Last updated August 1, 2019

1. Introduction

If you are here, you have reached us by visiting http://www.citadelstudios.net/, https://www.legendsofaria.com/, or one of the other websites owned and operated by Citadel Studios (the “Site”), or by registering or installing any of Citadel Studios’ game offerings (the “Game” or “Games”), or by using any of our other online or offline services (collectively, the “Services”). Citadel Studios (“Citadel”) is committed to protecting your privacy. This privacy policy explains our collection, use, disclosure, retention, and protection of your personal information, as well as your rights to your data under US and International Law, including but not limited to EU Directive 2002/58/EC and the EU General Data Protection Regulation (“GDPR”), the Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003 (“CAN-SPAM”), and the US Children’s Online Privacy Protection Act (“COPPA”). This Privacy Policy does not apply to any third-party websites, services or applications, even if they are accessible through our Services. We may refer to Citadel Studios herein as “Citadel”, “we” or “us”. Also, please note that, unless we define a term in this Privacy Policy, all capitalized terms used in this Privacy Policy have the same meanings as in our Terms of Service. So, please make sure that you have read and understand our Terms of Service. Where we are required to identify a data controller pursuant to regulation, Citadel is the designated controller of the data we collect.


This Privacy Policy describes:


  • The information we collect, how we collect such information and the purposes of our collection;
  • How we use and with whom we share such information;
  • How you can access and update your information; and
  • How we protect the information we store about you.

2. Information We Collect

When you interact with our Services, we may collect and store information from you directly as described below:


2.1 Registration Information

You must purchase a valid copy of the Game and create a user account through our website before you can play or access Legends of Aria (your “Account”). Your Account grants you access to player tracking and multiplayer features available in our Game, and may be used to publicly identify you as part of the social features of the Services. These may include but are not limited to user-to-user interaction, game forums, chat or messaging functionality, competitive or cooperative gameplay and matchmaking, and other similar features.


We may also offer you the option to complete a user profile or provide information in a player dashboard or on our forums, accessible and editable only by you, and that may be viewable to other end users. Your user profile may include your Citadel username and/or in game handle, biographical details that you voluntarily provide, details about the Games you play, and a Citadel user ID number that is created by Citadel and used to identify your profile.


Your username will be public and will be shown to other users, but will only permit access to information that is considered public or that you have designated as public in your user profile settings. The information you include in your profile is optional, and we advise you to limit the information you share through this feature if you have concerns about your privacy.


Your Account will be used to identify your transactions and payment history, player sessions and player ratings or rankings, individual user settings and customized characters, in-game currency, and other in game features that we may make available from time to time. We discourage you from sharing your Account information or password with anyone, and we will never request such information in order to provide Services to you.


2.2 Payment Information

When you order any good or service through the Game, including any virtual currency or virtual good, the purchase will be made directly through our payment, currency, and account solutions provider BrainTree, who may collect relevant information in connection with such purchase. Please review the terms and conditions and privacy policies of the third party marketplace through which you accessed the Game for more information. In addition, each time you make a purchase, we will collect information relating to that in-app purchase, including but not limited to player ID, device ID, session ID, your current available currency, the USD value of the currency, an other information related to the transaction. Our payment processing service provider may also retain this information to enable you to purchase additional items through our Game without having to re-enter it each time. Please note that purchases from third parties may also be subject to additional policies.


2.3 Information Collected by Customer Support

When you ask for assistance from our Customer Support team, we will collect and store the contact information you provide (generally your name and email address), information about your game play or activity on the Games, and your user name or account ID. We will also store the correspondence and any information contained within.


2.4 Technical and Usage Information

When you access our Services, we may collect (i) certain technical information about your gaming device, mobile device, or computer system, including IP Address, device ID (IDFA, Google Advertising ID or other identifiers), anonymized Player and Account ID, session ID, marketplace purchases, transaction history and currency information, game play and player information, and the current version of your operating system; and (ii) usage statistics about your interactions with the Games. In certain Games we will create and assign to your device an identifier that is similar to an account number. We may collect the name you have associated with your device, device type, country, and any other information you choose to provide, such as user name, character name, or email address. This information is typically collected through the use of third-party software development kits.


2.5 Location Information

We rely on Google Analytics to acquire certain player data, which includes information about the territory or region from which you access the Game by converting your IP address into a rough geo-location. We may use location information to improve and personalize our Services for you. To learn more, please review Google’s privacy policy for user data collected through Google Analytics.


