Transparency
Privacy Policy
Updated on
CaveCrafter is an independent tool for checking prices and planning factories and simulations in CraftWorld. It was developed by EsquivaZero, who is responsible for the service and for processing the data described on this page.
For questions, access, correction or deletion of data, write to esquivazero@gmail.com.
1. What data we use and why
You can check prices and use the planning features without signing in to an account. Some features, such as syncing preferences and managing alerts, require identification. We process data according to the features you use:
- Preferences and simulations: language, theme, factory levels, parameters and planning settings are kept in the browser's or app's local storage. When you sign in and change these settings with an active session, your preferences are automatically synced with your account on the server so you can retrieve them on subsequent visits. There is no separate control to disable syncing while you are signed in.
- Google sign-in, when made available in production: we receive your Google account identifier, name, email address, confirmation that the email has been verified and profile photo URL. We use this information to identify your CaveCrafter account, display your profile, sync preferences and enable the alerts you request. Google authorization is validated by the server; we store the profile data needed for the account and issue our own session. We do not receive your Google password or request access to the contents of Gmail, Drive, contacts or calendar.
- Wallet sign-in: we receive the public address and a message signature to verify your control of the wallet. The message is used for authentication. CaveCrafter does not request your recovery phrase or private key, hold your funds or execute trades on your behalf.
- Account and session: we record the sign-in method, identifier, available profile data, preferences and the dates of creation and last access. A CaveCrafter session token is stored on your device to keep you signed in and is valid for up to 30 days.
- Alerts: we process the email address provided, the token being tracked, the conditions chosen, the link to the account, the alert status and confirmation and trigger records to send and manage the notifications you request. Operational messages may include confirmation or cancellation links.
- Contact and support: when you write to our email address, we receive your address and the content you choose to send in order to handle your request. Avoid sending passwords, private keys or unnecessary documents.
- Usage limits: the combination search allows one use as a guest every 6 hours. All authenticated accounts have unlimited searches, free of charge. The session validated by the server identifies signed-in access.
- Usage identifier: checking access to the simulation creates an essential first-party cookie that is signed, HttpOnly and has a maximum lifetime of 400 days. It recognizes the browser for the guest limit. The control also uses identifiers cryptographically derived from the account and network (IP; /64 prefix for IPv6), the time of last use and the request identifier. The control table does not store the IP as text, but these identifiers are still used to recognize usage. We do not collect hardware fingerprints. People on the same network may share the guest limit; signing in to an account unlocks unlimited searches. Replacing or deleting the cookie does not delete the record on the server.
- Technical data: the infrastructure may record the IP address, date and time, requested path, browser information, response status and errors for operation, diagnostics and protection against abuse. Email delivery logs may contain recipient and message information; in test environments, delivery may be simulated in logs.
These operations support the functioning of the features you request, security and service support. Where applicable, processing is based on providing the service, legal obligations, legitimate interests compatible with your rights or consent for a specific purpose. Optional authorizations are not required to view public pages.
2. Sharing and external services
We do not sell personal data or use data received from Google for advertising, credit assessment or training artificial intelligence models. Use of this data is limited to the account, preferences, alerts, usage limits and authenticated access functions described above.
- Google: participates in authentication when you choose this sign-in method. Our email provider, Gmail/SMTP, also processes the addresses and content needed for message delivery and email support. This does not give CaveCrafter access to your inbox.
- GeckoTerminal: the external chart may load when you hover over or tap the TREND cell. This content is served directly by the third party, which receives connection data, such as IP and browser information, and may use its own cookies or other mechanisms. CaveCrafter does not send your session token or account profile to the chart.
- Wallets and blockchain: the installed wallet participates in signing for sign-in. Market data and public transfers may be queried through providers of access to the blockchain network. Addresses, amounts and transaction identifiers recorded on the blockchain are public.
- Service operation: infrastructure providers and authorized individuals may access the data needed for hosting, message delivery, maintenance or support. Information may also be provided to comply with a legal obligation or a valid order from a competent authority.
External services follow their own policies and may process data in other countries. See the Google Privacy Policy and the Privacy Policy of CoinGecko, which is responsible for GeckoTerminal. CaveCrafter does not install its own advertising or audience analytics tools in this version.
3. Donations
The donation feature uses cryptocurrency transfers to addresses published by the project. When you donate through the app, the wallet may request a network switch and your approval to send the transaction. We receive the submitted donation data and query the network to verify it; we record the network, sender address when available, transaction identifier, asset, quantity, date and confirmation status.
The app does not display a public list or summary of donations received. These records are available to the person responsible in the Admin application; anyone who sends a donation through the app can track the status of their own transaction. Data recorded on the blockchain remains public and may allow an address to be linked to your other activities on the same network. Do not include personal information in a transaction field.
4. Storage, retention and security
Account data, synced preferences, alerts and operational records are kept on CaveCrafter's infrastructure. We use HTTPS for public access, authentication and access restrictions for the server and database. No service can guarantee absolute security; report suspected unauthorized access using the contact on this page.
We retain data for as long as it is needed for the purposes described, for handling requests and for applicable obligations. This version does not automatically delete accounts due to inactivity or have a single disposal period for all categories. Requested deletion is reviewed by human support; any data that must be retained for a legal obligation, security or the exercise of rights will have its use restricted to those purposes. Backups may retain records until they are replaced in the backup cycle, without regular operational use.
Signing out does not delete data on the server. Clearing browser storage removes the local copy and the session, but does not automatically delete synced preferences, alerts or the account. Revoking CaveCrafter's access in Google prevents new authorizations through that access, but it also does not replace a deletion request to CaveCrafter.
You can remove the Google connection in your Google Account settings. This does not automatically invalidate a CaveCrafter session that has already been issued, which may remain valid for up to 30 days; also use “Sign out” on the device and contact us in the event of unauthorized access. Public and permanent blockchain records cannot be deleted by CaveCrafter.
5. Your rights and how to make a request
You may request confirmation of processing, access, correction, information about sharing, deletion, anonymization or blocking of inappropriate data, portability where applicable and withdrawal of consent. These rights are subject to the conditions and exceptions provided by applicable law, including the LGPD.
Send your request to esquivazero@gmail.com, with the subject “Privacy — CaveCrafter”, stating your request and the email address or public wallet address associated with the account. We may request identity confirmation proportionate to the request to prevent access or deletion by third parties. We will never ask for your Google password, recovery phrase or private key.
Support will explain the next steps and any legal or technical limits. If necessary, you may also contact the Brazilian National Data Protection Authority (ANPD).
6. Children and adolescents
CaveCrafter is not directed at children and does not ask for age when browsing public pages. If you are responsible for a child or adolescent and identify personal data that has been improperly provided, contact us for assessment and appropriate action.
7. Changes to this policy
We may update this page as the service evolves. The date at the top identifies the current revision. Significant changes in data use will be communicated through the service and, when necessary, we will request new authorization before applying a new purpose.