Privacy Policy

Last updated: September 13, 2026

1) Controller

Roland Becker
Am Maselakepark 47, 13587 Berlin, Germany
VAT ID: DE450323209
Email: hello@playliferpg.com

2) Scope

This Privacy Policy applies to the LiFE RPG web app ("App").

3) What data we process and why

3.1 Account and authentication

When you sign up or log in, we process:

  • Email address
  • Authentication/session data (e.g., session tokens)
  • Timestamps of signup/logins

Purpose: Provide account access, keep sessions secure, prevent abuse.
Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (security).

3.2 Gameplay and user content

The App processes data you enter and generate while using the App, such as:

  • Character/profile data (name, avatar URL, settings)
  • Quests, habits, streaks, check-ins, progress, rewards
  • Journal entries you write
  • In-game stats (e.g., XP, coins, Gems, HP)

Purpose: Deliver the App's functionality and save your progress.
Legal basis: Art. 6(1)(b) GDPR.

3.3 AI features (OpenAI)

If you use AI features (e.g., quest generation, recommendations, challenge generation, avatar/monster image generation), we process the necessary input context you provide or that the App sends for the feature to work (e.g., selected skills, quest context, prompts).

Important: Please do not enter sensitive personal data (e.g., health, political opinions, religion) into AI prompts.

Purpose: Provide AI features and improve reliability/safety.
Legal basis: Art. 6(1)(b) GDPR (contract), and where applicable Art. 6(1)(f) GDPR (security/abuse prevention).
Recipient/processor: OpenAI (API). Processing may involve transfers outside the EU/EEA, using GDPR-compliant safeguards (e.g., Standard Contractual Clauses) as applicable.

3.4 Payments (Stripe)

If you purchase a pass or Gems, we process:

  • Purchase status, product/price identifiers, transaction IDs
  • Stripe customer ID (if applicable)

We do not store full payment card details; Stripe processes payment details.

Purpose: Process payments, provide purchased services, prevent fraud.
Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (fraud prevention, evidence).
Recipient/processor: Stripe.

3.5 Technical logs and security data

We may process technical data such as:

  • IP address (typically in server logs), device/browser info
  • Error logs and timestamps

Purpose: Operate the App, ensure security, debug issues.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operations).

3.6 Product measurement

We count landing page views with the page path, referring website host and, when present, a predefined identifier for one of our publications. These records do not contain an IP address, a full referring URL or a unique visitor identifier. Automated browser visits are excluded from new view counts.

If you register through a publication link, we associate its campaign identifier with your account. We use saved game actions and limited navigation events to understand where players stop in the first adventure and whether they return. Measurement events do not include private habit names, journal entries or other free text.

Our restricted administration dashboard shows aggregate results and confirmed payment and refund amounts. Payment records include transaction identifiers, currency and available processing fees. Campaign attribution does not create an additional browser cookie or storage identifier.

Purpose: evaluate our own publications and improve the first session. Contact us using the details below to ask about or object to processing associated with your account.

4) Cookies / local storage

We use technically necessary storage (e.g., tokens) to keep you logged in and to provide core functionality. If we introduce non-essential tracking/marketing cookies, we will request your consent beforehand.

5) Sharing and processors

Depending on your usage, we share data with:

  • Supabase (database, authentication, functions)
  • Stripe (payments)
  • OpenAI (AI features)
  • Hosting/infrastructure providers as required to run the App (if applicable)

We use processors under appropriate data processing terms (DPAs) where required.

6) International transfers

If data is processed outside the EU/EEA (e.g., by OpenAI or other providers), we rely on GDPR-compliant safeguards such as Standard Contractual Clauses or adequacy decisions, as applicable.

7) Retention

We keep personal data:

  • For as long as your account exists and it is necessary to provide the App
  • Longer only if required by law (e.g., accounting) or to establish/exercise/defend legal claims

You can request deletion of your account data (see Section 9).

8) Your rights

You have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object (Art. 21 GDPR)
  • Lodge a complaint with a supervisory authority (Art. 77 GDPR)

9) Contact

For privacy requests (access, deletion, etc.), contact: hello@playliferpg.com