← Back to FINGERPOINT

Privacy

Privacy policy under Art. 13 GDPR

Who is responsible

FINGERPOINT, c/o POSTFLEX PFX-999-484, Emsdettener Straße 10, 48268 Greven, Germany. E-mail: fingerpoint.space@gmail.com

No account, no profile

You never register. A room needs a display name you type yourself and nothing else. We do not ask for e-mail, phone number, contacts or location, and we do not build a user profile.

Game data: 24 hours, then gone

Question, display names, avatars and the individual votes of a room exist only while the round is live. They are deleted automatically within 24 hours of the room being created. Nobody can look up an old room afterwards.

Legal basis: Art. 6 (1) (b) GDPR — we cannot run the game you asked for without this data.

IP addresses: only as a hash, only against abuse

To stop spam and automated room creation we store a one-way cryptographic hash of the IP address of a request. The IP address itself is never written to our database and the hash cannot be turned back into an address. These abuse records are short-lived.

Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in a service that stays usable.

Anonymous statistics we keep permanently

To understand how FINGERPOINT is used and which questions work, to improve the service, and to produce aggregated, anonymous trend and benchmark information that we may publish or provide to third parties such as business customers, we keep aggregated, anonymous statistics after a round ends: how many people took part, how many voted, how clear the result was, how long it took, plus coarse context derived from the request at the moment it happens — country, browser language, device type (mobile, tablet, desktop) and the channel a visit came from (for example WhatsApp, search, direct).

These records contain no IP address, no display names, no individual votes, no room code and no link back to a specific round or person. They cannot be traced to you.

Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in measuring and improving the service.

Questions are analysed anonymously

The text of a question is stored once per distinct question, together with anonymous performance figures such as how often it was played and how clearly it split a group. We use this to improve the question library, to build better suggestions, and — in aggregated, anonymous form — to describe how the platform performs and in commercial products, reports or insights for third parties.

Before a question is stored, personal names are automatically detected and replaced with the placeholder [NAME]. A question naming a real person is therefore never kept in readable form.

No tracking cookies

We use no advertising cookies and no cross-site tracking. Measurement happens on our own infrastructure. Returning visits are counted with a hash that rotates every day, so nobody can be followed over time. Only technically necessary storage is used to keep your session in a room alive.

Processors

Hosting and application delivery, the database and authentication service, the AI provider used to generate suggested questions, and — only if you ever use a paid feature — a payment provider. Question text sent for AI generation is processed for that request only and is not linked to you. All processors are bound by data processing agreements.

Your rights

You may request information, correction, deletion, restriction, data portability and object to processing based on legitimate interest (Art. 15–21 GDPR), and you may complain to a supervisory authority. Because the anonymous statistics contain no personal data, they cannot be assigned to an individual and are therefore outside the scope of an access or deletion request.

Changes

We update this page when the service changes. The current version always applies.

See also Terms and Legal Notice.