This is a courtesy translation. The German version at /datenschutz is the binding one; in case of any discrepancy, the German text prevails.
The controller responsible for processing personal data on this website and in this service is:
Jens Bösche
Am Piepenbrink 16A
29379 Wittingen
Deutschland
kappaxbeta@gmail.com
We have not appointed a data protection officer, as the statutory thresholds for doing so are not met. For any privacy matter, please contact us at the address above.
This service is built so that as little personal data as possible comes into existence in the first place. That is not a statement of intent — each of the following can be checked:
The application and the database run on servers we rent in Germany. No transfer to a third country takes place for hosting.
We have a data processing agreement under Art. 28 GDPR with both providers. Neither has access to the content of the data; they process it solely in order to operate the servers.
TLS certificates for encrypted transport are obtained automatically from Let’s Encrypt (Internet Security Research Group, USA). Only domain names are transmitted in that process — no visitor data.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the technically secure and reliable operation of this service.
When a page is requested, the web server automatically records log data transmitted by your browser:
This data is technically necessary to deliver the page and additionally serves to detect and defend against abuse and attacks. It is not combined with other data sources and is not evaluated for analytics. The legal basis is Art. 6(1)(f) GDPR. Logs are deleted, or their IP addresses anonymised, after 14 days at the latest.
We use strictly necessary cookies only. There is therefore no consent banner: under § 25(2) no. 2 TDDDG, no consent is required for cookies that are strictly necessary to provide a service the user has expressly requested. No cookie is set in order to measure you or to advertise to you. The only cookie related to analytics is the objection to it — set only when you ask for it, and its effect is that less is stored.
You can delete or block cookies in your browser at any time. If you do, you will not be able to sign in or use the protected areas of the service.
We measure how often which pages are opened, in order to understand what is being found and what is not. We use no third-party analytics tool and no cookie for this. One record is stored per page view, containing:
To group repeat views within a single day, we compute a cryptographic hash from your IP address, your user agent, the current date and a secret key known only to us. Only that hash is stored.
Your IP address is not stored.Because the date is part of the calculation, the hash changes completely at midnight UTC. The same person receives a different value the next day, and the two cannot be linked. Recognition across days, and therefore the building of any usage profile, is technically impossible; “unique visitors” here is a daily figure and cannot be anything else.
The country code is determined offline, from an address-registry allocation table built into our application. Your IP address is not transmitted to anyone for this purpose and is not passed to any geolocation service. The result is a country and never anything more precise.
You can object to this measurement at any time, at /notme. One click, no account needed. Nothing is stored about your visits from then on. The objection applies to the browser you declare it in, because it lives in a cookie — clear your cookies and it is gone and has to be declared again.
Views of our administrative area are not counted. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is in designing this service to meet actual demand. Given the design described above, the impact on your rights is low.
If you create an account, we process your email address and your password. The password is stored only as a hash; we do not know it in plain text. In addition, we process the details you enter in your profile, such as a display name and your choice of character, along with the spaces you are a member of and your role in them.
If you invite others to a space by email, we process the address you provide in order to deliver the invitation. Please only invite people who are happy to receive one.
The legal basis is Art. 6(1)(b) GDPR, as this processing is necessary to perform the user agreement.
Rooms can be entered via a guest link without creating an account. In that case we process the name you give yourself, the character you choose, and a technical identifier that identifies your session for its duration. We do not ask for an email address.
Guest access is time-limited and is deleted automatically once it expires. The legal basis is Art. 6(1)(b) GDPR.
A guest link can also be opened as a Telegram Mini App, in which case the room runs inside the Telegram app instead of in a browser. This applies only if you open a link that way. On every other visit, nothing described in this sub-section happens.
What we receive in return is the display name held by your Telegram profile. We use it to pre-fill the name field at the door and for nothing else — you can overwrite it before you enter, and what is stored is whatever the field says when you walk in, as described above. Your Telegram account also transmits an identifier and, depending on your settings, a username; we neither evaluate nor store either. We do not receive your telephone number, your contacts or your messages, and we do not ask Telegram for them.
