← All Legal Documents

Cookie Policy

Age of Aeternus | Last Updated: October 2, 2026

  • Terms of Service
  • Privacy Policy
  • Subscription Terms
  • Community Guidelines
  • DMCA Policy

1. Introduction

This Cookie Policy explains how NerdHonest LLC ("we," "our," or "us") uses cookies and similar technologies in Age of Aeternus. It covers:

  • the web app at app.aoathegame.com;
  • our website at aoathegame.com, including the legal pages and the DMCA form; and
  • the storage our mobile and desktop apps use on your device.

Read it together with our Privacy Policy, which explains how we handle personal data. In this policy, "Service" has the meaning given in our Terms of Service.


2. What These Technologies Are

  • Cookies
    • What it is: Small text files your browser stores for a website.
    • Where we use it: Web app and website.
  • Local storage and session storage
    • What it is: Browser storage for small settings; session storage is cleared when you close the tab.
    • Where we use it: Web app and website.
  • IndexedDB
    • What it is: Browser database for larger data.
    • Where we use it: Web app.
  • Service worker and Cache Storage
    • What it is: A browser feature that keeps copies of app files so the app loads faster and works offline.
    • Where we use it: Web app.
  • On-device storage
    • What it is: App storage on your phone or computer, including encrypted secure storage.
    • Where we use it: Mobile and desktop apps.

We don't use cookies or similar technologies for advertising, and we don't let advertisers place them.


3. What We Use and Why

3.1 Strictly Necessary

These make the Service work. You can't turn them off in our settings, because the Service doesn't work without them.

  • Sign-in session (Firebase Authentication)
    • Where: Web app: IndexedDB, or local storage if IndexedDB is unavailable. Apps: on-device storage.
    • Purpose: Keeps you signed in.
    • How long: Until you sign out.
  • Sign-in state (session storage)
    • Where: Web app.
    • Purpose: Completes the sign-in flow when you sign in with Google or Apple.
    • How long: Until the tab is closed.
  • aoa_signed_in cookie
    • Where: Web app; readable across aoathegame.com.
    • Purpose: Tells our website that you are signed in, so it can link you straight to the app. Its value is just "1".
    • How long: 1 year, or until you sign out.
  • Privacy choices (cookie_consent)
    • Where: Web app: IndexedDB. Apps: on-device storage.
    • Purpose: Remembers your choices about analytics and diagnostics.
    • How long: Until you change them. We ask again if the choices on offer change.
  • App data cache
    • Where: Web app: IndexedDB. Apps: on-device storage.
    • Purpose: Saves app settings and copies of your content, including drafts, so the app works offline and loads quickly.
    • How long: Until it is replaced, you clear site data, or you uninstall the app.
  • Device identifier (aoa_device_id)
    • Where: Web app: local storage (as FlutterSecureStorage.aoa_device_id). Apps: secure storage.
    • Purpose: A random identifier that lets the music player and virtual tabletop tell your devices apart.
    • How long: Until you clear site data or uninstall the app. On iOS and macOS, it is kept in the Keychain and can survive uninstalling the app.
  • Offline app files (service worker, cache aoa-shell-v1)
    • Where: Web app.
    • Purpose: Keeps copies of the app's own files so it loads faster and works offline.
    • How long: Until the app updates them or you clear site data.
  • App Check (Google reCAPTCHA Enterprise)
    • Where: Web app.
    • Purpose: Checks that requests come from our real app and not from bots. Google may set or read its own cookies when this runs.
    • How long: Set by Google.

