1. Controller
The controller responsible for the processing of personal data in connection with LudoLog is:
Petite Maison by André Kleinhaus
c/o IP-Management (974672634)
Ludwig-Erhard-Str. 18
20459 Hamburg
Email: support.ludolog@proton.me
We have not appointed a Data Protection Officer because, based on the current scope and nature of LudoLog, the legal requirements for appointing a Data Protection Officer are currently not met. If the scope of processing changes, we will reassess this.
2. Overview of the Data We Process
| Data category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | Email address, username, password hash | Account creation, login, password resets, account administration | Art. 6(1)(b) GDPR |
| Optional profile data | Bio, BGG username, avatar color, theme/date settings | Profile customization, account settings, and optional BGG-related features | Art. 6(1)(b) GDPR |
| App activity and content | Game library, achievements, shelves, favorites, progression data, votes, published achievements, showcase-related status, imported collection references | Core app functionality, optional collection import, and community features | Art. 6(1)(b) GDPR |
| Community content translation | Text of user-submitted achievements sent to an external provider for machine translation (EN/DE) | Making community content available in both languages | Art. 6(1)(f) GDPR |
| Feedback data | Feedback category, free-text message, page URL, browser/platform details | Handling bug reports, product feedback, and beta quality improvements | Art. 6(1)(f) GDPR |
| Moderation and admin data | Reports, moderation records, edit history, role assignments, admin/support communication | Community moderation, abuse prevention, support, and service integrity | Art. 6(1)(f) GDPR and, where applicable, Art. 6(1)(b) GDPR |
| Security data | IP address, request metadata, rate-limit records, security logs | Preventing abuse, brute-force attacks, fraud, and security incidents | Art. 6(1)(f) GDPR |
| Password reset data | Reset token hash, expiry timestamp | Secure password recovery | Art. 6(1)(b) GDPR |
| Error and performance data | Technical error reports, stack traces, browser/device data, user ID where necessary | Diagnosing bugs, ensuring stability, and improving performance | Art. 6(1)(f) GDPR |
| Product and usage analytics | Cookieless usage and interaction events (pages viewed, features used, device and browser type, approximate region), linked to your internal user ID while logged in | Understanding how the Service is used so that we can improve it | Art. 6(1)(f) GDPR |
| Session data | Authentication/session cookies and related security values | Keeping you logged in and protecting the login flow | Art. 6(1)(b) GDPR |
3. Mandatory, Optional, and Public Information
3.1 Mandatory Information
To create and use a LudoLog account, you must provide:
- your email address;
- a username;
- a password.
Without this information, we cannot create or operate your account.
3.2 Optional Information
You may additionally provide or configure:
- a bio;
- your BoardGameGeek username;
- avatar color;
- theme preferences;
- date format preferences;
- other optional profile or app settings made available in the Service.
You are not required to provide this information to use the basic account features.
If you choose to provide your BoardGameGeek username and use BGG-related features, such as collection import, we process that information in order to retrieve and associate the requested BoardGameGeek collection data with your LudoLog account.
Please do not enter sensitive personal data such as health data, political opinions, religious beliefs, or other special categories of personal data into free-text fields unless this is strictly necessary. LudoLog is not intended for processing such data.
3.3 Publicly Visible Information
Your profile is public by default. You can set your profile to private at any time in your account settings, in which case other users cannot view your profile or your personal achievement progress.
While your profile is public, the following information may be visible to other users:
- your username;
- your bio;
- your public game library;
- the number of showcase achievements associated with your account;
- the number of achievements you have published;
- your meta progression levels.
Other information is shown publicly only where the Service explicitly indicates this.
Individual voting behavior and downvote reasons are not publicly displayed as part of your profile unless the Service expressly states otherwise. Vote data may, however, be used internally for moderation, ranking, quality control, and aggregate statistics.
4. Purposes and Legal Bases of Processing
4.1 Account Registration, Login, and Account Administration
When you create an account, we process your email address, username, and password hash in order to create and manage your account, authenticate you, allow you to log in, and provide essential account-related functionality.
Legal basis: Art. 6(1)(b) GDPR.
4.2 Profile Data and Account Settings
If you choose to add profile information or configure account settings, we process that information to provide profile and customization features.
Legal basis: Art. 6(1)(b) GDPR.
4.3 Core App Activity, Optional BGG Collection Import, and Community Features
We process the content and activity data you create in order to operate the main functions of LudoLog, including:
- game library management;
- achievement suggestion, publication, editing, and tracking;
- shelves, favorites, and progression systems;
- public and community catalog features;
- showcase and meta progression features;
- voting and quality signals;
- role-based community curation features;
- optional import of BoardGameGeek collection data where requested by you.
