Back to home

Your data

Privacy policy

How Boardgames.io handles your personal data under the General Data Protection Regulation (GDPR). We collect only what the game platform needs, we show no advertising, and we do not use your data to profile you or to follow you onto other websites.

Controller

The controller responsible for the processing of personal data on this website is:

Julius Paszekc/o RA MatutisBerliner Straße 5714467 Potsdam

Full contact details, including [email protected], are listed in the legal notice.

Accounts and guest accounts

Merely opening the site does not create an account. If you choose guest play, we create a temporary account with a generated identifier and display name, an internal non-deliverable email placeholder, an account ID, the accepted legal-text version and activity timestamps. We do not ask a guest for an email address or password. The guest token stored in the browser connects later visits to that account.

For a registered account we process your chosen username, email address, securely hashed password, verification status, account settings, and the time and version of your acceptance of the terms and privacy notice. Account and guest data is required to provide the requested persistent identity, security, history and social features; without it, those features cannot be provided. Legal basis: performance of a contract (Art. 6 (1)(b) GDPR).

For login, email verification, password reset, email changes and account security we also process short-lived tokens and session records. New passwords are checked through the Have I Been Pwned range service using only the first five characters of a password-hash; neither your password, full hash, account identity nor IP address is sent to that service.

Signing in with Google or Apple

If you actively choose Google or Apple sign-in, we redirect you to that provider. We receive a stable provider identifier, your email address if supplied and whether the provider verified it; we never receive your provider password. Apple may supply a Private Relay address instead of your ordinary email. We use this data to create, link, secure or upgrade your account (Art. 6 (1)(b) GDPR). Google Ireland Limited and Apple Distribution International Limited are established in the EU and process the login as separate controllers; any onward transfer inside their global services happens under their own responsibility and their own published safeguards. Details appear under “Recipients and transfers”.

Game data, history and statistics

To provide matchmaking, private lobbies, invitations, live games and replays, we process player IDs, lobby and queue state, moves, results, timestamps and compact game snapshots. We also process history, internal ratings, season points, achievements, friendships, blocks and presence settings. If you have friends on Boardgames.io, they can see whether you are online or in a game; you can turn that off in Settings under “Privacy & safety” and then appear offline to everyone. In a live match your opponent still sees when you connect or lose your connection — that is part of the game. Legal basis for these requested account and game features: performance of a contract (Art. 6 (1)(b) GDPR).

Quick chat accepts no free text. We store only the game and sender IDs, message or reaction type, the fixed identifier of one predefined allowlist entry, and the send time so the event can appear at the matching move in the public replay. Deleting the game removes all its chat events; deleting an account or purging an inactive guest removes the events that account sent. Legal basis: performance of a contract (Art. 6 (1)(b) GDPR).

Registered players' usernames, ratings, ranks, achievements and game statistics may be visible publicly. Guests do not appear on public leaderboards. This is based on our legitimate interest in transparent competition and a useful community service (Art. 6 (1)(f) GDPR), balanced against using limited profile data. You can object at any time under Art. 21 GDPR and switch the public entry off in Settings under “Privacy & safety”; your internal rating will continue to update, and public player pages and achievement lists no longer answer for you. Once a game has finished, its replay can be opened by anyone who has the link, without an account: the replay shows the players' display names, every move and the quick-chat events, and it stays valid for as long as the game is stored. A registered player who switched the public entry off is not named in that public view; the people who played the game still see both names. The link is long and random, so it cannot be guessed.

Cookies and local storage

After you request guest play, registration or login, authentication tokens are stored in the browser's local storage so tabs can share one identity. They are short-lived and are renewed while you keep using the site; a guest token keeps working for a longer period, so that the same browser can reopen the guest account. These credentials are used only for your Boardgames.io session and authenticated API and server-sent event connections.

