Privacy Policy
Effective Date: August 9, 2026
Last Updated: August 9, 2026
Introduction
City of Gamers, Inc. ("CoG," "City of Gamers," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy is a single, company-wide policy: it applies to all of our products and services, including:
our website at www.cogfuture.com and any subdomains;
our games, including Brew Crew and Village of The Ages (VOTA), however you obtain them — including through the Epic Games Store, Steam, or other distribution platforms;
our production tools, including the RoyalTea platform at royalty.technology, its API, and its AI connectors;
our investor relations, support, and marketing communications.
We do not maintain separate privacy policies for individual products. Where a practice applies only to one product, this Policy says so.
By using any of our products or services, you agree to the practices described in this Policy.
Information We Collect and How We Collect It
We collect information in three ways: information you give us, information collected automatically as you use our products, and information we receive from third parties.
Information you provide directly to us
Account & profile
Examples: Name, email address, username, password (stored only as a salted hash), display name, avatar, bio, communication preferences
Where it comes from: Account signup and profile settings
Professional & collaboration data
Examples: Studio and project membership, roles, skills, availability
Where it comes from: RoyalTea platform
Payment information
Examples: Billing details and transaction records. Full payment card numbers are handled by our payment processor and never stored on our systems.
Where it comes from: Purchases, subscriptions, in-game purchases
Tax information
Examples: W-9 / W-8BEN details required to pay you, including taxpayer identification numbers
Where it comes from: RoyalTea payouts. Sensitive identifiers are encrypted at rest, and we never store a full Social Security Number
Revenue & royalty data
Examples: Revenue figures, expenses, royalty weights and points, contribution history, distribution and payout records
Where it comes from: RoyalTea platform
User-generated content
Examples: Tasks, comments, documents, time logs, milestones, messages, uploaded files, and other content you create
Where it comes from: RoyalTea platform
Investor information
Examples: Accreditation and investment-related information you submit
Where it comes from: Investor inquiry forms
Support correspondence
Examples: The contents of emails and support requests you send us
Where it comes from: support@cogfuture.com and in-product support
Information collected automatically
When you visit our website, play our games, or use our platform, some information is captured automatically by the software itself:
Device and connection data — IP address, device type and model, operating system and version, browser type and version, screen resolution, and language settings.
Log data — dates and times of access, pages or screens viewed, features used, referring URLs, and error and crash reports.
Gameplay and platform telemetry — game progress, achievements, session length, in-game events, settings, and save data.
Browser storage and similar technologies — small files and identifiers kept on your device, principally local storage entries that keep you signed in and remember your settings. See Section 8 (Cookies and Tracking) and our Cookie Policy (https://www.cogfuture.com/cookie-policy) for every item in use and how to clear it.
Authentication artifacts — session tokens, refresh tokens, and personal API tokens issued to keep you signed in and to authorize connected applications. These are stored hashed or encrypted.
Information we receive from third parties
Distribution platforms. When you obtain or play our games through the Epic Games Store, Steam, or a similar platform, that platform provides us with a platform account identifier and, depending on the platform and your settings, your display name and entitlement/ownership status. We use this to deliver the game, validate your purchase, and sync progress. We do not receive your payment card details from these platforms.
Payment processors. We receive confirmation of transactions, the last four digits of a card or a payment token, and payout status — not full card numbers.
Integrations you connect. If you link a third-party tool to RoyalTea (for example Todoist, Jira, GitHub, Trello, Clockify, or Calendly), we receive the data you authorize that tool to share. Access tokens are encrypted at rest and you can disconnect at any time.
Social and referral sources. If you reach us through a social platform or a referral link, we receive limited attribution information about how you arrived.
Information we do not collect
We do not knowingly collect biometric data, precise geolocation, government-issued ID documents (other than the tax identifiers described above), or health information.
How We Use Your Information
We use the information described above for the following purposes:
To provide the products and services you asked for
Create and maintain your account, and authenticate you when you sign in.
Run our games, save your progress, and sync entitlements with the platform you bought from.
Operate the RoyalTea platform: manage projects and tasks, calculate contribution points, model and execute revenue distributions, and generate the agreements and documents you request.
Process purchases, subscriptions, payouts, and refunds.
To keep the services safe and working
Detect, investigate, and prevent fraud, cheating, abuse, and unauthorized access.
Diagnose crashes and errors, monitor performance, and maintain security.
Enforce our Terms of Service and protect our rights and the rights of our users.
