Privacy Policy
How we handle your personal data, what we collect, why, on what legal basis, and what you can do about it. Written to meet Articles 13 and 14 of the General Data Protection Regulation.
This document still contains placeholder details. Fill in shared/utils/legal.ts before making the site publicly available in the EU.
Who is responsible
The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:
- Name
- Nethound Games
- Address
- TODO: street and house number, TODO TODO, TODO: country
- mail@nethound.org
Our representative in the Union
Because we are established outside the EU and offer this service to people in the EU, Article 27 GDPR requires us to designate a representative in the Union. You may address that representative on all questions relating to your personal data, instead of or in addition to us.
A representative in the Union has not yet been designated. Until one is, please address all data protection matters to the operator directly, using the contact details above. We will respond within the statutory time limits.
What we do not do
We want to be specific about the absences, because they are the part most privacy policies gloss over.
The games themselves are offline single-player products. They do not phone home, and playing them creates no data here.
- We run no analytics, statistics, heatmap or A/B testing tool of any kind.
- We run no advertising and no advertising cookies, and we take part in no ad network or consent framework.
- We do not profile you and we take no decisions about you by automated means within the meaning of Article 22 GDPR.
- We do not sell, rent or trade your personal data, and we do not share it for anyone else's marketing.
- We embed no third-party fonts, maps, videos or social widgets. Our webfonts are served from our own server, so no visitor data reaches a font provider.
- We ask for no data we do not need: an account requires a name, an email address and a password, nothing more.
What we process, and why
Each row below is one distinct thing we do with personal data, with the purpose, the legal basis and the storage period stated separately, as Articles 13(1)(c) and 13(2)(a) GDPR require.
| What we do | Data involved | Why | Legal basis | Kept for |
|---|---|---|---|---|
| Your account | Display name, email address, password (stored only as a scrypt hash, never in readable form), account role, registration date. | Create and maintain your account, sign you in, and let you use the parts of the site that need one. | Art. 6(1)(b) GDPR — performance of the contract you enter into when you create an account. | Until you delete your account. Deletion is immediate and self-service. |
| Staying signed in | A sealed, encrypted session cookie containing your user id, name, email and role. | Keep you signed in between page loads without asking for your password again. | Art. 6(1)(b) GDPR. The cookie is strictly necessary for a service you explicitly requested, so no consent is required for it. | 7 days, or until you sign out. |
| Support requests | Category, message text, status, timestamps, and the replies exchanged with us. | Receive, answer and track your bug reports and suggestions. | Art. 6(1)(b) GDPR — handling your request is part of the service. | Deleted together with your account, or earlier on request. |
| Screenshots you attach | Image files (PNG, JPEG, WebP, GIF) and their original file names, plus whatever those images happen to show. | Understand and reproduce the problem you are reporting. | Art. 6(1)(b) GDPR. Please do not upload images containing other people's personal data. | Deleted from disk together with the ticket or your account. |
| Donations | Amount, project, optional message, status, payment operation id, and the payer label the payment provider returns. | Record the donation, credit Golden Tickets, and keep the accounting record of money received. | Art. 6(1)(b) GDPR for the donation itself, and Art. 6(1)(c) GDPR for keeping the accounting record. | Linked to you until you delete your account, after which the record is anonymised and kept for accounting purposes only, with no link to a person. |
| Golden Tickets | The count credited to your account and the ticket messages recording each award. | Show and track the courtesy rewards granted for donations and useful reports. | Art. 6(1)(b) GDPR. | Until you delete your account. |
| Server logs | Technical request data recorded by the server and its hosting provider, and the content of payment notifications received from the payment provider. | Operate the service, diagnose faults, and verify that payment notifications are genuine and were delivered. | Art. 6(1)(f) GDPR — our legitimate interest in a working, secure service. You may object under Art. 21. | Short-term, no longer than needed for diagnosis and security review. |
| Abuse protection | Your IP address, held in the server's memory together with a counter. | Limit how often sign-in, registration and donation requests can be repeated, so the site cannot be brute-forced or flooded. | Art. 6(1)(f) GDPR — our legitimate interest in protecting accounts and the service against abuse. | Minutes. The counter is discarded when its time window expires, and nothing is written to disk. |
| Forum translation | The public text of your topics, messages and their titles, together with the language they are written in as detected by the model. | Automatically translate public forum content so members who read another language can follow and answer it. | Art. 6(1)(f) GDPR — our legitimate interest, and that of the community, in a forum that is readable across languages. You may object under Art. 21; ask us and your posts will be excluded from translation. | Translations are deleted together with the post they belong to, and therefore with your account. |
Who else sees your data
Your data is not disclosed to anyone except the parties below, and to public authorities where we are legally obliged to do so.
