0
Register now and get: 150.000 Zeny + Poring Cake Hat, Battle Manual Box, JOB Battle Manual Box, Bubble Gum Box
Offline

Privacy Policy

Last updated: 13 September 2026

This page explains what data we use when you create an account, play on the server or use the website, why we need it and what rights you have. SinaRO CP is an independent project and does not sell your data for advertising. This policy also covers the anti-bot system currently under testing.

1. Information We Collect

  • Account data: the username, email address, password (stored hashed, never in plain text) and character sex you provide when registering. Registration also checks the required self-declaration that you are at least 14, without collecting your date of birth or identity documents.
  • Content and interactions on the website: when you use a feature that accepts data, such as private or public messages, comments, votes, reactions, reports, applications, contact requests (name, email and message), screenshots or feedback answers, we record the content or action, the associated account where applicable, the date and time and the technical data needed for security. We may also show online presence to authenticated users where the feature supports it. Content intended for a public area may be shown under your public alias and moderated by staff.
  • Character and gameplay data: your characters, items, guild membership, chat and other in-game activity, as part of the normal operation of the game server.
  • Technical data: your real IP address, when available, and connection timestamps, recorded by the web, login, char and map servers for security, rate limiting, abuse prevention and enforcement of restrictions. When traffic passes through an authorised proxy, the system uses the real IP sent by that proxy rather than the proxy address itself.
  • Anti-bot security: when the relevant controls are active, we may analyse technical and gameplay data linked to an account or character to identify automation, misuse of the service and behaviour that does not comply with the rules. Data may be collected by the game servers and security systems, aggregated and retained only as necessary for the review.
  • Anti-bot assessment and cases: the information collected may be combined into a risk score or tier to decide whether to open a case or apply a temporary preventive measure. We do not publish the operational rules or thresholds of the controls, so that the system cannot be deliberately bypassed. A single signal does not prove a violation and does not automatically result in a permanent ban. Disciplinary decisions and disputed cases require human review.
  • Anti-bot cases and appeals: if a review is opened, we retain the account or character involved, the observed period, the elements needed for the review, reasons, staff actions, any limitations, appeals and decisions. Access is restricted to authorised staff and you may request an explanation or human review through the Control Panel.
  • Launching the game: when you start the game from the website, we create a temporary, single-use token so you can sign in without entering your password again. It does not contain your password and is no longer valid after use or expiry.
  • Acceptance of rules: we record that you accepted the Terms of Service and game rules, together with the date, account, IP address and accepted rules version.
  • Poring Staff chatbot: if you choose to use it after accepting its dedicated notice, we record the messages you send, generated replies and technical request data (account or session, date and time, IP address and user agent). This data is used to operate and secure the service, diagnose errors and improve it. Do not enter passwords, payment details or other sensitive information.
  • Cookies and browser preferences: we use technical cookies for session and security, Cloudflare Turnstile’s necessary abuse-prevention service, plus local browser storage for some website and game preferences. For the detailed list, see the Cookie Policy.
  • Browser notifications: if you enable notifications, we store the push endpoint and technical data needed to deliver alerts to your browser. You can disable them from the panel or your browser settings.
  • Polls: if you answer a non-anonymous poll, your answers are linked to your account (also required to grant any prize) and the page asks for your explicit consent before you submit. In anonymous polls your answers are never linked to your account - which is also why anonymous polls never grant prizes.
  • Beta programme and feedback: if you take part in the beta, we may record the invitation sent, participation status, questionnaire answers and sending date. Answers are associated with the account to understand participation and improve the service; invitations and service communications are sent to the account email address.
  • Account authentication and security: if you choose Google, we receive the identifiers and data needed from that provider to create or link the account. If you enable passkeys or two-factor authentication, we store technical credential and security-event data, not your private key or the biometric content of your device.
  • Purchases and rewards: for Control Panel purchases, we retain the account, recipient character, item, price, order status and processing and delivery dates. Payments handled by an external provider are also subject to that provider’s notices.

2. How We Use Your Information

  • To create and manage your account and let you play on the server.
  • To receive, publish, moderate and manage content you submit through website features available to authenticated users.
  • To keep the service secure - detecting abuse, cheating, and unauthorized access attempts.
  • To contact you about important account or service matters, if needed.
  • To provide and protect the chatbot, validate requests, diagnose failures and improve answer quality.
  • To protect forms from spam and abuse through Cloudflare Turnstile, which verifies requests without normally showing an interactive challenge.
  • To identify automation and abuse through progressive anti-bot controls. Some preliminary technical decisions may be automated using signals and scores, but cases and final sanctions are subject to human review. False positives may occur during testing; you can report them and appeal through the Control Panel.

