Legal · Privacy
Privacy policy
1. Controller
Lukas Schulte
Über den Tannen 17, 59469 Ense, Germany
Email: info@slowire.net
2. In short
- We process only what the game needs: your account, your game state and technical data for security.
- No tracking, no ads, no analytics, no sharing with third parties.
- The website runs on our own server in Germany. Fonts and scripts come from this server; your browser loads nothing from other services.
3. Visiting the website
Requests to pewhack.com pass through a reverse proxy (NGINX Proxy Manager) on our server. It logs accesses with IP address, time, requested address and browser identifier to detect attacks and errors. These logs are deleted after 14 days. The game itself stores no IP addresses in plain text.
The legal basis is our legitimate interest in running the service securely (Art. 6 (1) (f) GDPR).
4. Account
An account needs an invite code. When you sign up we store your email address, your handle and your password, the password only as a hash (Argon2id), never in plain text. We also note which invite code was used and when you last signed in.
The email address is used to sign in and to reset your password; other players never see it. Only you see your handle too; other players see your crew name. We currently send no emails.
The legal basis is providing the game (Art. 6 (1) (b) GDPR). The data is kept until the account is deleted (section 9).
5. Game state
For your crew we store what happens in the game: the crew name, structures, battery, compute and balance, your hackers and AI agents, contracts, market orders and trades, courses and gear, events and decisions, attacks, recon, poaching offers, bids, exploits and botnets, and a history per tick. The per-tick history is deleted after 30 days. Hackers, agents and all other characters in the game are fictional and generated by the game.
Every movement of balance is recorded in a ledger that is never changed, so the game stays traceable and fraud can be detected.
The legal bases are providing the game (Art. 6 (1) (b) GDPR) and our legitimate interest in fair play (Art. 6 (1) (f) GDPR).
6. What other players see
pewhack is a competition. Publicly visible, even without an account, are your crew name, your place on the leaderboards and your titles, the public crew profile (hackers with portrait, level and rarity, a rough count of your structures, recent public news) and news in the ticker, the Pewhack Daily and on the attack map. If another crew scouts yours in the game, it sees the numbers of your crew and your hackers for 24 hours, as the game describes them. Titles stay with your account across seasons.
7. Sign-in and security
When you sign in we create a session: a hash of the session key, start and expiry (30 days), the time of your last activity, a shortened browser identifier and your IP address only as a keyed hash (HMAC) that cannot be reversed. The session ends when you sign out or when it expires.
To limit sign-in attempts we briefly count attempts per IP hash and account in memory. Password reset links are valid for 24 hours and stored only as hashes.
If the game rules are broken (for example several accounts, or passing balance between linked accounts), the operator can freeze an account and reverse transactions. For a freeze we store the time and the reason.
The legal basis is our legitimate interest in protecting accounts from misuse and in fair play (Art. 6 (1) (f) GDPR).
8. Cookies
We set only two strictly necessary cookies:
__Host-pewhack_session: keeps you signed in, for up to 30 days.__Host-pewhack_csrf: protects forms against forgery by other websites, for up to 30 days.
They need no consent (§ 25 (2) no. 2 TDDDG). There are no other cookies.
9. Deleting your account
On request we delete your account. Your email address, handle, password hash, sessions and reset links are deleted, and your crew name is replaced by "Deleted crew" with a number wherever it is stored (crews, titles, news, the Pewhack Daily). The game state stays without any link to you, so the other crews' game history stays correct; the ledger is not changed, it holds nothing about you as a person.
10. Backups
The database is backed up every night; these backups are deleted after 14 days. The whole server is backed up regularly as well. Deleted data can therefore remain in these backups until they expire; they are used only to restore the service after a failure.
The legal basis is our legitimate interest in a reliable service (Art. 6 (1) (f) GDPR).
11. External services
Our server fetches weather data from Open-Meteo. No visitor data is sent there.
12. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Write to info@slowire.net. You can have your account deleted (section 9) by writing to this address.
You can also complain to a data protection supervisory authority (Art. 77 GDPR), in particular the one where you live.
There is no automated decision-making or profiling.
Last updated: September 27, 2026