Privacy Policy
Last updated: 22 September 2026
By using the Gameedy app and the website gameedy.com, you entrust us with your personal data. This policy explains how it is processed in accordance with the General Data Protection Regulation (GDPR — EU 2016/679) and the French Data Protection Act as amended.
1. Data controller
The controller of personal data is Mr. Grégoire Clément DELACROIX, sole proprietor operating under the trade name Gleedi, whose full contact details appear in the Legal Notice section. Contact: privacy@gameedy.com.
No Data Protection Officer (DPO) has been appointed, as the processing does not fall within the cases of mandatory designation under article 37 GDPR.
2. Data collected
- Identification and account data: email address, display name (username), generated avatar, login data via Google OAuth or Discord OAuth where applicable (email address, display name, unique identifier and profile picture, limited to the data transmitted by the identity provider at login), accepted Terms version (
terms_version), profile visibility (public/private). - Usage data: rated games, libraries and lists created or joined, tags and platforms associated with games, private notes, published comments, replies and comment likes, browsing history within the app, account time zone, preferences and settings, social relationships (followed users and followers), requests sent and received, in-app notifications, push notification preferences, technical history of release alerts sent (game, date, and global or platform-specific scope), submitted feature ideas and related votes, activity events visible according to privacy settings.
- Account-linked product measurement data: a limited set of functional events recorded on Gameedy's servers after certain actions succeed (account, library or list creation, game addition, generated recommendation, invitation sent or accepted, local import, and subscription activation), together with at most one daily activity record containing first and last activity times, mobile platform, and app version. No free-form text, comment, search, memo, library or list name, or game title is recorded in this data.
- Technical data: device identifier, operating system, application version, anonymized error reports (Sentry for the frontend and backend), push notification tokens. In the mobile app, the Sentry Flutter SDK generates an installation identifier (
installationId, a random UUID created at installation and stored locally), used only to deduplicate error reports. The collection of personally identifiable information is disabled (sendDefaultPii: false): IP addresses and session data are not transmitted. - Optional Firebase Analytics statistics: only after explicit consent, Google Analytics for Firebase collects a pseudonymous installation-specific identifier, session statistics, approximate geolocation, technical device and app information, automatic usage events, including in-app purchase events when reported by the platform, and limited functional events. The IP address may be used in transit to provide approximate location and secure the service, but Google Analytics states that it does not log or store it. No Gameedy account identifier, email, username, comment, search, memo, library or list name, or game title is transmitted. Advertising identifier collection, Google Signals, and ads personalization are disabled.
- Subscription data: RevenueCat application identifier (
app_user_id), subscription store (App Store / Google Play), environment (production / sandbox), subscribed product identifier, store subscription identifier, subscription status, period end date and any cancellation date. Gameedy neither collects nor stores your bank card data; this data is managed exclusively by Apple or Google depending on the platform. - Billing logs: when subscriptions are synchronized through RevenueCat webhooks, the backend logs technical events containing an event identifier, event type, user identifier (
userId), store, status and product identifier. This data is pseudonymized and kept solely for security and debugging purposes. - Scan data: when a barcode is scanned, the GTIN/UPC/EAN code is sent to EAN-Search in order to identify the product name. That name is then sent to OpenAI solely for normalization. This data does not identify you and is not retained after processing.
- Gaming news data: short elements from public RSS feeds or third-party editorial sources (title, source, URL, publication date, optional image and short description). These elements are not personal data about you. Short titles and descriptions may be automatically translated via OpenAI.
- Gameedy editorial articles: the Application retrieves recommendation article titles, summaries, links, and images from gameedy.com without sending an account identifier. This information may be cached on your device. The request to the website sends ordinary connection data, including your IP address, to its hosting provider. Game covers load directly from images.igdb.com, which also receives connection data, including your IP address. Opening an article displays the Gameedy website in a browser; the website privacy policy then applies.
- Account-free mode: libraries, lists, games, tags, platforms, and personal notes created without an account are stored only on the device. Gameedy receives this data only if the user confirms its import into an account.
Gameedy does not collect any sensitive data within the meaning of article 9 GDPR.
3. Purposes of processing
- Provision and personalization of the service (recommendations, game library, video game summary translation via OpenAI)
- Personalized recommendations through automated processing (profiling — see §4)
- User account management and authentication
- Subscription and billing management (via the App Store, Google Play and RevenueCat)
- Application improvement (bug fixing and stability)
- Limited measurement of activation, engagement, retention, and feature usage to evaluate and improve the service
- Production, with your consent, of pseudonymized installation and usage statistics through Firebase Analytics
- Tracking accepted Terms versions for regulatory compliance
- Sending notifications with your consent
- Managing push notification preferences selected in the app
- Organizing and filtering libraries according to the platforms associated with games
- Determining the relevant local day from the account time zone and sending global or selected-platform release alerts, without transmitting account or library data to IGDB
- Displaying an activity feed showing certain recent actions by followed players (comments, ratings, tags)
- Displaying gaming news from third-party sources and automatically translating short titles/descriptions via OpenAI
- Detecting and resolving technical errors
- Security and fraud prevention
- Legal and regulatory obligations
4. Profiling and personalized recommendations
Gameedy may generate personalized game recommendations at the user's request. When you initiate a recommendation by selecting a library or a list, the app analyzes the characteristics of the games it contains (theme, genre, developer, gameplay perspective, etc.) to identify similar games likely to match your interests. The results are displayed as a feed that you can browse freely and close at any time.
