Who this notice covers
Astrio operates this creator and game-information website. This notice applies when you browse the site, use an optional account or protected feature, load embedded media, or contact Astrio about the website. Privacy questions and requests can be sent to officialastrio@gmail.com.
Information Astrio may handle
Account and sign-in information
If you choose Continue with Google, Google and Supabase handle the OAuth exchange. Google may provide a stable account identifier, email address, basic profile information, and sign-in details within the requested openid, email, and profile scopes. Supabase creates and manages the resulting Astrio authentication session. The account email is used to operate and protect the account, send service or legal notices permitted by the Terms of Use, and is not displayed in Astrio's public interface.
Profile information and preferences
Astrio assigns a new account a random Star username, which the signed-in user may replace with a custom username. A user may also provide a Frostborn in-game public ID and save a language preference. The username appears as the account label and is reserved to one account without regard to letter case. Astrio records whether the username is still the generated label, how many of the three later changes have been used, and the latest successful username-change time for its 5-minute cooldown. The in-game ID is saved in uppercase. Astrio records the latest successful in-game ID and language-preference change times to enforce their 10-minute cooldowns. These preferences remain associated with the account until you change them or request deletion, subject to lawful retention needs described below.
Terms acceptance
When you accept the Terms of Use, Astrio records your account, the terms version, and the acceptance time. Earlier versions may be kept when needed to document the account's acceptance history. Choosing Not now creates no server-side acceptance record; it only avoids repeating the prompt during that browser session.
Cookies, browser storage, and device information
On an ordinary page visit, Astrio generally places a random, signed browser token in a first-party, HttpOnly cookie. The token is generated at random rather than derived from device characteristics. It can last for up to one year and is used to bind later sign-ins to the browser, protect registered features, prevent abuse, and keep an active access restriction tied to the same browser. Astrio does not use it as an advertising identifier.
Supabase authentication cookies keep a signed-in session until it expires or you sign out. A short-lived sign-in cookie generally lasts ten minutes. A first-party, HttpOnly access-lease cookie can last up to about 15 minutes plus a 30-second grace period and reduces repeated protected-access checks. Protected-media cookies and a temporary developer-tools gate can last up to six hours. A signed restriction marker can last for up to one year after sign-out so the restriction still applies in that browser. It is removed after the same account is signed in and Astrio confirms that the restriction was removed.
Choosing a language stores the preference in a first-party cookie and local storage for up to one year. Session storage may remember dismissed security notices and a choice of Not now for the current Terms prompt. Other first-party local storage may hold a cross-tab account-change timestamp, an administrator-view preference for authorized accounts, and baseline browser-window geometry used by the developer-tools detector. Those values remain until replaced, removed by the site, or cleared in the browser. Clearing browser data may require sign-in or browser verification again, but does not itself delete an account or remove a server-side restriction.
After sign-in, the browser creates a one-way digest from coarse categories: browser family, rounded screen dimensions and pixel ratio, touch or desktop class, touch-point category, time zone, and browser language. Astrio receives that digest rather than those raw details. The application database stores separately keyed one-way hashes of the digest, the random browser token, and the request IP address. It does not store the raw IP address, user agent, exact screen values, or raw device-signal input in its security tables. The hosting or network provider may still receive ordinary request information to deliver the site.
Like most websites, Astrio and the services that operate it may receive standard technical information such as an IP address, general browser and device characteristics, requested page, request time, referring page, response status, and basic diagnostic information. Limited signals may also be used to distinguish ordinary use from abuse. Astrio does not try to build an advertising profile from this information.
Security and access events
Astrio may record limited events connected to sign-in, unusually rapid requests, security warnings, suspected misuse, feature restrictions, and restriction reviews. These records can be associated with an account, browser, request, or approximate network source when needed to protect the website and apply the Terms of Use.
Donation information
The donation dialog loads PayPal's hosted-button software only after you open it. PayPal, including a Venmo option when offered, independently handles the checkout and may collect account, payment, device, network, and transaction information under its own privacy statement. Astrio does not receive or store your card number, bank credentials, or other payment credentials.
After PayPal reports a completed, refunded, or reversed donation, Astrio verifies the report and stores a minimal donation ledger: PayPal event and payment-resource identifiers, event type, amount, currency, event time, and receipt time. Astrio's application database does not store the payer's name, email address, mailing address, payment method, or complete PayPal webhook payload. The public monthly goal exposes only aggregate amount and donation-count totals.
Messages you send
If you email Astrio, the message, your email address, attachments, and any information you choose to include may be kept to answer the request, maintain a record of the issue, resolve a dispute, or meet legal and security obligations. Do not send sensitive information that is not needed for the request.
Service providers, external media, and links
Supabase provides hosted authentication and database services. Google provides account sign-in and receives messages sent to Astrio's Gmail address. Starting sign-in also loads Cloudflare Turnstile, an anti-abuse check that may process connection and browser signals and returns a short-lived result that Astrio verifies. PayPal provides the donation checkout described above. The provider that hosts or delivers the site receives ordinary request data needed to serve it.
You can review Supabase's Privacy Policy, Google's Privacy Policy, and YouTube's Terms of Service. Cloudflare publishes a Turnstile Privacy Addendum, and PayPal publishes its Privacy Statement.
Astrio may provide links to YouTube, Discord, X/Twitter, and other external services. The landing page does not automatically load an embedded YouTube player. If you follow an external link, your browser connects to a service Astrio does not operate. That service may receive your IP address, browser or device information, referring page, and interaction under its own terms and privacy notice.
