Skip to the notes

Privacy policy

Last updated: 4 September 2026 · Effective from 4 September 2026

1. Who is behind this site

RuneRecap is a personal publication about a single Android game. It is run by an individual, Lachlan Davies, at 87 McLennan St, Mooroopna VIC 3629, Australia. Telephone: +61 3 5825 2866. Email: editor@runerecap.com.

There is no organisation behind the site, no staff and nothing on it is for sale. It is written in spare hours and published because the game seemed worth writing about.

2. What this policy covers

This policy explains what happens to information when a browser requests a page from runerecap.com, what is kept, for how long, who else can see it, and what you can ask for. It covers this site only. It does not cover Google Play, the game itself, or any other site you reach from a link here.

3. Position under the Privacy Act 1988 (Cth)

A private individual publishing a non-commercial site is very likely a small business operator under section 6D of the Privacy Act 1988 (Cth) and therefore outside the direct reach of that Act. Rather than lean on that exemption, the site is operated as if the Act applied in full, and the thirteen Australian Privacy Principles (APPs) in Schedule 1 of the Act are treated as binding on it. Where this policy refers to an APP right, that right is offered voluntarily and will be honoured in the same way a covered entity would honour it.

4. What the site deliberately does not do

  • There is no contact form, no comment box, no search field and no field of any kind on any page.
  • There are no accounts, no sign-in and no profile.
  • There is no mailing list and no newsletter.
  • The site sets no cookies of its own.
  • There is no analytics package, no tag manager, no advertising script, no social widget and no push notification service.

The site therefore collects no personal information through its pages: there is nowhere to type and nothing to send.

5. What is recorded anyway

Two things sit between you and the pages you read, and both keep short technical records as a normal part of delivering a website.

5.1 Hosting server logs

The server that stores these files writes an ordinary access log for each request. A log line contains the IP address the request came from, the date and time, the path requested, the HTTP status returned, the number of bytes sent, the browser user-agent string and, where the browser supplies it, the page you arrived from.

5.2 Content delivery network

Traffic is served through Cloudflare, Inc., which operates a content delivery network and a security layer in front of the site. Cloudflare processes the same categories of technical data at the edge, and may derive aggregate performance and security metrics from it. Cloudflare’s edge measurement does not require a cookie and is not used here to build any profile of a reader.

5.3 Is any of this personal information?

An IP address can be personal information under Australian law where it is reasonably capable of identifying an individual. It is treated as such here so the protections below apply, even though no address is ever linked to a name.

6. Why each category is handled, and for how long

  • IP address — needed to route a response back to your device and to block abusive traffic. Retained in server logs for up to 30 days, then overwritten by log rotation.
  • Date, time, path and status code — used to see whether pages are being served correctly and to find broken links. Retained for up to 30 days.
  • User-agent string — used to check that the layout holds together on the browsers people actually use. Retained for up to 30 days.
  • Referring page — used to understand where readers found the site. Retained for up to 30 days.
  • Edge security and performance metrics — held by Cloudflare under its own retention schedule, generally in aggregated form.
  • Email correspondence — see section 8. Kept for as long as the matter is open, and in the mailbox archive for up to 24 months afterwards.

None of this is used for marketing, none of it is sold or traded, and none of it is used to make an automated decision about anybody.

7. Who else can see it

  • The hosting provider that operates the server, in its capacity as a technical service provider.
  • Cloudflare, Inc., 101 Townsend St, San Francisco, California, United States, as the content delivery and security provider.
  • The email provider that carries a message, if you choose to write.
  • A court, regulator or law enforcement body, where disclosure is required or authorised by an Australian law or a court order.

8. If you send an email

The only channel here is the published address. A message sent to it travels through your own mail provider and lands in an ordinary mailbox; it does not pass through this website and no part of it is stored on the web server. A reply will use the same address. Your address is not added to any list, is not used to send anything you did not ask for, and is not passed to anyone else.

Please do not send sensitive information by email. If a matter needs identity documents, health details or anything similar, say so first and a safer arrangement can be agreed.

9. No marketing messages: Spam Act 2003 (Cth)

The Spam Act 2003 (Cth) governs unsolicited commercial electronic messages sent to Australian addresses. RuneRecap sends none. There is no subscription, no announcement list and no promotional message of any kind, so the question of consent, sender identification and an unsubscribe facility does not arise. If you ever receive a message that claims to come from this site, it did not.

10. Sending data outside Australia (APP 8)

Because Cloudflare, Inc. is based in the United States and operates edge locations worldwide, technical data described in section 5 may be handled outside Australia. Before that happens the site relies on the contractual and security commitments Cloudflare publishes for its network. Reasonable steps are taken to satisfy APP 8.1, but you should understand that overseas privacy law may differ from Australian law and that enforcement abroad can be harder in practice.

11. Security

Pages are served over HTTPS. The site is static: no database, no server-side application and no upload path, which removes most of the openings a small site normally leaves open. Access to the hosting account and the mailbox is protected by long unique passwords and multi-factor authentication. No promise of absolute security is made.

12. Access and correction (APP 12 and APP 13)

You may ask what information about you is held and ask for it to be corrected. Write to the address in section 1. A request about server logs needs something to match on, such as the approximate date and time of a visit together with the IP address in use, or the relevant lines cannot be found. Requests are answered within a reasonable period, normally 30 days, at no charge. If access is refused, the reason is given in writing.

13. Deletion

Log lines are overwritten on the rotation schedule in section 6 without any action from you. An email exchange will be deleted from the mailbox on request, unless it must be kept for a legal claim.

14. Complaints, and the OAIC

If you think information has been handled badly, please raise it directly first: write to editor@runerecap.com with the word privacy in the subject line and a description of what happened. A written answer will follow within 30 days.

If the answer does not satisfy you, or you would rather not deal with the site at all, you may complain to the Office of the Australian Information Commissioner (OAIC):

The OAIC can investigate and make determinations about the handling of personal information in Australia.

15. Notifiable Data Breaches scheme

Part IIIC of the Privacy Act 1988 (Cth) sets up the Notifiable Data Breaches scheme. If a breach of information held in connection with this site were likely to result in serious harm, the affected people would be told directly where their contact details are known, a notice would be published on this site where they are not, and the OAIC would be notified as soon as practicable. Given how little is held here, the realistic scope of such an event is limited to server log data and email correspondence.

16. Readers under 13

This site is written for adults and is not directed at children under 13 years of age. Nothing here asks for personal information, so a child cannot submit any through the pages. If you believe a child has sent an email containing personal information, contact the address in section 1 and it will be deleted.

17. Links away from this site

Some pages link to the Google Play listing for the game. Following such a link takes you to a service operated by Google LLC under its own privacy terms, which this policy does not control and cannot change. Read that policy before using the service.

18. Changes to this policy

If the way the site works changes, this page is updated and the date at the top changes with it. The version in force when you visit is the one that applies to that visit.

19. Contact

Lachlan Davies, 87 McLennan St, Mooroopna VIC 3629, Australia. Telephone +61 3 5825 2866. Email editor@runerecap.com.