legal
Privacy Policy
Last revised: 11 July 2026
1. Controller
The controller within the meaning of the GDPR is:
Robert Gustinc/o COCENTER, Koppoldstr. 186551 AichachGermanyEmail: hello@gamorium.com. No data protection officer is appointed, as the thresholds of Art. 37 GDPR / § 38 BDSG are not met.
2. Our approach - privacy by design
Gamorium needs no account and no sign-up. Anything you classify or import (your Steam library, your self-portrait) is stored only in your browser (localStorage); we never store it on our servers. The one exception is deliberate: when you run an AI feature (the deep read or "Picked for you"), a slice of it - your most-played game titles and your derived axis profile - is sent through our API to Google Gemini to generate that result, and is not retained afterwards (section 5). Server-side we otherwise process the minimum needed to run the site, keep it secure, and produce the analysis you request. This document lists that minimum in full.
3. Hosting & server logs
Hosting: DigitalOcean (EU-Region, Frankfurt). Database: Neon (EU-Region, Frankfurt). Standard access data (IP address, timestamp, requested URL, HTTP status, referrer, user agent) is processed when handling each request. We keep no long-term access logs: the reverse proxy writes none, and application request logs (method, path, status, timing - without your IP) live only in size-bounded, rotating container logs that we do not archive.
Legal basis: Art. 6(1)(f) GDPR. Legitimate interest: secure, functioning operation. Necessity: a server cannot respond without processing request data. Balancing: minimal, not used to profile you, short-lived (see section 13).
4. Rate limiting (abuse protection)
To prevent abuse and runaway AI costs, we count requests per one-hour window using your IP address as a counter key. It is not combined with other data and no profiling takes place.
Legal basis: Art. 6(1)(f) GDPR. Legitimate interest: abuse and cost protection. Necessity: per-client counting requires a per-client key. Balancing: single-purpose, no profiling, deleted promptly (see section 13).
5. AI features (Google Gemini)
Scoring a game. If a game you search for is not yet catalogued, we send the game title only to Google's Gemini API (Google Ireland Ltd. / Google LLC) for scoring. No personal data of yours is transmitted. The result is stored in our catalogue so the next person sees it for free. Legal basis: Art. 6(1)(f) GDPR - only a game title leaves our system; no user identifier is involved.
Reading your profile (the deep read and "Picked for you"). These two features run only when you actively tap their button. When you do, we send a slice of your locally-held library to Gemini to generate the result:
- the deep read sends your derived four-axis profile (scores, dominant and weakest axis, region, total hours and game count) and up to 20 of your most-played game titles, so the read can reason about how you play;
- "Picked for you" sends your target axis profile and the titles of games you already own (so it does not recommend them back to you).
This data is sent only at the moment you request the feature, used only to produce that response, and is not stored by us afterwards. A list of your most-played games can qualify as personal data, so we name exactly what is sent and keep it to the minimum the feature needs. Legal basis: Art. 6(1)(b) GDPR - performance of the feature you actively requested.
Transfers to the USA (for any of the above) are covered by the EU-US Data Privacy Framework and, as a fallback safeguard, the EU Standard Contractual Clauses (see section 12).
6. Steam sign-in (optional)
You may connect Steam to import your library. Two distinct steps, two legal bases:
- Deciding to connect your Steam account - Art. 6(1)(a) GDPR (consent): initiating the Steam OpenID flow is your opt-in. You can withdraw any time via "sign out", which deletes the cookie; withdrawal does not affect prior lawful processing. As your library is never stored on our servers, withdrawing leaves no further data to delete beyond the cookie.
- Fetching and displaying your library once connected - Art. 6(1)(b) GDPR: performance of the feature you actively requested.
We receive your public SteamID64, store it in a signed, functional cookie in your browser (no server-side session store), and pass your library straight to your browser without storing it. Valve acts as a separate, independent controller (not a joint controller) for its own login and authentication data - we only use its OpenID to receive your public SteamID and do not jointly determine Valve's purposes (see section 11). Any US processing relies on the safeguards in section 12.
7. Cookies
Gamorium uses no tracking, advertising or analytics cookies. The only cookie set is a single, strictly-necessary one:
gamorium_steam- stores your Steam session (only if you connect Steam). Strictly necessary, lifetime 24 hours. Legal basis: § 25(2) no. 2 TDDDG (strictly necessary), no consent required.
The same rules cover the browser storage (localStorage) this site writes: your board, self-portrait and imported library are stored on your device solely to provide the feature you are actively using - § 25(2) no. 2 TDDDG (strictly necessary), no consent required. Nothing in that storage is read for any other purpose, and it leaves your device only in the cases section 5 describes. You can clear it at any time via your browser.
Because only a strictly-necessary cookie is set and no consent-requiring technologies are used, no consent banner is legally required; the brief first-visit notice is purely for transparency.
8. Reach measurement (Umami)
For anonymous reach measurement we use Umami - a self-hosted, privacy-friendly analytics tool running on our own EU infrastructure. Umami sets no cookies, stores no plaintext IP addresses and builds no cross-device profiles; only aggregated metrics (e.g. page views) are recorded.