To communicate with you
Send transactional messages about your account, purchases, payouts, and security.
Respond to your support requests and investor inquiries.
Send product news and marketing, where you have opted in or where otherwise permitted. You can unsubscribe at any time using the link in any marketing email.
To improve our products
Understand which features are used and how, to prioritize development.
Perform analytics and A/B testing on aggregated or de-identified data.
To meet legal and financial obligations
Maintain tax and accounting records, respond to lawful requests, and comply with applicable law.
AI features (RoyalTea only). RoyalTea includes an in-app AI assistant and lets you connect external AI clients through the Model Context Protocol. When you use an AI feature, the relevant request and context are sent to our AI providers to generate a response. Those providers act as processors under contracts that restrict their use of your data to providing that service. We do not use your private workspace content to train third-party foundation models. A connected AI client acts as you and is limited to your permissions; it can read and manage project data and read financial data, but it cannot run distributions, move money, change royalty weights, or sign agreements — those actions remain in the app. You can revoke any connection or token at any time in Preferences → AI & API Access.
Legal bases (EEA/UK users). Where the GDPR or UK GDPR applies, we process personal data on the basis of: performance of a contract (providing the service you signed up for); our legitimate interests (security, fraud prevention, product improvement); your consent (marketing and non-essential cookies, which you may withdraw at any time); and compliance with legal obligations (tax and accounting records).
How We Share Your Information
We share personal information only in the circumstances below. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Service providers (sub-processors)
We use a small number of vendors to run the service. They process personal information only on our instructions, under contract, and only to provide their service to us — never for their own purposes. By category:
Cloud infrastructure and hosting — application servers, the database, file and media storage, and content delivery.
Payment and payout processing — purchases, subscriptions, and creator payouts.
Transactional email delivery — account, security, and notification email.
AI inference providers — processing the prompt and context for RoyalTea's AI features (RoyalTea only).
All of these operate in the United States. Each is bound by data protection obligations at least as protective as those in this Policy. None is permitted to sell your information, and none may use your content to train its own models.
We maintain a current list of the specific companies in each category. If you are a customer, a prospective customer running a security review, or a data subject exercising your rights, request it at privacy@cogfuture.com and we will provide it.
Third parties your own browser contacts directly — such as our payment provider's checkout frame — are named in our Cookie Policy (https://www.cogfuture.com/cookie-policy), since they can place storage on your device.
Distribution and platform partners
We share the information necessary to distribute, license, and operate our games with platforms such as the Epic Games Store and Steam — for example, entitlement validation, achievement and progress data, and, where you enable it, leaderboard or friend-list features. These platforms handle your data under their own privacy policies, which we encourage you to read.
Other users and collaborators
On the RoyalTea platform, content you create is visible to the members of the studios and projects you belong to, according to their assigned roles. Email addresses of other members are withheld unless the member has chosen to share them.
In our games, information you choose to make public — such as a display name on a leaderboard or in a multiplayer session — is visible to other players.
Legal and safety
We disclose information where we believe in good faith that it is required by law, subpoena, or other legal process, or where disclosure is necessary to protect the rights, property, or safety of City of Gamers, our users, or the public, or to investigate fraud or a security incident.
Business transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your personal information becomes subject to a materially different privacy policy.
With your direction
We share data with third-party tools you explicitly connect to your account, and with anyone else you direct us to share it with.
How Long We Keep Your Information (Data Retention)
We keep personal information only as long as we need it for the purposes described in this Policy, and then delete or de-identify it. Our standard retention periods are:
Account and profile data: For the life of your account, then deleted within 30 days of account closure
Game progress and save data: For the life of your account, then deleted within 30 days of account closure
Project, task, and collaboration content (RoyalTea): For the life of your account or studio, then deleted within 30 days. Content shared with a studio may be retained by that studio as its own record
Financial and tax records — purchases, payouts, royalty distributions, W-9/W-8BEN: 7 years after the relevant transaction or tax year, as required by US tax and accounting law
Security and audit logs: 2 years
Usage analytics and telemetry: 90 days in identifiable form; aggregated or de-identified statistics may be kept indefinitely
Support correspondence: 2 years after the request is resolved
Marketing contact details: Until you unsubscribe or ask us to delete them
Session tokens, refresh tokens, one-time codes, and invitation links: Expire automatically, typically within minutes to days
Backups: Deleted data persists in encrypted backups for up to 35 days before those backups roll over
Deletion. When you delete your account, or ask us to delete it, we delete or irreversibly de-identify your personal information within 30 days, except where we are legally required to keep it — principally the financial and tax records above, which we retain for the statutory period and then delete. We may also retain a minimal record of the deletion request itself so that we can demonstrate compliance.
