Last updated: 11.07.2026
This website (sunshine-remastered.ch) is operated by the Sunshine Remastered team as a private, non-commercial Metin2 project. You can reach us through our Discord server (link at the bottom). This policy explains which personal data we process when you visit the site and when you use the Discord login and game accounts. Because the domain runs on .ch and we also have visitors from the EU, we follow both the Swiss Data Protection Act (DSG) and the EU General Data Protection Regulation (GDPR) and aim to comply with their requirements.
Accounts here are created exclusively through Discord. At login we request only the identify scope from Discord. That gives us your Discord ID, your (display) username and – if you have one – your avatar. We store these in your session and link them to your game accounts. We explicitly do not request or receive an e-mail address via Discord. We do not read messages, friend lists or your list of servers. The only further query concerns the alpha check (see point 6).
When you create a game account, you choose a login name (4–16 lowercase letters/digits) and a password yourself. The password is never stored in plaintext: we keep only hashes – a bcrypt hash (cost factor 12) plus the legacy hash required by the Metin2 game core. Neither the team nor any third party can read your password. In addition, a one-time, seven-digit deletion code is generated and shown to you exactly once; you need it to delete characters. All game accounts (up to three) are linked to you via your Discord ID. Characters, playtime, coins, etc. are only created once you play. The game database’s "e-mail" field holds only a technical placeholder of the form discord:<your-ID> and no real e-mail address.
We use as few cookies as possible:
PHPSESSID) that keeps you logged in during your visit. It expires at the end of the session and is set with the Secure, HttpOnly and SameSite=Lax flags.remember) that is set only if you explicitly consent in the cookie banner. It consists of a selector/validator pair; our database stores only the SHA-256 hash of the validator. The token is bound to your IP address and a hash of your browser (user agent), expires after 30 days and is rotated on every use. If the IP or browser does not match, the token is deleted immediately – so a stolen cookie cannot be reused elsewhere.lang) and your cookie decision (cookie cookieconsent).We use no tracking, no advertising and no third-party cookies or scripts – no analytics tools, no ad networks, no tracking pixels.
Your IP address is processed only transiently and for security purposes: for rate limiting / abuse defense (short-lived counters in volatile memory that expire automatically) and for the auto-login token binding described above. At the server level, fail2ban additionally bans suspicious IP addresses temporarily (for example on 404 floods or API abuse). IP addresses are not sold, not merged into profiles and not used for advertising.
Whether your Discord account holds the "Alpha Access" role on our Discord server is checked server-side via the Discord API (using our bot). This only evaluates your membership and roles within our own server – solely to unlock access to registration and the download.
You have the right to access, rectification and erasure of your data. You can change your password, safebox code and deletion code yourself at any time in the Control Panel; you delete characters with your deletion code. If you want your account and the associated data removed entirely, contact us on our Discord server – we delete the data on request.
The website and database run on our own server. We do not pass your data to data brokers or other third parties. The only external recipient is Discord as identity provider (login and role check); Discord’s own privacy policy also applies: https://discord.com/privacy.
For any privacy questions, reach us on our Discord server: discord.gg/wyaqfUFyys.