This processing constitutes profiling within the meaning of article 4(4) GDPR. It is initiated exclusively by your action and does not result in decisions producing legal or similarly significant effects concerning you within the meaning of article 22. There is no passive or background profiling.
The app also offers a non-personalized discovery mode: you may manually enter raw criteria (genre, theme, platform, etc.) without any link to your personal library. This mode is based on no profiling and constitutes the non-personalized recommendation option required by article 27 of Regulation (EU) 2022/2065 (DSA).
Legal basis: performance of the contract. You may object to this processing by contacting privacy@gameedy.com; in that case, the recommendation feature will no longer be available.
5. Legal basis for processing
- Performance of the contract: account management, provision of the service, subscriptions, tracking accepted Terms versions, barcode scanning, personalized recommendations on request, activity feed, notification preference management and discovery features
- Legitimate interest (art. 6.1.f GDPR): security, abuse prevention, improvement and limited measurement of service usage on Gameedy's servers, error monitoring, and billing event logging for debugging and security audit purposes
- Consent: optional Firebase Analytics statistics (changeable under Settings → Usage analytics) and push notifications (withdrawable under Settings → Notifications → Gameedy or from the app notification settings)
- Legal obligation: retention of accounting and tax data for 10 years (art. L.123-22 of the French Commercial Code)
6. Recipients of data
Processors (processing data on behalf of Gameedy):
- Hetzner Online GmbH — backend hosting — Germany
- Scaleway SAS — database hosting — France
- IGDB (Twitch Interactive, Inc.) — video game data, images, videos and related media — United States
- RevenueCat, Inc. — subscription management and synchronization — United States
- Sentry (Functional Software, Inc.) — frontend and backend error monitoring — United States
- Google LLC (Google OAuth) and Discord Inc. (Discord OAuth) — social authentication — United States
- Google LLC (Firebase Cloud Messaging) — push notifications — United States
- Google LLC (Google Analytics for Firebase) — optional usage statistics — United States
- Relaxed Communications GmbH (EAN-Search.org) — barcode scanning — Germany
- OpenAI, LLC — artificial intelligence (barcode-scan normalization, video game summary translation and short gaming-news excerpt translation) — United States
- Gaming-news publishers and third-party websites — when you open an article from the app, the source website acts as an independent data controller under its own privacy policy
Third-party data controllers (processing your data in their own name, under their own policies):
- Apple Inc. (App Store) — iOS payment processing and store subscription management; privacy policy: www.apple.com/legal/privacy/en-ww/
- Google LLC (Google Play) — Android payment processing and store subscription management; privacy policy: policies.google.com/privacy
When you subscribe via the App Store or Google Play, Apple or Google collects your payment data directly. Gameedy does not receive this data and is not responsible for its processing.
Gameedy does not sell your personal data to third parties.
7. Transfers outside the EU
Some processors and third-party data controllers operate in the United States. Transfers outside the EU are governed as follows:
- Hetzner Online GmbH: established in Germany (EU) — no transfers outside the EU for backend hosting
- Scaleway SAS: established in France (EU) — no transfers outside the EU for database hosting
- Google LLC and Discord Inc.: Standard Contractual Clauses (SCCs) and Data Privacy Framework (DPF), these companies being DPF-certified
- Apple Inc.: DPF-certified for activities falling within the scope of the program
- RevenueCat, Inc. and Sentry (Functional Software, Inc.): Standard Contractual Clauses (SCCs) — data processing agreement (DPA) available from each provider
- IGDB (Twitch Interactive, Inc.): SCCs
- OpenAI, LLC: SCCs only — not DPF-certified
- EAN-Search.org (Relaxed Communications GmbH): established in Germany (EU) — no transfers outside the EU for that service
For users in the United Kingdom, transfers to EEA countries benefit from the adequacy decisions adopted by the United Kingdom. Transfers to the United States are governed by the International Data Transfer Agreement (IDTA) or contractual clauses approved by the ICO.
8. Retention period
- Account data and content (profile, libraries, lists, comments, social relationships): retained for the lifetime of the account and, where applicable, until the active subscription expires, then permanently deleted within one month. This deletion is irreversible.
- Subscription and billing data: 10 years from the transaction
- Technical logs, error reports and billing logs: rolling 12 months
- Account-linked product measurement events and daily activity: rolling 13 months, then automatically deleted, or earlier if the account is deleted
- Firebase Analytics data: no more than 14 months for detailed user-level and event-level data, according to the Google Analytics property settings; aggregated statistical reports may be retained longer without directly identifying a Gameedy user
- Scan data: not retained after processing
- Activity events (comments, ratings, tag changes displayed in the activity feed): 6 months
- Gaming news articles and associated short excerpts: 30 days by default, unless operational retention is adjusted
- Push notification preferences: retained for the lifetime of the account or until changed/account deletion
- Platforms associated with games and account time zone: retained as long as necessary for the feature, and no later than their modification, deletion of the relevant content, or account deletion
- Technical history of release alerts sent: 12 months from dispatch, then automatically deleted, or earlier if the account is deleted
- Account-free mode data: stored locally until successfully imported, the app's data is erased, or the app is uninstalled. Before import, it is not included in an account export because Gameedy does not hold it.