3. How We Collect Your Information

We may collect information about you in any one or more of the following ways:


3.1 Communications Features

You may be able to take part in certain activities through our Services that give you the opportunity to communicate or share information not just with Citadel, but also with other users of our Services. These include:

  • Participating in player forums and message boards;
  • Posting public comments to other users’ profiles or gameboards;
  • Sending private messages or invitations to other users, either directly through the Games or to their email accounts;
  • Sharing user generated content or photos, if such feature is made available; and
  • Chating with other users

We may use, record and store archives of these communications on Citadel’s servers to protect the safety and well being of our users and Citadel’s rights and property in connection with the Services.


3.2 Cookies and Automated Information Collection

When you access our Services, we collect certain technical information in order to (i) analyze the usage of our Services; (ii) provide a more personalized experience; and (iii) manage advertising. We and service providers acting on our behalf may use Log Files and tracking technologies to collect and analyze certain types of technical information, including Cookies, Flash Cookies, and Web Beacons.


“Log Files” means certain information about how a person uses our Services, including both registered and unregistered users (either, a “User”). Log Files may include information such as a User’s Internet Protocol (IP) addresses, device name, user language, time played, platform type, number of page clicks, player skill levels, player history, pvp sessions and rankings, Game state and the date and time of activity on our Site or the Games, webpage interactions and pages viewed, and other similar information. In some cases, we will associate this information with your Account ID number for our internal use.


“Cookies” are small text files that are placed on your device by a web server when you access our Services. We may use both session Cookies and persistent Cookies to identify that you’ve logged in to the Services and to tell us how and when you interact with our Services. We may also use Cookies to monitor aggregate usage and web traffic routing on our Services and to customize and improve our Services. Unlike persistent Cookies, session Cookies are deleted when you log off from the Services and close your browser. Although most browsers automatically accept Cookies, you can change your browser options to stop automatically accepting Cookies or to prompt you before accepting Cookies. Please note, however, that if you don’t accept Cookies, you may not be able to access all portions or features of the Services. Some third-party services providers that we engage (including third-party advertisers) may also place their own Cookies on your device. Note that this Privacy Policy covers only our use of Cookies and does not include the use of Cookies by such third parties.


”Web Beacons” (also known as web bugs, pixel tags or clear GIFs) are tiny graphics with a unique identifier that may be included on our Services for several purposes, including to deliver or communicate with Cookies, to know if a certain page was visited or whether an email was opened,to advertise more efficiently by excluding our current users from certain promotional messages, to identify the source of a new installation, to delivering ads to you on other websites. Unlike Cookies, which are stored on the device, Web Beacons are typically embedded invisibly on web pages (or in an email).


“Flash Cookies” are local shared objects, which help us to prevent fraud, remember your in-Game preferences and speed up load times.


Please note that companies delivering advertisements in the Games or on our Site may also use cookies or other technologies, and those practices are subject to their own policies.


3.3 Other Sources

We may collect or receive information from other sources including (i) other Citadel users who choose to upload their email contacts, and (ii) third party information providers. We do not condition participation in our Services on you providing more personal information than is reasonably necessary for that activity.


4. How We Use the Information We Collect

In general, we collect, store and use your information to provide you with a customized experience. For example, we may use information collected from you in any one or more of the following ways:

We use your personal information to fulfill a contract with you and provide you with our Services, to comply with our legal obligation, protect your vital interest, or as may be required for the public good. This includes:


  • To create Accounts and allow play of the Games;
  • To facilitate in-app purchases;
  • To enable user-to-user communications;
  • To provide technical support and respond to user inquiries;
  • To prevent, detect, mitigate, and investigate fraud or potentially illegal activities, and enforce our Terms of Service;
  • To provide other services requested by you as described when we collect your information;
  • To notify users of in-Game updates, or updates to our Terms of Service or this Privacy Policy; and
  • To provide in-Game leader boards and to promote in-Game player achievements.

We use your personal information to pursue our legitimate interests where your rights and freedoms do not outweigh these interests. We have implemented controls to balance our interests with your rights. This includes:


  • To track user retention and aggregated gameplay information to improve the overall user experience for Citadel’s products and services;
  • To solicit input and feedback to improve Citadel’s products and services and customize your user experience;
  • To use general location information to provide you with location based services (such as matchmaking, search results, and other personalized content);
  • To contact you with information that we reasonably believe may be relevant to you; and

With your consent, we or our authorized third parties may use your personal information:


  • To inform users about new products or promotional offers;
  • To provide personalized and targeted advertising through our third party advertising partners

If you have provided your email address to us, we may use it to respond to (i) customer support inquiries, and (ii) keep you informed of your in-Game activity, including comments from friends and notifications about in-Game status. With your consent, we may also send promotional email messages (“Promotional Communications”) directly or in partnership with parties other than Citadel. Each Promotional Communication will generally offer recipients choices about withdrawing consent so you no longer receive additional messages.