Legal basis: Art. 6(1)(f) GDPR - data-minimal statistics. Balancing: nothing is stored on or read from your device, so no consent is required under § 25 TDDDG. To derive its anonymous daily-visitor count, Umami briefly processes your IP address in memory without storing it in plaintext - a minimal, transient step covered by the same legitimate interest. If you prefer not to be counted at all, common content blockers block Umami's script; the site works fully without it.
9. Submitting your own take & anonymous statistics
If you submit a take (a thumbs verdict or suggested scores with an optional comment), your input is stored deliberately without IP address, session identifier or any other identifier. Please do not enter personal data into the free-text field.
Portrait percentiles. When your self-portrait shows "top N% on an axis", your browser sends your four rounded axis scores - four numbers from 0 to 10, with no game titles, hours, or identifier of any kind - to our server to compare against an anonymous distribution. At most about once per day per browser, those four numbers are also added to that distribution, so the percentile exists at all. The stored histogram holds only counts per score value and cannot be traced back to any person or portrait.
Legal basis: Art. 6(1)(f) GDPR - our legitimate interest in improving the classifications and statistics from voluntary, anonymous input. No consent (Art. 6(1)(a)) is claimed, as none is captured.
10. Contacting us
If you contact us by email, we process your details to handle the request (Art. 6(1)(b) or (f) GDPR). The data is deleted once your request is resolved, unless a statutory retention period requires otherwise.
11. Recipients & external parties
| Party | Role | Notes |
|---|---|---|
| Valve (Steam) | Separate (independent) controller | Determines its own purposes for your Steam login/session data - not a joint controller; we only use its OpenID to receive your public SteamID. Its own privacy policy applies. |
| Google (Gemini API) | Sub-processor (Art. 28) | Receives a game title when scoring; and, when you run the deep read or "Picked for you", your derived axis profile plus your most-played / owned game titles. Used to generate the result, not retained by us. See section 5. |
| DigitalOcean | Sub-processor (Art. 28) | Hosting, Frankfurt / EU. |
| Neon (Databricks) | Sub-processor (Art. 28) | Managed database, Frankfurt / EU. |
| IGDB (Twitch / Amazon) | Data source - not a sub-processor | Server-to-server metadata lookup; no personal data about you is sent. |
| Microsoft (Bing / IndexNow) | Recipient of public URLs - not a sub-processor | When a new catalog page is created, our server notifies search engines of the new public address via the IndexNow protocol. The notification contains only the page URL - never any information about you. |
| COCENTER | Postal service provider | Receives physical mail at the c/o address only; no website data. |
12. International transfers
Hosting and database are in the EU (Frankfurt), so your data is not routinely transferred outside the EU for those services. Where a US-based provider processes data, transfers are covered by the EU-US Data Privacy Framework (DPF) and, as a fallback safeguard, the EU Standard Contractual Clauses (Art. 46 GDPR):
- Google LLC - EU-US DPF certified (official list). Only the game title is sent.
- DigitalOcean, LLC - EU-US DPF certified (official list).
- Databricks, Inc. (its certification expressly covers Neon, LLC) - EU-US DPF certified (notice).
- Valve (Steam) - independent controller for your login data; its own terms and safeguards apply.
13. Retention
| Data | Retention |
|---|---|
| Server access logs | None kept long-term. The reverse proxy writes no access log; application logs carry no IP and live only in size-bounded, rotating container logs (not archived). |
| Rate-limit IP counters | Pruned hourly; deleted within a few hours of the one-hour window closing. |
gamorium_steam | 24 hours (auto-expiry) or on sign-out. |
| Library / self-portrait | On your device (localStorage) until you clear it; never on our servers. |
| “Your take” submissions | Retained indefinitely - identity-free, containing no personal data. |
| Email correspondence | Until your request is resolved, unless a statutory (tax / commercial) period requires longer. |
14. Your rights
Under the GDPR you have the following rights:
- access (Art. 15)
- rectification (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- objection to processing based on legitimate interests (Art. 21)
- withdrawal of a given consent with future effect (Art. 7(3))
An informal message to hello@gamorium.com is enough. Because we deliberately keep no server-side user profiles, we usually cannot identify you beyond the data itself (Art. 11 GDPR).
15. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority competent for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)Promenade 1891522 Ansbachhttps://www.lda.bayern.deUnder Art. 77 GDPR you may equally complain to the supervisory authority in your own EU member state of residence, place of work, or the place of the alleged infringement.
16. Children's privacy
Gamorium is not directed to children. You must be 16 or older to use the site and to submit contributions. We operate no age verification and knowingly collect no data from children; if you believe a child has submitted data, contact hello@gamorium.com and we will delete it.
17. Data breach notification
In the event of a personal-data breach likely to pose a risk, we will notify the competent supervisory authority (BayLDA) within 72 hours of becoming aware (Art. 33 GDPR). Where a breach is likely to result in a high risk to affected individuals, we will inform them without undue delay (Art. 34). As we hold no accounts or contact details for most visitors, such notice will generally be given by a prominent notice on the website (and by email where we have one).
18. Data security
All transmission is TLS-encrypted (HTTPS). Security headers and a Content Security Policy are additionally in place.
19. Changes to this policy
We update this policy when the underlying processing changes. As we hold no accounts or email addresses, updates are communicated by publishing the revised version here with a new revision date; the current published version applies.