9. Your rights
In accordance with the GDPR and the French Data Protection Act, you have the following rights:
- Right of access (art. 15): obtain a copy of your data
- Right to rectification (art. 16): correct inaccurate data
- Right to erasure (art. 17): delete your account and your data
- Right to restriction (art. 18): restrict processing in certain circumstances
- Right to data portability (art. 20): receive your data in JSON format directly from the Privacy & Data page in the app, or on request at privacy@gameedy.com. This export includes in particular your profile and time zone, subscription, libraries and lists you belong to, tags and platforms associated with games, notes, ratings, reviews, comments, ideas and votes, social relationships, requests, in-app notifications, push notification preferences, release alert history, activity events, account-linked product measurement events, daily activity, activation date, and Analytics consent state concerning you.
- Right to object (art. 21): object to processing based on legitimate interest
- Right to withdraw consent (art. 7.3): revoke at any time processing based on your consent, without retroactive effect. For Firebase Analytics: Settings → Usage analytics. For push notifications: Settings → Notifications → Gameedy.
- Post-mortem instructions (art. 85 of the French Data Protection Act as amended): define instructions regarding the retention, deletion or disclosure of your data after your death
Your pseudonymized billing logs are available on written request to privacy@gameedy.com. These time limits run from receipt of your request and may be extended by a further two months in the case of complex or numerous requests, with prior notice.
To exercise your rights: privacy@gameedy.com or via the app settings. If your complaint is not resolved, you may contact your national data protection authority: CNIL (France), ICO (United Kingdom), BfDI (Germany), AEPD (Spain), Garante (Italy), UODO (Poland), ANPD (Brazil), OPC (Canada), OAIC (Australia).
California residents — CCPA/CPRA
California residents have the following rights: to know, delete, correct and opt out of sale or sharing. Gameedy does not sell your personal data and does not share it for cross-context behavioral advertising. Contact: privacy@gameedy.com (subject: "CCPA Rights Request").
Residents of Canada — PIPEDA and Law 25 (Québec)
Canadian residents benefit from rights of access, rectification, portability and, in Québec, de-indexing. Gameedy designates privacy@gameedy.com as the person responsible for the protection of personal information. Authorities: www.priv.gc.ca · www.cai.gouv.qc.ca.
Residents of Brazil — LGPD
Brazilian residents benefit from rights of confirmation, access, correction, portability, information on recipients and withdrawal of consent. In accordance with article 41 of the LGPD, Gameedy designates privacy@gameedy.com as Encarregado de dados. Authority: www.gov.br/anpd.
Residents of Australia — Privacy Act 1988
Australian residents benefit from rights of access, correction and erasure. Authority: www.oaic.gov.au. Contact: subject "Australian Privacy Request".
Residents of the United Kingdom — UK GDPR
UK residents benefit from the same rights as those described above under the UK GDPR and the Data Protection Act 2018. The competent supervisory authority is the Information Commissioner's Office (ICO).
10. Cookies & trackers (website)
Gameedy places no cookies on your device, and gameedy.com uses neither audience analytics nor an advertising network. Fonts are self-hosted. Game covers in articles load from images.igdb.com: this sends ordinary connection data, including your IP address and browser information, to that service. The website hosting provider's standard access logs (IP address, date/time, browser) are processed for security purposes — legitimate interest (art. 6.1.f GDPR), never for advertising purposes.
11. Security
Gameedy implements appropriate technical and organizational measures: encryption of data in transit (TLS), secure authentication, restricted access to personal data. In the event of a data breach likely to create a risk to the rights and freedoms of data subjects, Gameedy notifies the competent supervisory authority within the applicable legal deadlines (72 hours under the GDPR — art. 33, and as soon as reasonably possible in other jurisdictions). In the event of a breach presenting a high risk to your rights and freedoms, you will also be informed as soon as possible in accordance with article 34 GDPR.
12. Minors
The features of the app that require an account are intended for persons aged at least 16. Persons under 16 are not allowed to create an account. Gameedy does not knowingly collect personal data from persons under 16. If Gameedy learns that an account belongs to a person who does not meet this condition, the account and associated data may be deleted in accordance with applicable law.
Children in the United States — COPPA
For users residing in the United States, the app is not intended under any circumstances for children under 13. If we learn that a user is under 13 and resides in the United States, we will immediately delete the account and data, in accordance with the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §6501 et seq.).
13. Website (landing page)
The website gameedy.com is a purely informational static website. It does not collect or store any personal data directly. The data described in sections 2 to 8 concern exclusively the Gameedy mobile app (iOS and Android).
14. Updates to this policy
This policy may be updated at any time. Any material change will be notified in the app. The last update date is indicated at the top of this page.