About › Privacy and analytics
Privacy: what City Defense measures and stores
You can play without an account and the game itself uses no cookies. Your browser only gets a protective cookie from the map catalog server when you play the official map or a map from the catalog, rate, report or publish; only authors with an account have a sign-in cookie. We measure visits and games with our own instance of the open-source tool Umami, as aggregate numbers only. Your settings and your missions in progress stay in your browser.
City Defense is free to play in your browser – no download, no sign-up. First mission: Brno, náměstí Svobody.
Play freeWho runs the game
The game is operated by, and the data controller is, František Jánoš, company ID (IČO) 02721864, Husovická 902/18, Brno - Husovice, 614 00, Czech Republic, registered in the Czech Trade Licensing Register. Contact: frantisek@trefa.app.
What we measure and why
We want to know how many people play the game, where they come from and where the game gets stuck – for example, in which wave people stop or where the map fails to load. For this we use Umami, an open-source tool without cookies, which we run ourselves on a server in Germany (Hetzner). It measures:
- pages and game screens you view (start, mission, editor) – always without the part of the address after
#, where a shared mission carries the whole mission; - the referring website or search engine and campaign parameters (
utm_…); - browser type, operating system, device type, screen size and language;
- approximate location at the level of country, region and city, derived from the IP address;
- game progress: the start of a mission (built-in, your own or shared; the chosen look, style and quality, and one of seven broad city-look regions, such as Central Europe or East Asia), the wave number, win or loss, lives left, the number of enemies destroyed and game length in minutes;
- setting changes (look, city style and quality) and an accepted low-quality offer when the game stutters on a device;
- use of the editor (opening, steps, saving, sharing) and technical errors, such as missing WebGL 2 or a map that failed to load;
- the player map catalog: switching tabs and using the city filter (only yes / no, not which city), starting a map from the catalog with its difficulty, a vote (up, down, cancel), a report with its reason, publishing a map with its difficulty and number of waves, a refused publication with its reason, and an author sign-in (only that it happened, not the sign-in method).
We never measure mission names, descriptions or authors, the exact location of your own missions (only the broad region mentioned above), places you search for in the editor, or links to shared missions — and for the map catalog never the code, name or city of a map, a nickname or an e-mail.
IP address and visit identifier
The IP address is not stored. The server uses it only at the moment of the request, to derive an approximate location and to compute a visit identifier – a hash of the IP address, the browser and a secret key that changes every month. It cannot be used to follow you across months or to link you to other websites. The measurement stores nothing on your device.
Legal basis and retention
We measure on the basis of legitimate interest (Art. 6(1)(f) GDPR): so that we can fix and improve the game. Records are deleted after 13 months. We process author accounts and published maps to provide the map catalog the author asked for (Art. 6(1)(b) GDPR); protection against abuse (rate limits, reports) is based on legitimate interest.
Player map catalog and author accounts
Players can publish their own maps to the catalog on the start screen. The catalog runs on our server api.citydefense.app (Hetzner, Germany), map images on img.citydefense.app.
- You can play and rate without an account. For this the game creates a random device key in your browser (
td.device) that contains nothing about you. It sends the key to the server with every play of a catalog map and of the official Brno map (which map, the wave reached, win or loss, time), with a vote (thumbs up or down) and with a report (the reason). If you clear the browser data, the game creates a new key. - Protective cookie. So that the server accepts such a record, it gives your browser, with the first of them, the strictly necessary cookie
csrftokenonapi.citydefense.app— it protects against forged requests from other websites, contains nothing about you and lasts 1 year. Just opening the game or the start screen does not create it. - IP addresses are not stored in the database. To limit the number of requests, the server keeps a shortened salted hash of the address only briefly in a cache. For reports, the server remembers with the map a hash of the network the report came from (part of the address — /24 for IPv4, /48 for IPv6 — salted with the server's secret key), so that a map hides itself only after reports from three different networks. The server keeps this network hash for 30 days after the map's last report in an on-disk cache, and it stays even after the map is deleted; the address cannot be recovered from it without the secret key, but it is a pseudonym, not anonymous data.
- An author account is needed only by those who publish maps: e-mail, nickname (public with your maps, the e-mail never), sign-in method (Google — e-mail only, e-mail and password, or a code sent by e-mail), the date of sign-up and of the last sign-in. When signing up you confirm that you are at least 15 years old and agree to the Map publishing terms. The sign-in is kept by the strictly necessary cookie
sessionidonapi.citydefense.app(30 days, no consent banner). E-mails with codes are sent by the Resend service. - A published map is public: the mission (location and settings), name, description, city, the author's nickname and an automatic picture of the map. What does not belong in a map and which rights you grant are set out in the Map publishing terms.