The legal basis is Art. 6(1)(b) GDPR: this is the route you chose in order to enter.
What you create in the service is stored: pages and their content, rooms you build, chat messages, game state and comparable input. This content is visible to the members of the space in question and to guests who have been granted access. Please note that chat messages and things you build are visible to everyone present.
When you play a level (an “XP”), we record one entry at the end of the session: which level in which version, when the session began, how long it lasted, which room or match it took place in, and — if you are signed in — your account. We store nothing about how you played: no positions, no input, no scores.
These entries answer one question: how much a level was played. Whoever created a level sees totals only — the number of sessions and how long they lasted altogether — never the individual entries, and never who played when. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is in giving the authors of a level feedback about its use and in shaping the service to what is actually used.
If you delete your account, the reference to you is removed from these entries; the entry itself remains as an anonymous figure, because removing it would retroactively falsify the usage counts of other people’s levels. For guest access this happens automatically once the guest access expires and is deleted.
The service stores changes as an append-only log (“event sourcing”). An entry is never overwritten; a further entry is appended instead. That is the reason content survives a lapsed subscription.
This does not affect your right to erasure. If you request deletion, we delete your account and overwrite the personal details in the affected log entries so that they can no longer be attributed to you. The entry itself remains in anonymised form, because removing it would destroy the state of rooms shared with other people. Please contact us at the address in section 1.
If you write to us via the contact form or the event enquiry form, we process the details you provide there — in particular your name, email address and the content of your message — in order to deal with your enquiry.
The legal basis is Art. 6(1)(b) GDPR where the enquiry is aimed at entering into a contract, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in answering enquiries. We delete enquiries once they have been dealt with, unless statutory retention obligations apply.
For paid subscriptions we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. You enter payment details — card details in particular — directly with Stripe. We neither receive nor store them.
In our own database we store only the Stripe customer id, the subscription id and its status, so that we know which features are unlocked. Stripe may also transfer personal data to the USA; that transfer is based on standard contractual clauses and certification under the EU-US Data Privacy Framework.
The legal basis is Art. 6(1)(b) GDPR. Invoice-related data is retained under Art. 6(1)(c) GDPR for the statutory periods of up to ten years.
System messages such as sign-up confirmations, password resets and invitations are sent via a mail server we run ourselves on our own infrastructure. No external mail delivery provider is involved. There is no open or click tracking, and we do not send a newsletter.
Where we run a contest, we process the data its running requires. For the beta launch contest that is the entrant’s account name on X, the link to their post and the picture published in it; for winners, additionally the email address the voucher is sent to.
Entry happens on X rather than with us: a post is published there publicly, and we see it as any other reader does. We therefore receive the information from a public source rather than from you. What X does with your post and your data follows X’s own terms; X is responsible for that, not us.
The legal basis is Art. 6(1)(b) GDPR — entering creates an obligation whose performance would be impossible without this data. It is used for the contest alone. It is not used for advertising, and entering does not result in your receiving messages from us that have nothing to do with the contest.
We delete the list of entries and the record of the draw three months after the draw; we keep them that long so that a question about the result can still be answered. Records of a prize actually issued form part of our accounts and are subject to retention periods under tax and commercial law of up to ten years (Art. 6(1)(c) GDPR).
The full conditions are in the contest terms.
Beyond the parties named in sections 3, 8, 11 and 13, we do not pass your data to third parties. Disclosure occurs only where we are legally obliged to make it. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR, and your data is not sold.
You have the following rights in relation to us:
Where we process data on the basis of a legitimate interest under Art. 6(1)(f) GDPR — which covers the server logs and the analytics — you have the right to object at any time on grounds relating to your particular situation (Art. 21 GDPR). An informal message to kappaxbeta@gmail.com is sufficient.
You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority competent for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
https://www.lfd.niedersachsen.de
We update this policy when the service or the legal position changes. The version available here is the one that applies.
Last updated: August 2026