If you choose to use collection import, we process your BoardGameGeek username and retrieve the relevant collection information from the BoardGameGeek API in order to provide that feature within LudoLog.
Imported collection data becomes part of your LudoLog account data. If you later change or remove your BoardGameGeek username or stop using the BGG-related feature, previously imported collection data may remain stored within LudoLog unless you separately remove that data within the Service or delete your account.
Legal basis: Art. 6(1)(b) GDPR.
4.4 Feedback and Bug Reports
If you submit feedback or bug reports, we process the submitted information in order to improve the Service, diagnose issues, prioritize improvements, and respond where appropriate.
This may include:
- your user ID;
- the feedback category;
- structured feedback fields;
- optional free-text content;
- the page URL from which the feedback was sent;
- browser and platform details where needed to reproduce an issue.
Legal basis: Art. 6(1)(f) GDPR.
Our legitimate interest is to maintain and improve the functionality, usability, and reliability of LudoLog, especially during beta operation.
4.5 Moderation, Trusted Users, Curators, and Admin Functions
LudoLog includes moderation and community curation features. To operate these features, we process data relating to:
- reports and complaints;
- moderation decisions and review records;
- achievement edit histories;
- trusted user, curator, and admin role assignments;
- support and moderation-related communication;
- abuse prevention and community integrity.
Trusted users have extended editing rights for achievements within the community catalog. Curators may additionally manage showcase titles and progression track content. Only admins may change user roles or access email addresses and comparable account administration data.
Legal basis: Art. 6(1)(f) GDPR and, where moderation is directly necessary to provide the Service to you, Art. 6(1)(b) GDPR.
Our legitimate interest is to operate a safe, functional, and high-quality community platform and to enforce the rules of the Service.
4.6 Password Resets
If you request a password reset, we generate a one-time reset token and send it to your email address. The token is stored only in hashed form together with an expiry timestamp.
Legal basis: Art. 6(1)(b) GDPR.
4.7 Security, Rate Limiting, and Abuse Prevention
To protect the Service and its users, we process technical security data such as IP addresses, request metadata, and temporary rate-limit information.
This processing is used, for example, for login protection, password reset protection, report abuse prevention, and protection against brute-force attacks and other misuse.
Where possible, such data is stored only temporarily and with limited retention.
Legal basis: Art. 6(1)(f) GDPR.
Our legitimate interest is to ensure the security, integrity, and availability of the Service.
4.8 Error Tracking and Performance Monitoring
We use technical error and performance monitoring tools in order to detect bugs, diagnose failures, and improve the stability and performance of the Service.
Depending on the event, this may include:
- stack traces and error messages;
- request and response metadata;
- page URLs;
- browser, operating system, and device information;
- internal user identifiers where necessary to reproduce account-specific issues.
We do not use session replay.
Legal basis: Art. 6(1)(f) GDPR.
Our legitimate interest is to maintain a stable, secure, and functional Service.
4.9 Analytics and Performance Insights
We use privacy-friendly analytics and performance tools to understand how LudoLog is used and how it performs, so that we can improve it. These tools are configured without advertising or marketing purposes, and we do not use them to build advertising profiles or for cross-context behavioral tracking.
For product analytics we use PostHog, hosted in the European Union (PostHog Cloud EU). PostHog is configured to run cookieless: it stores no identifier on your device (no cookies and no browser storage) and keeps analytics state only in memory for the duration of your current page session.
Through PostHog we process usage and interaction events (such as pages viewed and features used), technical information about your browser, operating system, and device type, and an approximate location derived from your IP address. While you are logged in, these events are linked to your internal LudoLog user ID so that we can understand how account holders use the Service. We do not use your email address, your name, or the content of your submissions (such as feedback text) as analytics data.
We also use aggregate performance tools (such as Vercel Web Analytics and Speed Insights) to measure technical performance and stability.
Legal basis: Art. 6(1)(f) GDPR.
Our legitimate interest is to understand how the Service is used and how it performs so that we can maintain and improve it. You have the right to object to this processing at any time (see Section 10).
4.10 BoardGameGeek Metadata and Optional Collection Import
LudoLog retrieves game-related metadata from the BoardGameGeek XML API, such as game names, identifiers, rankings, and related reference information.
Where you choose to use BGG-related account features, such as collection import, LudoLog may also use the BoardGameGeek username you provide in order to retrieve the relevant collection data from BoardGameGeek and associate it with your LudoLog account.
