Rally Point - Privacy Policy

Last updated: 27 August 2026

Rally Point is made by one person. This policy describes exactly what the game sends, when it sends it, and who can see it. It describes the game as it actually behaves - not a generic template - and it is kept in step with the code.

Who is responsible

Hugh Shelton, sole developer of Rally Point, is the data controller for the personal data described here. Contact: support@rallypointgame.com.

The short version

1. Bug reports you send

The game has a "Report a Bug" form in the settings/pause menu and on the game-over screen. It transmits only when you fill it in and press send. If you never use the form, it never sends anything.

When you do press send, the report contains:

About those logs. They are freeform diagnostic text written by the game as it runs - error messages, stack traces, and networking events. They are not a structured or filtered dataset, and they are the part of a report we can least precisely describe in advance. They are not designed to contain personal information and in normal play they do not, but because they are freeform we cannot promise that a stray file path (which on Windows usually contains your account name) or a co-op peer identifier never appears in one. If that concerns you, do not send a bug report; nothing else in the game attaches them.

Where a bug report goes

The report is sent over HTTPS to a relay we run on Cloudflare Workers, which forwards it - unchanged - into a private Discord channel that only the developer reads. The relay exists so that the credential for that channel is not shipped inside the game. Reports are not published, and they are not visible to other players.

2. Automatic crash reports

This one is not player-initiated, and we want to be plain about that. If the game crashes, it writes a report to your disk as it closes, and the next time you launch the game that report is uploaded automatically, without asking you. A crash cannot upload itself - by the time the handler runs there is nothing left to send with - so the report has to wait for the next launch. The crash dialog itself tells you this at the moment it happens.

An automatic crash report contains the same snapshot listed in section 1 above (including your Steam display name and run state), plus the error message and the stack trace of the crash, plus the tail of the error log. It contains no typed message, because you were not asked for one. It goes to the same relay and the same private Discord channel.

Delivery is attempted at most three times; after that the report is deleted from your machine unsent.

There is currently no setting that turns automatic crash reporting off. We would rather say so than list an option that does not exist. What you can do is delete the report before it is sent: it sits on your own machine as crash_pending.txt in %LOCALAPPDATA%\rtt\ between the crash and your next launch, and deleting that file stops it going anywhere. You can also write to us and we will delete any report we have already received.

3. The online cup (Skirmish Cup) and the ranked ladder

Rally Point includes a recurring online tournament. Its results are shared through a second Cloudflare service we run. If you enter a cup, the game sends:

Your Steam display name is published publicly. Cup standings are served as a public web page so they can be shared in the community Discord. Anyone with the link can see the names and results of everyone in that event. Your numeric Steam ID is stored but is not shown on the public page.

This data is stored in a Cloudflare D1 database. The online cup is active by default in the full game. It is disabled entirely in the demo build, which never contacts the cup service. If you do not want to appear in the standings, do not enter a cup - and if you already have, contact us and we will remove your rows.

The ranked ladder

Ranked matches feed two season ladders (a skill rating and a participation score) held by the same service, in the same database. A match is ranked only when the host of a custom game switches its RANKED setting on, which every player in the room can see before the match starts; a ranked room can be a 1v1, a 2v2 or a free-for-all of up to four players, and only matches with no computer-controlled seats can be ranked. When a ranked match finishes, the game sends the Steam display name and numeric Steam ID of every player in the match, along with which side won and roughly how long the match ran.

Every player's machine sends the report. If you play a ranked match, each machine reports the result it saw, naming every player, and the service records the match only when two reports agree - that cross-check is how a result both sides agree on gets recorded, and it is also an anti-cheating measure. If the other machines crash or disconnect, your report alone is accepted after a short wait.

The report carries a Steam authentication ticket, to prevent impersonation. When a ranked match begins, the game asks Steam for a short-lived authentication ticket, and the report carries it. Our service passes that ticket to Steam, which confirms the reporting player's identity - so nobody can submit results in your name. The ticket is used for that one check and is not stored; the confirmed identity is the same Steam ID described above. The service also runs automated fair-play checks over reported results (for example, results arriving faster than matches can be played, or the same two accounts trading wins). These use only the match data described here - your ladder row keeps a short list of the Steam IDs of your recent ranked opponents for the win-trading check, which lives and dies with the row under the retention window in section 8 - and their only effect is temporary: they can pause an account's rating changes or its ranked play for a bounded time that lifts itself.

Your numeric Steam ID is stored, but it is not handed out in the ladder. It is the key your row is kept under. When the game reads the ladder to show it to you, every row carries a display name and a score, and no row carries a Steam ID - the same choice the cup standings page makes. Reading the ladder also requires the community join code, as every other part of this service does. Be aware that this code is built into the game rather than being a password only you know, so treat the display names on the ladder as public.

The FRIENDS tab sends us your Steam friends' IDs, and only that tab. The ladder screen can show just the players you know. Because the ladder itself no longer carries anyone's Steam ID, your game cannot work that out on its own, so opening that tab sends the numeric IDs of your Steam friends to us. We use them to answer one question in that single request - which rows on the ladder belong to your friends - and then discard them. They are never written to our database and never recorded in a log. If you never open the FRIENDS tab, your game never collects or sends your friends list at all.

Ranked play is optional and, like the cup, is absent from the demo build. Unranked and co-operative matches send nothing to us. If you would rather not be on the ladder, do not join a room marked RANKED - and if you already have, contact us and we will remove your row.

