The Fatui Project
Privacy policy
Your account, your connections and your choices.
Last updated: 20 September 2026
Privacy contact
This policy covers The Fatui Project, including Paimon, Irminsul and Akasha. You can contact us with privacy questions or requests by email at [email protected]. See also our legal notice.
Data we use and why
Your account and plans
We process your display name, email address, verification status, password hash where applicable, and sign-in/session information. We store the progress, inventory, teams, wish plans, settings and other tracking data you save. These are used to provide and secure your account and the features you request. The legal basis is Article 6(1)(b) GDPR for providing the service, and Article 6(1)(f) for preventing abuse and keeping it secure.
Optional connections
If you connect Discord, we receive account information needed for sign-in and account linking. If you connect HoYoLAB or HoYoverse, we store your supplied credentials encrypted, your Genshin UID and relevant connection status. These connections support character imports, resin information and, when enabled, daily reward claims and promo-code redemption. Requests send the necessary credentials and game-account information to the relevant provider. We also retain claim results to avoid repeated redemption attempts. You can disable optional automation or disconnect in Settings.
The basis for these user-requested features is Article 6(1)(b) GDPR. Connections are optional; without the necessary information, the corresponding feature cannot operate.
Feedback and contact
Feedback includes your message, category, submission time, current page path, screen resolution and browser type. The application stores feedback linked to your account. A server worker copies feedback into the project’s private GitHub repository. Each issue contains the message, category, submission time, page path without query parameters, screen resolution and browser type. New issues do not include a feedback reference ID. Your account ID, name and email are not included as separate fields. The application retains an internal export record linking feedback to its GitHub issue until the feedback record is deleted. Previously exported issues may still contain a feedback reference ID. Message content and submission details may also identify someone. Authorised repository collaborators and GitHub can process these reports. Please do not include personal information, passwords or tokens in messages.
Email enquiries include your email address and whatever you send. We use feedback and correspondence to respond and improve the service, based on Article 6(1)(f) GDPR; account-related service requests may also fall under Article 6(1)(b).
Cookies and browser storage
We use the following cookies for account access and website security:
- __Secure-better-auth.session_token: keeps you signed in to your account. It is set on www.thefatuiproject.com with a seven-day expiry and may be renewed while you use the service.
- cf_clearance: stores Cloudflare security-check and challenge-clearance information to help protect the website against automated abuse. It is set for .thefatuiproject.com. In our browser check on 20 September 2026, it had an expiry approximately one year later; its lifetime can vary with Cloudflare settings and how it is issued.
Both cookies were marked Secure (sent over HTTPS) and HttpOnly (not accessible to page scripts). Local and session storage remember choices such as filters, search terms and page position. Local storage remains until cleared or replaced; session storage normally lasts for the browser tab session, although browser session restoration may preserve it. Some preferences are separated by account. You can clear this storage and cookies in your browser, which may sign you out or reset preferences.
The application does not embed advertising scripts. Cloudflare Web Analytics (Real User Measurements) is enabled with EU visitors excluded: Cloudflare automatically adds its measurement script for eligible visitors outside the EU. Cloudflare states that this measurement script does not use cookies or browser storage. Cloudflare also processes requests for delivery and security. Bot Fight Mode and browser integrity checks are enabled; security challenges may use cookies such as cf_clearance or __cf_bm. Security processing is separate from Web Analytics and is not disabled by the EU analytics exclusion.
Service providers and recipients
OVHcloud — hosting
The website and application database are hosted on our VPS in Frankfurt, Germany. OVH GmbH provides the hosting infrastructure and processes the hosted application data on our instructions under an Article 28 GDPR Data Processing Agreement (Auftragsverarbeitungsvertrag). Our account confirms acceptance of the agreement dated 17 October 2025. The agreement permits necessary remote processing for security and maintenance subject to its transfer restrictions. Where applicable, EU standard contractual clauses cover processing from countries without an adequacy decision. The contract catalogue also lists authorised subprocessors and affiliated companies. See OVHcloud’s contracts and data-protection information.
Cloudflare — delivery and security
Cloudflare proxies website traffic and processes IP addresses, requested URLs and request/security metadata to deliver and protect the service. Its international network can involve processing outside the EEA, including in the United States. Cloudflare’s Data Processing Addendum describes its processor obligations, the EU–US Data Privacy Framework and standard contractual clauses for restricted transfers. See also its privacy policy. The browser measurements and security settings are described above.