Imported collection data may remain part of your LudoLog account even if you later remove your BoardGameGeek username or discontinue the related feature, unless you separately delete the imported data or delete your account.
BoardGameGeek metadata requests are generally made server-side by LudoLog. In the normal operation of these metadata requests, we do not intentionally transmit your LudoLog account email address or password data to BoardGameGeek.
LudoLog may store BoardGameGeek metadata and related image URLs in its own systems for a limited period in order to reduce repeated lookups, improve performance, and keep imported or referenced game information available within the Service.
Legal basis: Art. 6(1)(b) GDPR where this is necessary to provide requested BGG-related features, and otherwise Art. 6(1)(f) GDPR.
Our legitimate interest is to provide game reference data efficiently and maintain the technical performance of the Service.
4.11 BoardGameGeek Images and External Image Requests
LudoLog stores BoardGameGeek image URLs, such as thumbnail URLs, in its database for as long as the corresponding game remains part of our catalog, in order to reduce repeated metadata lookups and improve application performance.
Game cover images are delivered in two ways, depending on where in the Service they appear:
- Via our hosting infrastructure. For many surfaces, images are requested from our own domain and fetched, optimized, and temporarily cached by our hosting provider (Vercel) on our behalf. In this case, your browser communicates only with LudoLog's infrastructure and no technical data is transmitted from your device to BoardGameGeek.
- Directly from BoardGameGeek / Geekdo. On some surfaces, your browser loads the image directly from the BoardGameGeek or Geekdo image infrastructure. In this process, technical data such as your IP address, browser information, and request metadata may be transmitted directly to that external provider.
We do not control the data processing carried out by such third-party providers once your browser connects directly to them.
Legal basis: Art. 6(1)(f) GDPR.
Our legitimate interest is to display relevant game imagery efficiently while keeping our own infrastructure lightweight.
4.12 Compromised-Password Check (Have I Been Pwned)
When you set or change a password (during registration, password reset, or in your account settings), LudoLog checks whether that password is known to have appeared in publicly known data breaches, using the "Pwned Passwords" service operated by Have I Been Pwned.
This check uses a privacy-preserving method (a so-called *k-anonymity range query*). Your password is hashed on our server, and only the first five characters of that hash are transmitted to the service. Your password itself, your full password hash, your email address, and your username are never transmitted. The service cannot determine which password you checked.
If the password is found in known breach data, we ask you to choose a different one. We do not store the result of this check.
Legal basis: Art. 6(1)(f) GDPR.
Our legitimate interest is to protect user accounts against credential-stuffing and the reuse of passwords already exposed in breaches elsewhere.
4.13 Machine Translation of Community Content
To make community content available in both English and German, LudoLog sends the text of user-submitted achievement content (titles and descriptions) to a machine-translation provider (OpenAI) and stores the resulting translations alongside the original content.
Account credentials, email addresses, and usernames are not transmitted for this purpose. Please avoid entering personal data into achievement text, as such content may be processed by the translation provider.
Legal basis: Art. 6(1)(f) GDPR.
Our legitimate interest is to make community-created content accessible to users across the supported languages.
5. Cookies and Similar Technologies
LudoLog uses cookies and similar technologies for authentication, login security, session management, and functional user preferences.
Based on the current configuration, LudoLog uses only technically necessary and functional cookies. We do not use advertising cookies, marketing cookies, or any cookie-based tracking.
Our product analytics tool (PostHog, see Section 4.9) is configured to run without cookies or browser storage: it keeps no identifier on your device and stores analytics state only in memory for the duration of the page session. It therefore does not set any tracking cookies and does not rely on access to information stored on your device, and accordingly does not require consent under Section 25 TTDSG/TDDDG.
Authentication and security cookies include authentication session cookies, CSRF protection cookies, and callback/redirect helper cookies that are required for the login flow.
Functional preference cookies: if you explicitly choose a display theme in your account settings, a preference cookie ("ludo-theme") stores that choice on your device so it can be applied before the page renders. It contains only the selected theme value and is set solely as a result of your own action.
Browser storage (localStorage / sessionStorage): LudoLog also uses your browser's local storage for functional purposes you request through normal use of the Service, for example: recent search terms (stored on your device only when you are not logged in), interface preferences such as sorting, grouping, and tab selections, and temporary values used to restore your scroll position when navigating back. These entries contain no tracking or advertising data, are not read by third parties, and some are automatically removed when you close the browser tab.
These cookies and storage entries are strictly necessary for, or directly requested through, the features you use, and therefore do not require consent under applicable law.
