Downloads
Last updated 8 September 2026

Privacy Policy

Last updated 8 September 2026

This policy explains what Nucleus collects, why, and what happens to it. It is written to be read, not to be skimmed past.

The short version. We collect the minimum needed to run accounts, downloads, and payments. We have no analytics, no tracking pixels, and no advertising anywhere on this site. We do not sell, rent, trade, or share your personal data with anyone for their own purposes, ever. The only companies that touch it are the service providers who run the site on our behalf, named below.

1. Who we are

FirstGearGames, a registered trade name of a Wyoming limited liability company, is the data controller for the information described here.

Contact for any privacy question or request: FirstGearGames@gmail.com

2. What we collect, and why

2.1 Account information

When you create an account we collect your email address, any name you provide, and an account identifier. If you sign in with Google or Discord, we receive your email address and basic profile from that provider, never your password.

*Why:* to give you an account and let you sign in. *Lawful basis:* performance of a contract.

2.2 Agreement acceptance records

Nucleus is in closed beta under a confidentiality agreement. Each time you download a build, we record who accepted (your account identifier and email), which version of the agreement you were shown and a cryptographic hash of its exact text, which build was released to you, the date and time, your IP address, and your browser user agent.

*Why:* the agreement is accepted by clicking rather than by signature, so this record is the only proof that it was entered into. It also lets us trace an unauthorised copy back to the account it was released to. *Lawful basis:* legitimate interests, namely establishing that a contract was formed, and protecting confidential pre-release software from unauthorised distribution.

We consider this proportionate: it is a small amount of data, retained for a defined period, and there is no way to run a confidential beta without it. You can object to this processing (see Section 7), though we may then be unable to give you access to beta builds.

2.3 Purchases

If you buy something, our payment processor handles the transaction and we store the amount, currency, status, product, and the processor's reference identifiers, plus invoice records.

We never see or store your card number, CVC, or bank details. Those go directly to our payment processor and never touch our servers.

*Why:* to sell you a licence, provide receipts, and meet tax and accounting obligations. *Lawful basis:* performance of a contract, and legal obligation for the accounting records.

2.4 Discord (only if you choose to link)

If you link a Discord account, we store your Discord user id and username, and we check your membership and roles in our server so we can grant the right access. If you are part of a team plan, we store the Discord ids of members you add and the identifier of any private channel created for you.

*Why:* to give subscribers access to Discord channels and roles. *Lawful basis:* performance of a contract. Linking is entirely optional, and you can unlink at any time from your dashboard, which removes these identifiers.

2.5 Technical and server data

Our hosting provider keeps standard server and content-delivery logs, which include IP addresses and request details, for security and reliability.

*Why:* to keep the service running and defend against abuse. *Lawful basis:* legitimate interests.

2.6 Google user data, if you sign in with Google

Signing in with Google is optional. If you choose it, Google shares a limited set of information with us: your email address, basic profile information such as your name and profile picture, and a Google account identifier. We never receive your Google password, and we request no other Google scopes: no access to Gmail, Drive, Contacts, Calendar, or any other Google service.

We use that information for exactly one purpose: to create your Nucleus account and to sign you in. It is held by our authentication provider, and your email address and display name are stored in our database so the site can show your account and attach your purchases and downloads to it.

Specifically, regarding data received from Google:

Nucleus's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can withdraw our access at any time from your Google account's third-party access settings at myaccount.google.com/permissions. That stops future sign-ins; to also delete the data we already hold, email us and we will remove it, subject only to the retention limits in Section 6.

2.7 What we deliberately do not do

3. Cookies and local storage

We use only what is necessary:

There are no advertising or analytics cookies, which is why this site has no cookie banner: there is nothing non-essential to consent to.

4. Who your data reaches

We share data only with the service providers who operate the site for us, and only so far as they need it to do that job. Each is bound by contract to process it on our instructions.

ProviderWhat it handles
ClerkAccounts, sign-in, and authentication
SupabaseThe database holding the records described above
StripePayments, card processing, invoices
Amazon Web ServicesHosting and content delivery for this site
DiscordOnly the identifiers needed for role and channel access, and only if you link an account
GoogleOnly if you choose to sign in with Google

Beyond these, we disclose personal data only where we are legally required to by a valid court order or lawful request, or where it is necessary to establish, exercise, or defend a legal claim, such as enforcing the beta confidentiality agreement against someone who has breached it.

If the business is ever sold or merged, personal data may transfer to the buyer, who would remain bound by this policy or give you notice before changing it.

5. International transfers

Our providers are largely based in the United States, so your data may be transferred and processed there. Where data is transferred out of the UK, EEA, or Switzerland, that transfer relies on appropriate safeguards, typically the European Commission's Standard Contractual Clauses, or the provider's certification under the EU-US Data Privacy Framework. You can ask us for details of the safeguards that apply.

6. How long we keep it

DataRetention
Account informationWhile your account exists, then deleted on request
Agreement acceptance recordsFor the beta, and up to six years after it ends
Payment and invoice recordsSeven years, to meet tax and accounting obligations
Discord identifiersUntil you unlink, or your account is deleted
Server and delivery logsShort-term, per our hosting provider's standard retention

The six-year figure for acceptance records is deliberate: it covers the period in which a claim under the agreement could still be brought, which is the whole reason the record exists. Data protection law expressly allows retention where it is necessary to establish, exercise, or defend legal claims, and that is the basis we rely on if you ask us to erase a record while it is still within that window.

7. Your rights

If you are in the UK, EEA, or Switzerland, the GDPR gives you the rights to:

If you are in California or another US state with comparable law, you have similar rights to know, delete, correct, and opt out of sale or sharing. As Section 2.6 says, we do not sell or share personal data, so there is nothing to opt out of.

To exercise any of these, email FirstGearGames@gmail.com. We will respond within one month. We do not charge for this and we will not treat you differently for asking.

8. Security

Data is encrypted in transit. Access to the database is restricted to the application and to the operator of this site. Downloads are served over expiring, signed links rather than public URLs. Payment card details never reach our systems.

No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to put your rights at risk, we will notify the relevant authority within 72 hours and tell you directly where the law requires it.

9. Children

This site is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, email us and we will delete it.

10. Changes

If this policy changes materially, we will update the version and effective date at the top and, where the change matters to you, tell you by email. Continuing to use the site after a change means the current version applies.

11. Contact

FirstGearGames: FirstGearGames@gmail.com

For anything about this policy, a request about your data, or a complaint, that address reaches a person, not a queue.

Theme:
Nucleus Privacy Policy