PRIVACY.TXT

Privacy Policy

Loafstead does not capture, read, or transmit anything from your screen. It cannot see your windows' contents, your browsing history, or what apps you have open.


Related documents


What Loafstead does not do

  • Does not capture or read screen contents, text, or pixels
  • Does not record window titles, document names, app names, or URLs
  • Does not log keyboard input or mouse movements
  • Does not collect analytics or behavioral data without your opt-in consent (off by default)
  • Does not collect your Steam ID, username, or any Steam account data
  • Does not sell, share, or trade your personal information with third parties

How Loafstead interacts with your desktop

To know where to put the cats, Loafstead reads window positions and sizes from the operating system. This is the same information any window manager uses.

Window titles are never loaded into memory. The code uses only numeric window identifiers (like #12345). Human-readable window titles, document names, and app names are never stored, logged, or transmitted.

All of this happens locally on your computer. None of it is ever sent anywhere.


Update checks

This applies to the direct download only. The Steam version uses Steam's own update system and never contacts loafstead.gg for updates.

On startup, and then once per hour while the app is running, Loafstead makes an HTTPS request to check for a newer version. This request goes through Cloudflare to loafstead.gg. The server receives your IP address and User-Agent. No account information, game data, or device identifiers are sent. This happens regardless of your crash report preference and cannot be disabled.

If a newer version is available, it downloads and installs automatically, then restarts Loafstead.


Crash reports (optional, off by default)

If Loafstead crashes, it saves a crash report to disk. No data is sent unless you choose to share it. The default is not opted in.

On the next launch after a crash, a dialog explains your right to withdraw consent at any time and offers four choices: Send Once, Always Send, No Thanks, or Never Ask. You can change your choice at any time using the menu bar (macOS) or system tray (Windows). Choosing "Always Send" also enables real-time error reporting for errors that occur during normal gameplay, not just after a crash.

A crash report contains:

  • App version, OS name and version, CPU architecture
  • GPU model name, vendor, and graphics API (e.g. "Apple M4 Max", "Metal")
  • System locale (e.g. "en_AU")
  • Screen layout: number of monitors and their exact dimensions and positions
  • Stack trace and error message (file paths are scrubbed to remove usernames)
  • Game state snapshot: which pets and visitors are on screen and what they are doing, their positions, coin balance, screen size, game session uptime, and a handful of UI state flags
  • Recent game log entries (up to 1000, scrubbed of file paths)
  • An anonymous install ID: a randomly generated 16-character identifier stored in your save file. It has no connection to your name, account, or hardware. It is used only to group multiple crash reports from the same installation.

A crash report does not contain:

  • IP addresses (the app tells the crash reporting library not to include them)
  • Usernames, file paths, window titles, or screen content
  • Your name, email, or any account information

Where crash data is stored

Crash reports are sent to GlitchTip, an open-source error tracking tool (similar to Sentry), running on a server we host ourselves in Tasmania, Australia. This is not a third-party analytics or cloud service. Your crash data does not go to Google, Amazon, Microsoft, or any other company.

While crash reports themselves do not contain IP addresses, the server receives your IP as part of the HTTPS connection. This IP appears in server access logs but is not embedded in the crash report file. IP addresses are anonymized and not stored alongside crash data.


Security

Crash reports are transmitted over HTTPS (TLS). Access to our GlitchTip instance is restricted to authorised personnel. Crash data is automatically deleted after 90 days.


Gameplay analytics (opt-in, off by default)

Loafstead can optionally send gameplay events to help improve the game. This is turned off by default. You can enable or disable it at any time in Settings.

This data is pseudonymous: a random install ID links your events. It is not tied to your name, account, or hardware, and you can reset it or request deletion at any time.

Events include things like app start, session end, visitor spawned, and cat adopted. Each event carries:

  • Your random install ID
  • Event name and timestamp
  • App version, operating system, and build channel
  • A cryptographic attestation confirming the event came from the app
  • A daily-rotated hash of your IP address (used only for rate-limiting and abuse detection; never stored as a raw IP)

We keep events no longer than 90 days. Cloudflare Analytics Engine enforces this automatically and we do not re-ingest or archive to extend it. If this ever changes, we will update this page first.

Your IP address is seen by Cloudflare at the edge solely for rate-limiting and abuse detection within a single UTC day. We store only a daily-rotated hash. It cannot link your sessions across days, and we never write your raw IP to the analytics dataset.

Analytics data is processed by Cloudflare, Inc. (United States) via Cloudflare Analytics Engine. The transfer is covered by the Cloudflare Customer DPA, which provides contractual protections for cross-border data transfers as required by Australian Privacy Principle 8. See Cloudflare's sub-processor list for full details.