Resend — account emails
Resend (Plus Five Five, Inc., United States) processes recipient email addresses, message contents and delivery information for verification and password-recovery emails. Our sending region is Ireland (eu-west-1). This controls email routing, not data storage: Resend states that customer data is stored in the United States. Its Data Processing Addendum is incorporated into its service terms and includes EU standard contractual clauses. Resend also describes participation in the EU–US Data Privacy Framework.
Resend publishes a 30-day email/log retention period for Free, Pro and Scale plans; Enterprise retention can differ. Its own backups persist for seven days. These are separate from our application backup periods. See Resend’s processing, location and retention information and subprocessor list.
Discord — optional sign-in and linking
Connecting Discord exchanges the account information needed to authenticate and link your account. Discord operates its own service under its privacy policy; for EEA users it identifies Discord Netherlands B.V. as the responsible entity. Discord’s policy explains its international processing and applicable transfer arrangements. Disconnecting here removes the website connection; it does not delete your Discord account.
HoYoverse and HoYoLAB — optional game-account features
When you request these features, our server sends the necessary connection credentials, game UID and server information to HoYoverse/HoYoLAB endpoints for account lookup, character imports, resin information, daily rewards or promo-code redemption. HoYoverse identifies COGNOSPHERE PTE. LTD., Singapore, in its privacy policy, which describes international processing. These providers operate the underlying game and account services independently. Removing a connection here does not delete your game account.
GitHub — private feedback repository
We use a private repository in our GitHub Free organization to manage the feedback issues described above. Report content is available to authorised repository collaborators and GitHub. GitHub uses service providers and affiliated companies to operate its services; its published subprocessor list identifies their functions and processing locations.
Reports may be stored or processed outside the EEA, including in the United States. GitHub’s privacy statement describes its use of EU standard contractual clauses for international transfers and participation in the EU–US Data Privacy Framework. Its Data Protection Agreement sets out obligations for services governed by that agreement. Our feedback deletion process is described under Retention and account deletion.
OVHcloud Zimbra — contact correspondence
Our contact mailbox, [email protected], uses OVHcloud Zimbra. OVHcloud processes sender and recipient addresses, message contents, attachments and associated delivery information to provide the mailbox. The OVHcloud Data Processing Agreement described above governs processing on our behalf. See OVHcloud’s service terms and data-processing documents. This mailbox is separate from the Resend service used for automated account emails.
You may contact us for information about the safeguards applicable to your data. A provider’s privacy policy describes its own practices; linking it does not replace our responsibilities for the information we send.
Retention and account deletion
- Account and tracking records: retained to operate your account. The account-deletion feature removes the account and linked application records, including locally stored feedback and connection credentials, through the database deletion process.
- Update recovery backups: database copies are made before updates and normally kept for two to three days. Deleted data may remain in those restricted recovery copies until they expire. Code/schema backups are separate and do not include user accounts or profiles.
- Beta diagnostic logs: account-linked diagnostic activity is retained for 48 hours for bug investigation.
- After beta: account-linked diagnostic logging is enabled during updates and disabled and deleted when the update recovery period ends.
- Bug reports and correspondence: kept as needed to investigate and resolve the matter. Deleting your account removes the local feedback records and their export-tracking records. Associated GitHub issues are queued for deletion by the server worker. Failed deletions remain queued for retry; unresolved exports require manual review. Minimal feedback references and issue numbers are retained for this cleanup and removed after successful deletion. Email correspondence is handled separately as part of the deletion process; you do not need to submit a second deletion request.
Provider security/access logs may have separate retention periods; the diagnostic-log periods above should not be read as a promise about every provider’s logs. Any legally required retention must be limited to the relevant data and purpose.
Your choices and rights
You can manage connections in Settings and request account deletion through My account. You may also email [email protected] to exercise your data-protection rights. A separate email is not required to repeat an account-deletion request already made through the website.
Subject to the applicable conditions, you have rights of access, correction, erasure, restriction and portability. You can object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Requests are handled without undue delay, normally within one month. If an extension is legally permitted, we will explain it within that first month. We may request proportionate information to verify your identity, but never your password or authentication tokens.
You can complain to a data-protection supervisory authority, including the authority where you live or work. Find the German state authorities.
Automated actions
Enabled reward claims, promo-code redemption and account-data retrieval run automatically. They are service features, not decisions producing legal or similarly significant effects about you. If new features change how personal data is processed, we will update this policy and provide any additional information required before that processing begins.