If we introduce non-essential cookies or similar technologies in the future, we will request consent where legally required.
6. Recipients and Categories of Recipients
Your personal data may be disclosed to the following categories of recipients where necessary:
6.1 Other Users
While your profile or content is public (profiles are public by default and can be set to private at any time), other users may see the information that is marked as publicly visible in the Service.
6.2 Trusted Users, Curators, and Moderators
Depending on their assigned role, trusted users and curators may access:
- community submissions;
- achievement edit histories;
- reports and moderation queues;
- related internal identifiers where necessary for moderation or curation tasks.
Trusted users have extended editing rights for achievements within the community catalog. Curators may additionally manage showcase titles and progression track content.
They are not permitted to use this information for purposes outside LudoLog.
6.3 Administrators
Administrators may access account-related and moderation-related data where necessary to operate the Service, handle abuse, review reports, provide support, or comply with legal obligations.
Only administrators may access email addresses and comparable account administration data. Feedback submitted through the feedback form is accessible only to administrators.
6.4 Processors and Technical Service Providers
We use technical service providers for hosting, database services, authentication-related infrastructure, email delivery, error monitoring, analytics, security, and similar operational purposes.
These providers process personal data on our behalf under data processing agreements where required.
6.5 BoardGameGeek and Other Independent Third Parties
If you use BGG-related features, such as collection import, LudoLog may retrieve relevant data from BoardGameGeek based on the BoardGameGeek username you provide.
When cover images are loaded directly from BoardGameGeek or Geekdo image infrastructure, your browser connects directly to those external providers and may transmit technical request data such as your IP address.
BoardGameGeek is not our processor for these direct third-party requests.
6.6 Authorities and Legal Recipients
We may disclose personal data to courts, authorities, law enforcement bodies, lawyers, or other recipients where legally required or where necessary for the establishment, exercise, or defence of legal claims.
7. International Transfers
We aim to use EU-based processing regions wherever available and have configured our current providers accordingly where technically offered.
However, some service providers may be established outside the European Economic Area, may use sub-processors outside the EEA, or may permit remote access from outside the EEA.
Some of our providers are established in the United States (for example, Vercel, Sentry, and OpenAI). Where such a provider is certified under the EU-U.S. Data Privacy Framework (DPF), transfers to it are covered by the European Commission's adequacy decision of 10 July 2023 pursuant to Art. 45 GDPR.
Our product analytics data (PostHog) is stored in the European Union (PostHog Cloud EU). Where the provider's US-based operations access data for support or maintenance, such access is covered by the safeguards described in this section.
Where personal data is transferred to a country outside the EEA and no adequacy decision applies, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with any supplementary measures required under applicable law.
You may contact us if you would like more information about the safeguards used for specific transfers.
8. Service Providers
LudoLog currently uses the following service providers and external services:
| Provider | Role | Purpose |
|---|---|---|
| Vercel | Processor | Hosting, content delivery, deployment infrastructure, analytics, and performance insights |
| Turso | Processor | Database hosting |
| Upstash | Processor | Rate limiting and security-related Redis infrastructure |
| Sentry | Processor | Error monitoring and performance monitoring |
| Resend | Processor | Transactional email delivery, such as password reset emails |
| PostHog | Processor | Cookieless product analytics (usage and interaction events); analytics data hosted in the EU (PostHog Cloud EU) |
| OpenAI | Processor | Machine translation of user-submitted achievement content (EN/DE) |
| BoardGameGeek XML API | Independent third party | External game metadata source and optional collection import source |
| BoardGameGeek / Geekdo image infrastructure | Independent third party | External game-related image delivery |
| Have I Been Pwned (Pwned Passwords) | Independent third party | Privacy-preserving check whether a chosen password appears in known data breaches (only a 5-character hash prefix is sent; no password, email, or username) |
Where required, we have entered into data processing agreements with our processors.
We aim to use EU-based processing regions wherever available and have configured our current providers accordingly where technically offered. However, some providers may still involve transfers outside the EEA, sub-processors outside the EEA, or remote access from outside the EEA. For certified U.S. providers, such transfers are covered by the EU-U.S. Data Privacy Framework adequacy decision; otherwise we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses together with any supplementary measures required under applicable law.
For more information about a specific provider or transfer safeguard, you may contact us.
9. Data Retention and Deletion
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
9.1 Account Data
Account login data, profile data, and non-public account data are retained for as long as your account exists.
Imported collection data retrieved through optional BoardGameGeek features becomes part of your LudoLog account data and may remain stored within your account even if you later remove your BoardGameGeek username or stop using the related import feature, unless you separately delete the imported data or delete your account.