Data Security
We use industry-standard technical and organizational safeguards, including:
Encryption in transit — all traffic to our sites, games, and APIs is served over HTTPS/TLS.
Encryption at rest for sensitive fields, including OAuth and integration tokens and tax identifiers, using AES-256-GCM.
Password and token hashing — passwords and refresh tokens are stored as bcrypt hashes and are never recoverable in plaintext, by us or anyone else.
Access controls — least-privilege access to production systems, with authentication required for all administrative access.
Payment isolation — card data is handled by a certified third-party payment processor and does not touch our servers.
Monitoring and regular security assessments.
No method of transmission or storage is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the applicable regulators as required by law, and without undue delay.
Your Rights and Choices
Regardless of where you live, you can:
Access and correct your account and profile information directly in the product.
Export your data, or request a copy in a portable format.
Delete your account and associated personal information.
Unsubscribe from marketing email using the link in any such message.
Disconnect third-party integrations and revoke AI connections and API tokens at any time.
Clear what we store on your device through your browser settings — see the Cookie Policy for the exact steps.
If you are in the EEA, the UK, or Switzerland, you additionally have the right to object to or restrict processing, to withdraw consent at any time (without affecting processing already carried out), and to lodge a complaint with your local supervisory authority.
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; the right to delete it; the right to correct it; the right to data portability; and the right to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months. We do not knowingly sell the personal information of consumers under 16 years of age.
How to exercise your rights. You can submit a request in either of two ways: email privacy@cogfuture.com from the address associated with your account, or use the account and privacy controls inside the product (Settings → Account, where you can export or delete your data directly). We will verify your identity before acting on the request and will respond within the timeframe required by applicable law — generally 30 days, or 45 days in California. You may use an authorized agent where the law allows; we will ask for proof of authorization. There is no charge for exercising these rights.
Cookies and Tracking
We use very little here, and none of it is for advertising. We do not use advertising, marketing, or cross-site tracking cookies, and we do not run Google Analytics. The RoyalTea platform sets no cookies at all — it uses browser local storage to keep you signed in and remember your settings — and our marketing website uses cookieless page-view measurement. Our games do not use web cookies, but they do store save data and settings on your device.
Because we set no non-essential cookies, there is no consent banner: strictly necessary storage is exempt from consent, and there is nothing else to refuse. If that ever changes, we will add a banner and update our policies before those cookies are set.
Full detail — every stored item, why it exists, how long it lasts, and how to clear it — is in our Cookie Policy (https://www.cogfuture.com/cookie-policy).
We honor Global Privacy Control (GPC) signals as a valid opt-out request where required by law.
Children's Privacy
Our services are not directed to children, and we do not knowingly collect personal information from them.
We do not knowingly collect personal information from children under 13 anywhere, consistent with the US Children's Online Privacy Protection Act (COPPA).
In the EEA and the UK, where the applicable age of digital consent is higher, we do not knowingly collect personal information from children under 16 without verifiable parental consent.
If you are a parent or guardian and believe your child has provided us with personal information, contact privacy@cogfuture.com and we will delete it promptly.
International Data Transfers
We operate from the United States, and our service providers are located in the United States. If you access our products from outside the United States, your information will be transferred to, stored in, and processed in the United States, which may have data protection laws different from those in your country.
Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary measures including encryption in transit and at rest and strict access controls.
Contact Information
City of Gamers, Inc. is the data controller for the personal information described in this Policy. We are an online business and operate without a public walk-in office, so we handle all privacy correspondence by email:
Privacy, data protection, and data subject requests: privacy@cogfuture.com
General support: support@cogfuture.com
We aim to acknowledge every privacy request within five business days. If you need a postal address for a formal legal notice, email privacy@cogfuture.com and we will provide our registered agent's address for service.
Changes to This Privacy Policy
We may update this Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. If we make material changes — for example, a new category of data collection or a new purpose for using your data — we will provide prominent notice before the change takes effect, such as an in-product notice or an email to the address on your account. Your continued use of our products after an update takes effect means you accept the revised Policy.
Previous versions of this Policy are available on request from privacy@cogfuture.com.
