Privacy policy
Last updated:
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
GoStonePrivacy contact:
f.neu.dev@gmail.com
Scope and data sources
This policy applies to the GoStone website, web application, APIs, and any GoStone application that links to it. We receive data directly from you, automatically from your device and use of the service, and—in games, blocks, or reports—from the other participating player. We do not purchase personal data from data brokers.
Processing when the service is accessed
When you access GoStone, the hosting infrastructure processes technical request data needed to deliver and secure the service. This can include the IP address, date and time, requested address and search parameters, request method, response status, referrer, user agent, language header, request identifier, and processing region. The purpose is reliable delivery, troubleshooting, and protection against attacks and misuse. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are the secure and reliable operation of GoStone. Vercel runtime logs are retained according to the booked plan for no more than 30 days.
Accounts and authentication
You can create an account with a username and password. We store a generated user ID, username, display name, password hash, creation and update times, and hashed session tokens. We never store the password in plain text, and an email address is not required for this method. The data is used to create and authenticate the account and to retain the profile, ratings, and game history. The legal basis is Article 6(1)(b) GDPR. Guest play remains available.
Alternatively, you can choose Google or Apple sign-in. You are redirected to that provider, which processes the authentication request under its own privacy terms. GoStone receives the provider-specific account identifier, verified email address, and—when supplied—your name. We store the identifier mapping, email and verification status to recognize the account; we do not store provider access or refresh tokens. The legal basis is Article 6(1)(b) GDPR because this processing performs the sign-in method you request.
Playing and platform features
- Guest play and matchmaking: a random guest ID, hashed guest-session token, selected board size, time control, queue status, timestamps, and game assignment are processed to provide the requested match. Legal basis: Article 6(1)(b) GDPR.
- Games: participant identifiers, moves, board positions and hashes, clocks, scoring decisions, result, timestamps, and rule settings are stored to run, resume, validate, score, and review games. Account games also update ratings and rating history. Legal basis: Article 6(1)(b) GDPR.
- Chat: the participant identifier, display name, message of up to 500 characters, game assignment, and timestamp are processed to provide game chat. Messages are visible only to the two participants while chat is available. A local rules-based filter checks messages before storage; rejected messages are not stored. Legal basis: Article 6(1)(b) GDPR.
- Puzzles, bots, and analysis: puzzle selections, attempts, progress, solution status, and timestamps are stored. Bot moves and end-score proposals are calculated locally on your device; only the proposed action is sent to GoStone for rule validation and storage. If you request a KataGo review, the game identifier, rules, moves, and generated analysis are processed by our separate KataGo worker. Legal basis: Article 6(1)(b) GDPR.
Public information and other players
- Your username or display name is shown to opponents. Public leaderboards show account display names, position, rating, game count, and wins. Do not choose a username that reveals information you do not want to make public.
- Game state and chat are disclosed only to the participating players through protected game routes. Aggregate activity counts are public and do not identify individual players.
- We do not sell personal data and do not disclose it for advertising. Further disclosure occurs only to the processors named below, when legally required, or when necessary to establish, exercise, or defend legal claims.
Safety, rate limits, blocks, and reports
To prevent automated attacks, account takeover, spam, and misuse, GoStone creates one-way SHA-256 rate-limit keys from the IP address and, depending on the action, a username or verified player identifier. The raw IP address, cookie, and player identifier are not stored in the rate-limit table. Blocking stores the two player identifiers and blocks future matching and chat. If the reporting function is enabled and a report is submitted, the game, reporter, reported player, fixed report category, and time are stored; no free-text report or copied chat transcript is collected. These processes are based on Article 6(1)(f) GDPR. Our legitimate interests are service security, fair play, protecting users, and enforcing platform rules.
Contact requests
If you contact us, we process your contact details, message, and related communication metadata to answer and manage the request. The legal basis is Article 6(1)(b) GDPR for service- or contract-related requests, Article 6(1)(c) GDPR where a legal duty applies, and otherwise Article 6(1)(f) GDPR based on our legitimate interest in responding to inquiries and documenting relevant communications.
Retention and deletion
We retain personal data only while it is needed for the stated purpose or while legal obligations or legal claims require it. The following criteria apply:
- Account and guest sessions expire after 30 days. Expired database entries are removed periodically; logging out deletes the current account session.
- Waiting matchmaking entries are deleted after cancellation or when stale; a successful match becomes part of the game record.
- Persistent rate-limit keys become eligible for periodic deletion 48 hours after their last update. In-memory rate limits are evicted automatically and disappear when the server instance ends.
