Loneshard
Privacy Policy
Updated October 2, 2026
Loneshard is designed to work without an account. It does not display advertisements or use background location tracking. Supported iOS and Android builds offer optional, limited ad measurement, described below. It is off by default.
Information stored on your device
The game stores saves, settings, and randomly generated co-op and AI client identifiers on your device. The iOS and Android apps use operating-system local preferences so this information can survive ordinary app relaunches. It remains on your device unless you deliberately use an online feature or share a diagnostic report.
Optional ad measurement
Under Settings, you may enable Ad measurement to help us measure and improve advertisements for Loneshard. On iOS, this requires both your choice in the game and Apple's App Tracking Transparency permission. On Android, it requires your choice in the game and an available Google advertising ID with ad tracking not limited. Declining has no effect on gameplay, purchases, or offline access. The web version does not use this integration.
While enabled, the app reports its first consented activation, the first eligible tutorial completion, and new full-game purchases. An activation is not treated as proof of a new installation. iOS purchases are verified by StoreKit on your device; Android purchases are verified locally and checked against Google Play by the Loneshard server before reporting. Restores, family-shared entitlements, failed or pending purchases, test purchases, and previously observed purchases are excluded.
These events include their time, a random installation identifier, an
event identifier for duplicate prevention, the advertising identifier
(IDFA on iOS or Google advertising ID on Android), and the app's version,
build, package identifier and operating-system version. Purchase reports
add the actual amount and currency. They pass through
measure.loneshard.com to Meta's Conversions API for ad measurement
and optimization. We do not include character names, chat, save files,
contacts, precise location, Game Center identifiers or payment-card details.
We do not forward your IP address or request user agent to Meta.
For an eligible Android purchase, the app sends its Google Play purchase token to the Loneshard server. An unsent token can remain in the app's private event queue for up to 24 hours. The server uses it temporarily to check the product, purchase status, time, test-purchase status, and actual amount paid with Google. Purchase tokens and Google order identifiers are not logged, retained in a server event queue, or shared with Meta. Meta receives a keyed event identifier to prevent duplicate purchase reports. Purchase amounts from Google include applicable discounts and tax; reports exclude orders already pending refund, partially refunded, or fully refunded when checked.
The app stores consent and milestone flags, local purchase identifiers for duplicate prevention, and a bounded queue of eligible events on your device. Unsent events expire after 24 hours. Disabling measurement in Settings clears that queue, cancels outstanding requests, and stops new reporting. Removing iOS tracking permission, or limiting or deleting the Android advertising ID, also stops reporting when the app resumes or next checks permission. An Android advertising-ID change clears pending events, replaces the random installation identifier, and requires a new opt-in. Events that occur while measurement is off are not reported later. A request already delivered to the server may finish; turning measurement off cannot retract data already sent.
The Loneshard server forwards events without a durable event queue. It keeps only short-lived, hashed duplicate and rate-limit counters in memory; hosting services necessarily process connection information, including IP addresses. Meta processes received data under its Privacy Policy. Meta may combine this data with information from other services to personalize ads and other content, including Feed and AI responses, depending on your Meta settings and location. You can use Meta's privacy controls and contact support@loneshard.com with privacy questions.
Online co-op
When you use online co-op, the relay processes a room code, live game state, a random co-op identifier, and messages needed to connect the two players. Rooms are held in memory and removed after players disconnect; Loneshard does not intentionally retain room content. A local block list is stored only on your device. If you choose Report and leave, your mail app prepares a message containing the build, the other player's random identifier, and up to five recent messages for you to review before sending to Loneshard support. The hosting provider necessarily processes network information, such as IP addresses, to deliver the service.
Simulated-player replies
AI-powered simulated-player replies are an optional full-game feature. They remain off until you affirmatively enable them, and can be disabled at any time under Settings. Authored offline replies remain available when AI is off.
When enabled, the game sends your latest message, up to eight recent chat lines, your character name, class, and level, limited world context, and a random AI client identifier to the Loneshard server. The server sends that material to OpenAI to produce a short in-character reply. Do not put personal information in game chat.
Loneshard does not store ordinary chat text and sends store: false on
each OpenAI Responses API request. OpenAI does not use API data to train its
models by default, but may retain prompts and responses in abuse-monitoring
logs for up to 30 days. Loneshard keeps pseudonymous client and network-usage
counters that reset on the next UTC-day service cycle, plus a monthly aggregate
cost total with no client identifier, to enforce rate and spending limits. Raw
IP addresses are not written to that usage file.
Reports of AI replies
Open chat, tap Chat options (⋯), then Report a reply and choose a recent AI-generated reply to flag it without leaving the game. Before sending, you can review the reply, speaker, selected reason, and game version. Only those fields and a signed verification receipt are submitted; your prompt and other chat history are not included.
Submitted reports are kept in a private Loneshard review queue for up to 30 days, then automatically deleted. A keyed, pseudonymous network identifier is stored with the report to prevent abuse; the queue does not store your raw IP address. Loneshard uses these reports to investigate offensive replies and improve its safeguards. To request earlier deletion, send your report ID to support.
Beta feedback
The Playtest Report action prepares build, device, performance, location, and recent error details for you to review and share. Reports are not uploaded automatically and do not include your save data.
Purchases
The public iOS and Android apps offer a one-time, non-consumable full-game unlock. Apple or Google Play processes the transaction; Loneshard receives the verified entitlement needed to unlock the game but does not receive your full payment-card information.
Optional reviewer access
Android app reviewers can enter a private access code under Settings. The app sends that code and a random installation identifier over HTTPS to verify free full-game access. Loneshard signs a grant valid for up to 24 hours and does not retain the submitted code or identifier in request records. The app stores the code and grant locally to renew access. They are excluded from character exports and can be deleted with Settings → Reviewer access → Remove reviewer access. Failed-code attempts use an in-memory hashed network identifier and a one-minute rate-limit window to limit guessing. The hosting provider processes network information needed to deliver this service.
Your choices and deletion
You can disable future AI sharing under Settings, leave or block a co-op player at any time, and delete local characters from the title screen. Because Loneshard has no accounts and does not retain ordinary co-op rooms or AI chat text, it generally has no chat history tied to you to delete. Pseudonymous AI usage counters are discarded at the next UTC-day service cycle. Reports you deliberately email can be deleted on request by contacting support from the same email address.
Children and changes
Loneshard does not knowingly solicit personal information from children. This policy may change when the game or its online services change. The effective date above will be updated when that happens.
Contact
Questions or privacy requests can be sent to support@loneshard.com.