Privacy Policy

Your Privacy Matters

Elysium does not use tracking scripts, and will not sell or distribute your data to any external service. We collect only what is necessary to operate the platform.

Last updated: March 2026

1. What We Collect

  • Email address - required to create your account and to send you transactional emails such as verification codes and password resets.
  • Password - hashed with Argon2 before storage. Your plaintext password is never stored or logged.
  • Google account data - if you choose to sign in or link with Google, we store your Google user ID and the email address associated with your Google account. This is optional.
  • Two-factor authentication secret - if you enable two-factor authentication, we generate a secret that is used to verify your authenticator app codes. This secret is encrypted at rest. This is optional.
  • Resonite account link - if you verify your Resonite account, we store your Resonite username and user ID to link your web and in-game accounts. This is optional.
  • Activity and event logs - we log actions such as balance changes and game events. These logs are tied to your account while it exists, and anonymized if you delete your account.
  • Balance history and share tokens - if you create a shareable balance history link, we store the date range and a unique token. You can delete these at any time from your dashboard.
  • Ko-fi display name - if you link a Ko-fi account for donations, we store your Ko-fi display name. This is optional.

2. Cookies

All cookies are HTTP-only and encrypted. We do not use analytics cookies, advertising cookies, or any third-party tracking cookies.

  • Session cookie - keeps you signed in. Expires after 7 days.
  • OAuth flow cookies - temporary cookies used during Google sign-in. Expire after 10 minutes and are automatically cleared.
  • MFA pending cookie - temporary cookie used during two-factor verification. Expires after 5 minutes.

3. What We Do Not Collect

  • IP addresses - your IP address is used transiently for rate limiting and is never persisted to any database or log file.
  • Analytics and tracking - we do not run any analytics scripts, fingerprinting, or behavioral tracking on this site.
  • Data selling - we do not sell, license, or distribute any of your data to any third party.

4. Third-Party Services

We use a limited number of third-party services to operate the platform. Here is every one of them and what they are used for:

  • Google - OAuth authentication. Used only if you choose to sign in or link with Google.
  • Ko-fi - payment processing for donations.
  • PayPal - alternative payment processing for donations.
  • Amazon Web Services (SES) - transactional email delivery. Used only to send verification codes, password resets, and policy update notifications. No marketing emails.

5. Account Deletion

  • You can delete your web account at any time from your account settings.
  • Deleting your account permanently removes your login credentials, sessions, MFA secrets, OAuth links, Resonite verification data, and all balance share links.
  • Activity and event logs that reference your account are anonymized - the link to your identity is removed, but the aggregate event data is retained.
  • Your Resonite game account is managed independently within Elysium's game systems and persists separately from your web account.

6. Age Requirement

You must be at least 18 years old to use Elysium. We do not knowingly collect data from anyone under 18.

7. Hosting and Jurisdiction

Elysium is hosted in the United States and serves users globally. By using the platform, you acknowledge that your data is processed and stored in the United States.

8. Policy Changes

If we make changes to this privacy policy, we will notify all registered users via email. The “last updated” date at the top of this page will also be revised.

9. Contact

If you have questions about this privacy policy or your data, contact us at [email protected].

Elysium Enterprises