Privacy policy
We collect a nickname, an email address, a password hash and a coin balance. That is very nearly the whole story — the rest of this page explains the details and your rights.
Last updated: 28 July 2026
1. Who is responsible for your data
The data controller is Emerald Fortune Interactive Ltd, company number IE 742318, registered at Clover House, 41 Harcourt Green, Dublin 2, D02 XW71, Ireland, Republic of Ireland. For any privacy matter, write to [email protected]and mark your message “privacy”. We handle these requests ourselves; there is no outsourced ticket queue between you and us.
2. What we collect
If you only browse
Our web server records the standard access log entries needed to keep a site running: the requesting IP address, timestamp, requested path, response status, referring page and browser user-agent string. Your age confirmation is stored in your own browser, not on our servers.
If you register an account
- Nickname — chosen by you, displayed to you in the lobby.
- Email address — your login identifier and the only way we can reach you.
- Password — never stored. We keep only a scrypt hash with a per-account random salt, from which the original password cannot practically be recovered.
- Coin balance and bonus timestamps — your virtual balance, the date you registered, and when you last claimed the daily bonus.
What we never collect
No payment card details, no bank details, no wallet addresses, no government identifiers, no date of birth, no home address, no phone number, no biometric or location data. We could not process a payment if we wanted to, because the site has no payment function at all.
3. Why we process it, and on what legal basis
- Providing your account (nickname, email, password hash, balance) — necessary to perform the agreement you enter into under our terms of use.
- Keeping the site secure and available (server logs, rate limiting, abuse investigation) — our legitimate interest in running a service that is not being attacked or abused.
- Enforcing the 18+ restriction — our legitimate interest in operating a lawful, age-appropriate service, and our legal obligations where they apply.
- Answering your emails — our legitimate interest in responding to the person who contacted us.
We do not run behavioural advertising, we do not build marketing profiles, and we do not send promotional email. There is no newsletter to unsubscribe from.
4. Cookies and similar storage
We set one cookie, and only after you log in: a session cookie that identifies your account. It is HTTP-only, restricted to this site, and signed with a secret key so it cannot be forged or edited. Your age confirmation lives in your browser's local storage rather than in a cookie. We load no analytics, advertising or social media trackers of our own. Full detail is on our cookie policy page.
5. Third parties
Game windows are loaded from the demo servers of the studios that publish them. When a game frame opens, your browser connects directly to that studio and, as with any web request, it will see your IP address, browser details and the fact that the game was opened from our site. That connection is between your browser and them; we do not send them your account data, and we receive no personal data back. Those studios operate under their own privacy notices.
Beyond that, our hosting provider processes data on our instructions in order to run the servers. We do not sell, rent or share personal data with anyone for their own purposes.
6. Where your data is held
Account data is stored in a database on our own server infrastructure within the European Economic Area. Where any transfer outside the EEA becomes necessary, we rely on the European Commission's standard contractual clauses or an adequacy decision.
7. How long we keep it
- Account data — for as long as your account exists.
- Dormant accounts — deleted after 24 months with no logins.
- Deletion requests — actioned within 30 days, after which the account row and its coin history are removed.
- Server access logs — rotated and deleted within 90 days.
- Support email — kept for 12 months after the conversation ends.
8. Your rights
Under the General Data Protection Regulation you have the right to access your data, correct it, have it erased, restrict or object to our processing, and receive a portable copy of it. You can exercise any of these by emailing [email protected] from the address on your account. We will not charge you, we will not ask why, and we will reply within 30 days.
If you believe we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to a supervisory authority — in Republic of Ireland that is the Data Protection Commission (dataprotection.ie), or the authority in your own country of residence.
9. Children
Emerald Fortune is not intended for anyone under 18 and we do not knowingly hold data about children. If we learn that an account belongs to a minor we delete it and its data. If you are a parent or guardian with a concern, email us and we will treat it as urgent.
10. Security
The site is served over HTTPS. Passwords are hashed with scrypt and a random per-account salt. Session cookies are signed with a HMAC key that is unique to this installation, are HTTP-only, and expire. Access to the production server is restricted to named administrators. No system is perfect, but the amount of data we hold is deliberately small — the best protection against a breach is not having your information in the first place.
11. Changes
If this policy changes we will publish the new version here and update the date at the top. If a change materially affects how we use your data we will say so prominently on the site.