A strictly necessary cookie records that an account or guest session exists, for up to 30 days, so server-side rendering can show the correct view; it contains no token and no user identifier. If you choose a language or theme, that choice is stored for up to one year in a cookie and in local storage. Besides these, the app keeps a small number of strictly necessary technical values on your device once you have used the matching feature: the resolved API address, an offline cache of the app files and of public statistics responses in a service worker, your notification switch, which achievement notices you have already seen, hints you dismissed, and short-lived tab and navigation state. None of these values recognises you on other websites. These writes are necessary for the service or preference you requested (§ 25 (2) TDDDG); the related personal-data processing follows Art. 6 (1)(b) or (f) GDPR as described above.

Logging out removes the session credentials and account hint. A guest can also delete the guest account in Settings. Clearing this site's cookies and site data in your browser removes all tokens and preferences from that device; without the guest refresh token, that browser can no longer reopen the guest account.

Aggregate usage statistics

Once a day our server calculates aggregate usage statistics from data we already hold — for example how many accounts and guest sessions were started, how many games were started and finished per game, how many accounts came back on a later day, and how registrations split across the ways people reach us. Only counted totals per day and per group are stored; those tables contain counts, not identities. Whenever these figures leave the database — for example into a dashboard — they pass through views that hide any group of fewer than five people, so that no individual can be singled out. Because the totals carry no identifier, we keep them without a fixed time limit, while the underlying accounts, games and social records follow the retention rules described below. We use these figures to understand how the platform is used and to develop it, on the basis of our legitimate interest in operating and improving the service (Art. 6 (1)(f) GDPR). This is not browser analytics: we count in our own database rather than in your browser, we place no tracking pixel and no analytics code for this, the totals carry no cross-site identifier, and they are never used to make decisions about you.

Server logs and telemetry

DigitalOcean's ingress and runtime, our backend and our server-side frontend process technical request and error data, in particular:

  • IP address
  • date and time of access
  • requested address, response status and request duration
  • referrer URL and request metadata
  • browser and operating-system information and, where logged, a user or trace ID

We use this data to deliver requests, diagnose failures, protect accounts and apply rate limits that block abuse. Legal basis: our legitimate interest in a secure and reliable service (Art. 6 (1)(f) GDPR). We retain operational logs and telemetry only for the configured service lifecycle and while they are needed to investigate reliability or security events; how long our hosting platform keeps its own runtime logs depends on the DigitalOcean service configuration.

Application and server-side frontend logs, metrics and traces are sent directly to the Grafana Cloud EU gateway over OpenTelemetry (OTLP); our hosting platform has no local collector. Grafana Cloud keeps these logs and traces for 14 days; metrics are generally aggregated. This operational telemetry is not browser analytics: it serves the operation and troubleshooting of the service and is not combined into profiles about you.

Traces of our server-side frontend are minimized before they leave the server: your IP address is shortened to its network block (IPv4 to /24, IPv6 to /48) and your user agent is reduced to the browser and operating-system family, without version number or device model. Requested address, response status, duration and the technical trace ID remain, so we can still investigate errors and abuse. The ingress, our backend and the platform's own runtime logs continue to process the technical data listed above.

Transactional email

We send account-verification, password-reset and email-change messages, and the acknowledgement and decision messages for a legal notice you submitted, through Scaleway Transactional Email (TEM). Scaleway receives the recipient email address and message required for SMTP delivery. Scaleway states that the TEM technical stack and TEM personal data remain within the EU. Legal basis: performance of the requested account service (Art. 6 (1)(b) GDPR) and, for the messages about a legal notice, compliance with a legal obligation (Art. 6 (1)(c) GDPR).

Feedback, bug reports and legal notices

The feedback form sends us your free text, an optional contact address, the browser identification your browser transmits (user agent) and limited technical context such as the current page without its query string, app version, language, display settings and whether the sender uses a guest or registered account. We use it to diagnose defects and improve the service on the basis of our legitimate interests (Art. 6 (1)(f) GDPR). Please do not include sensitive personal data in free text.