- If someone reports a map as a private place, or reports hide it, the admin gets an e-mail with the map's details — not with the details of whoever reported it.
- Retention: the account until it is deleted, maps permanently (withdrawn maps stay in the archive too), plays and votes permanently as anonymous numbers.
- Deleting the account works at any time in the game (Your maps in the catalog → Delete account) and takes effect immediately: it deletes the e-mail, the nickname, the sign-in data and the link to Google; maps stay with “unknown author”. To get a copy of your account data, write to us by e-mail.
How to opt out
- If your browser sends the Global Privacy Control or Do Not Track signal, the measurement is not loaded at all.
- Permanently in one browser: open the developer console (F12) on citydefense.app and run
localStorage.setItem("umami.disabled", "1"). - Ad and tracker blockers usually stop the measurement – the game works unchanged.
What stays in your browser
The game remembers settings in your browser's storage (localStorage): the look (td.theme), the city style and quality (td.cityStyle, td.cityQuality), see-through buildings (td.seeThrough), the game language (td.lang), the graphics savings level on this device and a declined low-quality offer (td.perfLevel, td.perfDeclined), the “Build without confirming” choice on a phone (td.noConfirm), whether the gesture help was shown, whether the tower upgrade tip was shown and whether the “Add to Home Screen” card was closed (td.gestureHelp, td.upgradeTip, td.installCard) – and the missions in your “My missions” list (td.missions). A mission you are editing is kept until you close the tab (sessionStorage, td.editor.draft). None of this is sent anywhere; you delete it by clearing the site data in your browser.
For the map catalog the game also remembers the device key (td.device — the only one sent to the server, see Player map catalog), the codes of the last 200 maps you finished, for the “played” mark, and your thumb (up or down) on the maps you rated, so that the map card shows how you voted (td.played), the bot test result and the wave reached in “Try it” or when playing your own mission from My missions for the last 20 versions of your missions (td.publishProof) and the codes of maps you published from this browser (td.published).
Who else sees your IP address
Your browser sends its IP address to every server it downloads something from. For City Defense, these are:
- Cloudflare – hosting of citydefense.app;
- OpenFreeMap – map tiles and the map style;
- Photon (komoot) – only when you search for a place in the mission editor (it receives the search text) and when you publish a map (it receives the coordinates of the mission center, so that the game can offer the city);
- our own Umami server – the measurement described above;
- our map catalog server
api.citydefense.appand imagesimg.citydefense.app– on the start screen, when playing and rating catalog maps and when publishing; - Cloudflare Turnstile – only when reporting or publishing a map and on the sign-in pages (see below);
- Google – only when you sign in with a Google account (your browser goes to Google's sign-in page).
Protection against bots
The sign-in and sign-up pages for map authors on api.citydefense.app are protected by the invisible Cloudflare Turnstile check: it tells that a person, not a bot sending out code e-mails, is filling in the form. You don't have to fill in or confirm anything. For this, Cloudflare processes data about your browser and device and your IP address under its Turnstile Privacy Addendum. In the game on citydefense.app, Turnstile loads only when you report or publish a map — until then the game downloads nothing from Cloudflare Turnstile.
Your rights
You have the right of access, rectification and erasure, the right to restrict processing and the right to object to processing based on legitimate interest. Because the measurement holds nothing that identifies you, we usually cannot find your records (Art. 11 GDPR) – the simplest option is to turn the measurement off. You can lodge a complaint with your data protection authority; in the Czech Republic that is the Office for Personal Data Protection (uoou.gov.cz).
Advertising
The game does not show ads at the moment. Before we turn them on, we will add here what data the ads use, and where the law requires it, the game will ask for your consent.
Frequently asked questions
Does City Defense use cookies?
Not the game itself on citydefense.app. The map catalog server on api.citydefense.app gives your browser the strictly necessary protective cookie csrftoken (no data about you, 1 year) when you play the official Brno map or a map from the catalog, rate, report or publish; a signed-in author also has a sign-in cookie. The measurement stores nothing on your device.
How do I turn the measurement off?
Turn on Global Privacy Control or Do Not Track in your browser – the measurement is then not loaded at all. Or open the console (F12) on citydefense.app and run localStorage.setItem("umami.disabled", "1"). The game keeps working.