3.2 Preferences

  • aoa_theme cookie
    • Where: Website.
    • Purpose: Remembers whether you chose the light or dark theme.
    • How long: 1 year.
  • aoa_roadmap_expanded
    • Where: Website: local storage.
    • Purpose: Remembers whether you expanded the roadmap section.
    • How long: Until you clear site data.
  • loading_bg, loading_accent
    • Where: Web app: local storage.
    • Purpose: Colors for the loading screen, matching your theme.
    • How long: Until you clear site data.
  • aoa_vtt_renderer_v1
    • Where: Web app: local storage.
    • Purpose: Remembers the graphics renderer chosen for the virtual tabletop.
    • How long: Until you clear site data.
  • get_the_app_banner_dismissed_at, pwa_install_dismissed_at
    • Where: Web app: local storage.
    • Purpose: Remember when you dismissed the "Get the app" banner or the install prompt, so we don't show it again too soon.
    • How long: Until you clear site data.
  • App settings (keys starting with flutter.)
    • Where: Web app: local storage. Apps: on-device storage.
    • Purpose: Remembers settings you choose in the app, and a few values the app needs to start up. flutter.boot_last_authenticated_uid holds the ID of the last account that signed in on this device. flutter.boot_bootstrapped_<account ID> and flutter.boot_schema_version_<account ID> record that this account's offline data has been set up. If you open an invite link, flutter.pending_referral_code holds its referral code until you sign up.
    • How long: Until you clear site data or uninstall the app. The values about the last account are kept after you sign out, together with that account's offline data, so the same account keeps offline access. They are replaced, and that data cleared, when a different account signs in on the device. A stored referral code is removed once it is used; one older than 30 days is ignored and removed.

3.3 Diagnostics

  • Technical diagnostics (web crash beacon)
    • Where: Web app and apps.
    • Purpose: When the app hits an error, it sends us a short crash report: error type, code location, the screen you were on, app, Flutter and platform versions, and recent app activity (screens opened, earlier errors and failed network requests). It contains no error-message text and no account ID. It uses no cookies. It is on by default under our legitimate interest in keeping the app stable, and you can turn it off. On our mobile and desktop apps, each report is also saved on your device first, including while the switch is off, and is sent only while it is on. See Privacy Policy Section 2.2.
    • How long: Reports are deleted from our servers after 30 days. On the apps, your device keeps up to 200 saved reports (at most 10 MB), removing the oldest first.
  • aoa_skwasm_runtime_reload_v1
    • Where: Web app: session storage.
    • Purpose: Lets the app reload once, without looping, if its graphics engine crashes.
    • How long: Until the tab is closed.
  • aoa_skwasm_runtime_crash_v1
    • Where: Web app: local storage.
    • Purpose: A note that lets the app tell, on its next start, that its graphics engine crashed last time.
    • How long: Until the app reads and clears it on its next start, or you clear site data.
  • aoa_freeze_breadcrumb_v1
    • Where: Web app: local storage.
    • Purpose: A freeze log used only in our development and test builds. The released web app doesn't write it, and deletes it if an earlier version left one behind.
    • How long: Deleted the next time you open the released web app.

3.4 Analytics (Only If You Accept)

  • Google Analytics for Firebase (gtag.js)
    • Where: Web app.
    • Purpose: Would record which screens and features are used. Analytics isn't currently active: it isn't connected to a Google Analytics account, so no analytics data is collected, even if you accept. On the web, the analytics script loads only after you accept analytics, and never if you decline. If we turn Analytics on, Google would set its own cookies (named _ga and _ga_…), and we will update this policy first.
    • How long: Google's cookies usually last up to 2 years.
  • App-health events and performance summaries
    • Where: Web app and apps.
    • Purpose: If you accept Analytics, the app also sends us app-health events (app version, startup and server-call timings and errors) and performance summaries (frame, save and sync timings, and database read counts), linked to your account. These are active today, and they use no cookies. See Privacy Policy Section 2.2.
    • How long: App-health events are deleted after 7 days, and performance summaries after 30 days.

On our mobile and macOS apps, Firebase Analytics and Crashlytics are off until you accept. Our Privacy Policy explains what accepting turns on.

3.5 Purchases (RevenueCat)

  • RevenueCat purchases SDK
    • Where: Web app, mobile apps and our macOS app.
    • Purpose: Checks your subscription status and handles store purchases. It starts when the app opens, before you sign in, and contacts RevenueCat with a random anonymous ID. After you sign in, it uses your account ID instead. It may store an anonymous identifier in your browser's or device's storage.
    • How long: Until you clear site data or uninstall the app.

Subscriptions can't be bought on the web app yet, but the SDK still starts there.

3.6 Third-Party Content on Our Website

  • Google reCAPTCHA (DMCA form only). The form at aoathegame.com/dmca loads Google reCAPTCHA only when you start filling it in. reCAPTCHA collects information about your browser and how you interact with the page, and Google may set its own cookies. Google's Privacy Policy and Terms apply.
  • Videos. Our website has a space for a video that plays only when you click it, from youtube-nocookie.com. No video is set up there today, so nothing loads from YouTube.
  • Fonts. We host our fonts ourselves. Our website and web app don't load fonts from Google.
  • No analytics on our website. The aoathegame.com website runs no analytics.

