Sanctuary Brief
Privacy Policy
Last updated: September 14, 2026
Sanctuary Brief is an unofficial fan project at sanctuarybrief.com. It is not affiliated with, sponsored by, or endorsed by 37GAMES or the creators of Puzzles & Survival. This policy explains the limited information the site handles when you use its decision tools.
Aggregate analytics
Sanctuary Brief uses Google Analytics 4 on public pages to understand aggregate page use only after you choose Allow analytics
. Before sending a page view, the site removes query strings and URL fragments from the page URL and sends only the referring site's origin, never its path, query, or fragment. The integration does not add form values, recruitment profile fields, user IDs, screenshots, or other custom player data to analytics. It does not load for signed-in users, previews, search results, or recruitment short-link pages, and the browser tag does not load when Global Privacy Control or Do Not Track is enabled.
Google signals, enhanced measurement, user-provided data collection, granular location and device collection, and advertising personalization are disabled. Analytics user and event data retention is set to two months without resetting on new activity. After consent, the site configures a non-renewing first-party analytics cookie with a maximum lifetime of 60 days. Google receives standard connection and device information as part of an analytics request and processes it under Google's business data responsibility terms. Google states that Google Analytics does not log or store individual IP addresses.
Sanctuary Oracle questions
When you ask the Sanctuary Oracle a question, your question, the conversation context, and the generated answer are processed by DocsBot so the Oracle can respond. DocsBot states that it stores sources, questions, answers, and chat history, passes this information through OpenAI APIs, and may allow authorized staff to review it for support, quality control, and enforcement. Standard connection information may also be processed. Do not enter legal names, contact details, account credentials, private messages, payment information, or other personal or sensitive information. See the DocsBot privacy policy for its current practices.
Screenshot-assisted entry
Screenshot entry is optional. If you choose it and press the clearly labeled scan button, the prepared image is sent to OpenAI for one recognition request. Sanctuary Brief does not save the screenshot or the extracted board or mission on its server. Review the extracted values before using them, and avoid screenshots containing messages, account details, purchases, or anything outside the relevant game screen. OpenAI processes the image under the data controls for the site owner's API project. Manual entry remains available.
Recruitment profiles
If you create a recruitment profile, Sanctuary Brief stores the visible self-reported profile, a random public identifier, a hashed private update/deletion secret, moderation and aggregate report information, and lifecycle dates. Recruiting details need confirmation after 30 days and are excluded from future active matching while stale. The public link remains available so its owner can update or delete it with the separate private management link. Unattended profiles are deleted 180 days after their last confirmation.
Do not include game passwords, legal names, precise real-world locations, sensitive demographics, private messages, or other information you do not intend to make public.
Tool feedback and resource suggestions
When you choose to rate a tool, Sanctuary Brief stores the tool and version, rating and selected reasons, optional written feedback or correction details, and a small allowlisted set of non-sensitive operating context. It does not automatically include profile answers, board layouts, names, contact details, screenshots, raw IP addresses, or user-agent strings. A temporary one-way connection hash is used only to limit automated submissions. Feedback is private to site administrators and is automatically deleted after 18 months.
When you suggest a guide or video, Sanctuary Brief stores the URL, your explanation, and the current tool and mission for private editorial review. Suggestions never publish automatically, and unapproved suggestions are removed after 18 months. Helpful or outdated signals use a random browser identifier transformed into a one-way site-specific hash. Raw IP addresses and the browser identifier are not stored in resource records; signal hashes are removed after 24 months.
Alliance Command Center scheduling pilot
If you request a private-beta invitation, the commander name, role, email, alliance name and tag, alliance state number and time zone, and optional note you submit are emailed to commander@sanctuarybrief.com for human review. Sending a request does not create an account, alliance, membership, or invitation. The request is not stored in the Command Center database; the email and reply history may remain in the support mailbox as needed to review the pilot and respond to you.
You can create a Sanctuary Brief account using an account username, commander display name, email address and password. WordPress stores the password using its one-way password hashing. Sanctuary Brief sends a time-limited account-confirmation link to the address you provide and stores only a one-way hash of that link while it is valid. It also records the account-rules version and acceptance time. Unconfirmed accounts are deleted after seven days. Your account email is not enrollment in event alerts and is never shown to an alliance leader or member.
Your private My Sanctuary profile can also store a preferred time zone, optional player state, an optional birthday month and day, and—only when you separately request SMS alerts—an optional mobile number. No birth year is requested. A mobile number is normalized, encrypted before it is written to your WordPress profile, and shown back to you only by its last four digits. Sanctuary Brief also stores a one-way lookup hash, the consent wording version, the time and source of your choice, and whether the number is awaiting verification, active, or withdrawn.
Birthday information is reserved for a future opt-in birthday feature and is not shown publicly. Mobile numbers are never shown to alliance leaders, officers, other members, or the public. Profile information is reused only in Sanctuary Brief experiences where it saves you from entering the same relevant details again; you can review the information before it is submitted or published in another feature.