To stop analytics collection and delete your data: disable analytics in Settings, then email privacy@gak.dev. We will stop collecting your data within 7 days of your email. Existing events age out automatically within 90 days. EU users: we will confirm full deletion within 30 days of your request. California residents: we do not sell or share your personal information.

For full details on the analytics infrastructure, data pipeline, and retention, see the Gak Dev privacy policy.


This website

loafstead.gg is a static website hosted on Cloudflare. We do not set cookies or use tracking analytics on this website. Cloudflare collects standard server-side request logs (including IP addresses) as part of hosting; see Cloudflare's privacy policy.


Newsletter

The landing page has an email signup form for the Loafstead newsletter. Submitting the form sends your email address to Buttondown, a third-party newsletter service. Buttondown, Inc. is based in the United States.

Buttondown may track email opens and link clicks in newsletters they deliver on our behalf.

You can unsubscribe at any time using the link at the bottom of any email. To request deletion of your email address, contact us at hello@loafstead.gg.


Twitch integration (optional, streamers only)

If you are a streamer and you connect your Twitch account from the in-game menu, Loafstead stores your Twitch access token and refresh token in your operating system's secure keyring (macOS Keychain, Windows Credential Manager, or equivalent).

These tokens allow the game to listen to your chat channel for viewer commands such as !feed and !visitor.

  • What is stored locally: your access token and refresh token go in your OS secure keyring (macOS Keychain, Windows Credential Manager, or equivalent). Your Twitch login name (lowercase username) is stored in your save file so the in-game UI can show which account is connected.
  • Scopes requested: read-only chat access (chat:read) and, if needed for your channel type, a basic identity scope.
  • Viewer data: only the numeric sender ID of viewers who send recognised commands is processed transiently (held in memory for seconds to enforce rate limits). Display names, login names, and chat message bodies are never stored or transmitted by Loafstead.
  • Deletion: to remove your tokens and login name, disconnect your Twitch account from the in-game menu. Loafstead deletes the keyring entry and clears the login name from your save file immediately. You can also revoke the app's access directly in your Twitch account settings.
  • Third party: Twitch Interactive, Inc. (USA) is the OAuth provider. See Twitch's privacy notice.

Note: Twitch viewer-username display above visitor cats is a planned feature currently in development. This policy discloses that data category in advance.


Discord

The Loafstead community has a Discord server. Discord is a separate service operated by Discord Inc. Joining and using the Discord server is subject to Discord's privacy policy.


Feedback form

The feedback form at loafstead.gg/feedback/ lets you submit bug reports and suggestions. Submitting the form sends the following data to our Cloudflare Worker:

  • Your message and the feedback type you selected
  • Email address (optional, only if you choose to provide one)
  • App version and platform (optional; pre-filled if you open the form from inside the app, otherwise you can fill them in or leave them blank)
  • Your approximate country, derived from Cloudflare's network infrastructure (not from your IP address directly)
  • A random submission ID generated at the time of submission

Submissions are forwarded to a private Discord channel operated by Slowchop Studios. Discord, Inc. is based in the United States; see Discord's privacy policy for how they handle data on their platform.

The feedback form uses Cloudflare Turnstile to prevent automated spam. Turnstile verifies that the submission comes from a real person without using intrusive tracking. See Cloudflare's privacy policy.

Feedback data is used only to improve Loafstead. If you include your email, we may reply to follow up on your report. We do not add you to any mailing list. If you want your submission deleted, email hello@loafstead.gg with the approximate date and feedback type.


Children

Loafstead is not directed at children under 13. We do not knowingly collect personal information from children under 13. Children under 13 must not enable analytics or crash reporting.

If you are a parent or guardian and believe your child submitted a crash report or enabled analytics, contact us at privacy@gak.dev and we will delete it promptly.


Your rights

You can withdraw consent for crash reporting or analytics at any time in Settings. Withdrawing is as easy as granting it, and does not affect the lawfulness of any data already collected.

You can unsubscribe from the newsletter at any time using the link at the bottom of any email, or by contacting hello@loafstead.gg.

You can request access to, correction of, portability of, or deletion of your data by emailing privacy@gak.dev. For crash reports, we may need identifying details (such as a crash timestamp) to locate specific reports.

If you have a privacy concern we have not resolved, you can lodge a complaint with a data protection authority:

  • Australia: Office of the Australian Information Commissioner (OAIC), oaic.gov.au, enquiries@oaic.gov.au, 1300 363 992
  • UK: Information Commissioner's Office (ICO), ico.org.uk
  • EU/EEA: your national supervisory authority, edpb.europa.eu
  • South Korea: Personal Information Protection Commission (PIPC), pipc.go.kr
  • Brazil: Autoridade Nacional de Proteção de Dados (ANPD), gov.br/anpd

Drag the windows. Pet the cats.

Use arrow keys to move this window. Hold Shift to resize.