Account & Settings

Account security, two-factor authentication, privacy settings, email preferences, and GDPR data controls.

LAST UPDATED: APRIL 2026

1. Account Security

Your account holds your characters, progression, inventory, and any purchased Gems. Protecting it is critical. We recommend enabling all available security features and reviewing your active sessions periodically.

Password Requirements

When creating or updating your password, the following rules apply:

  • Minimum length: 10 characters
  • Must contain at least one uppercase letter, one number, and one special character (e.g., !, @, #, $)
  • Cannot be identical to your username or email address
  • Cannot reuse any of your last 5 passwords
  • We recommend using a password manager to generate a unique, high-entropy password for this account

Two-Factor Authentication (2FA)

2FA adds a second verification step at login. Even if someone obtains your password, they cannot access your account without the second factor. Two methods are supported:

  • Email 2FA: A one-time code is sent to your registered email address at login. Codes expire after 10 minutes. Suitable for most players.
  • Authenticator App: Compatible with any TOTP-based authenticator (Google Authenticator, Authy, etc.). Scan the QR code in Settings > Security to link your app. Generates a new code every 30 seconds. Recommended for accounts with significant progression or gem balances.

To enable 2FA, navigate to Settings > Security > Two-Factor Authentication and follow the setup wizard. You will be prompted to save a set of backup codes — store these in a secure location. Backup codes allow account recovery if you lose access to your 2FA device.

Session Management

Under Settings > Security > Active Sessions, you can view all currently logged-in sessions including device type, approximate location, and last activity time. Use the "Sign Out" button next to any session to revoke it remotely. Use "Sign Out All Other Sessions" to immediately invalidate every session except your current one.

Suspicious Login Alerts

If a login attempt is detected from a new device or from a significantly different geographic location to your usual pattern, the system will:

  1. Require email verification before the login is permitted, regardless of whether 2FA is enabled.
  2. Send an alert email to your registered address describing the login attempt (time, device, and approximate location).
  3. Lock the account for 30 minutes if three consecutive suspicious logins fail verification — this prevents automated attacks.

WARNING

We will never ask for your password via in-game chat, email, or Discord. If anyone claiming to be VvW staff requests your password, report them immediately at support@duskmaw.com.

2. Email Settings

All email notifications from Vampires vs. Werewolves are opt-in by default. No marketing or promotional emails are sent without explicit consent. Transactional emails (password reset, 2FA codes, account deletion confirmation) cannot be disabled as they are essential to account function.

Notification Types

Notification Description Default
Daily Quest Reminder Sent once per day at 08:00 UTC if you have not logged in that day and have unclaimed daily quests. Off
Arena Challenge Received Sent when another player initiates an Arena challenge directed at your character specifically. Off
Dungeon Reset Sent when weekly dungeon locks reset on Monday, reminding you to run dungeons for the new week. Off
Event Start Sent 1 hour before a scheduled event (Blood Moon, Eclipse War, Seasonal events) goes live. Off
Auction House Sale Sent when an item you listed on the Auction House sells successfully. Off
Clan Activity Sent when your clan completes a major milestone or when a clan war is declared against you. Off
Battle Pass Expiry Sent 48 hours before a Battle Pass season ends, prompting you to claim remaining rewards. Off
Security Alerts Sent for suspicious logins, password changes, and 2FA configuration changes. Cannot be disabled. Always on

To manage these settings, go to Settings > Notifications > Email. Changes take effect immediately. You can also unsubscribe from all optional emails using the one-click unsubscribe link at the bottom of any notification email.

3. Privacy Settings

VvW respects your right to control your in-game presence. Privacy settings are found under Settings > Privacy.

Online Status

  • Show Online Status (default: On): When enabled, other players can see that you are currently online via the friends list and player search. Disabling this shows you as "Offline" to all other players, including friends — you can still play normally and receive messages.
  • Show Last Seen: When online status is hidden, this option controls whether your "Last seen X hours ago" timestamp is visible. Default: Off when online status is hidden.

Profile Visibility

  • Public (default): Any player can view your character profile, including character name, level, faction, equipped gear appearance, and achievements.
  • Friends Only: Profile is only visible to players on your friends list.
  • Private: Profile is hidden from all other players. Your name still appears in combat logs and leaderboards.

Arena Challenges

You can control who is allowed to send you direct Arena challenges:

  • Anyone (default): Any player of appropriate level can challenge you to a duel or Arena match.
  • Friends Only: Only players on your friends list can issue direct challenges. Random matchmaking is unaffected.
  • Nobody: Disables direct challenges entirely. You can still participate in Arena through the matchmaking queue.

