zero, not refunded), your alliance chat, your voice notes, your profile picture, your feedback, your crash reports, your telemetry, your ForgeBuddy tallies and your chat translation tallies. Your Forge Pass progress is lost to you the same way; its records stay with the purchase records, unlinked from your name (see below). Your fleets are destroyed wherever they are, your planets are released to the map as abandoned with their names, your artifacts are used up, and other commanders' radar forgets your name. Your global chat messages are replaced with "This message was deleted"; the original is kept where only a moderator can read it. The commander record itself is kept as a nameless placeholder — "Departed commander" with a number, every profile field cleared — so that other commanders' records still make sense, and your commander name is held until the round that is running ends so nobody can take it over (deleted between rounds, the hold runs to the latest round end the server knows of, which may already have passed; see section 7). After the seventh day it cannot be undone. To play again you would sign in as a new commander.

Some things do not come out, and we would rather name them than let you assume otherwise:

Asking for a copy, or a correction

Email the same address. There is no automatic export button, so this is done by hand too. If something we hold about you is wrong, tell us and we will correct it. Depending on where you live you may have further rights over your data — ask, and we will do our best to honour them.

9. Age, and children

Moonforge is for players aged 18 and over, and that is the target audience we declare on Google Play. It is not made for children.

The reason is what players can send each other. Moonforge has open text chat, private messages between players, pictures, and voice notes in alliance chat. A filter blocks some words before a written message is published, but nothing screens a picture or a voice note before you see or hear it — those are caught only after the fact, when somebody reports them. Moon Credits and the Forge Pass are sold for real money.

We never ask your age at any point in signing up, and we do not check it. There is no age gate in Moonforge, and we never ask for and do not store a date of birth or an age. So "18 and over" is who the game is meant for, not something we are able to verify. We do not knowingly collect anything from a child under 13.

If you are under 18, Moonforge is not meant for you.

If you believe a child has an account, email support@moonforge.co.za and we will delete it.

10. Security

Everything the app sends to the server goes over HTTPS, including your sign-in, your chat, your pictures and your voice notes. A ForgeBuddy question goes on from our server to Anthropic over HTTPS too.

On the server, every game table is protected by row-level security. Almost everything the app shows you arrives through a named server function that checks who you are and what you are allowed to see — which is why a stranger's profile arrives already stripped of your fleet strength and your Moon Credit balance, rather than being trimmed on the phone. A few things the app reads from the tables directly, with row-level security deciding what comes back: the ship catalogue, your own planets, fleets, queues and reports, and the short public list of commanders described in section 5. Everything else about an account, including your Moon Credit balance and when you were last seen, cannot be read that way.

The voice-note table is the strictest case: it is unreachable by any client at all, and audio can only come back through one function that checks your alliance, your Comm Station level and your blocks.

Profile pictures are stored in a private bucket that no other player can list or browse. The links used to show them are signed and valid for a year, and they need no sign-in, so treat one as you would treat a link to a private photo anywhere else.

There is no password to steal. Your session token is stored in the app's own private storage area on your phone, which other apps cannot read, but it is not in a hardware keystore.

Being straight about the limits: the five people in section 1 can read a great deal about your account, two of them can read all of it, and no part of Moonforge is end-to-end encrypted. We can read your chat and play your voice notes. We do not do it for entertainment, but we can, and a report is exactly the situation where we will.

11. Where your data lives

Moonforge's database, sign-in service and picture storage run on Supabase, in Amazon Web Services' London region (eu-west-2), in the United Kingdom. There is no second, live copy of the database in another region — no read replica, no standby. Backups are a separate matter: they are taken and held by our hosting provider, and we cannot tell you from here which region holds them.

Every request from the app reaches that server through Cloudflare, whose network answers your connection at whichever of its locations is nearest to you before passing the request on to London.

Moonforge is played from all over the world; in a single ordinary hour the server took traffic from South Africa, Nigeria, China, Japan and Taiwan. Wherever you play from, your data is sent to and stored in the United Kingdom, and it passes through our providers' networks on the way. If you are in South Africa, Asia or anywhere outside the UK and Europe, that is a cross-border transfer, and using Moonforge means your data makes that trip.

Push notifications go through Google's global infrastructure, and the website and app download are served from Netlify's global network.

A question you ask ForgeBuddy goes further. Our server sends it, with the snapshot described in section 2, to Anthropic, a company based in the United States. Our request does not ask for any particular region, so which country's machines answer it is up to Anthropic, and we cannot tell you from here which country that is.

Chat translation goes to Anthropic the same way ForgeBuddy does: our server sends the message there, and we cannot tell you from here which country's machines translate it either.

12. Changes to this policy

This page carries a version number and a date at the top. When we change it, we change the date.

If a change matters — new data collected, a new company handling it, a shorter or longer retention period — we will say so in the app's update notes, and for anything significant we will announce it in the game itself, not just quietly edit this page.

The current version is 1.4, 25 September 2026. It switches chat translation on (sections 2, 4, 5 and 11 now say so in the present tense; nothing else about it changed). Version 1.3, the same day, added ForgeBuddy, chat translation (then not yet switched on) and Anthropic (sections 1, 2, 4, 5, 7, 8, 10 and 11), and reworded one sentence each in sections 5 and 6.