5. Sharing of Your Information

We may share your information (in some cases personal information) with third parties in the following circumstances:


5.1 Third Party Service Providers and Third Party Products and Services

We will provide your information to third party companies to perform certain services, including but not limited to payment processing, data analysis, email delivery, hosting services, customer service and to assist us in our marketing efforts. We direct all such third party service providers to maintain the confidentiality of the information disclosed to them and to not use your information for any purpose other than to provide services on Citadel’s behalf.


We do not routinely share personal information with third parties except as may be necessary to provide Services to you. We may share (i) aggregated information (information about you and other users collectively, but not specifically identifiable to you); (ii) anonymous information; (iii) certain technical information (including IP Addresses and device or player IDs) to develop and deliver Services to you, including payment solutions; (iv) personally identifiable information, including first and last name, payment information, address, phone number, identity verification, credit card number, and other personal information as may be necessary to provide such Services.


We may also allow third parties to collect these types of information within the Games and they may share it with us. Advertisers may collect this information through the use of tracking technologies like browser cookies and web beacons.


We may disclose aggregated and anonymous information to describe the Services to prospective partners, advertisers, and other third parties, and for other lawful purposes. We may use aggregate, non-personally identifiable information for our own internal promotion or marketing purposes and we may share such aggregate non-personally identifiable information with others for marketing purposes.


In certain instances, you may need to opt in or opt out of advertising directly through our partners.


You may view a complete list of our third party service providers with links to their respective privacy policies here.


5.2 Friends and Other Players

In many Games, friends and other players will be able to see your Game profile, which may include your name or a “game name” and your profile photo, which in certain cases can reveal your Account ID. Access to an Account ID may allow others to view the public information associated with your related Citadel account. This information may also be shared with friends you invite to play when you participate in our Referral Program.


5.3 Safety, Security and Compliance with Law

Your information may be disclosed: (i) when we have a good faith belief that we are required to disclose the information in response to legal process (for example, a court order, search warrant or subpoena); (ii) to satisfy any applicable laws or regulations; (iii) where we believe that the Games are being used in the commission of a crime, including to report such criminal activity or to exchange information with other companies and organizations for the purposes of fraud protection and credit risk reduction; (iv) when we have a good faith belief that there is an emergency that poses a threat to the health and/or safety of you, another person or the public generally; and (v) in order to protect the rights or property of Citadel, including to enforce our Terms of Service.


5.4 Sale or Merger

In the event that Citadel undergoes a business transition, such as a merger, acquisition by another company, change of control, or sale of all or a portion of its assets, we may transfer all of your information, including personal information, to the successor organization in such transition.


6. Our Policies Concerning Children

Our Services are intended for a general audience and are not intended for Children. We do not knowingly collect personal information from users deemed to be children under their respective national laws. If we learn that we have collected PII of any child we will take steps to delete such information from our files as soon as possible. We urge parents to instruct their children to never give out their real names, addresses or phone numbers without permission. We recognize a special obligation to protect personal information obtained from young children.

Should you wish to have your child’s personal information deleted from our records, please contact us at [email protected]. We will be happy to remove your child’s information as appropriate.


7. How to Control Your Information

Under the EU General Data Protection Regulation, individuals residing in the EU and other territories that have adopted GDPR compliance or comparable regulation have a right to:


  • Access your user data
  • Correct the data you have provided to us
  • Have information provided to you in a portable format
  • Request the deletion of the data we have collected
  • Restrict processing
  • Object to processing or the legal basis on which we rely to process your data

You may send an email to [email protected] with your request to exercise any of the rights identified above. Place the reason for your request (e.g. “Delete my Data” or “Correct my Data”) in the subject line and include your first name, last name, and email address in the body of the email. We will respond to your request within thirty (30) days. Please note that certain records, for example those pertaining to payments or customer service matters, will be retained for legal and accounting purposes. If you have sent or posted content through the Services, we may not be able to delete it. Accounts created with Citadel are considered active until we receive a user request to delete them or deactivate them. Any request to deactivate or delete an account will not automatically result in information deletion unless so requested by the End User, and only to the extent we are not required to retain such data to satisfy our legal obligations.


Please note that requests to restrict processing or delete your data may require the termination of your user account if we require the information subject to the deletion request to maintain your user account or otherwise provide gameplay services to you.


We are unable to delete data controlled solely by third parties; for example, if you purchase our Game through Steam, we won’t be able to delete your Game from your Steam library, nor the data collected by Valve in connected with your purchase or your Valve account. Similarly, if you access any of our Services through third party social media or service platforms, such as Discord, or if you are routed to a third party service provider’s web page through our Services, you will need to make any deletion requests to those respective third parties separately.


