Privacy Policy
Ця сторінка англійською. Якщо переклад відрізняється, діє англійський текст.
Esta página está en inglés. Si una traducción difiere, se aplica el texto en inglés.
Last updated: October 5, 2026
1. Introduction
BIGBOARD.GAMES ("we", "our", or "us") is the controller of the personal data described here. BIGBOARD.GAMES is operated by its founder as an independent business. This policy explains what we record when you visit bigboard.games or play its games, why, who else processes it, how long we keep it, and how to see, change or delete it.
In short:
- You can play without an account. To us, a player is a random device id, not a person we can name. If you sign in, we also hold your email address and link your play to your account.
- We record basic play data for every player: which games are played, at which table, on which devices, with the results, the times and an approximate location (city level at most). We don't keep IP addresses in our records.
- Games run directly between the devices at your table, never through our servers.
- No ads, no advertising cookies, and we don't sell your data. We email you about new games only if you ask.
- You can delete your account at any time: Profile › Delete account.
2. Information we collect
When you play (no account needed)
- A device id. Your browser creates a random id on your first visit and keeps it on your device. Our server stores only a salted hash of it (the "device key"), to tell devices apart, keep your seat at a table and count returning players.
- Your player name, face and preferred color. They start out generated, and you can change them. The other devices at your table see them, and so do devices on the same network in the list of nearby tables. Play records keep the name and color you played under.
- Device details: the kind of device, its model when the browser reports it, its screen size, the browser and its version (the "user agent"), the language and the app version.
- Tables: each table's random id, when it opened and closed, which devices joined, how (a code, a QR code, a link, the nearby list or a knock), when they joined and left and why, and how many matches were played.
- Matches: the game, mode and options, how the devices were arranged, when the match started and ended and how, each seat's result and score, whether a player left early, the game's random seed, the app version, and how the devices were connected (directly or through a relay) with measured delays. Games played on a single device are recorded the same way, reported by your device.
- Approximate location. For each connection, Cloudflare, our host, tells us the country, region, city, continent and time zone it comes from, and which Cloudflare data center handled it. We store that, never the IP address, and nothing finer than the city. It is often wrong: a VPN or a mobile network can place you in another city.
- Where you came from: on your first visit, the site that sent you, campaign tags in the link (such as
utm_source) and the page you landed on. A link shared from a table also says it was shared and which app opened it. - First and last seen: the first and the most recent day each device used the service.
If you create an account (optional, 16 and over)
- Your email address. With Google, also your name, profile photo and Google account id, as Google shares them; we ask only for
openid email profile. Your Google photo becomes one of your faces, and the devices at your table load it straight from Google. - Your saved profile: name, face, preferred color, language, your best score in each game, and the link to your Google photo, if any. The "where you came from" details are copied to your account when you sign up.
- Sign-in history: when you signed in, how (Google or an email link), from which device (its device key and browser) and from roughly where (city, region, country).
- Sessions: a hash of the token in your sign-in cookie, when the session started, was last used and expires, and the browser.
- Email sign-in requests: the address, the device that asked (such as "iPhone · Safari"), its user agent, approximate location and time zone (shown in the email, so you can check it was you), a salted hash of its IP address (to limit requests per network), and when the link was sent and used.
- Your email choices: whether you asked for news about new games or for a game's launch email, when, where in the app, and the exact wording you agreed to; also when you unsubscribed. An address counts as confirmed once you open the sign-in link we send to it.
- Emails we send you: the kind of email, when, and whether our email service accepted it.
What you send us
- Feedback: a thumbs up or down after a match, notes and messages, and an email address if you want a reply (used only to answer you). Each carries the app version, your language and the game or screen it is about. With "Include device details" on, a message also carries your device, browser, connection type and the last 2 minutes of connection events (no names, table codes or locations). We also store the device key, and your account id if you're signed in.
- Game ideas and votes (signed in): each idea's title and description, who posted it, and who voted for what. Approved ideas appear on the public ideas board with their vote count, without your name.
- Emails to hello@bigboard.games: your message and your address.
Only on your device
Your browser keeps these on your device and sends them to us only as described above: the device id; your name, face and color; your settings; the devices and tables you've played with, so you can rejoin and merge tables; tables you chose not to merge with; your seat at the current table; a recent log of connection events; a draft game idea; feedback waiting for a connection (up to 7 days); the ideas board as you last saw it (up to 24 hours); which tips you've seen or dismissed; and the app's files for playing offline. Clearing this site's data in your browser removes all of it, and you start again with a new device id.
3. How your devices connect
- Your IP address is used, not stored in our records. While our server handles a request, it uses your IP address to limit floods of requests and to find devices on the same network for nearby tables. Cloudflare's logs of requests to our server may include it (see §7).
