Privacy Policy

Last updated: January 18, 2026

1. Controller

Marcel Krück
Hauptstraße 46
63546 Hammersbach
Germany
Email: contact.gamoody@gmail.com

2. Data We Collect and Process

2.1 Account Data (Steam Login)

When you log in via Steam OpenID, we collect and store:

  • Steam ID (unique identifier from Steam)
  • Login timestamps (first login, last login)

Legal basis: Art. 6(1)(b) GDPR (necessary for contract performance - providing our service)
Purpose: Authentication, user account management, game recommendations
Storage duration: Until you delete your account or request deletion

2.2 Game Data

After login, we automatically synchronize your Steam games:

  • App IDs (game identifiers)
  • Playtime (total minutes played)
  • Last update timestamp

Legal basis: Art. 6(1)(b) GDPR (necessary for providing personalized game recommendations)
Purpose: Provide personalized game recommendations
Storage duration: Until you delete your account
Third-party access: We retrieve this data from Steam's public API

2.3 Analytics Data (with your consent)

If you accept analytics cookies, we track:

  • IP address (anonymized after 7 days)
  • Page views (visited pages, timestamps)
  • User agent (browser/device information)
  • Referrer (page you came from)

Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner)
Purpose: Improve website performance, understand user behavior
Storage duration: 90 days, then automatically deleted
Your choice: You can decline analytics via the cookie banner (Essential Only)

2.4 User Questions/Feedback

When you submit questions via our input form, we store:

  • Question text
  • IP address
  • Steam ID (if logged in)
  • Timestamp

Legal basis: Art. 6(1)(a) GDPR (your voluntary submission implies consent)
Purpose: Improve our AI recommendation system, respond to feedback
Storage duration: 2 years, then automatically deleted

2.5 Server Log Files

Our hosting provider automatically logs:

  • IP address
  • Date/time of access
  • Requested pages/files
  • Browser type and version
  • Operating system

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security and error analysis)
Purpose: Technical provision, IT security, error analysis
Storage duration: 7 days, then automatically deleted

3. Cookies and Local Storage

3.1 Essential Cookies (always active)

  • gamoody_session - Authentication cookie for login (30 days)

3.2 Analytics Cookies (require consent)

  • Tracking cookies for page view analytics (see section 2.3)

3.3 Local Storage

  • gamoody_cookie_consent - Stores your cookie preference (Essential Only / Accept All)

You can manage your cookie consent via the cookie banner or delete cookies in your browser settings.

4. Third-Party Services

4.1 Steam (Valve Corporation)

  • Service: Steam OpenID authentication, Steam Web API
  • Data shared: Your Steam ID (only when you click "Login with Steam")
  • Privacy Policy: https://store.steampowered.com/privacy_agreement/
  • Purpose: User authentication, retrieve public game library data

4.2 Steam Store API

  • Service: Retrieve game images and videos
  • Data shared: Game App IDs (no personal data)
  • Purpose: Display game media on our website

5. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • HTTPS encryption for all connections
  • Secure session management (httponly, secure, samesite cookies)
  • Database access controls
  • Regular security updates

6. Data Sharing

We do not sell your personal data. We only share data with:

  • Steam/Valve - only when you log in (Steam ID)
  • Hosting provider - for technical infrastructure (server logs)

7. Your Rights (GDPR)

You have the right to:

  • Access (Art. 15) - Request a copy of your stored data
  • Rectification (Art. 16) - Correct inaccurate data
  • Erasure (Art. 17) - Delete your account and all associated data
  • Restriction (Art. 18) - Limit processing of your data
  • Data Portability (Art. 20) - Receive your data in a structured format
  • Objection (Art. 21) - Object to data processing
  • Withdraw Consent (Art. 7(3)) - Revoke analytics consent anytime

To exercise your rights, contact: contact.gamoody@gmail.com

8. Right to Complain

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

German supervisory authority:
Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit
Graurheindorfer Str. 153
53117 Bonn
Germany
Website: https://www.bfdi.bund.de

9. Children's Privacy

Our service is not intended for users under 13 years of age. We do not knowingly collect data from children under 13.

10. Changes to This Privacy Policy

We may update this privacy policy. The "Last updated" date at the top indicates the latest revision. Continued use after changes constitutes acceptance.

11. Contact

For privacy-related questions:
Email: contact.gamoody@gmail.com

← Back to Home