Privacy policy
Last updated: 2026-08-25
Note for the operator: the details of the responsible party are missing. Set them as environment variables (LEGAL_OPERATOR_NAME, LEGAL_STREET, LEGAL_POSTAL_CODE, LEGAL_CITY, LEGAL_EMAIL) – without them the imprint is incomplete.
This policy describes what data Perfume Guesser processes and why. The short version: as little as possible. There is no advertising, no analytics, no tracking and no sharing of data for advertising purposes.
1. Responsible party
Responsible for data processing on this website:
2. What happens when you simply open the site
When you open a page, your browser transmits technically necessary data to our host: IP address, date and time, the address requested, browser type and operating system. These server logs serve secure operation and troubleshooting.
The legal basis is Art. 6(1)(f) GDPR – our legitimate interest in a functioning and secure service. Our host keeps these logs only briefly.
No fonts, scripts or images are loaded from third-party servers. Opening the site therefore creates no connection from your browser to Google, to a content delivery network or to any other third party.
3. Cookies
We only use cookies that are necessary to run the game. There are no advertising or analytics cookies. That is also why there is no consent banner: strictly necessary cookies do not require consent under § 25(2)(2) TDDDG.
| Name | Purpose | Duration |
|---|---|---|
| pg_player | Holds a random identifier so your progress survives without an account. No name, no third-party identifier. | 1 year |
| pg_locale | Remembers the chosen language (German or English). | 1 year |
| better-auth.session_token | Only after signing in: keeps your session alive. | 30 days |
| better-auth.state, better-auth.pkce_code_verifier | Only during a sign-in: protect the sign-in process against tampering. | a few minutes |
You can delete cookies in your browser at any time. Without pg_player anonymous progress is lost; without the session cookie you are signed out.
4. Playing without an account
Even without signing in we store your game history so that streaks and statistics work. It is linked to the random identifier in the pg_player cookie – not to your name, your email address or your IP address.
We store:
- which perfume a round was about and which game mode it belongs to
- your guesses, the hints you bought, the score and whether you solved it
- when the round started and ended
- figures derived from that: rounds played, hit rate, streak, rating and rank
- a display name you chose yourself, if you entered one
The legal basis is Art. 6(1)(b) GDPR – without this data the game features you asked for would not exist.
5. Signing in with GitHub or Google
Signing in is optional. It makes your progress apply across all your devices. No password is created and none is stored.
When you sign in you are redirected to GitHub or Google. The sign-in happens there; we never see your password. After a successful sign-in we receive and store:
- the name held there
- your email address and whether the provider reports it as verified
- the address of your profile picture
- the identifier of your account at that provider
- the provider's access tokens, for as long as the session lasts
For each session we additionally store a random session key, its expiry, and the IP address and browser identification of the device you signed in with. This serves security: it makes unauthorised access recognisable.
The legal basis is Art. 6(1)(b) GDPR. Opening the sign-in page does not yet transmit anything to GitHub or Google – that only happens once you click one of the two buttons.
Processing at the providers themselves is governed by their own privacy policies: GitHub Inc. (docs.github.com/site-policy) and Google Ireland Limited (policies.google.com/privacy).
6. Leaderboard
The leaderboard for the daily puzzle shows display name, score, number of guesses and number of hints. Without a display name you appear as “Anonymous”. You can change or remove the name at any time under “Stats”.
7. Service providers
We do not run the application on our own servers. The following providers process data on our behalf; data processing agreements under Art. 28 GDPR are in place with both:
| Provider | Role | Place of processing |
|---|---|---|
| Vercel Inc., USA | Running the website, serving pages, server logs | European Union, plus transfers to the USA |
| Neon Inc., USA | Database (game progress, accounts, sessions) | Frankfurt am Main, Germany (AWS eu-central-1) |
Where data is transferred to the USA, the transfer is based on the European Commission's standard contractual clauses and/or the provider's certification under the EU-US Data Privacy Framework.
8. How long we store data
- Sessions expire after 30 days at the latest and become invalid.
- Account data is stored for as long as your account exists.
- Game history is stored for as long as it belongs to an existing account or an active cookie identifier.
- Our host's server logs are deleted automatically after a short period.
On request we delete your account together with all associated game data. An informal message to the address above is enough.
9. Your rights
You have the following rights:
- access to the data stored about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing based on legitimate interests (Art. 21 GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority – either where you live or where the responsible party is based.
10. What we do not do
- We use no analytics or statistics tools.
- We show no advertising and embed no ad networks.
- We do not sell data and do not share it for advertising purposes.
- We load no fonts or scripts from third-party servers.
- We make no automated decisions with legal effect.
11. Changes
If the application changes, we update this policy. The version published here is the applicable one.