4. Your Choices

4.1 In the Web App, Before You Sign In

If you visit the web app without signing in, we show a cookie banner with three options:

  • Accept All: turns on analytics and technical diagnostics.
  • Reject Non-Essential: turns off analytics and technical diagnostics.
  • Customize: lets you choose. Essential storage is always on; Analytics and Technical diagnostics each have their own switch.

Until you choose, analytics stays off and technical diagnostics is on.

4.2 When You Are Signed In

Once you have an account, you make these choices in the app rather than in the banner:

  • When you sign up, the "Privacy choices" step asks about analytics with equal Accept all and Decline buttons. Its heading names what your answer covers on that platform: "Analytics and crash reporting" on Android, iOS and macOS, "Analytics and app health data" on the web, and "App health and performance data" on Windows and Linux. Nothing is pre-selected, unless you already made a choice on this device. Technical diagnostics and gameplay data are shown on, with switches to turn them off.
  • Existing users are asked on each device in a "Before you continue" screen, until they answer.
  • At any time: open Account › Privacy Settings in the side menu (also reachable from Profile Settings › Privacy, Data & Legal). The switches are Analytics, Technical diagnostics, Crash Reporting (Android, iOS and macOS only), Share anonymized gameplay data, and Marketing Emails.

4.3 Browser and Device Controls

You can also delete or block cookies and site data in your browser, usually under its privacy or site-settings menu. If you block strictly necessary storage, you won't be able to sign in. Your phone or computer may offer similar controls for apps.


5. Do Not Track and Global Privacy Control

We don't currently respond to "Do Not Track" browser signals or to Global Privacy Control (GPC) signals. Analytics stays off unless you opt in. We don't sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising, so there is nothing for these signals to opt you out of.


6. Records of Your Choices

  • On your device, we store your choices as described in Section 3.1.
  • In your account, when you are signed in, we keep a history of your choices: the date and time, what you chose, the version of the choices shown, your platform, and how you chose. If you make a choice while signed out, we add it to your account history after you sign in.
  • After account deletion, we keep a minimal proof of these choices for 3 years. The Privacy Policy explains what it contains.

7. Changes to This Policy

We may update this Cookie Policy when our practices, technology or the law change. We will update the "Last Updated" date. If we start using a new kind of non-essential cookie or similar technology, we will ask for your consent where the law requires it.


8. Contact Us

For questions about this Cookie Policy, email privacy@nerdhonest.com.

NerdHonest LLC, 8735 Dunwoody Place, Suite R, Atlanta, GA 30350, United States (mailing address)


9. Additional Information by Jurisdiction

9.1 European Economic Area and United Kingdom

Under the ePrivacy rules and the GDPR (and their UK equivalents):

  • we ask for your consent before using non-essential cookies and similar technologies for analytics;
  • you can withdraw consent at any time, in the banner (before you sign in) or in Privacy Settings, without affecting earlier processing; and
  • strictly necessary storage doesn't need consent.

9.2 United States

We don't sell personal information or share it for cross-context behavioral advertising. Section 5 explains how we treat Do Not Track and Global Privacy Control signals.


Document History

  • Version 2.0 (October 2, 2026). Rewritten to list the storage the web app, website and apps actually use. Removed items that don't exist (a language cookie, a security cookie, and a 1-hour sign-in limit). Added the aoa_signed_in and aoa_theme cookies, local storage, IndexedDB and the service worker. Explained that the banner is for signed-out visitors, and that signed-in users choose in the app. Disclosed reCAPTCHA on the DMCA form, the inactive video space, and that we self-host fonts. Explained that accepting Analytics also turns on app-health and performance reports, and which app settings keys hold an account ID. Corrected the crash-report retention to 30 days. Corrected Do Not Track: we don't respond to it.
  • Version 1.3 (March 20, 2026). Previous version.

Effective Date: October 2, 2026

Version: 2.0

© 2026 NerdHonest LLC. All rights reserved.

Age of Aeternus | Legal Center