← Back to Playmoir

Privacy Policy

Last updated: [FECHA DE PUBLICACIÓN]

This Privacy Policy explains how Playmoir (“we,” “us,” “our”) collects, uses, and protects your personal information when you use the Playmoir mobile application and website at playmoir.app (together, the “Service”). By using the Service, you agree to the collection and use of information as described in this policy.

1. Who we are

Playmoir is operated from Spain. If you have questions about this Privacy Policy or how your data is handled, you can reach us at hello@playmoir.app.

2. Information we collect

2.1 Information you provide directly

DataPurpose
Email addressAccount creation, login, verification, password reset, service communications
UsernamePublic identity within the Service
PasswordStored as a one-way cryptographic hash (bcrypt); we never store or can view your plain-text password
Profile photoOptional, displayed on your public profile
User-generated contentReviews, journal entries, and any text or images you choose to add about the games you play

2.2 Information collected automatically

DataPurpose
IP addressSecurity, rate limiting, abuse prevention, server logs
Device and app version informationDebugging, error monitoring, compatibility
Usage data (crash reports, error logs)Improving stability and fixing bugs
We do not collect: precise location data, contact lists, payment information, government ID numbers, health data, or any other category of sensitive personal information as defined under GDPR or CCPA.

3. How we use your information

We do not sell your personal information, use it for third-party advertising, or share it with data brokers.

4. Legal basis for processing (EEA/UK users)

Where GDPR applies, we process your data on the following legal bases:

5. Third-party service providers

We use the following third-party providers to operate the Service. Each processes data only as necessary to perform their function for us, under their own privacy and security commitments:

ProviderPurpose
RailwayApplication hosting and database infrastructure
CloudflareDNS, CDN, and object storage (R2) for uploaded images
ResendTransactional email delivery (verification, password reset)
SentryError monitoring and crash reporting

We do not use Google Analytics, Meta/Facebook Pixel, advertising networks, or any other third-party tracking or remarketing service.

6. International data transfers

Our infrastructure providers may process data in the United States or other countries outside the EEA/UK. Where this occurs, we rely on the safeguards provided by our providers (such as Standard Contractual Clauses) to ensure your data remains protected to a standard equivalent to that required under GDPR.

7. Data retention

We retain your personal data for as long as your account remains active. If you delete your account, your personal data and user-generated content are deleted or anonymized within a reasonable period, except where retention is required by law (e.g., for fraud prevention or legal compliance).

8. Data security

We apply industry-standard security measures, including: password hashing (bcrypt), encrypted connections (HTTPS/TLS) across the Service, JSON Web Token-based authentication with short-lived access tokens, rate limiting on authentication endpoints, and restricted, need-to-know access to production systems.

No system is perfectly secure. In the unlikely event of a data breach affecting your personal information, we will notify the relevant supervisory authority and affected users as required by applicable law (including within 72 hours under GDPR, where applicable).

9. Your rights

Depending on where you live, you may have some or all of the following rights regarding your personal data:

You can exercise most of these rights directly from the app (editing your profile, deleting entries, or deleting your account from Settings). For anything else, contact us at hello@playmoir.app. If you are in the EEA/UK, you also have the right to lodge a complaint with your local data protection authority (in Spain, the Agencia Española de Protección de Datos, www.aepd.es).

If you are a California resident, you have rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete it, and the right to non-discrimination for exercising these rights. We do not sell or share personal information as defined under the CCPA.

10. Children’s privacy

The Service is not directed at children and is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Cookies and tracking technologies

The Playmoir mobile app does not use cookies. Our website may rely on strictly necessary technical cookies set by our infrastructure provider (Cloudflare) for security purposes (e.g., bot protection). We do not use analytics or advertising cookies, and we do not currently respond to Global Privacy Control (GPC) signals, as we do not engage in the type of data sale or sharing these signals are designed to prevent.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at the address associated with your account before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision.

13. Contact

Questions, concerns, or requests regarding this Privacy Policy or your personal data can be sent to hello@playmoir.app.