Reporting a player

After a ranked match - or from a recorded replay of one - you can report an opponent you believe cheated. A report is entirely player-initiated: if you never press the report button, this feature sends nothing. When you do, the report carries your Steam name and ID, the reported player's Steam name and ID, the match reference, the reason you chose, and the filename of your local replay of that match (the recording itself stays on your machine - we may ask you for it if a review needs it). Reports go to the same Cloudflare service as the ladder and are read only by the developer, who reviews them by hand; automated fair-play data (section above) is attached to help that review. Filing a report does not punish anyone by itself, and reports are capped per player per day so the system cannot be used to harass. Reports are deleted on the schedule in section 8.

Post-match feedback questions

Occasionally, after a campaign battle, the game asks one yes/no question about what you just played - whether you enjoyed the arena, whether a unit or an upgrade felt fair. Answering is optional (SKIP is always offered and the question never returns), and your response - your yes or no, or the fact that you skipped - is sent to a service we run with nothing identifying attached: the question, that response, and what was played (the arena, unit, or difficulty in question, and the game build). No name, no Steam ID, no account link - we cannot tell who answered, and there is therefore nothing in it to request or delete. The record of which questions you have already been asked lives only in your own save file.

4. Steam statistics and campaign leaderboards

Two features send gameplay results to Steam itself rather than to any server of ours. They are opposites in what they reveal - one is anonymous by construction, the other is public by design - so they are described side by side here rather than left to blur together.

Anonymous aggregate statistics

Rally Point records aggregate gameplay statistics - things like how often a card is played, or how many players reach a given act - through Steam's own global stats system.

These are counters only. No account link, no name, no identifier, and no IP address is attached to them, and they are not sent to any server of ours. For these counters we can read only the global sum across all players; we cannot see an individual player's contribution. Even measurements that would normally require identifying you, such as whether a player returns a week after installing, are worked out on your own machine and reported as a single anonymous "+1" to a global counter.

Because the counters contain no personal data, there is nothing in them to opt out of, request, or delete. An earlier telemetry system that did transmit account identities has been removed from the game entirely - it has no address to send to and no code to send with.

Campaign leaderboards

This is the opposite of the counters above: a leaderboard entry is per-player, public, and posted automatically. When a campaign run ends - in victory or in defeat - the game posts the run's score to Steam's leaderboards for Rally Point. If you won, it also posts your completion time to a speed board. There is currently no setting that turns this off; we would rather say so than list an option that does not exist.

What a post contains: a single number per board. That number encodes the run's score (or its time), the threat level you played at, and which commander you used, so the in-game board can show how a result was earned. Each run posts to the all-time boards and to that week's rotating weekly boards, and Steam keeps only your best entry per board - a worse run never replaces a better one.

Steam attaches the entry to your Steam account, and that is what makes it personal data: anyone viewing a board sees your Steam display name next to your score - every player's copy of the game downloads the top of the board to draw it, so treat your presence there as public. The board's FRIENDS view is Steam filtering the same global board down to the viewer's own friends; unlike the ranked ladder's FRIENDS tab in section 3, it sends nothing to any server of ours.

The boards are hosted by Valve as part of Steam, like the multiplayer networking in section 5: we decide what the game posts - which is why this section exists - but the entries live on Valve's servers under Valve's Privacy Policy, and Valve is the data controller for what the boards store. The demo build never posts to any leaderboard. If you want an entry of yours removed, contact us (section 9) and we will remove it.

5. Multiplayer

Co-op and versus matches are carried over Steam's peer-to-peer networking. To play together, your Steam ID and display name are necessarily visible to the player you are matched with, in the same way they are in any Steam multiplayer game. This is handled by Steam, not by us, and is covered by Valve's Privacy Policy. We do not operate a game server and do not record your matches.

6. Why we collect this, and our lawful basis

Under the UK GDPR and EU GDPR, we rely on:

The campaign leaderboards, like the multiplayer networking in section 5, are Steam platform features for which Valve is the data controller; section 4 describes them so you know exactly what the game posts. The anonymous Steam statistics in section 4 are not personal data, so no lawful basis is required for them.

7. Who else can see it

We do not sell, rent, or share your data with advertisers, data brokers, or any third party for their own purposes. The only other parties involved are the services that carry or store the data on our behalf:

We may also disclose data where we are legally required to. Our services are hosted on infrastructure that may process data outside your country, including in the United States.

8. How long it is kept

These deletions are automatic. Scheduled jobs run daily and remove everything past its window - cup and ladder rows from the database, bug and crash reports from the channel they were delivered to - so they do not depend on anyone remembering. The Steam leaderboard entries are the exception worth naming: they live on Valve's infrastructure, not ours, so no job of ours sweeps them - removal there happens on request, not on a schedule.

9. Your rights, and how to exercise them

If you are in the UK, the EU, or another region with comparable law, you have the right to ask for a copy of the personal data we hold about you, to have it corrected or deleted, to restrict or object to our processing of it, and to complain to your data protection authority (in the UK, the ICO).

There is no deletion button inside the game. Rally Point currently has no in-product way to review or erase what you have sent. Requests are handled by hand, by email. We would rather say that plainly than imply a self-service flow that does not exist.

Email support@rallypointgame.com and tell us your Steam display name, and roughly when you sent the report or played the cup. That is enough for us to find and delete it. We will respond within 30 days. We do not ask you to prove your identity with documents; if a request is ambiguous we will ask a follow-up question rather than act on the wrong data.

10. Children

Rally Point is not directed at children and we do not knowingly collect personal data from them. Steam requires its users to be at least 13 years old, and the game is distributed only through Steam. If you believe a child has sent us a bug report, contact us and we will delete it.

11. Changes to this policy

If what the game collects changes, this page changes with it, and the date at the top is updated. Material changes will be noted in the game's Steam news posts. This page is the current version; there is no archive of previous ones.