The hosting provider acts as our processor under a data processing agreement pursuant to Article 28 GDPR: it may only process the data on our instructions. The payment provider is an independent controller for the payment transaction and applies its own privacy policy; we never receive or store your card, bank or wallet details.
Public forum content — topic titles, message text and category descriptions — is additionally sent to a machine-translation provider so the forum can be read in every language the site offers. Only content that is already publicly visible is sent: never support tickets, account data, private messages or anything held for moderation. The provider acts as our processor under Article 28 GDPR and may not use the text for anything else.
- Hosting and infrastructure (processor)
- TODO: hosting provider
- Payment processing for donations (independent controller)
- YooMoney, NBCO LLC, Russia — their privacy policy
- Machine translation of forum content
- OpenAI, L.L.C., United States — Privacy policy of the translation provider
Transfers outside the European Economic Area
We operate from outside the EEA, so running this site necessarily involves transferring personal data to a country outside the EEA.
Where the destination country is not covered by an adequacy decision of the European Commission under Article 45 GDPR, the transfer is based on the Standard Contractual Clauses adopted by the Commission under Article 46(2)(c) GDPR, supplemented by the technical measures described under Security below. You may request a copy of the safeguards in place by writing to the address in the Legal Notice.
Donations are processed by a payment provider outside the EEA. If you would rather not have your data transferred there, do not donate — nothing else on the site depends on it.
The machine-translation provider is likewise established outside the EEA and receives public forum content on the same Standard Contractual Clauses. If you would rather your posts were not transferred there, do not post publicly — the rest of the site does not depend on it.
How long we keep things
The storage period for each processing activity is given in the table above. Two general rules apply on top of it.
First, deleting your account deletes your profile, your support requests, your ticket replies and every image you attached, permanently and immediately. Second, donation records survive that deletion in anonymised form, because accounting law requires us to retain a record of money received. Article 17(3)(b) GDPR permits this. What survives is the amount, the project and the date, with no link to you.
Your rights
Under the GDPR you have the following rights, free of charge. We answer within one month, extendable by two further months for complex requests, and we will tell you if we need that extension.
To exercise any of them, write to the email address in the Legal Notice, from the address associated with your account where possible. Where we cannot identify you from a request, we may ask for further information — but only what is needed to confirm it is you.
Access, export and erasure are also available immediately and without asking us, from your profile page.
- Article 15 — access: get confirmation of whether we process your data, a copy of it, and the information in this notice.
- Article 16 — rectification: have inaccurate data corrected and incomplete data completed.
- Article 17 — erasure: have your data deleted, subject to the accounting exception described above.
- Article 18 — restriction: have processing limited instead of deleted, for example while a dispute over accuracy is resolved.
- Article 20 — portability: receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
- Article 21 — objection: object at any time to processing based on our legitimate interests, including the server logs and abuse protection described above.
- Article 7(3) — withdrawal: withdraw any consent you gave, at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of what was done before it.
- Article 77 — complaint: lodge a complaint with a supervisory authority.
Complaining to an authority
If you think our processing of your data infringes the GDPR, you may lodge a complaint with a data protection supervisory authority, in particular in the EU Member State where you live, where you work, or where the alleged infringement took place. Doing so does not prejudice any other remedy.
You are welcome to raise the matter with us first — but you are under no obligation to.
How we protect it
We apply the technical and organisational measures required by Article 32 GDPR, appropriate to the risk of a site holding accounts, support conversations and donation records.
- Passwords are never stored or logged in readable form. They are hashed with scrypt, a deliberately slow, memory-hard function.
- The session cookie is httpOnly, Secure, SameSite=Lax and cryptographically sealed, so it cannot be read by scripts or forged.
- All traffic is served over HTTPS with HTTP Strict Transport Security.
- Uploaded images are validated by inspecting their actual file contents, not the name or the declared type, stored under generated names outside the web root, and served only through an authorisation check.
- Sign-in, registration and donation endpoints are rate-limited per IP address.
- Administrative permissions are verified on the server on every request, never inferred from anything the browser sends.
- The site loads no third-party scripts, so there is no supply chain through which your data could leak.
Children
This site is not directed at children. You must be at least 16 years old to create an account. If you are under 16, you may only use the account features with the consent of the holder of parental responsibility, in line with Article 8 GDPR and the age set in your country, which may be lower.
If you become aware that a child has given us personal data without that consent, tell us and we will delete it.
Changes to this notice
We may update this notice as the site changes. The version and effective date are shown at the top of the page. Material changes to how we process your data will be brought to your attention on the site rather than made quietly.