Privacy Policy
Last updated: 2026-07-19
Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data-protection laws is:
Marco Manzari
Koppoldstr. 1 · 86551 Aichach · DE
Email: mail@metadeath.me Phone: +49 30 55570662
Provision of the website and server log files
Each time you visit our website, our hosting provider automatically captures technical information that your browser transmits. This is stored temporarily in so-called log files:
- IP address of the requesting device
- Date and time of access
- Name and URL of the requested file
- Volume of data transferred and HTTP status code
- Browser type and version, operating system
- Referrer URL (the previously visited page)
Processing is carried out on the basis of Art. 6(1)(f) GDPR. The legitimate interest of Marco Manzari is the secure and stable operation of the website and the prevention of attacks. Log files are automatically deleted after 30 days, unless a security incident requires longer retention.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
Cookies
We set technically necessary cookies so that our website functions correctly. These cookies are required for the operation of the site (e.g. for storing language preferences or for load balancing) and are placed without consent on the basis of § 25(2) No. 2 TDDDG.
We only set technically necessary cookies and do not use any non-essential cookies.
You can completely deactivate the setting of cookies in your browser at any time or delete cookies that have already been set. Instructions can be found in your browser's help function.
Legal basis: § 25 TDDDG (Germany) and Art. 6(1)(f) GDPR (legitimate interest)
Data processors
To carry out our tasks, we use carefully selected service providers who process personal data on our behalf ("data processors" pursuant to Art. 28 GDPR). A data-processing agreement (DPA) is in place with each of these providers.
| Provider | Purpose | Country | DPA |
|---|---|---|---|
| Hetzner Online GmbH | Hosting und Datenbank (Server, PostgreSQL) | DE | Agreement |
| Scaleway SAS | Domain, DNS und transaktionaler E-Mail-Versand | FR | Agreement |
| Migadu Email AB | E-Mail-Postfach für die Kontaktadresse | CH | Agreement |
Our website is hosted with Hetzner Online GmbH (DE).
Retention period
We retain personal data only for as long as is necessary for the respective processing purposes or as required by statutory retention periods (in particular under § 257 HGB and § 147 AO — typically 6 or 10 years).
Specific retention periods for individual processing activities are set out in the relevant sections of this privacy policy.
Game sessions, callsigns and room state
To run a game you have joined, our server processes:
| Data | Why |
|---|---|
| The callsign you type | Free text of your choosing. It labels your seat and is shown to everyone else at your table. |
| A session token | 24 random bytes, generated by us and held on your device. It returns you to your seat after a disconnect. It is tied to nothing else — there are no accounts. |
| The events of the running game | Seat order, roles, nominations, votes and phase changes, kept as an append-only log so a game survives a dropped connection or a server restart. |
| Notes a game master writes into that log | Free text, entered at the game master's discretion and visible only to them. |
A callsign is free text: if you type your real name, your real name is what we process. We ask for nothing else — no account, no email address, no telephone number, no date of birth.
Legal basis: Art. 6(1)(b) GDPR — this processing is what running the session you requested consists of.
Retention. Room state is deleted, not archived. A room and everything attached to it — callsigns, tokens, event log, game-master notes — is erased from both the server's memory and its database at the latest 30 minutes after the last participant disconnects, and in every case no later than 12 hours after the room was created. A sweep runs every five minutes. Room state is not backed up and is not copied anywhere else.
Application logs record room codes, player counts and game durations for operational purposes. They contain no callsigns and no session tokens.
Data stored on your device
The app keeps one entry, named meta-death-prefs, in your browser's local storage — or, in the mobile app, the equivalent local store. We set no cookies and use no analytics, tracking or advertising identifiers of any kind.
| Entry | Purpose | Lifetime |
|---|---|---|
nickname | Prefills the callsign field so you need not retype it. | Until you change it or clear your browser data. |
lastSession | Room code and session token, so you can rejoin after closing the tab. | Expires 30 minutes after the session ends, matching the server's room retention. |
note | A game master's scratch note for the room currently in play. Never leaves your device. | Deleted when you leave the room. |
showScript | Whether the read-aloud game-master script is shown. A display preference. | Until you change it or clear your browser data. |
All four are strictly necessary for the service you asked for, so under § 25(2) No. 2 TDDDG they are stored without consent. You may delete them at any time by clearing site data in your browser, or by uninstalling the app.
The mobile app
The iOS and Android app is the same client as the website and processes the same data as above. It contains no advertising SDK, no analytics SDK and no crash-reporting SDK; it reads no device or advertising identifier, sends no push notifications and asks for no system permissions. If you install it from Apple's App Store or Google Play, that download is a transaction between you and the store concerned, governed by that store's own privacy policy — we receive no personal data from it.
Your rights as a data subject
You have the following rights at any time with regard to your personal data:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of incorrect or incomplete data (Art. 16 GDPR)
- Erasure of your data ("right to be forgotten", Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of a consent given with effect for the future (Art. 7(3) GDPR)
To exercise these rights, an informal notification to mail@metadeath.me is sufficient.
Independently, you have the right to lodge a complaint with a data-protection supervisory authority (Art. 77 GDPR; see below).
Right to Object (Art. 21 GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to the processing of your data, where such processing is carried out on the basis of legitimate interests (Art. 6(1)(f) GDPR) or in the public interest (Art. 6(1)(e) GDPR).
Where your data are processed for the purposes of direct marketing, you have the right to object at any time and without giving reasons. After your objection, your data will no longer be processed for that purpose.
You may submit your objection informally to: mail@manzari.dev
Right to lodge a complaint with a supervisory authority
Under Art. 77 GDPR you have the right to lodge a complaint with a data-protection supervisory authority concerning the processing of your personal data — in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement.
Competent supervisory authority for the controller:
Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59-61, 10555 Berlin