Product feedback is deleted after twelve months by default. We may correct or delete it earlier when a person exercises their data-protection rights.

The separate legal-notice form stores the username snapshot and location, allegation, category, declaration, workflow and decision evidence, plus your name and email when supplied. It does not retain an IP address, full user agent or display details. We process complete legal notices to meet applicable legal obligations (Art. 6 (1)(c) GDPR) and other moderation reports to enforce the terms and defend rights (Art. 6 (1)(f) GDPR). Information may be sent to a competent authority where the law requires it. Reporter identity is not routinely disclosed to the reported user.

A completed legal-notice record is normally deleted twelve months after the decision. A case-specific legal hold may extend that period only with a documented reason and end date. Account deletion clears account attribution; the evidence snapshot remains only until the report retention date. Due deletions are applied again after a backup restore.

If someone reports you, we process data about you that we did not receive from you: the report itself, the place it points to, your username as it was at that time, and our decision. We use it to check the report against our terms and applicable law (Art. 6 (1)(c) and (f) GDPR). We inform you about this within a reasonable period and at the latest one month after we receive the report; if we contact you about the case sooner, we inform you at the latest with that first message, and if we pass the information on to another recipient, at the latest when we first disclose it (Art. 14 (3) GDPR). That message also states that the information came from a report by another user. We may postpone or omit this information only in the cases the law allows, in particular where informing you would be impossible or disproportionate or would obstruct the establishment, exercise or defence of legal claims (Art. 14 (5) GDPR). We do not routinely reveal who reported you. This record follows the legal-notice retention above, and all the rights listed under “Your rights” apply to it, including the right to object.

How long we keep data

We keep account data until you delete the account, or until a specific token expires. A guest account that has not been used for 90 days — no token refresh and no game started — is no longer needed for the service. That is the criterion by which we will delete guest accounts; the automatic clean-up is not switched on yet, so for now such accounts are only identified and not deleted, and they can persist beyond 90 days. You can delete a guest account yourself at any time in Settings.

Finished games are kept without a fixed time limit. Move-by-move records, final positions, results, ratings, rating history, season points, achievements and leaderboard entries are the substance of the replay, statistics and ranking features, so they are retained for as long as those features exist. We review this periodically and will publish a retention period here if we introduce one. Deleting your account removes the link between these records and your identity, but it does not delete the games themselves, because they are also your opponents' game history.

Deleting an account immediately removes its identity, sessions, recovery tokens, connected Google/Apple identities and social graph from the production database. Completed games, snapshots, ratings, season points, achievements and leaderboard records remain under a player ID that is no longer linked to an account, so opponents' histories and results are not rewritten; the former name is replaced by a neutral deleted-account label. We treat these remaining records conservatively as personal data and rely on our legitimate interests in preserving the integrity of competition records (Art. 6 (1)(f) GDPR).

Deleted data can remain in encrypted operational or platform backups until the configured backup lifecycle expires. Backup copies are not used in the live product. If a backup is restored, deletion requests received after that restore point must be applied again before normal operation resumes.

