CL:TD // DATA CHANNEL
Gameplay Analytics Privacy Notice
Effective: August 16, 2026
The short version
- The Steam demo records required, minimized gameplay analytics and uploads them when a supported verified connection is available. It begins collection automatically during launch after its bounded local queue is ready. There is no startup disclosure or acknowledgement input; F1, Config, the bundled policy, and this page remain available.
- The full game's analytics are optional and off by default.
- The browser demo does not use this gameplay-analytics system.
- The native Steam demo keeps an isolated local profile, settings, bounded recovery images, and Campaign/Rogue/Descent resume points so tutorial completion and demo progression persist. Config's guarded erase removes all of those local progress records and queued analytics; this does not opt out of required collection if the demo continues running.
- No name, email, SteamID, username, IP field, hardware ID, persistent install ID, raw command text, or other-Steam-game data is stored in the analytics database.
- Every launch gets a new random session ID; it is never reused to track a player across launches.
Network providers necessarily process source IP addresses to deliver and protect internet traffic. CL:TD does not put them in analytics payloads or store them in its gameplay-analytics database.
What is collected
We collect allowlisted, structured CL:TD facts:
- app, build, analytics schema, and content identifiers;
- random launch-local session, event, and retry IDs, plus event wall-clock time rounded to a 15-minute UTC interval before upload;
- total, foreground, active, menu, build, wave, and paused time;
- modes and runs started, resumed, restarted, completed, lost, or abandoned;
- the last CL:TD screen, operation, wave, depth, or phase reached;
- waves, lives, leaks, kills, resources, spending, known command categories, and objective outcomes;
- aggregate tower placement, upgrade, cost, active-time, target, damage, and kill facts;
- account level at wave start, applied difficulty scaling, enemy durability, route coverage, and completed or incomplete wave measurements;
- aggregate outcomes and response-time histograms for disclosed combat windows, plus accepted, rejected, and cancelled strategic command counts;
- aggregate shop, draft, route, firmware, quarantine, boot, and Frontier-system choices; and
- clean exit status, or a possible crash inferred when heartbeats stop without a session-end event.
“Modes played” means modes inside CL:TD. We do not inspect a Steam library. We do not send raw commands, aliases, output, chat, exact key timing, paths, dumps, accessibility settings, or free-form input.
Steam validation and network data
When queued events can be sent through a verified connection, Steam supplies a short-lived authentication ticket. Our server asks Valve to confirm that the ticket was issued for the stated CL:TD AppID. Valve's successful response contains a SteamID; the server checks the response and immediately discards the SteamID. Neither it nor the ticket is stored or returned to the game. To prevent replay while allowing safe retries, the server keeps a keyed one-way ticket digest and launch-local nonce with the short-lived authorization row. It cannot be reversed without the server secret and is used only for authentication idempotency.
The game also reports its Steam BuildID. The service accepts only publisher-allowlisted BuildIDs, but Valve does not attest that value in its ticket response. It supports version grouping and screening; it is not proof that unmodified code produced an event.
Valve/Steam, OpenAI, and Cloudflare infrastructure necessarily sees connection data such as an IP address while authenticating, routing, rate-limiting, and securing traffic. Those providers may retain limited operational or security logs under their terms. CL:TD does not add IP addresses to gameplay records or use them to link sessions. At the edge, the service transiently transforms the connection address into a secret-keyed rate-limit key used only for the provider's short limiter window; it is not written to CL:TD application tables or logs. Authenticated batch requests are separately limited by their random, short-lived authorization-token ID.
Purpose and legal basis
Data is used to find balance problems, difficulty spikes, defects, unclear onboarding, abandonment points, and underused or overused towers and choices; and to keep invalid submissions out of analysis. Behavior may suggest friction or engagement, but cannot prove how an individual felt. It is not used for advertising, sale, or decisions with legal or similarly significant effects.
