Privacy policy
Version 1.1 · Effective 6 July 2026
Who is responsible
Boardgame Tracker is a free, non-commercial hobby service operated by a private individual based in the Netherlands (the “controller” in GDPR terms). For anything in this policy — questions, complaints, or exercising your rights — contact boardgametracker-47c0d@googlegroups.com.
What we collect
- Account data — your email address, display name, unique handle, and sign-in provider (Google or email/password). If you upload a profile picture, we store the cropped image.
- Social data — your friends list, friend requests, and any private nicknames you give friends (visible only to you).
- Content you create — game sessions (date, time, and the free-text “where” you enter), recorded plays (who played, winners, scores, notes), your game library, collections, and tags.
- Names of people without accounts — if you add a “guest” or type a one-off player name, we store that name as part of your sessions and plays. If someone has stored your name this way and you want it removed, email us.
- Technical data — sign-in metadata (such as IP address and last sign-in time, kept by Firebase Authentication), server request logs and technical error reports (kept up to about 90 days — see “Error and diagnostic logs” below), and abuse-prevention signals (see “Keeping the service safe” below).
We keep anonymous, aggregate usage counts (for example, the total number of accounts, or how many games are added, sessions created, or pages viewed per day) with no cookies, no identifiers, and no IP stored — they count events, not people, and can’t be traced back to you. We do not use advertising trackers, we do not profile you, and we do not sell data.
Why we process it (legal bases)
- Providing the service — storing and showing your library, sessions, plays, and friends is the product itself (GDPR art. 6(1)(b), performance of a contract).
- Keeping the service safe — abuse prevention, rate limiting, and request attestation (GDPR art. 6(1)(f), legitimate interest: keeping a free service affordable and available).
We do not use your data for marketing.
What other users can see
- Sessions and plays are shared with the people in them: every participant of a session can see its details, its recorded plays, and the names of the other participants. Leaving a session replaces your name with “[deleted user]”.
- Your display name, handle, and profile picture are visible to other signed-in users (that’s how friends find you). Your email address is not — it is never stored in the profile other users can look up.
- Profile pictures are served via hard-to-guess public links — anyone holding the exact link can view the image.
Error and diagnostic logs
When something goes wrong we record a technical error report — an error message and stack trace, and the page it happened on; server-side logs may also include limited technical data such as an IP address. We use these only to diagnose faults and keep the service secure (GDPR art. 6(1)(f), legitimate interest), never to track you or build a profile. Error reports carry no account identifier, and logs are kept for a limited period (up to about 90 days) before automatic deletion. This stays within our existing Google Cloud infrastructure — it adds no new third party and sets no cookies.
Keeping the service safe (reCAPTCHA)
The app uses Firebase App Check with Google reCAPTCHA v3 on every page to verify requests come from the real app and not from abusive scripts. reCAPTCHA sets a cookie (_GRECAPTCHA) and analyses interaction signals; Google processes this data as described in Google’s privacy policy. We rely on legitimate interest (fraud and cost-abuse prevention) for this; it is the only third-party script in the app.
Who processes your data, and where
The app runs on Google Firebase / Google Cloud (Google as our processor under the Google Cloud Data Processing Addendum): Authentication, the Firestore database, file storage, and server hosting. The database is located in the European Union (multi-region eur3). Some processing (such as authentication and request handling) involves Google LLC in the United States; those transfers are covered by the EU-US Data Privacy Framework and EU Standard Contractual Clauses.
Game metadata (titles, images, player counts) is fetched from BoardGameGeek by our server. These requests normally include no personal data. The one exception is the optional “Import from BoardGameGeek” feature: if you use it, we send the BGG username you type so we can fetch that public collection. We use the username only for that import and do not store it; BoardGameGeek is an independent service with its own privacy policy.
How long we keep it
- Account and content data — for as long as your account exists, deleted or anonymized when you delete your account (or on request, see below).
- Server request logs — roughly 30 days (Google default).
- Abuse-prevention counters — minutes to hours.
Your rights
Under the GDPR you can ask for access to your data, correction, deletion, a machine-readable export, or object to processing. Most of this is self-service: correct your profile and content in the app, and use Settings → Your data to download everything (JSON, plus a CSV play log) or to delete your account — deletion removes your profile, library, collections, guests, friendships and sign-in, and anonymizes your seats in shared sessions to “[deleted user]”. For anything else, email boardgametracker-47c0d@googlegroups.com and we will handle it within 30 days.
You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
No automated decisions
The app makes no automated decisions about you and does no profiling. The “pick a game for us” feature runs entirely on the game data in your own library.
Age
Boardgame Tracker is not directed at children. You must be 16 or older to create an account.
Changes to this policy
If the app starts processing new kinds of data or using new services, this policy will be updated first and the version number above will change. Material changes will be announced in the app.