3. Data Sharing

Your data is not sold or used for personalised advertising. It may be accessed, only as needed for their duties and with restricted access, by the controller and authorised admins for administration, support, moderation, security and anti-bot reviews. It may also be processed by technical, authentication, payment, email, notification and chatbot providers when needed for the requested feature, or shared to protect security or comply with a legal obligation.

4. Data Retention

Account and character data is kept while your account remains active. Control Panel technical logs and audits follow a configured retention period of 30 days, except where data is needed for an incident, dispute or legal obligation. Character previews in the technical cache are kept for up to 90 days. Completed chatbot messages are removed after 90 days; requests still queued are not removed by the automatic cleanup. Anti-bot signals and scores follow their technical decay windows; closed cases, appeals and decisions are kept for 12 months, while automatic cleanup preserves pending appeals and active quarantines. Beta feedback answers are kept while needed to evaluate the beta or handle disputes, then archived or removed according to the internal retention cycle. Access, verification and security tokens expire according to their technical lifetime and are no longer valid after expiry. After a deletion request, some data may be retained for as long as necessary to meet legal obligations or handle security issues.

5. Your Rights

You can request access to, correction, updating or deletion of your personal data. You may also object to certain processing, request restriction or portability where applicable law provides for it. Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing. You can also contest an anti-bot case and request human review through the Control Panel.

6. Children's Privacy

The service is available to people aged 14 or older and is not intended for anyone under 14. Registration requires a mandatory age self-declaration checked by the server; we do not collect a date of birth or identity documents for this check. If someone under 14 declares this or is reported as such, the account may be blocked or removed.

7. Changes to This Policy

This policy may be updated from time to time. We display the date of the latest review; when a change materially affects your rights or processing purposes, we may request renewed acknowledgement or consent where necessary.

8. Data entered through account features

When you complete registration and accept this notice, the same processing rules also apply to data you later enter through website features connected to your account. Each feature still shows a specific notice when needed about the purpose, publication and moderation of the content. Data submitted through anonymous forms remains subject to this notice and to any consent requested directly in that form.

10. Legal bases

For accounts, characters, game access and features requested by you, processing is necessary to perform the service relationship or take pre-contractual steps. For security, abuse and automation prevention, anti-bot controls, technical records and defence of the service, we rely on the controller’s legitimate interest, balanced against your rights. For tax, accounting or other legal duties, we rely on compliance with a legal obligation. For the chatbot, browser notifications and optional polls, we rely on consent where required; you can withdraw it without affecting earlier processing. Data needed to provide a feature cannot be refused without giving up that feature.

11. Providers and international transfers

To provide the service we may use hosting and database providers, abuse-prevention services, CDNs, Google authentication, Stripe payments, Mailjet email, browser notification services and the chatbot provider configured when a request is made. Providers receive only the data needed for their function: for example, Google for authentication chosen by the user, Mailjet for email and the push provider for browser delivery. Each provider operates under its own notice and terms. Where a provider processes data outside the European Economic Area, the transfer must be covered by an adequacy decision or safeguards provided by the GDPR, such as Standard Contractual Clauses.

Cloudflare Turnstile

The CP uses Cloudflare Turnstile to prevent spam, abuse and automated submissions. When you interact with a protected form, Cloudflare may receive technical request data and interaction signals to verify that the request is legitimate. SinaRO does not use this data for personalised advertising. The service is provided by Cloudflare under its Privacy Policy and Terms of Service.

Cloudflare Privacy Policy · Cloudflare Terms of Service

Complaints and supervisory authority

If you believe that the processing of your data breaches applicable law, you can lodge a complaint with the competent supervisory authority, in Italy the Garante per la protezione dei dati personali. You can contact us first so that we can investigate the issue.

Italian Data Protection Authority (Garante)

For the detailed list of technical cookies and browser preferences, see the Cookie Policy.

12. Controller and contact

The data controller is Giuseppe Mazzullo, creator and operator of the SinaRO project. Questions about this policy, or requests regarding your data, can be sent to [email protected].

We use technical cookies and browser storage to keep your session active, protect the site, and remember your preferences. Learn more in our Cookie Policy.