When you delete your account through the Service, your account access is disabled automatically without undue delay. Account login data, profile data, and non-public account data will then be deleted or irreversibly anonymized without undue delay in our productive systems, unless retention is required by law or necessary for security, abuse prevention, or legal claims.
9.2 Public Community Contributions
Public community contributions, such as published achievements and related public catalog records, may remain available after account deletion where and to the extent necessary to preserve the integrity, continuity, and usability of the Service.
In such cases, we may remove direct profile attribution and retain the contribution in anonymized or de-personalized form.
9.3 Votes, Favorites, and Progress Signals
Votes, favorites, completion states, progression signals, and similar interaction data may be deleted, anonymized, aggregated, or detached from your account when your account is deleted.
Where aggregate counts, ranking signals, or community statistics are retained, they will no longer be linked to your identifiable account unless retention is legally required.
Personal game records and achievement completions are not published as part of your public profile. Only aggregate or count-based public indicators expressly shown by the Service may remain visible where applicable.
9.4 Moderation, Security, and Legal Records
Reports, moderation records, abuse-prevention records, and legal documentation may be retained for up to 1 year and then reviewed for deletion, anonymization, or further retention where necessary to enforce the rules of the Service, protect users and the Service, or establish, exercise, or defend legal claims.
Feedback submissions may also be retained for up to 1 year and then reviewed for deletion, anonymization, or further retention where necessary for support, debugging history, abuse prevention, or legal reasons.
9.5 Technical Logs and Security Data
Temporary security-related records, such as rate-limit entries and comparable technical protection data, are retained only for a short period and deleted automatically according to the applicable security window.
9.6 Error Monitoring Data
Technical error and performance monitoring data is retained only for a limited period appropriate to debugging and service maintenance, based on the configured retention settings of the relevant provider.
9.7 Product Analytics Data
Product analytics event data collected via PostHog (see Section 4.9) is retained in line with our analytics provider's standard retention for our current plan — currently approximately one year — after which it is deleted. This data does not include your email address, your name, or the content of your submissions.
9.8 Backups
Backup copies may remain in secure backup systems for a limited period until they are overwritten in the ordinary backup cycle.
For database backups and comparable infrastructure-level backups, the effective retention period may depend on the standard or configured retention settings of the relevant provider.
10. Your Rights
Subject to the applicable legal requirements, you have the following rights under data protection law:
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing based on legitimate interests;
- the right to withdraw consent at any time where processing is based on consent;
- the right to lodge a complaint with a supervisory authority.
To exercise your rights, please contact us at support.ludolog@proton.me.
You may lodge a complaint with the competent supervisory authority, including, for example:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
You may also contact the supervisory authority in your place of residence or work.
11. No Sale of Personal Data / California Requests
LudoLog is operated as a small business (Kleinunternehmen) and does not sell personal data or share personal data for cross-context behavioral advertising.
If you are a California resident and wish to request access, correction, or deletion of your personal information, you may contact us at support.ludolog@proton.me. We will handle such requests in accordance with applicable law.
12. No Automated Decision-Making
We do not currently use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of applicable data protection law.
If this changes in the future, we will update this Privacy Policy and provide any legally required information.
13. Children and Minimum Age
LudoLog is not directed to children under the age of 16. We do not knowingly create accounts for users under 16.
If we become aware that personal data of a child under 16 has been processed in violation of this rule, we will take appropriate steps to delete the account and associated data in accordance with applicable law.
14. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, alteration, and misuse.
These measures may include, where appropriate:
- HTTPS/TLS encryption in transit;
- password hashing using industry-standard methods;
- hashed password reset tokens with expiry controls;
- session protection using secure cookie settings;
- rate limiting and abuse prevention mechanisms;
- role-based access controls for admins, trusted users, and curators;
- technical filtering to avoid transmitting sensitive token parameters to monitoring tools where possible.
No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security.
15. Changes to This Privacy Policy
We may update this Privacy Policy where necessary to reflect changes in the law, our processing activities, technical configuration, or the Service.
If we make material changes, we will notify users in an appropriate manner.
Where a change requires consent, we will request consent before the relevant processing begins.
16. Contact
If you have questions about this Privacy Policy or wish to exercise your rights, please contact:
Petite Maison by André Kleinhaus
c/o IP-Management (974672634)
Ludwig-Erhard-Str. 18
20459 Hamburg
Email: support.ludolog@proton.me
LudoLog — Play. Track. Achieve.