Recipients and transfers

  • Other players in your game see your display name and every move you make, in real time. The general public can see what we publish about your account — username, rating, rank, achievements and game statistics on public leaderboards and profiles — and can open any finished game through its replay link, without an account. This disclosure to an indefinite group of people cannot be undone for copies others have already made.
  • DigitalOcean hosts the application, its ingress and runtime logs, the database and our container images using App Platform, Managed PostgreSQL and the container registry in the Frankfurt region (fra1). Your data is stored and processed there. DigitalOcean is a United States company, so where support or group access from outside the EU occurs, that transfer is covered by the EU-U.S. Data Privacy Framework and, where the framework does not apply, by the standard contractual clauses in DigitalOcean's published data processing terms.
  • Grafana Cloud receives operational logs, metrics and traces sent directly from our backend and server-side frontend to its EU gateway. Grafana Labs is based in the United States. Where support or group access from outside the EU occurs, that transfer is covered by the EU-U.S. Data Privacy Framework, in which Grafana Labs participates, and, where the framework does not apply, by the standard contractual clauses in Grafana's published data processing terms. You can ask us for information about these safeguards.
  • If you choose their login, Google Ireland Limited and Apple Distribution International Limited receive the OAuth request. Both are established in the EU, so we do not rely on a third-country safeguard for them; they act as separate controllers for their own identity and abuse-prevention services, not as our processors, and any onward transfer inside their global services happens under their own responsibility.
  • Scaleway Transactional Email receives transactional email delivery data. According to Scaleway its TEM technical stack is managed within the EU; see “Transactional email”.
  • Tutao GmbH (Tuta Mail) hosts the mailbox behind [email protected] and therefore receives the messages you send us, including data-protection requests and reports about other users. Tutao GmbH is based in Hanover, Germany, and its servers are located in the EU, so we do not rely on a third-country safeguard for this.
  • Scaleway SAS stores our external daily database backup in its object storage in the Paris region (fr-par), inside the EU, so we do not rely on a third-country safeguard for this. Each backup is encrypted before it leaves our systems, so Scaleway cannot read its content. This external backup currently runs for our test stage only; for the live service it is prepared but switched off, and we will say so here once it is in use.
  • When you create an account or turn a guest session into an account, Cloudflare, Inc. performs a bot check on that form. Your browser contacts Cloudflare directly for that check, so Cloudflare receives your IP address together with device and browser signals. We neither read nor store those signals, and our server does not pass your IP address on to Cloudflare in addition. Cloudflare acts on our behalf when it runs the check for us, and on its own account when it uses the same signals to improve its bot detection. We do this to keep automated sign-ups from creating accounts and from sending verification mail to addresses that are not yours, on the basis of our legitimate interest in protecting the service and third parties (Art. 6 (1)(f) GDPR). Cloudflare is a United States company; the transfer is covered by the EU-U.S. Data Privacy Framework and, where the framework does not apply, by the standard contractual clauses in Cloudflare's data processing addendum.
  • Law-enforcement and judicial authorities receive personal data where the law requires us to inform them — in particular where information gives rise to a suspicion of a criminal offence involving a threat to the life or safety of a person. What we pass on includes the account data of the reported person and the evidence we preserved. The legal basis is Art. 6 (1)(c) GDPR in conjunction with Art. 18 DSA, and each disclosure is limited to the individual case the law requires.

We do not sell personal data and do not share it for advertising.

Your rights

Under the GDPR you have the following rights regarding your personal data:

  • access to the data we hold about you (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure of your data (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on legitimate interests, in particular to public visibility (Art. 21 GDPR)

Send a request to [email protected] or use the postal address above. We may ask for proportionate proof of identity. We normally respond within one month. There is no self-service export in the product: we handle every request, including data portability, manually by email. You may also object under Art. 21 GDPR specifically to a public profile or leaderboard entry.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 GDPR).

Automated ratings and matchmaking

Matchmaking and game ratings are calculated automatically from queue choices and game results. Your rating is an automated assessment of how you play — a form of profiling — but it affects only who you are matched with and how you appear in competitive views within Boardgames.io. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you (Art. 22 GDPR).

Changes to this policy

We update this policy when the platform, providers or legal requirements change. Before we switch on browser analytics, advertising, A/B testing, convenience identifiers, a further third-party widget or a new browser SDK, we carry out a fresh Section 25 TDDDG and GDPR assessment and describe the result here. The current dated version published on this page applies.

This policy is published under the same dated versions as the terms of use, and each version is marked as either editorial or material. When a material version is published, your account is held until you agree to it: a screen names the new version, the date it was published, a short summary of what changed and links to both current documents. An editorial version takes effect without interrupting you. Your agreement to the terms of use is what we record; the processing described here rests on Art. 6(1)(b) and (f) GDPR, not on your consent.