The Command Center stores the alliance name, tag, alliance state number, public routing code and primary time zone; your alliance role, optional event team and time zone; event titles, control type, clock ownership, times, audience and short game-related notes; voluntary Going, Maybe or Cannot attend responses; and a limited audit history of schedule and access changes. It never collects a game login. A temporary one-way connection hash limits automated account and confirmation requests.
Alliance members see the schedule permitted for their team and aggregate availability counts. A public alliance code can join an authenticated account to a schedule but cannot grant leader or officer authority. If you create a private calendar link, the full random link is shown once and only a one-way hash plus its last four characters is stored. Anyone who obtains that link can read the schedule permitted to that membership until you replace the link, revoke it or leave the alliance.
Past event and availability records are removed after 90 days, and audit records are removed after 365 days. A non-owner can leave an alliance schedule to delete that membership, its availability and its calendar access immediately. An owner can archive the alliance to delete its operational schedule, availability, memberships and calendar access immediately; the minimal archived alliance record is removed after 90 days.
Community Field Guide contributions
Email-confirmed members can submit a game-related Pro Tip with an exact subject, tip type, text, and the date it was last checked in the game. If the subject is missing from the catalog, the submission may include a short proposed subject name for moderator review. Sanctuary Brief stores the author’s account ID and displays the author’s commander name if a moderator approves the tip. Pending and rejected tips are available only to administrators. Report details are also private to administrators; an approved tip remains visible until a moderator changes its status. Unapproved tips are removed after 18 months if they remain unattended.
Signed-in members can cast one changeable Helpful or Not helpful vote per tip, report a tip as outdated, incorrect, unsafe, or otherwise concerning, and hide another contributor from their own Field Guide. Votes, reports, and blocks are tied to account IDs so the controls cannot be multiplied anonymously. Reports are kept separate from helpfulness ranking and reviewed by a human; resolved reports are removed after 18 months. Community popularity never turns a tip into a confirmed gameplay rule.
Tip authors can edit a tip, which returns it to moderation, or permanently delete it with its votes and reports. Administrators can approve, return for review, reject, or permanently delete a contribution. Do not include private messages, contact details, account credentials, or personal information about another player.
Alliance event alerts
Private-beta accounts may voluntarily provide a mobile number and separately request recurring automated game-related alliance event alerts. SMS consent is optional and is not required to create an account. Saving a number places the request in pending verification; recurring texts do not begin until Sanctuary Brief verifies that you control the number and you complete the alliance alert choices. Sanctuary Brief processes the phone number you personally provide, your alliance selection, time zone, event and reminder preferences, subscription status, and records showing what consent language you saw, when and how you responded, and when you changed or withdrew that consent. Delivery providers may also return message identifiers, timestamps, delivery status, error information, and standard connection information needed to deliver and protect the service.
Text messages will be delivered through Twilio, which will process mobile numbers, message content, consent and opt-out signals, and delivery information under Twilio's privacy terms. Future email alerts may use a separately identified email provider. Sanctuary Brief will disclose that provider before email enrollment becomes available. An alliance leader will control event schedules, not member phone numbers or email addresses. Leaders may not upload a roster or consent for members; every recipient must enroll directly.
Mobile information, email addresses, opt-in records, and consent will not be sold, rented, or shared with third parties for their own marketing or promotional purposes. They may be shared with service providers that operate the alert program under Sanctuary Brief's instructions and when required for security or law. Contact details and preferences will be kept while a subscription is active. After an unsubscribe or deletion request, Sanctuary Brief may retain the minimum consent, suppression, security, and delivery records needed to prove the request and keep the opt-out honored.
Support requests
If you email Sanctuary Brief, the message, your email address, attachments, and related reply history are used to answer the request, investigate abuse, and protect the service. Do not send game passwords, verification codes, payment-card information, legal identification, private messages, or full player rosters. For game-account, purchase, or missing-item problems, use the customer-service route inside Puzzles & Survival.
Your choices
You can use manual entry instead of sending a screenshot. You can allow, decline, or later revoke analytics from the Analytics choices
control in the site footer. The choice is stored only in your browser. Revoking removes Sanctuary Brief's first-party Google Analytics cookies and prevents new analytics events; clearing site data also removes the stored choice. Global Privacy Control or Do Not Track prevents the analytics tag from loading regardless of the stored choice.
Recruitment-profile owners can use their private management link to update or delete a stored profile. Do not share that private link. Signed-in members can update their private My Sanctuary profile, remove a saved mobile number and withdraw a pending SMS request, and permanently delete their own Pro Tips. Command Center members can reset their password through WordPress, replace or revoke a calendar link, and leave an alliance schedule; alliance owners can archive their pilot. To request deletion of the underlying Sanctuary Brief account or review blocked contributors, use the Support page. Deleting an account also removes its authored Pro Tips, votes, reports, and block relationships. Event-alert subscribers can change preferences from the alert controls and reply STOP to end all texts from the shared alert number. Some information may be retained when required to honor an opt-out or for security, legal, or administrative reasons.
Changes to this policy
This policy will be updated when the site's data practices materially change. The date at the top identifies the latest revision.