Entropy Records Ltd · Leeds, United Kingdom

Privacy archive

A company-wide record of how Entropy Records Ltd handles personal data across entropyofficial.com, Entropy Engine, Entropy OS, KORUPT, embedded app surfaces, game features, and public forms.

Last updated
July 2026
Controller
Entropy Records Ltd

01

Contact and requests

For privacy questions, account support, data deletion, or data review requests, contact Entropy Records Ltd at contact.entropyrecords@gmail.com.

You can ask us to review the personal data connected to your account, explain how it is used, correct inaccurate information, export a copy where reasonably possible, delete account data, remove a public profile or leaderboard entry, or review a moderation or submission decision affecting your data.

We may need to verify that a request comes from the account owner or person connected to a submission. If something cannot be fully deleted for legal, security, fraud-prevention, or legitimate operational reasons, we will explain what remains and why.

02

Services covered

This archive covers entropyofficial.com, Entropy Engine, Entropy OS, KORUPT, embedded app surfaces, game features, public action forms, demos, events, and related interactive services operated by Entropy Records Ltd.

Entropy currently uses email and password login through Supabase. Google Sign-In is planned but is not active in the website code at the time this archive was last updated. If enabled, it will request only the basic permissions needed to sign in or connect an Entropy account, and Entropy's use and transfer of Google API data will comply with the Google API Services User Data Policy, including Limited Use requirements.

03

Information we collect

We collect only the information needed to run the site, provide account features, process public submissions, protect the service, and understand limited product performance.

Accounts and interactive features

  • Email address, authentication identifiers, and session or refresh tokens used to keep you signed in.
  • Profile username, optional avatar or cosmetic selections, XP, level, Entrobucks, inventory, rewards, quests, game scores, leaderboards, friends, and limited presence dates.
  • Chat or terminal messages where interactive chat is enabled.

Forms, events, and submissions

  • Demo submissions may include artist name, email, private track or SoundCloud URL, genre, BPM, mood, notes, status, and review information.
  • Event RSVPs may include email, name, event ID, source, RSVP status, and related event metadata.
  • MIDI challenges and campaign claims may include username, submission URL, notes, challenge or target ID, vote tokens, reward status, and related progress.

Security and technical data

  • Hashed rate-limit identifiers derived from request IP, email, username, session, or token values, where possible instead of raw keys.
  • Standard server logs and browser technical data processed by hosting, database, security, and infrastructure providers.

04

Purposes and legal bases

  • To create accounts, verify sessions, provide profiles, quests, cosmetics, inventory, friends, leaderboards, and game progress.
  • To process demos, RSVPs, challenges, event interest, campaign claims, and support requests you submit.
  • To prevent spam, abuse, duplicate votes, suspicious submissions, and security incidents.
  • To comply with legal duties and protect the rights, safety, and integrity of Entropy, artists, users, and the public.

We use the legal basis appropriate to the service: performance of a contract or steps requested by you for account features, compliance with legal obligations where applicable, consent where required, and legitimate interests for limited service operation and security where those interests are balanced against your rights. You may object to processing based on legitimate interests.

05

Cookies and local storage

Entropy uses cookies, local storage, and session storage where needed for login, embedded app sessions, game settings, progress, and the limited KORUPT product analytics described below.

  • Supabase Auth stores browser session data under keys such as entropy-auth-token so you can remain signed in.
  • Entropy may set an HTTP-only bridge cookie such as entropy-bridge-access-token so embedded app surfaces can recognise a signed-in session.
  • Preview and app features may store local IDs, settings, unlocks, high scores, daily progress, audio preferences, and temporary reload flags.
  • You can clear browser storage through browser settings. Doing so may sign you out or reset local-only preferences and progress.

06

KORUPT product analytics

KORUPT records limited first-party product-use events so Entropy can find broken steps, understand aggregate journeys through the sampler, and improve reliability. This is not used for advertising, cross-site tracking, individual marketing decisions, or account profiling.

Events may contain a fixed event name, the page pathname without query strings or fragments, allow-listed campaign labels, device class, KORUPT world, entry type, and fixed technical or export outcomes. Raw events use short-lived random visit and share references. They do not include your email, account information, licence data, stored IP address, full browser fingerprint, audio, or full recipe.

We turn raw KORUPT events into daily aggregate statistics and remove the raw events, typically within 24 hours. Daily statistics are kept for up to 24 months and contain no visit or share identifiers. Named breakdowns are retained only when at least five visits contribute.

Product analytics are on unless you object. You can turn off analytics or turn them on again at any time using the permanent KORUPT product analytics control beneath the sampler journal. The choice applies to that browser profile and sampler origin. Turning analytics off does not reduce access to KORUPT.

Entropy relies on the PECR statistical-purpose exception for this limited first-party storage and access. Where the raw event is personal data, Entropy relies on its legitimate interests in diagnosing and improving KORUPT, balanced against the short retention, data minimisation, and your immediate right to object.

07

Processors and sharing

We do not sell personal data. We share data only where needed to run Entropy services, process submissions, protect users, or comply with legal obligations.

  • Supabase: authentication, database, storage, and related backend services, including the service-only KORUPT analytics lifecycle.
  • Render and Vercel: hosting, deployment, and technical delivery for Entropy services; they process technical data required to run those services.
  • Framer: public website hosting and presentation; it may process technical data required to deliver the public site.
  • Google services: only where Google Sign-In is enabled in future or Google-hosted media is embedded or played. Entropy does not add Google-hosted fonts to this archive.
  • Artists, staff, and collaborators: may review demos, RSVPs, challenge entries, or support requests where needed for label operations.
  • Public features and legal/safety reasons: content designed to be public may be visible to other users; we may disclose information where required by law, to prevent abuse, protect security, or defend legal rights.

08

Retention schedule

  • Account data is retained while an account is active or needed to provide features, resolve disputes, protect security, or comply with legal duties.
  • Demo submissions, RSVPs, challenges, and campaign records are retained for label operations, event planning, artist review, moderation, audit, and legitimate business records.
  • Chat may be short-lived where cleanup is enabled; gameplay, transaction, leaderboard, moderation, rate-limit, and security records may remain as needed for integrity, abuse prevention, or investigation.
  • KORUPT raw events are typically removed within 24 hours after aggregation. Daily KORUPT aggregate statistics are kept for up to 24 months.

09

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You can ask us to review your data, explain how it is used, and review decisions or public entries affecting your account or submissions.

Send contact, deletion, and review requests to contact.entropyrecords@gmail.com. We will respond as soon as reasonably possible and may ask for information needed to verify your identity or locate your account.

10

Security

We use reasonable technical and organisational measures to protect personal data, including HTTPS in production, managed authentication, access controls, row-level database permissions where applicable, server-side validation, rate limiting, and HTTP-only cookies for bridge sessions where possible.

No internet service can guarantee perfect security. If you believe your account or data has been exposed, contact us immediately at contact.entropyrecords@gmail.com.

11

Children

Entropy services are not intended for children under 13. If you are in the United Kingdom or European Economic Area and are below the age at which you can legally consent to online services, use Entropy only with permission from a parent or guardian. If we learn that we have collected personal data from a child without appropriate consent, we will take reasonable steps to delete it.

12

Changes

We may update this privacy archive when Entropy features, login methods, data practices, or legal requirements change. If we make material changes to how Google user data or other personal data is used, we will update this page and, where required, ask for consent before using data in the new way.

This page is intended to be available at https://www.entropyofficial.com/privacy.html and should match the Privacy Policy URL used in any Google OAuth consent screen for Entropy.

Entropy Records Ltd · Privacy archive · July 2026
Entropy Logo