- Finding your public address. To find devices nearby, the app and our home page ask two address-echo services run by Cloudflare (icanhazip.com and 1.1.1.1) which public address your device connects from.
- Nearby tables and knocks. While a device has BIGBOARD.GAMES open, our nearby server stores, under a salted hash of each network address the device is on (never the address itself): its device key, its network operator's number (ASN) and what kind of operator that is, what kind of device it is (phone, tablet, computer), the name, face and color it shows, when it arrived and was last seen, the device keys it chose to keep apart from, and, when it hosts a table, the table's code, how many players and open seats it has, whether a game is under way and which game it's on. A knock stores the knocking device's key, the network hash, the table's code, the time and the answer. Two devices that have played together before, each alone at a table on the same network, join into one table by themselves; either can leave it again. On a home network, a device that opens BIGBOARD.GAMES can join a table there by itself (Leave takes it back out).
- Devices at a table connect directly. Games use WebRTC, device to device. To find a path, the devices exchange their network addresses, IP addresses included, through our table server, which passes them on without storing them. So the other devices at your table can see your IP address, as with any direct connection. When no direct path exists, they connect through Cloudflare's relay (TURN), which forwards the encrypted traffic without seeing the game.
- Compass and motion. Some steps and games read your device's compass or motion sensors. The readings stay with the devices at your table; our table server may pass them on, but we don't store them.
4. How we use your information, and why we may
- To run the service: tables, connections, nearby tables, relays, holding your seat when you drop, and results. Basis: our legitimate interest in providing the service you use (GDPR Art. 6(1)(f)); for account holders, our contract with you, the Terms (Art. 6(1)(b)).
- To keep it safe: rate limits, the bot check, stopping abuse, finding and fixing errors. Basis: legitimate interest.
- To understand and improve it: which games get played, on which devices and networks, where matches drop or players leave, and which links bring players who come back. Basis: legitimate interest.
- For leaderboards and replays later: results and game seeds are kept so they can come later. Basis: legitimate interest. We'll update this policy before anything about you appears publicly.
- Your account: sign-in, sessions, your profile on every device, and the sign-in and account-deletion emails. Basis: contract.
- Emails about new games: only if you tick the box or say yes when we ask. Basis: your consent (Art. 6(1)(a)), which you can withdraw at any time.
- A game's launch email: when you tap Get notified on a coming-soon game with "Email me when {game} comes out" ticked, we email you once when it comes out, and that subscription ends. Basis: your consent, given by that tap.
- Feedback, ideas and emails to us: to read them, answer you and run the ideas board. Basis: legitimate interest; for ideas posted from an account, also the contract.
- Legal duties: answering lawful requests and keeping records the law requires. Basis: legal obligation (Art. 6(1)(c)).
Why recording play data is fair to you. There is no setting that turns play records off, so here is why our interest in them doesn't override yours: they are what you'd expect a game service to record; a player is a random device id unless you sign in; we keep no IP addresses in our records and location only to city level; there are no ads, no selling, no marketing profiles and no tracking across other sites; analytics run without cookies or person profiles; detailed records are kept for a limited time (§7); and you can object at any time (§9).
5. Cookies and analytics
BIGBOARD.GAMES sets one cookie:
__Host-session: set only when you sign in. It keeps you signed in on that browser for 90 days from the last time you used it, can't be read by page scripts, and goes when you sign out. Accounts can't work without it.
That is the entire list: no advertising or tracking cookies, so there is no cookie banner. The app also keeps the device id, your settings and the rest of §2 "Only on your device" in your browser's local storage, which it needs to work. Google sets its own cookies on google.com when you sign in with Google, and Cloudflare's bot check on email sign-in (Turnstile) may store its own data; both follow their own policies.
Analytics, without cookies
- PostHog (its EU cloud) receives a fixed list of events from the app, such as "game opened" or "sign-in started", and errors the app runs into. For a sample of visits it also records the screen (a "session replay") so we can see where people get stuck: what you type is masked, and recording pauses during matches and on any address that names a table. A replay can still show what was on screen, such as the names and faces at your table.
- Events carry your device key, and your account id once you sign in, so we can match them with your play records. PostHog stores nothing on your device and keeps no person profiles.
- The app sends events through our own server, which passes on neither your IP address nor any cookie, and PostHog is set to discard IP addresses.
- If your browser sends a Do Not Track signal, PostHog doesn't load.
- Cloudflare Web Analytics counts page views (the page, the referring site, the browser, the country, how fast it loaded), without cookies.