Trade and Messages

  • Allow Trade Requests: Toggle whether other players can initiate a trade with your character directly.
  • Allow Private Messages: When disabled, only clan members and friends can send you private messages. Useful for avoiding unsolicited contact.

NOTE

Privacy settings apply across all characters on your account. You cannot set different visibility levels per character.

4. Data & GDPR

Vampires vs. Werewolves complies with the EU General Data Protection Regulation (GDPR) and equivalent data protection laws. All data rights described below apply to all players globally, not only EU residents.

What Data We Store

  • Account data: Email address, username, hashed password, account creation date, and country of registration.
  • Character data: All game progress including level, stats, inventory, skills, achievements, and clan membership.
  • Transaction data: Gem purchase records, Battle Pass activations, and Auction House transactions — retained for 7 years for legal compliance.
  • Session data: Login timestamps, IP addresses (hashed after 90 days), and device type — retained for 12 months for security purposes.
  • Communication data: In-game chat logs retained for 90 days for moderation purposes, then permanently deleted.

Requesting a Data Export

You have the right to receive a copy of all personal data we hold about you. To request an export:

  1. Navigate to Settings > Data & Privacy > Request Data Export.
  2. Confirm your identity via the email verification step.
  3. Your data will be compiled and emailed to you as a JSON archive within 14 days.

Requesting Account Deletion

You may request permanent deletion of your account and all associated data at any time:

  1. Navigate to Settings > Data & Privacy > Delete Account.
  2. A 30-day grace period begins. During this period your account is deactivated but not yet deleted — you can cancel the deletion by logging in within this window.
  3. After 30 days, your account, characters, and all personal data are permanently and irreversibly deleted.
  4. Transaction records required by law (purchase history) are retained for 7 years in anonymised form before deletion.

WARNING

Account deletion is irreversible after the 30-day grace period. All characters, items, Gems, and progress will be permanently lost. We cannot recover deleted accounts under any circumstances.

5. Linked Accounts

We are actively developing integrations with third-party platforms to enhance the community experience. The following linked account features are planned or in development:

Discord Integration (Coming Soon)

Link your VvW account to your Discord account to receive automatic server role assignment based on your faction, level bracket, and clan membership. Verified players will receive the Verified Adventurer role in the official VvW Discord server, unlocking exclusive channels and giveaway access.

  • Role sync will update automatically whenever your in-game status changes (e.g., reaching level 50 grants a new role).
  • Linking Discord does not share your personal data with Discord beyond your VvW username.
  • You may unlink Discord at any time from Settings > Linked Accounts — roles are removed within 1 hour of unlinking.

Social Sharing (Coming Soon)

A future update will allow optional linking of social accounts for one-click achievement sharing. When you unlock a major achievement (Prestige rank, dungeon world-first, etc.), you will be able to share a styled card to your linked social profiles directly from the achievement popup.

  • Social linking will be strictly opt-in and used only for sharing actions you explicitly initiate.
  • No automated posting will ever occur.
  • Details will be announced in the blog before rollout.

NOTE

No linked account integrations are live yet. This page will be updated when features launch. Follow the Blog for announcements.

6. Banned & Suspended Accounts

We take fair play seriously. Violations of the Terms of Service result in temporary suspensions or permanent bans depending on severity and history.

Common Ban Reasons

  • Cheating / Exploiting: Using third-party software to gain an unfair advantage, exploiting known bugs to duplicate items or currency, or manipulating game mechanics outside intended design. Results in an immediate permanent ban.
  • Real-Money Trading (RMT): Selling in-game items, gold, or accounts for real-world currency outside the official Gem Shop. Permanent ban on all involved accounts.
  • Harassment: Sustained targeted harassment of other players via messages, Arena challenges, or clan war declarations. First offence: 7-day suspension. Repeat: permanent ban.
  • Inappropriate Content: Using character names, clan names, or chat to display slurs, hate speech, or explicit sexual content. First offence: 3-day suspension + forced rename. Repeat: escalating suspensions.
  • Account Sharing: Sharing your account login with another person violates ToS and can result in a 14-day suspension. Repeated violations result in a permanent ban.
  • Chargebacks: Initiating a fraudulent chargeback for Gem purchases. Immediate account suspension pending investigation.

Appeal Process

If you believe your account was suspended or banned in error, you may submit an appeal:

  1. Email appeals@duskmaw.com with your account email, username, and a description of the situation.
  2. Our moderation team reviews all appeals within 5–10 business days.
  3. You will receive a response to your email with the outcome. If the ban is upheld, a reason will be provided.
  4. If the ban is overturned, any lost in-game time (for temporary bans) will be compensated with equivalent event access where feasible.

NOTE

Bans for cheating and RMT are generally not eligible for appeal on first review. A second-level review can be requested by replying to the initial decision email within 14 days.