Why information is used
Astrio may use the information described above to:
- provide, maintain, and troubleshoot the website;
- create and manage an optional account and profile;
- record Terms of Use acceptance;
- process verified donation events and display aggregate goals;
- answer requests and correct reported problems;
- prevent fraud, abuse, attacks, and unauthorized access;
- apply and review warnings, request limits, and restrictions;
- protect users, Astrio, third parties, and legal rights; and
- comply with applicable law and valid legal requests.
Depending on applicable law, these uses are based on providing a service you request, Astrio's legitimate interests in operating and protecting the website, your consent where it is specifically requested, or compliance with legal obligations.
When information may be shared
Categories of recipients include authentication and database providers (Supabase); identity, email, and external-media providers (Google and YouTube); anti-abuse providers (Cloudflare Turnstile); payment providers (PayPal and a Venmo option when offered); hosting and content-delivery providers; and services you choose to visit through external links. The information each receives depends on the interaction described above and on that provider's own role.
Astrio may also disclose information when reasonably necessary to comply with law or valid legal process; investigate fraud, abuse, or a security incident; protect a person from serious harm; protect Astrio's or another person's rights; obtain professional advice; or transfer the website to a successor operator subject to applicable law.
Astrio does not sell personal information and does not use or share it for cross-context behavioral advertising or targeted advertising. Astrio has not installed an advertising pixel or analytics service. External providers may process information under their own policies when you open the sign-in panel or continue with Google, open the donation dialog, send an email, or follow a link.
California Do Not Track and browser privacy signals
Astrio does not track a visitor's activity over time across unrelated websites, so it does not change its first-party operational processing in response to the legacy browser Do Not Track signal. Astrio also does not currently sell or share personal information for cross-context behavioral advertising, so a Global Privacy Control signal does not change the site's current behavior: there is no such sale, sharing, or targeted advertising to opt out of.
Google, Supabase, Cloudflare, PayPal, the hosting or network provider, and services reached through external links may collect identifiers or activity during those interactions and may be able to recognize a browser across services as described in their own notices. Astrio does not control how those parties respond to Do Not Track or other browser signals. If Astrio later adds cross-site tracking, analytics, advertising, a sale, or covered sharing, this notice and any required choices must be updated before that new practice begins.
Automated protection and access decisions
The website uses automated checks to identify unusual or prohibited activity. These checks may warn you, slow or block a request, or temporarily or permanently restrict New Update Changes, Information, and Calculators. Public creator pages and Guides may remain available, and an account may remain signed in.
Automated signals are not perfect. You may request a review by emailing officialastrio@gmail.com with your username, approximate time, and a short explanation. Astrio may need to keep limited information about the event while reviewing or enforcing the restriction.
How long information is kept
Astrio keeps personal information only as long as reasonably necessary for the purposes in this notice. The period depends on the type of information and why it is needed:
- session state lasts until it expires or you sign out, while necessary browser recognition and restriction state can remain until it expires, is cleared, or is no longer needed;
- account and profile information is generally kept while the account exists or until it is changed or deleted;
- terms-acceptance records may be kept as needed to document the agreement;
- security, restriction, and correspondence records are kept only as long as needed to protect the site, enforce rules, investigate an issue, resolve a dispute, or meet legal obligations; a security event may be de-linked from a deleted account and remain with keyed hashes rather than a direct account identifier;
- the minimal PayPal donation ledger is retained separately from an Astrio account for payment verification, refunds and reversals, accounting, fraud prevention, dispute resolution, and legal records; it is not automatically deleted when an Astrio account is deleted; and
- operational logs and backups may remain according to provider retention, security, and recovery practices.
A deletion request removes information that Astrio is not still reasonably required or legally permitted to keep. Deleting account information may end access to registered features.
Your choices and privacy rights
You can browse public pages without an account, choose Not now on the account Terms prompt and keep using public pages subject to the Terms of Use, edit available profile fields, sign out, clear browser data, choose not to start Google sign-in or open the PayPal donation dialog, or choose not to follow external links. Some account and security features will not work if their required cookies or browser storage are blocked. Third-party interactions are described above.
Depending on where you live, you may have rights to request access to a copy of personal information, correction, deletion, restriction or objection to processing, portability, or withdrawal of consent where consent is the basis. You may also have the right to complain to your local privacy regulator and to receive no unlawful discrimination for exercising a privacy right.
Send a request to officialastrio@gmail.com. Astrio may reasonably verify that the request concerns you. Rights can be limited by applicable law, and some information may be retained for security, fraud prevention, legal obligations, or dispute resolution. Because some operational records contain limited identifiers, Astrio may not be able to reliably connect every record to a particular person.
Children
This is a general-audience game-information and creator site and is not directed to children under 13. Children under 13, or a higher minimum age where local law requires it, may not create an account or submit profile information. A person who meets that minimum age but is below the legal age of adulthood may use an account only with the parent or legal guardian review and agreement described in the Terms of Use. If you believe a child provided personal information, contact officialastrio@gmail.com so it can be reviewed and deleted where appropriate.
International processing
Astrio and the providers that support the website may process information in countries other than the one where you live. Privacy protections can differ between countries. Where required, information will be handled using safeguards recognized by applicable law.
Security
Astrio uses reasonable administrative and technical measures intended to protect information and limit access. No website, transmission, or storage method can be guaranteed completely secure. If you believe your account or information is at risk, contact officialastrio@gmail.com promptly.
Changes and contact
The date above will change when this notice changes. Astrio will provide additional notice when reasonably required for a material change. New uses that require consent will not be treated as accepted merely because you continue browsing. Questions and requests can be sent to officialastrio@gmail.com.