Privacy Policy

Last updated: 3 August 2026. This page tells you exactly what asobi.dev and the Asobi Cloud console at console.asobi.dev collect, why, where the data lives, and what you can ask us to do with it.

Controller

Widgrens IT AB, org.nr 559241-2752, Melongatan 15, 754 49 Uppsala, Sweden. VAT no. SE559241275201. Contact: privacy@asobi.dev.

What we collect and why

Website analytics

Aggregate page-view statistics via Plausible Analytics (EU-hosted, Estonian company). Plausible does not use cookies and does not store raw IP addresses or User-Agent strings. It generates a daily-rotating hash from salt + domain + ip + user_agent and discards the salt every 24 hours. What is recorded: page URL (without query strings), HTTP referrer, coarse device type, and country derived from IP.

Lawful basis: legitimate interest (Art. 6(1)(f) GDPR) - measuring traffic with the least privacy-invasive tool we could find. No cookies means no consent banner is required under the ePrivacy Directive.

Access request form

Asobi Cloud is invite-only. The access request form at console.asobi.dev is hosted by us, on our own infrastructure. If you choose to submit it we collect: email address, your name or studio name, target engine, and an optional free-text note, plus whether the request is pending, invited, declined, or joined.

Lawful basis: performance of pre-contract steps you asked for (Art. 6(1)(b)) and/or consent (Art. 6(1)(a)). We use this information only to decide on and act on your access request, and to contact you about onboarding. We do not share it with advertisers, brokers, or any third party outside the processors listed below.

Where data lives

Everything we host is in the EU. The asobi.dev website, the console at console.asobi.dev, and the databases and backups behind them all run on Hetzner in Germany. Our processors:

  • Hetzner (Germany) - website, console, database, and backup hosting.
  • Plausible Analytics (Estonia, servers in the EU) - aggregate analytics for the website.

Browsing asobi.dev calls no Google, Cloudflare, or AWS service. Fonts are self-hosted, and the Plausible script is the only request your browser makes to anyone but us.

Two companies we do not host

Using the console brings in two companies outside that set. Each is an independent controller for the data you give it directly, under its own privacy policy - not a processor acting on our instructions:

  • GitHub - your identity provider. Signing in to the console sends your browser to GitHub, which then returns the account data listed under Asobi Cloud console accounts below. See GitHub's privacy statement.
  • Paddle - merchant of record for Asobi Cloud subscriptions. Checkout and payment happen at Paddle; card details never reach us. See Paddle's privacy policy.

Neither is involved in browsing asobi.dev, and neither receives your players' data. Sub-processors for the game backends we run for you are listed in the Data Processing Agreement.

Cookies and local storage

The asobi.dev website sets no cookies and writes nothing to localStorage or sessionStorage. No cookie banner is shown because there is nothing to consent to. The console sets strictly necessary session cookies only - see Asobi Cloud console accounts below.

Retention

  • Analytics: retained by Plausible for the lifetime of our account (no raw identifiers kept - the daily hash cannot be reversed beyond 24 hours).
  • Access requests: kept until the request is decided and, if you go on to join, for as long as the resulting account exists. Deleted sooner on request.

Your rights

Under the GDPR you can ask us to:

  • Confirm what personal data we hold about you (access).
  • Correct inaccuracies (rectification).
  • Delete the data (erasure).
  • Export it (portability).
  • Object to its processing, or withdraw consent you gave.

Email privacy@asobi.dev and we'll respond within 30 days. You can also lodge a complaint with your local supervisory authority (IMY in Sweden).

No profiling

We don't profile visitors, don't build advertising audiences, and don't make any automated decisions about you. There is no cross-site tracking.

Asobi Cloud console accounts

If you use the Asobi Cloud console we process, as controller:

  • Account data - your GitHub username, display name, email address, and avatar, received from GitHub when you sign in (GitHub is your identity provider; we never see your GitHub password). Plus your team membership and role.
  • Contract records - which terms version you accepted, when, and by whom.
  • Billing state - your subscription and payment status, received from Paddle. Paddle is the merchant of record and an independent controller of your purchase and payment data (card details never reach us) - see Paddle's privacy policy.
  • Operational logs - security-relevant console actions, with bounded retention.

Lawful bases: performing our contract with you (Art. 6(1)(b) GDPR) for account, contract, and billing data; legal obligations (Art. 6(1)(c), e.g. bookkeeping) for transaction records; and our legitimate interest in securing the service (Art. 6(1)(f)) for logs.

Cookies: the console sets strictly necessary session cookies to keep you signed in - nothing else, no tracking. The marketing site still sets none at all.

Retention: account data for the life of your account plus the 30-day wind-down; records we must keep under Swedish bookkeeping law for 7 years; logs per their bounded retention windows.

Your players' personal data is a separate matter: there the game studio is the controller and we are the processor under the Data Processing Agreement.