Full-game analytics rely on opt-in consent where consent applies. It can be withdrawn at any time. For the required evaluation-demo analytics, where applicable we rely on legitimate interests in evaluating and balancing the prerelease slice and securing the service. The data is minimized and identifiers rotate each launch; the policy is available before download and through persistent in-game surfaces, and a player who does not wish to participate can exit and remove the demo. This basis will be reviewed for every place where the demo is offered.
Offline storage and retention
HTTPS protects data in transit. Offline events use a separate local queue, distinct from profile data, settings, recovery images, and saved games. It is capped at 256 events and 256 KiB. Records older than seven days are removed and the oldest are evicted first. Uploads do not make gameplay or shutdown wait for the network. The required demo does not begin if its local queue or secure randomness cannot initialize. Full-game opt-out deletes the queue; removing the demo and its local application data does too. It is stored in the game's operating-system-managed application-data directory without separate CL:TD at-rest encryption, so someone with access to that local account's files may read it. The queue also keeps exact epoch-second creation and next-retry times only on the device to enforce expiry and upload backoff. Those values are deleted with their batch and are never uploaded. The native Steam demo additionally stores its bounded profile, settings, recovery images, and Campaign/Rogue/Descent resume points under the separate cltd-steam-demo application identity. It does not read or write the full game's local identity. Config's two-step erase removes the demo profile, settings, recovery images, and embedded resume points and asks the analytics system to purge its queue. A failed deletion is reported instead of presented as success. Because demo analytics are required, collection begins again if the player continues using the demo after an erase. Steamworks SDK 1.65 cannot enforce its certificate-verification option on Linux, so current Linux builds keep and expire this bounded queue rather than sending through an unverified connection.
The full-game preference and session-start witness carry privacy notice version 1. Missing, malformed, or incompatible preference data defaults to off, so a future material change can require a new choice instead of silently reusing an older opt-in.
| Record | Target |
|---|---|
| Accepted detailed gameplay events | 90 days |
| Quarantined implausible/outlier events | 14 days |
| Authorization rows | 24 hours |
| Retry-deduplication receipts | 9 days |
Structured events and short-lived authorization metadata are stored in Cloudflare D1 active tables for the OpenAI Sites deployment. Cleanup runs hourly and after successful ingestion, so an eligible row may remain until the next successful sweep, ordinarily up to about one additional hour. These targets apply to active tables. The database provider's point-in-time recovery may retain deleted database state for up to 30 additional days, depending on the service plan. Expired analytics will not be restored except for disaster recovery or a legal obligation. Truly anonymous aggregate statistics may be kept longer to compare game versions.
Validation, sharing, and security
The endpoint permits only known builds, exact fields, known categories, bounded values, and launch-local IDs. Duplicates are ignored; contradictions and impossible-looking records are quarantined. Steam authentication does not prove an unmodified client or honest human play, so client analytics remain untrusted evidence.
Data is disclosed only to providers needed to authenticate, host, secure, and operate the service: Valve/Steam, OpenAI, and Cloudflare. Processing may occur outside the player's country under applicable transfer mechanisms. We do not sell, rent, or share analytics for cross-context behavioral advertising.
Choices and rights
Full-game players can leave analytics off, opt in, or opt out; opting out stops collection and removes unsent events. Demo analytics are required for that evaluation build and begin automatically during launch. A player can use Config's guarded local-data erase, exit, or remove the demo's local application data. Erase is not an analytics opt-out; required collection resumes while the demo is used.
Depending on location, rights may include information, access, correction, deletion, restriction, objection, portability, consent withdrawal, or complaint to a data-protection authority. Contact support@cltd.sh.
Because we intentionally keep no account, SteamID, persistent install ID, IP field, or cross-launch ID, we normally cannot determine which launch-local records without a direct or cross-launch identifier belong to a requester. We will not collect new identity data merely to do so, but will explain and honor any request that can be reliably completed without exposing another player's data.
Children, changes, and contact
CL:TD is not directed to children under 13. The analytics system is not intended for a child who cannot lawfully use the game or provide required authorization in their location.
This notice may change with the game, providers, or legal requirements. Its date will change and material changes will be shown in an appropriate game or store notice where required.
Privacy questions: support@cltd.sh