Legal — Artsmodjo Games

Privacy Policy.

How Artsmodjo collects, uses, and protects your data when you play Dash Go and Modjo Brawl on artsmodjo.biz.id.

01 — Scope

This policy covers the browser games operated by Artsmodjo at artsmodjo.biz.id:

  • Dash Go — a tile-match browser game at /games/dashgo/. Play as guest, or sign in with Google. Guest and Google progress is saved separately.
  • Modjo Brawl — a browser fighting game at /games/modjo-brawl/. Play as guest, register with email and password, or sign in with Google.

The operator is Artsmodjo. Contact: hello@artsmodjo.biz.id. Each game also ships a short in-game version of this policy (Dash Go, Modjo Brawl); this page is the canonical text.

02 — Data we collect

Account data (Modjo Brawl registered accounts)

  • Email address, username, and display nickname you choose.
  • Password — stored only as an Argon2id hash. We never store plaintext passwords.
  • Public player handle (for example MB-XXXXXX), avatar choice, and the timestamp you accepted the Terms.

Google sign-in (both games)

  • When you choose Google sign-in, Google provides a verified identity token. We request only the openid, email, and profile scopes.
  • We receive your verified email address, stable Google subject ID, and basic profile (name, picture). The sign-in completes through our single callback at /auth/google/callback.php.
  • Accounts are matched by the stable Google subject ID — never by email alone — so changing your Google email cannot hijack another account.

Guest play (no account needed)

  • Dash Go issues an anonymous visitor identity so your session and progress persist between visits.
  • Modjo Brawl issues a guest token and display name. A guest can later be claimed into a registered account, once, by its owner.

Gameplay data

  • Game sessions, scores, tiles matched, hints and shuffles used, match results, wins and losses, ratings and rankings, unlocked fighters, stages, rewards, and reward claim records.
  • Dash Go collects first-party gameplay analytics events (capped batches) to keep the game fair and working.

Technical data

  • Hashed IP address and user-agent (SHA-256 hashes, not raw values) for sessions, rate limiting, and abuse prevention.
  • Append-only security audit events (for example sign-in, registration, guest claims).
  • There is no advertising SDK, no cross-site tracker, and no payment provider in the games.

03 — Cookies & storage

Both games need a small number of strictly-necessary cookies to function. There are no advertising or tracking cookies.

  • Identity / session cookie (HttpOnly, Secure, SameSite) — keeps you signed in or remembers your guest. This is the single trust root: the server looks up your identity from this cookie only.
  • CSRF cookie — double-submit token sent back on every mutating request to block cross-site forgery.
  • Guest cookie (Modjo Brawl) — remembers a guest fighter between visits until it expires or is claimed.
  • OAuth binding cookie (am_oauth_bind) — short-lived, binds a Google sign-in attempt to the browser that started it (about 15 minutes).
  • Device-local game data — progress, sound settings, and UI state may be kept in your browser (local storage) so the games work smoothly.
  • Google libraries — loaded from Google only when you use Google sign-in, subject to Google's own policies.

Blocking strictly-necessary cookies will sign you out or reset guest progress; the games cannot keep score or save rewards without them.

04 — How we use data

  • Operate the games: run sessions, save progress, keep guest and Google saves separate, and show your profile, collection, and rank.
  • Verify reward eligibility and deliver reward codes exactly once, with anti-fraud and abuse checks.
  • Secure the service: authenticate requests, enforce rate limits, detect cheating and bots, and investigate incidents.
  • Respond to support requests sent to hello@artsmodjo.biz.id.

We do not use game data for advertising, and we do not build marketing profiles.

05 — What we never do

  • We never sell your personal data.
  • We never store plaintext passwords (Argon2id hashes only) or raw session tokens (SHA-256 hashes only).
  • We never auto-link accounts by email address; Google identities link by verified subject ID only.
  • There are currently no in-game purchases — the store is dormant — so we collect no payment data.

06 — Sharing

  • Google — only when you choose Google sign-in, to verify your identity (OAuth 2.0 / OpenID Connect).
  • Infrastructure — hosting and database providers that store and serve the games on our behalf. They process data only as instructed.
  • Legal — if required by applicable law or to protect the security of the service and its players.

Public game surfaces (rankings, winner screens) show only nicknames and game statistics — never emails or passwords.

07 — Retention & deletion

  • Guest sessions expire automatically. A claimed guest is transferred to its new account once.
  • Account, gameplay, and reward records are kept while your account is active so progress, rankings, and claims remain consistent.
  • Deleted accounts are soft-deleted and anonymized — never hard-erased in a way that breaks game integrity records.
  • Short-lived security artifacts (OAuth states, PKCE verifiers, handoff and registration tickets) expire within minutes and are single-use.

To request access, correction, or deletion of your data, email hello@artsmodjo.biz.id from your account email and include your username or player handle. We reply within a reasonable time.

08 — Children

Both games require players to be at least 13 years old. Modjo Brawl registration asks you to confirm this with a required checkbox, and the acceptance timestamp is recorded. If we learn an account belongs to someone under 13, we will suspend or delete it.

09 — Security

  • HTTPS in production; HttpOnly + Secure + SameSite identity cookies; CSRF double-submit checks on mutating requests.
  • Google sign-in uses PKCE, one-time state and nonce, and short-lived HMAC-signed handoff tickets.
  • Per-visitor and per-IP rate limits, server-side validation on every action, and append-only audit logs.
  • Schema changes run via controlled migrations — never through public endpoints.

No system is perfectly secure. If you suspect your account is compromised, sign out everywhere you can and contact us immediately.

10 — Rights & changes

You may request a copy of your data, correction of inaccurate data, or deletion/anonymization of your account at any time via hello@artsmodjo.biz.id.

We may update this policy as the games evolve. Material changes will be reflected in the “Last updated” date above, and continued play after the update constitutes acceptance. For questions, contact hello@artsmodjo.biz.id. Also see our Terms of Service.