this notice applies only to Aeon Arena's authenticated V3 pre-access waiting room and release updates. broader V3 is not publicly available through this flow.
what this flow does
you choose email link, Google, or Apple to verify one identity through Firebase Authentication. verification may create a new Firebase Auth credential and UID or reuse an existing UID.
after verification, you separately confirm whether you want V3 pre-access and release updates. confirmation creates no V3 actor, handle, Profile, Mark, Record, Season entry, competition identity, access grant, gameplay access, or Prize entry.
information we process
Firebase Authentication processes the sign-in credential, verified email address, provider, and UID. Aeon stores only the waiting-room information needed to operate this request: an encrypted email address; keyed, non-reversible lookup digests for the email and UID; provider identifier; consent purpose, version, source, and timestamp; confirmation and retention timestamps; minimized delivery state; and security or rate-control records.
we use minimized source attribution only to understand how the request reached us. it cannot change access, priority, reward, or visible status. aggregate monitoring contains counts rather than raw email addresses or UIDs.
purpose and legal choice
we use this information only to verify the request, prevent abuse, send and record the separate confirmation, provide V3 pre-access and release updates after confirmation, support deletion, and operate aggregate security and reliability monitoring.
confirmation is optional. if you do not confirm, the pending request expires automatically. ignoring a message does not create a confirmed request.
service providers and storage
Google Firebase Authentication verifies credentials. Aeon's authenticated server stores minimized waiting-room records only in the named aeon-v3-prod Firestore database; browsers and native clients receive no direct Firestore access. Resend processes the destination address and delivery metadata needed to send the separate confirmation message.
we do not sell waiting-room personal information. we do not use it for queue position, personal referral rewards, competition scoring, public profiles, or gameplay identity.
retention
an unconfirmed pending request expires after 14 days. a confirmed request expires after 180 days unless you renew consent. short-lived security and rate-control records expire under their operating window. deletion and administrator retention actions produce minimized audit evidence without publishing personal data.
delete or get help
to delete a waiting-room request, return to the pre-access identity page, verify the same Firebase identity, and choose delete my pre-access request. this removes the waiting-room record; it does not merge identities or silently delete the underlying Firebase sign-in credential.
for help, email support@aeonarena.com. do not send passwords, sign-in links, or confirmation tokens.
security and changes
we use encryption, keyed lookup digests, server-only storage, access controls, rate limits, independent switches, and audit evidence to reduce risk. no online system can be guaranteed completely secure.
if this notice or its purpose changes, the waiting room must present the new fixed version for review and consent; a rolling or silently changed date is not consent.