Privacy policy
Last updated: 1 September 2026
RogueMT2 is a small, independent Metin2 server. This page explains what the website, the launcher and the game itself collect, why, and what you can ask us to do about it. It is written to be read rather than to be survived.
The short version
- You need an account name and a password to play. An email address is optional and is used only to let you recover your account.
- Your password is never stored. Only a scrypt hash of it is.
- There is no advertising, no analytics, no tracking pixels and no profiling anywhere on this site or in the game client. The site sets exactly one cookie, and it is the one that keeps you logged in.
- The launcher and the game send nothing about your computer or its contents. The launcher downloads game files; the game connects to the game server.
- We never see your card details. Payments are handled entirely by Stripe.
- Nothing is sold, rented or handed to advertisers. Ever.
- You can have your account and its data deleted by asking at [email protected].
Who this is, and what it covers
RogueMT2 is run by a private individual in the European Union, as a non-commercial hobby project. For the purposes of the General Data Protection Regulation (GDPR), that person is the data controller. They can be reached at [email protected], and the full postal details of the controller are available on request to that address.
This policy covers:
- the website at roguemt2.com — including the account pages, the rankings, the wiki and the item shop;
- the RogueMT2 launcher, the Windows program that installs, updates and starts the game;
- the RogueMT2 game client, and the game servers it connects to.
It does not cover Discord, WhatsApp, the toplist site, or anything else you reach by following a link away from here. Those services have their own policies and their own operators.
What is collected
Your account
There is one account, shared by the website and the game. Creating it stores:
- An account name, which you choose. Two to thirty letters and digits, stored in lower case.
- A password, stored only as a scrypt hash. The plain password is never written to disk, never logged and never sent to the database — not by the website and not by the game server. Nobody running this server can read it or recover it for you.
- A seven-digit deletion code, which the game asks for before it will delete one of your characters.
- An email address, only if you give one. It is optional, it is used for exactly one thing — sending you a link to choose a new password — and an account without one simply cannot be recovered that way. It is not used for newsletters, announcements or anything else, because there is nothing else that sends mail.
- When the account was created, and when it last played.
Your characters and how you play
Playing on a server means the server holds the game world. That includes your characters' names, levels, class, position, statistics, inventory, storage, guild membership, playtime, and the record of any run that ended in a permanent death — which is what the public rankings and the memorial on this site are drawn from. Character names, levels and playtime are shown publicly on those pages; nothing about your account is.
The game servers also keep operational records of significant in-game events, so that lost items can be traced, cheating can be investigated and bugs can be diagnosed: logins and logouts, money and item movements, level-ups, upgrade attempts, trades, public shouts, and staff commands. Some of those records include the IP address the action came from. Private conversation is not stored. Whispers, party chat and ordinary local chat pass through the server to reach the person you are talking to and are not written down anywhere.
Technical data
- Your IP address. Any server you connect to necessarily sees it. It appears in web server logs, in game server connection logs and in the security records described above. It is also used, in memory only, to rate-limit login attempts, signups and password-reset requests.
- Ordinary request data — the page or file asked for, the time, the response, and the browser or launcher's user agent string.
- Which version of the client you are running, which the game server checks so that an out-of-date install is told to update rather than left to misbehave.
Payments
The item shop sells in-game currency. If you buy some, your card details never reach this server: the payment is taken on Stripe's own hosted checkout page, and Stripe is the merchant of record. What is stored here is the record of the order — which pack, the amount and currency, whether it settled, when, and the identifiers Stripe gives us so a payment can be matched to a receipt or a refund — together with a ledger of every movement of your in-game coin balance.
Stripe handles the card itself and holds it under its own privacy policy. This site cannot see a card number, and has no way to charge you again without you going through the checkout.
Cookies
The site sets one cookie. It is called
hm_session, it is what keeps you logged in, and
it contains a signed account identifier and a token that protects forms
against cross-site request forgery. It is marked HttpOnly and
SameSite=Lax, and it is deleted when you log out.
There are no analytics cookies, no advertising cookies and no third-party cookies, so there is nothing here for a cookie banner to ask you about. The one image loaded from another server is the toplist badge in the footer, which is hotlinked from metin2pserver.net because that request is how the toplist counts a visit — loading it tells them your IP address and that you were on this page, and nothing else.
What the launcher and the game do on your computer
This is the part a store reviewer usually wants stated plainly, so it is stated plainly. Neither program contains analytics, telemetry, an advertising SDK, or any code that reports on your machine.
The launcher:
- downloads a manifest and the game's own files over HTTPS, and checks each one against a SHA-256 hash;
- asks you once where to install, and remembers that folder in
HKEY_CURRENT_USER\Software\RogueMT2so it does not offer to install a second copy next time; - writes the game's settings file, a small state file recording which version is installed, and a cached copy of the release notes — all inside the game's own folder;
- fetches the release notes from this website to show them in its news panel;
- starts the game.
