Privacy Policy
Last updated 4 September 2026.
Foundly Labs Pty Ltd, an Australian company trading as Mythryl Studio ("Mythryl"), of Brisbane, Queensland, is responsible for the personal information described in this policy. Mythryl is the data controller for the purposes of the General Data Protection Regulation and an APP entity for the purposes of the Privacy Act 1988 (Cth).
This policy applies to the website at mythryl.com, the Mythryl Online account service, the games published by Mythryl, and the Mythryl mailing list. It forms part of the Terms of Service.
Mythryl handles personal information in accordance with the Australian Privacy Principles, the EU and UK General Data Protection Regulation, and the California Consumer Privacy Act. Where one of those instruments does not apply to Mythryl by its terms, Mythryl applies it as a matter of policy.
Enquiries may be sent to hello@mythryl.com.
Information collected
Account information. On sign-in, Mythryl records an account identifier, the display name and avatar supplied by the platform used to authenticate, and an email address where the platform provides one. For each linked platform, Mythryl records the platform, its identifier for you, and the tokens it issues, which are used to verify that the link remains valid. For a passkey, Mythryl records only the public key. Steam does not disclose email addresses to third parties, so an account authenticated solely by Steam carries no address at which you can be contacted.
Session information. While you are signed in, Mythryl records a session token stored in a cookie on your device, together with your IP address and browser user-agent string. That information maintains the session and supports detection of unauthorised access.
Mailing list. On subscription, Mythryl records your email address, the date of subscription and the page from which it was made, and subsequently any unsubscription, delivery failure or spam complaint. Those records ensure that Mythryl does not contact an address that has been withdrawn. Mythryl does not employ open or click tracking.
Analytics. Mythryl uses Google Analytics to measure page traffic. See Cookies and analytics below.
Server logs. The hosting provider retains standard web server logs, including IP addresses, which are used to maintain the site and to investigate misuse.
Correspondence. Mythryl retains support enquiries and defect reports.
Information not collected
The games published by Mythryl, including demonstration and playtest builds, transmit no gameplay information. Mythryl does not collect telemetry, analytics, crash reports, saved games or in-session chat from a game client. The only transmission between a game client and Mythryl is authentication, and only where you elect to sign in. Mythryl will amend this policy, and give notice, before that changes.
Mythryl does not receive payment card or bank details, which are held by the storefront that sells the game. Mythryl does not hold passwords.
Purposes and legal bases
Account and session information is processed because it is necessary to provide the account service you have requested. The mailing list and analytics are processed on the basis of your consent, which you may withdraw at any time. Server logs, security monitoring and enforcement are processed on the basis of the legitimate interest of Mythryl in maintaining and protecting the Services. Correspondence is processed on the basis of the legitimate interest of Mythryl in responding to enquiries. Mythryl also processes personal information where required to do so by law.
Mythryl does not carry out automated decision-making producing legal or similarly significant effects. Enforcement decisions are made by a person.
Cookies and analytics
Cookies that maintain a session and protect the authentication exchange are strictly necessary and cannot be disabled without preventing sign-in.
Analytics cookies are set by Google Analytics. In the European Economic Area and the United Kingdom, no analytics cookie is set and no data is transmitted to Google until you consent. In other jurisdictions analytics operates by default. In either case you may disable analytics at any time using the cookie settings control in the site footer, and a browser transmitting a Global Privacy Control signal is treated as having disabled it. Google Analytics is configured with IP anonymisation enabled and advertising features disabled. Mythryl uses no advertising or cross-site tracking cookies.
Disclosure
Mythryl does not sell personal information and does not disclose it for advertising purposes.
Personal information is processed on behalf of Mythryl by Neon (database), Vercel (hosting), Resend (email delivery) and Google (analytics), in each case only for the purpose of providing those services.
Platforms used for authentication are sources rather than recipients. They disclose information to Mythryl when you elect to sign in, under their own privacy policies.
Mythryl otherwise discloses personal information only where required to do so by law, in which case it will notify you unless prohibited from doing so, or to an acquirer of its business, in which case it will give prior notice.
Overseas disclosure
The service providers of Mythryl operate principally in the United States. Personal information may therefore be processed outside the jurisdiction in which you reside. Transfers from the European Economic Area and the United Kingdom are made under the applicable standard contractual clauses. For the purposes of Australian Privacy Principle 8, Mythryl takes reasonable steps to ensure that overseas recipients handle personal information consistently with the Australian Privacy Principles.
Retention
Account information and associated records are retained until the account is deleted, and are removed from active systems within 30 days of a deletion request. Sessions expire automatically. Analytics data is deleted by Google after 14 months. Server logs are retained for approximately 30 days and correspondence for approximately 24 months.
Suppression records, being an email address together with the fact that it must not be contacted, are retained indefinitely. Mythryl will delete a suppression record on request.
Deletion of an account
On request, Mythryl deletes your account together with its sessions, linked platform records and passkeys. Backup copies are superseded within 30 days. Where an account has been terminated for serious misconduct, Mythryl retains a minimal record for the purpose of enforcing that decision.
Mythryl cannot delete information held by a storefront, by an authentication platform, or by a player-operated server. Requests of that kind must be directed to those parties.
Your rights
You may request access to the personal information Mythryl holds about you, request its correction, and request its deletion. You may withdraw consent to the mailing list or to analytics at any time. In the European Economic Area and the United Kingdom you may additionally object to or restrict processing and request portability.
Requests should be sent to hello@mythryl.com. Mythryl verifies a request by requiring that it be made from the address recorded on the account. Requests are handled without charge and answered within 30 days.
Complaints should be directed to Mythryl in the first instance. If a complaint is not resolved, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au), the United Kingdom Information Commissioner's Office (ico.org.uk), or the supervisory authority of your Member State.
Children
An account may not be held by a person under 13 years of age, or under 16 in the European Economic Area, the United Kingdom, and any other jurisdiction that sets a higher age. Mythryl does not knowingly collect personal information from a person below the applicable age. A parent or guardian may request deletion by contacting hello@mythryl.com. Mythryl does not profile minors and does not direct advertising to them.
Security
Traffic is transmitted over HTTPS. The database is encrypted at rest and access is restricted to personnel who require it. Mythryl holds no passwords. No system is entirely secure. Where a breach is likely to result in serious harm, Mythryl will notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and, where the General Data Protection Regulation applies, the relevant supervisory authority within 72 hours. Vulnerabilities should be reported to hello@mythryl.com before public disclosure.
Changes
Mythryl may amend this policy. The date above records the current version. Where an amendment is material, Mythryl will publish notice on the site and notify account holders by email at least 14 days before it takes effect.
Contact
Foundly Labs Pty Ltd, trading as Mythryl Studio
Brisbane, Queensland, Australia
hello@mythryl.com