Null MeridianPublic record

Null Canticle / Data boundary

Privacy & Data Notice

Null Meridian needs enough information to authenticate commanders, resolve a deterministic strategy game, protect fair play, and publish deliberately public outcomes. It does not need to watch private Discord conversations or sell player profiles.

Version
1.2-playtest
Effective
6 August 2026
Service
Public playtest
Scope and principle

Collect what command requires. Keep private strategy private.

This notice covers the Null Meridian website, game service, official Discord integration called Null Canticle, and the public-playtest community operated for playnullmeridian.com. The service is currently an open public playtest, not a commercial launch.

PostgreSQL is the authoritative game record. Discord is an optional identity, orientation, and public-news surface. It never becomes the authority for Fleets, resources, scans, battles, permissions, or account ownership.

Information held

The record follows the systems you use.

Account and profile

  • Email address, a one-way password hash, account role, and account status.
  • Commander display name, timezone, quiet-window preference, reputation, and season history.
  • Opaque session and CSRF digests, issue and activity times, and a fourteen-day session expiry. Raw session secrets are kept only in secure browser cookies.

Game and integrity record

  • Planet, economy, structures, research, queues, Fleets, missions, scans, intelligence, battles, reports, rankings, System and Alliance participation, and public news.
  • Structured audit events needed to investigate sensitive actions, tick retries, permissions, security incidents, or fair-play reports.
  • Short-lived rate-limit windows. Login and registration identifiers are persisted only as domain-separated HMAC digests, not as readable email or network-address strings.
  • Feedback deliberately submitted through the playtest form, linked to the submitting commander, planet, faction, season, current tick, and game page. The form does not collect browser storage, device fingerprints, or private messages.
Never stored as account data

Null Meridian does not store payment-card data, advertising profiles, private Discord messages, voice activity, contact lists, device fingerprints, or raw passwords.

Discord boundary

Link one identity without importing a social profile.

Discord linking is optional. The OAuth request uses only the identify scope. Null Meridian receives the Discord user ID required for a one-to-one link. It does not request Discord email, guild lists, friends, contacts, messages, or a bot token.

  • The OAuth access token is used once to resolve the identity, immediately revoked, and never stored.
  • One-use OAuth state is stored only as a SHA-256 digest, expires after ten minutes, and is removed after expiry during subsequent flows.
  • Signed command receipts retain the interaction, application, guild, approved command, pseudonymous actor key, and expiry for replay defence. They expire after 24 hours.
  • /me status and /me alerts are ephemeral, requester-only summaries. They do not include resource amounts, Fleet composition, destinations, scans, operations, or notification text.

Native Discord Rules Screening governs community participation. Null Canticle does not enumerate members, monitor joins, read community conversations, assign authoritative game roles, or send unsolicited direct messages.

How data is used

Operation, security, history—nothing for behavioural advertising.

  • Authenticate the correct account and maintain secure sessions.
  • Resolve authoritative ticks, queues, movement, combat, territory, and scoring.
  • Show each commander the state and intelligence they are allowed to see.
  • Prevent duplicate processing, abuse, credential attacks, and unfair automation.
  • Provide support, investigate incidents, and preserve season records and honours.
  • Publish only events explicitly shaped as public dispatches to the website or official Discord channels.

Player information is not sold, rented, or used to target third-party advertising.

Visibility and sharing

Public results are deliberate; private operations remain authorised views.

Commander names, charted planet identity, public rankings, territorial outcomes, public season events, and selected battle summaries may be visible to other players. Public dispatches are governed by a strict allowlist before they can reach Discord.

Hidden Fleet composition, private economy, detailed queues, unshared scans, intelligence, live targets, and private operation commitments are not public Discord data. They remain available only through authenticated, permission-filtered game views.

Information may be processed by the hosting and network providers needed to run the service, and by Discord when a commander deliberately uses the Discord integration. Those providers operate under their own terms and privacy notices. Information may also be disclosed where required by applicable law or necessary to protect people and the service.

Retention and control

Temporary credentials expire. Seasonal history is meant to endure.

  • Sessions expire after fourteen days and expired rows are pruned on new issuance.
  • Rate-limit windows last from seconds to fifteen minutes and expired rows are pruned during subsequent protected actions.
  • Discord OAuth state expires after ten minutes; replay receipts after 24 hours.
  • Active Discord links remain until unlinked. Link, login, and revocation times may stay in the account security history.
  • Seasonal material state resets at Collapse. Account identity, honours, reputation, audit evidence, and season history may persist across Fractures.
  • Playtest feedback may be retained with the relevant season while it is needed to improve the game, investigate a reported problem, or verify a fix.

Retention may be extended where a record is needed to investigate abuse, protect the service, resolve a dispute, or satisfy applicable law. The service operator may remove test data when it no longer serves those purposes.

Security and choices

You control the optional link. The server controls authoritative access.

  • Sign out to revoke the current session. Unlink Discord from authenticated Settings to revoke the link and invalidate other game sessions.
  • Use a unique passphrase and never share passwords, SSH keys, cookies, webhook URLs, OAuth secrets, or authentication tokens with staff or Null Canticle.
  • Ask the service operator to correct profile information, review the account record, or remove an account where operational, legal, and audit obligations permit.

The service uses secure cookies, CSRF and origin checks, strict validation, rate limits, least-privilege database roles, immutable releases, HTTPS, and auditable server-side decisions. No system can promise absolute security; suspected exposure should be reported promptly without posting the sensitive material publicly.

Changes and contact

The public record changes with the service.

This notice may change as the playtest adds account recovery, moderation, additional hosting, or new community features. Material changes will update the version or effective date and be announced through an official service channel.

For privacy, account, or security help, use the official Null Meridian Discord #help-and-questions route and do not include passwords, tokens, private intelligence, or other people’s personal information. The current public playtest has no automated account-deletion or data-export workflow.

Use of the service is also governed by the Null Meridian Terms.