It reads no other part of your disk, enumerates no other software, and sends no information about your computer. The only thing our servers learn from it is what any web server learns from any download: your IP address, the file requested and the time.
The game client:
- connects to the game server to play, sending your login and then your actions in the game world;
- stores your settings and, if you tick "remember my login", your account name and password in a scrambled — not encrypted — local file, on your machine only;
- writes local error logs next to itself, which stay on your machine unless you choose to send one to us;
- if the Discord application happens to be running on the same computer, tells it what you are doing in the game so that it can show a "playing" status. That is a local connection to your own Discord client; what Discord then does with it is covered by Discord's privacy policy, and closing Discord stops it.
Why it is collected, and on what legal basis
| What | Why | Basis under the GDPR |
|---|---|---|
| Account name, password hash, deletion code | To let you log in and to keep your characters yours | Performance of a contract (Art. 6(1)(b)) |
| Characters and game progress | To run the game and show the public rankings | Performance of a contract (Art. 6(1)(b)) |
| Email address | To let you recover a lost password | Consent (Art. 6(1)(a)) — it is optional, and you can remove it |
| IP addresses, connection and action logs | Security, abuse and cheat investigation, and diagnosing faults | Legitimate interests (Art. 6(1)(f)) — keeping the server usable and fair |
| Order and ledger records | To deliver what was bought and to handle refunds and disputes | Performance of a contract (Art. 6(1)(b)), and legal obligation (Art. 6(1)(c)) for accounting records |
Nothing here is used for profiling or automated decision-making, and none of it is used to build an advertising profile of you, because nothing on this server advertises anything.
Who else sees your data
Your data is never sold, rented, licensed or traded. It is shared only with the services that are needed to run the game, and only with the part of it each one needs:
- Hetzner (Germany) — the servers and the database are hosted there.
- Cloudflare — sits in front of the website and the file downloads as a CDN and a filter against attacks, and so sees the requests passing through it.
- Stripe — takes payments, and holds the card details we never see.
- Brevo — the mail relay that delivers a password-reset message, when you ask for one. It sees the address and the message.
- metin2pserver.net — the server toplist. Its badge in the footer is loaded from their servers, and if you use the in-game vote reward we ask them whether the character in question has voted.
- Law enforcement, if we are ever legally required to hand something over. This has not happened.
All of these are established providers with their own published policies. Some of them process data outside the European Economic Area; where that happens, they do so under the safeguards their own policies describe, such as the European Commission's standard contractual clauses.
How long it is kept
- Account and character data — for as long as the account exists. Ask us to delete it and it goes.
- Ended runs on the public memorial — kept while the character exists, because that record is the point of a permadeath server. Deleting a character takes its runs off the boards.
- Security and action logs — kept while they are useful for investigating abuse, and cleared out periodically after that.
- Payment records — kept as long as tax and accounting rules require, which is longer than the rest and is not something we can shorten on request.
- Password-reset links — hold no server-side record at all. They are self-contained signed links that expire in 30 minutes and stop working the moment they are used.
Your rights
If you are in the EU, the EEA or the UK, the GDPR gives you the right to ask for a copy of the data held about you, to have it corrected, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. If you are in California, the CCPA gives you comparable rights — including the right not to be discriminated against for using them, and the right to know that we do not sell personal information, because we do not.
You already hold some of these directly: you can change your password, your deletion code and your recovery address from your account page, and you can delete your characters in the game.
For anything else — including deleting your account outright — write to [email protected] from the address on file, or ask the staff on Discord if your account has no address. Requests are answered within 30 days, and it is normally the same day. We may have to ask you something that proves the account is yours; we will not ask for your password, and no one running this server will ever ask you for it.
If you think your data has been mishandled, you can complain to the data protection authority in the country where you live.
How it is protected
- The whole site is served over HTTPS, and the session cookie is refused over anything else.
- Passwords are hashed with scrypt and a per-account salt, and rechecked in constant time. Old hashes are silently upgraded when you log in.
- The website connects to the database as a restricted user that cannot delete anything and can change only three columns of one table.
- Logins, signups and reset requests are rate limited, and every form that changes something is protected against cross-site request forgery.
- The site sends a strict content security policy and loads no third-party scripts, because it has none to load.
No system is perfect, and this one is run by hobbyists. If something here is ever breached in a way that puts you at risk, we will say so publicly and tell affected players directly where we have a way to reach them.
Children
This game is not directed at young children, and accounts are not knowingly created for anyone under 13 — or under the minimum age of digital consent where you live, which is 16 in some EU countries. If you are below that age, please do not make an account without a parent or guardian's agreement. If you believe a child has made one, write to [email protected] and it will be removed.
Changes to this policy
If what we collect changes, this page changes with it, and the date at the top moves. Anything that materially affects players will also be announced in the release notes and on Discord rather than quietly edited in.
Contact
Questions about this policy, or about anything held about you: [email protected]. The contact page has the community links as well.