6. Sub-processors
We keep the list of companies that process data for us short, and we name all of them:
- Cloudflare — hosting, our servers and database, security checks, analytics, the connection relay and email.
- PostHog — usage analytics, stored in the European Union.
- Google — sign-in when you choose "Continue with Google", and our email inbox.
- Telegram — internal notifications for our team.
Each processes your data only to provide the service we use it for. Our database runs at Cloudflare in Europe; requests are handled at the Cloudflare location nearest you, so a table server or relay may run in your region. Cloudflare and Google are US companies: transfers to them rely on the EU–US Data Privacy Framework where the company is certified, and otherwise on the European Commission's Standard Contractual Clauses (and their UK and Swiss equivalents). We don't sell personal data and don't share it for advertising. We disclose it only when the law requires it, to protect players or the service from abuse, or to a new owner if the service is ever transferred, and we'd tell you before that happens.
7. Data retention
We keep personal data only for as long as it is doing something:
| What | How long |
|---|---|
| An email address never confirmed (its sign-in link never opened) | 30 days |
| Email sign-in requests, including the IP hash | 1 day |
| Sessions | Until you sign out, or 90 days without use |
| Your account, saved profile and email choices | Until you delete your account; an account unused for 3 years is deleted after a warning email |
| A game's launch subscription | Until its launch email is sent |
| Nearby presence and table listings | 10 minutes after the device's last update, then deleted within the hour |
| Knocks on nearby tables | About 10 minutes |
| Sign-in history | 2 years, or until you delete your account |
| Play records: tables, matches, seats, single-device games, devices | 25 months in full; after that, only totals with no device key, account, name or city |
| Feedback | 2 years; a reply address only until we've answered, at most 1 year |
| Game ideas | Approved ideas stay on the board; ideas never approved, 1 year |
| The log of emails we sent | 1 year |
| PostHog events and session replays | 12 months and 30 days |
| Cloudflare's logs of requests and errors (which may include IP addresses) | Up to 7 days |
| Database backups | 30 days |
8. Deleting your account
Profile › Delete account (tap your avatar in the app) deletes, right away, your account, email address, saved profile and Google photo link, sessions, sign-in history, email choices, subscriptions, votes, and the log of emails we sent you. We send one email to confirm it.
Some records stay, without your email address:
- Play records keep only the random device key, like any signed-out player's.
- PostHog events keep your account id and device key until they expire (12 months).
- Feedback you sent stays without your account, and any reply address is deleted.
- Approved ideas stay on the board, anonymous; ideas still in review are deleted.
Deleted data is gone from our backups within 30 days. To also remove a device's play records, write to us.
9. Your rights
Depending on where you live, you may have the right to:
- Get a copy of the personal data we hold about you, in a machine-readable file if you like
- Correct it (you can edit your profile in the app yourself)
- Delete it (Profile › Delete account, or write to us)
- Object to how we use it on the basis of our legitimate interest, play records and analytics included; we'll stop for your device or account unless we have a compelling reason, such as investigating abuse
- Restrict its use while we look into a complaint
- Withdraw consent to emails: use the one-click unsubscribe link in any of them, or untick the box in Profile
- Complain to your local data protection authority
To exercise any of these, write to hello@bigboard.games, from the address on your account if you have one, and we will answer within 30 days, free of charge. We may ask you to confirm it's you. Signed-out play sits under a random device id, so we can find it only if you can show us which device it belongs to; write to us and we'll work it out with you.
If you live in a US state with a privacy law (such as California), you have similar rights to know, delete and correct your data. We don't sell personal information or share it for cross-context behavioral advertising, and we won't treat you differently for using your rights.
We make no automated decisions about you with legal or similarly significant effects. Rate limits and the bot check slow or block traffic that looks like abuse; if that blocks you, write to us.
10. Children
Accounts are for people 16 and over, and the sign-in sheet asks you to confirm it. Playing never needs an account. We don't ask anyone's age, so younger players' games are recorded like everyone's: under a random device id, without a name we know or an email address. If you believe a child under 16 has given us an email address or created an account, write to us and we'll delete it.
11. Security
We use HTTPS everywhere. Session and sign-in tokens are stored only as hashes, device ids only as salted hashes, and sign-in links work once, for 15 minutes. Only we can reach the admin tools and the database. No system is perfectly safe; if a breach puts your data at risk, we'll tell you and the authorities as the law requires.
12. Changes to this policy
We'll update this page when what we collect, or why, changes, with a new date at the top. Before a significant change takes effect, we'll say so in the app and email account holders. If a translation of this policy differs from the English version, the English version applies.
13. Contact
If you have any questions about this policy or your data, write to hello@bigboard.games.