House of games
Privacy
What we collect, why, and what you can do about it.
Who?
PLAYSOBR is published as a multiplayer party-games project. The data we process exists to make the service work. No reselling, no targeted ad profiling.
Data collected
- Account: email, display name, password (hashed with bcrypt - never stored in clear). The minimum age of 15 is declared at sign-up; no date of birth is asked.
- Google sign-in (optional): Google identifier and profile picture.
- Game stats: games played, wins, game sessions tied to your account.
- Night recap by email (optional, no account needed): email address and nickname left at the end of a game, room code. One email two days after the night, with a link to stop; the address is removed from mailings as soon as you click it.
- Subscription data (if you subscribe to TV Mode Premium): status (trialing / active / cancelled), Stripe identifiers (customer_id, subscription_id), current period dates. No card data is stored on PLAYSOBR - everything is handled by Stripe.
- Audience measurement: anonymous navigation events (rooms created and joined, games started and finished, clicks on the main homepage buttons), plus a random identifier specific to your device, kept in your browser and renewed after 13 months. It is only used to count devices - for instance to tell whether a table comes back to play another night - never to profile you or follow you across other sites, and it is shared with no one. These statistics stay internal to PLAYSOBR and fall under the consent exemption granted by the CNIL for audience measurement: you can object at any time by choosing "Essential" on the banner.
- IP address: used briefly to rate-limit spam and abuse. No persistent log.
- Live game flow: what the room screen shows (game, phase, nicknames, scores), recorded every ten seconds and kept for thirty days. Never what a player sees alone on their phone: not their hand, not their role, not their secret votes.
- Anonymous device identifier: a random number kept in your browser and in a small file set by the game (thirteen months). It says nothing about you and is never matched across sites: it only tells us whether a table comes back to play.
- Local preferences: sound volume and on/off, stored in localStorage. No personal data.
Why?
- Authentication and profile persistence.
- Real-time multiplayer gameplay.
- Leaderboard and personal stats.
- Understand where a table gets stuck, to fix the game (support and improvement).
- Contact you by email about the service, if you have an account: ask for your feedback, tell you about an important change. Never advertising, and you can ask us to stop at any time.
- Abuse mitigation (rate-limit, AI moderation).
How long?
- Refresh tokens: 30-day rolling window.
- Game sessions: kept indefinitely until an automated archival policy lands.
- Audience-measurement identifier: renewed automatically after 13 months. The measurement events themselves are deleted after 90 days.
- Account: kept until you delete it yourself.
- Game flow: thirty days, then automatic deletion.
Third parties
- Google: if you sign in via Google SSO, we receive your identifier and profile picture. Subject to Google's privacy policy.
- Gemini API (Google): used by Les Témoins · Catastrophe to generate verdicts and scenarios. The inputs sent are anonymised (no real display name).
- Stripe: PCI-DSS certified payment processor. If you subscribe to TV Mode Premium, Stripe handles your card and bills your subscription. PLAYSOBR stores no card data. Stripe may send transactional emails (receipts, payment failures).
Cookies & local storage
- One technical cookie only:
refreshToken, with httpOnly and sameSite=strict. Required to keep your session alive. - No tracking cookie, no persistent third-party analytics.
- localStorage: sound preferences, consent banner state, current room session (room code, chosen nickname, session token), guest avatar, games already rated, and the audience-measurement identifier described above. You can wipe all of it by clearing this site's data in your browser.
Your rights
You have the usual GDPR rights: access, rectification, deletion, portability, opposition. You can exercise them:
- By deleting your account from the danger zone of your profile.
- By contacting us for any other request (see below).
Contact
For any privacy- or personal-data-related question, reach us at [email protected].
Last updated: September 2026.