← Back to the game
Privacy policy

Privacy information

A complete, feature-specific overview of how this Connect 4 deployment handles data.

Last reviewed: 25 July 2026

Privacy contact

Sharbel Murad · connect-4@sharbel.de

Data at a glance

Local storage

Game state and preferences remain on the device.

Online play

Only after you start an online match.

Analytics

Only if the deployment enables it.

1. Controller and contact

The controller for the processing described on this page is Sharbel Murad. You can reach the controller about privacy matters at connect-4@sharbel.de. No data protection officer has been appointed unless a deployment separately identifies one.

2. Scope and data categories

This notice applies to the Connect 4 web app and its Android WebView build. The app is designed for local play. It does not create user accounts and, by default, does not ask for your name, email address, contacts, precise location, photos, microphone, camera, payment data, or advertising identifiers.

Depending on the feature you choose, the app may process technical connection data, device/browser information, locally stored game data, online-match connection data, and data generated by an explicit sharing action.

3. Local game storage

The game stores the current board, moves, timers, selected mode and variant; it also stores statistics, theme, language, dark mode, and tabletop mode. These values are kept in browser local storage or Android WebView storage on your device, rather than in a game account.

Purpose: to restore your game and preferences. Legal basis where the GDPR applies: Article 6(1)(b) GDPR where necessary to provide the feature you request, or Article 6(1)(f) GDPR for a stable, user-friendly operation. Retention: until you clear site/app storage or uninstall the app.

4. Delivery, hosting, and security

When you open the app, the hosting and reverse-proxy providers necessarily process technical request data such as IP address, date and time, requested resource, user agent, and transport/security information. The provider is a recipient or processor for delivery, abuse prevention, and service security.

The concrete hosting provider and its log-retention settings are deployment-specific. The deployment operator must keep those settings, contractual arrangements, and this notice aligned. The legal basis is generally Article 6(1)(f) GDPR, based on the legitimate interest in secure and reliable operation.

5. Optional online matches: PeerJS and WebRTC

Online play starts only when you select it. The default serverless flow uses PeerJS signaling and WebRTC to connect two players. Peer identifiers, signaling and connection metadata, network information including IP addresses, and the game state exchanged with the opponent can be processed by connection infrastructure and visible to the other participant where the technology requires it.

Purpose: establish and maintain the requested match. Legal basis: Article 6(1)(b) GDPR where applicable to the requested service, otherwise Article 6(1)(f) GDPR. Retention: game traffic is intended to be transient; infrastructure providers may retain technical logs under their own documented policies. Do not use online play if you do not want your network information shared through this connection.

6. Optional PocketBase transport

A deployment can deliberately disable the serverless setting and use PocketBase for online match state. In that configuration, the deployment operator must identify the PocketBase host, recipient/processor, categories of match data, retention, and any international transfers before enabling it. It is not the default public configuration.

7. Analytics

Umami analytics is not enabled in this deployment. If a future deployment enables it, the operator must identify the analytics endpoint, event scope, retention, legal basis, and any consent mechanism before enabling collection.

Analytics, if enabled, must rely on a documented legal basis selected by the deployment operator. You can contact the controller to object where Article 6(1)(f) GDPR is used.

8. Sharing and clipboard

The copy-link and share controls act only after you choose them. They pass an invite link and message to your operating system clipboard or selected share target. The destination application and its provider process that data under their own privacy information. The app does not read unrelated clipboard content for analytics.

9. Recipients, transfers, and retention

Possible recipients are the hosting/reverse-proxy provider, the PeerJS/WebRTC connection infrastructure, your online opponent, an optional PocketBase provider, an optional Umami provider, and the app or service you choose in the share sheet. These providers can be outside the EU/EEA or use infrastructure there. Where a transfer occurs, the responsible deployment operator must ensure an applicable transfer mechanism and make the relevant information available on request.

Local data remains until you delete it. Online match traffic is used for the match. Provider-side technical logs and optional analytics are retained according to the selected provider configuration; the operator must set and document that period.

10. Your rights

Subject to the legal requirements, you may request access, rectification, erasure, restriction, data portability, or object to processing based on Article 6(1)(f) GDPR. Where processing is based on consent, you may withdraw it at any time for the future. You also have the right to lodge a complaint with a competent data-protection supervisory authority. To exercise a right, contact connect-4@sharbel.de.

11. No automated decisions and changes

The app does not use automated decision-making or profiling that produces legal or similarly significant effects. This notice must be reviewed before changing hosting, logging, analytics, online-match providers, Android permissions, or data categories.