Abyssus Demo Review
With "Abyssus", DoubleMoose Games and Dotemu deliver an atmospheric action-adventure with roguelite elements that draws players into the dark depths of a sunken world. But as compelling as the gameplay may be, privacy risks lurk beneath the surface.
What does the product do?
"Abyssus" is a rogue-lite FPS with single-player and multiplayer components. It is offered via platforms like Steam and features in-game progress saving, matchmaking, and cross-device usage. The game mechanics are closely linked to online functions and telemetry-based optimizations.
Who operates the product?
- DoubleMoose Games AB (Sweden) – Developer
- Dotemu SAS (31A rue de Bellefond, 75009 Paris, France) – Publisher and contractual partner, responsible for data processing
Which service providers are involved?
-
Epic Games, Inc. - 620 Crossroads Blvd, Cary, NC 27518, USA
-
Valve Corporation - PO Box 1688, Bellevue, WA 98009, USA
-
Microsoft Corporation - One Microsoft Way, Redmond, WA 98052-6399, USA
-
Amazon.com, Inc. - 410 Terry Avenue North, Seattle, Washington, 98109, USA
What data is collected?
Epic Online Services (Epic Games, Inc.)
All data collected in the game is processed via Epic Online Services. The data examples only show the data that is already collected before the user gives consent:
User identification:
Username, Password, access_token, id_token, ProductUserId, ProductUserIdCreated, Organization_id, Organization_user_id, nonce, Token_type, TTL, Expires_at, Expires_in
Platform and device information:
Platform, IntegratedPlatform, PlatformAgeInSeconds, OSName, OSVer, UserAgent, SDKVer
Product and game information:
ProductId, ProductName, ProductVersion, SandboxId, BuildId
Session and usage data:
CurrentLoggedInUsers, NumLogins, NumLogouts, SessionTicket, SecondsSinceLastHeartbeat, SecondsSincePlatformInit, TickHz, NumTicks, DateOffset, DeploymentId, DurationSeconds
Tracking and event data:
EventName, OperationName, ServiceName, Source, ApiName, ComponentName, Components, RequestProperties, CorrelationId, URIs, StatusText, HttpStatusCode, Result
Performance and error metrics:
FailureCount, SuccessCount, RetryCount, ThrottledCount, InvalidUsageCount, NumDroppedEvents, Features
This data is automatically processed, in part permanently stored and linked to user identifiers.
Valve Steam Datagram Relay (SDR)
As part of multiplayer functionality, Abyssus uses Valve's
Steam Datagram Relay (SDR) service to mediate network connections between players. The following data is processed:
Connection and network information:
- IP addresses of participants (temporarily, mediated via Valve)
- Connection metadata such as latency, relay selection, routing IDs
This information is processed for game networking purposes and is relevant under data protection law, as it can indirectly allow identification and is transmitted without explicit consent.
Microsoft PlayFab (Microsoft Corporation)
In later stages of the game, personal data is also processed via the Microsoft PlayFab service. Authentication is handled via the API playfabapi.com through the LoginWithCustomID call. The following information is transmitted:
User identification and login:
PlayFabId, CustomId, SessionTicket, EntityToken
Platform and client information:
BuildId, IsEditor, IsDemoBuild, TitleId
Device and focus data:
GatherDeviceInfo, GatherFocusInfo
These data are also personal or personally identifiable under the GDPR and subject to the same requirements of transparency, consent and purpose limitation.
Privacy policy and opt-in/out
In the game, a screen appears offering the option to choose between "Continue with tracking" and "Deactivate". This notice suggests a voluntary choice regarding data processing.
In reality, however, data collection begins before this dialog is displayed. Furthermore, the "Deactivate" button has no technical effect. The tracking service of Epic Games, Inc. remains active.
The supposed opt-out option thus acts as a placebo and misleads users about the actual state of data processing.
The displayed privacy policy names Dotemu as the responsible party and refers to the privacy page at https://pullupent.com/in-game-privacy-policy. A valid opt-in in accordance with the GDPR is not implemented. Data is collected regardless of consent.
Who is behind the privacy policy?
PulluP Entertainment , an alliance of Focus Entertainment Publishing, Dotemu, Deck13 Interactive, The Arcade Crew and many others
Spyware yes/no?
- Hidden data collection before visible consent (non-functional opt-in/out)
- Automated activity without user knowledge or control
- Purpose-driven use against user interests
- Privacy mechanisms deliberately bypassed
GDPR violations and risks
- No valid consent in accordance with Art. 7 GDPR
- Processing of personal data without legal basis (Art. 6 GDPR)
- Deception regarding the function of the opt-out button
- Violation of principles of data minimization, purpose limitation, and transparency
Risks for users
- Unwanted profiling and traceability
- Lack of control over personal data
- Security risks from processing sensitive login data
If the mechanics remain unchanged, the behavior in the main game will be the same.
Can the behavior be blocked?
Limited. While all mentioned services can technically be disabled for this title (e.g., via hosts file and firewall rules), doing so leaves consumers with only a partially functional product. Additionally, Epic Games' API is required by many other titles, so a system-wide block would only benefit a subset of users.