- Account data, games, moves, ratings, chat, puzzle progress, and analysis are retained while needed to provide profiles, histories, rating integrity, game review, and shared opponent records. After a justified deletion request, data is deleted or separated from the account where possible; records may remain where the opponent’s rights, platform integrity, legal duties, or legal claims require this.
- Account-player blocks remain until you remove them. Blocks involving a guest become eligible for periodic deletion after 30 days.
- Report records, if reporting is enabled, are retained only while needed for review, user safety, enforcement, or legal claims. Contact communications are deleted when fully resolved unless legal retention or evidence requirements apply.
- Deleted data can remain temporarily in rolling provider backups until the configured backup cycle overwrites it; it is not restored for ordinary operations.
Security
GoStone uses measures appropriate to the risk, including encrypted transport, HTTP-only and secure production cookies, password hashing, hashed session tokens, server-side authorization, input limits, database access controls, row-level security, and restricted worker access. No internet service can guarantee absolute security.
Automated processing and required data
GoStone automatically performs matchmaking, rule validation, scoring, rating updates, chat filtering, rate limiting, and KataGo analysis or bot moves. These functions do not produce decisions with legal or similarly significant effects within the meaning of Article 22 GDPR. We do not create advertising profiles.
Technical request data is necessary to deliver and secure the service. Feature-specific data is necessary only when you use that feature. Without it, the relevant request, account, game, chat, puzzle, or analysis cannot be provided. There is no statutory obligation to provide data.
Changes to this policy
We update this policy when processing activities, providers, or legal requirements change. The current version and its date are always available on this page. Material changes are communicated in an appropriate manner before they take effect where required.
Cookies and device storage
GoStone currently uses only first-party cookies needed for authentication, guest play, and the language selected by the user. They are based on Section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG); subsequent personal-data processing is based on Article 6(1)(b) GDPR or, for security, Article 6(1)(f) GDPR.
| Name | Purpose | Duration |
|---|---|---|
gostoned_session | Authenticates an account session; the server stores only a hash of the token. | 30 days; deleted earlier on logout |
gostone_guest_session | Authenticates a randomly generated guest identity for play and puzzles. | 30 days |
gostone_oauth_google / gostone_oauth_apple | Temporarily binds a Google or Apple sign-in response to the browser that started it and prevents login request forgery. | 10 minutes; deleted after the callback |
gostone_locale | Remembers the language explicitly selected by the user. | 1 year |
No analytics, advertising, cross-site tracking, or social-media cookies are used. GoStone does not currently use localStorage for personal data. If optional technologies are added later, this policy and any required consent mechanism will be updated before activation.
Processors and international transfers
We use the following providers under data-processing agreements. They may use their documented subprocessors only to provide their services:
Vercel Inc.
Website hosting, content delivery, server functions, request routing, security, and runtime logs.
Provider privacy informationSupabase
Managed PostgreSQL database, database connection pooling, operational database logs, and rolling backups in the project region selected by the operator.
Provider privacy informationModal Labs, Inc.
Isolated cloud execution of the KataGo worker for requested game analysis and puzzle generation. Normal bot moves are calculated locally in the browser and are not sent to Modal. Relevant analysis positions and moves are processed in worker memory; logs are retained according to the Modal plan.
Provider privacy informationVercel, Supabase, Modal, or their subprocessors may process data outside the European Economic Area, including in the United States or Singapore. Where no adequacy decision applies, transfers are protected by the European Commission’s Standard Contractual Clauses under Article 46 GDPR and, where necessary, supplementary safeguards. You may request information about the applicable safeguards from the controller.
Your rights
Subject to the legal requirements, you have the following rights regarding your personal data:
- access and a copy of your data (Article 15 GDPR);
- rectification of inaccurate data (Article 16 GDPR);
- erasure where the legal conditions are met (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability for data processed by automated means on the basis of a contract or consent (Article 20 GDPR);
- objection at any time, on grounds relating to your situation, to processing based on Article 6(1)(f) GDPR (Article 21 GDPR);
- withdrawal of consent at any time for future processing, if processing is based on consent; GoStone currently uses no optional consent-based tracking;
- a complaint to a competent data protection supervisory authority, particularly in the country of your habitual residence, workplace, or the alleged infringement (Article 77 GDPR).
Send requests to the privacy contact shown above. We may request information needed to verify your identity. Exercising your rights is generally free of charge; statutory exceptions remain unaffected.