8. Opt Out Options

8.1 Opting out of Promotional Communications

You can choose to opt out of receiving promotional emails and product updates from Citadel by clicking on the “unsubscribe” link in any such e-mail, or by opting out of such communications in your Game or Account preferences. Please note that once we receive your request, it may take an additional period of time for your opt-out to become effective. Your unsubscribe or e-mail preference change will be processed promptly, usually within 10 business days.


8.2 Opt Out Limitations

Please note that if you opt-out of our Promotional Communications or other forms of communication, we may still e-mail or communicate with you from time to time if we need to: provide you with information and updates concerning this Privacy Policy or our Terms of Service, respond to a customer support or technical support inquiry, notify you of changes to your account (including suspension or deactivation), respond to any customer service or technical support inquiry, request information from you with respect to a transaction initiated by you, or for other legitimate non-marketing reasons.


9. Security of Your Information

Accessing your account or any personally identifiable information stored through your account is password protected and requires two-step authentication using OTP when first accessing our Services through any new computer or device, or when cookies are disabled. It is important that you protect and maintain the security of your Account and that you immediately notify us of any unauthorized use of your Account. We encrypt the transmission of all information using secure socket layer technology (“SSL”).


We further encrypt all data we store or share, and each transfer of data is tokenized and signed with a secret. However, while we take reasonable precautions against possible security breaches of our Services, no website or Internet transmission is completely secure, and we cannot guarantee that unauthorized access, hacking, data loss, or other breaches will never occur. Although we strive to protect your personal data, we cannot guarantee the security of your data while it is being transmitted through our Services; any transmission is at your own risk. Once we have received your information, we have procedures and security features in place to try to prevent unauthorized access.


10. Changes to Our Privacy Policy

Any information that is collected via our Services is covered by the Privacy Policy in effect at the time such information is collected. If we decide to make material changes to our Privacy Policy, we will notify you and other users by placing a notice on Citadelstudios.com or by sending you a notice to the email address we have on file for you, and we’ll update the “Last Updated Date” above to indicate when those changes will become effective. We may supplement this process by placing notices in the Games and on the Site. You should periodically check www.citadelstudios.com and this privacy page for updates.


11. Sharing Your Information for Direct Marketing Purposes

We do not share personal information with third parties for their direct marketing purposes unless you affirmatively agree to such disclosure, typically by “opting in” to receive targeted advertising from a third party (such as Facebook or Twitter) through our Services. If you do ask us to share your personal information with a third party for its marketing purposes, we will only share information in connection with that specific promotion, as we do not share information with any third party (other than our service providers) on a continual basis. To prevent disclosure of your personal information for use in direct marketing by a third party, do not opt in to such use when you provide personal information through our Services.


12. Links to Other Sites

Our Services may contain links to websites and services that are owned or operated by third parties (each, a “Third-party Service”). Any information that you provide on or to a Third-party Service or that is collected by a Third-party Service is provided directly to the owner or operator of the Third-party Service and is subject to the owner’s or operator’s privacy policy. We’re not responsible for the content, privacy or security practices and policies of any Third-party Service. To protect your information we recommend that you carefully review the privacy policies of all Third-party Services that you access.


13. California Residents: Responding to Do Not Track Signals

In September 2013, California enacted amendments to the California Online Privacy Protection Act (California Business & Professions Code §§22575-22579) which require operators of websites to disclose how they respond to “do not track” (DNT) signals from browsers used by consumers or other mechanisms that provide consumers a choice regarding the collection of personally identifiable information about the consumer’s online activities over time and across different websites or online services. While some newer browsers have incorporated “Do Not Track” features which, when turned on, send a signal or preference to the web sites you visit indicating that you do not wish your online activity to be tracked, a DNT protocol that can be implemented across multiple devices and sites has not yet been widely adopted. Currently, our computer system does not support, and cannot act on DNT signal headers that we may receive; accordingly, the choices that we provide you concerning out collection and use of personally identifiable information will continue to operate as described in this policy.


14. International Transfer

Your personal information may be transferred to, and maintained on, computers located outside of your state, province, country or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. If you’re located outside the United States and choose to provide your personal information to us, we may transfer your personal information to the United States and process it there.


15. Contact Us

If you have any questions, comments or concerns regarding our Privacy Policy and/or practices, please send an email to [email protected].


Citadel Studios
10900 University Blvd
Katherine G Johnson Hall 147, MS 1J2
Manassas, Virginia, USA 20109
(571) 535-3741