Privacy Policy
This is a courtesy English translation. The binding version is the German Datenschutzerklärung.
1. Controller
Pixelsplit Games GmbHAlfred-Herrhausen-Allee 3-5
65760 Eschborn
Germany
Email: [email protected]
2. Data Protection Officer
A Data Protection Officer is currently not required. The conditions set out in § 38 (1) BDSG (at least 20 people regularly engaged in automated processing) are not met, and a documented Art. 35 GDPR pre-assessment has not identified a threshold-exceeding risk. Both bases are reassessed whenever headcount or product scope changes; the outcome is documented internally per the accountability principle (Art. 24 GDPR).
3. Purposes and legal bases
- Account creation, login, session management: Art. 6(1)(b) GDPR (contract performance).
- Generating an analysis you requested for a Steam game (you input an App ID, we deliver a SWOT): Art. 6(1)(b) GDPR (contract performance).
- Querying the Steam Web API: processes personal data of review authors and game metadata, not the requesting user's personal data. The controllership relationship with Valve Corporation does not flow through us.
- Per-IP rate-limit windows: Art. 6(1)(f) GDPR (legitimate interest in abuse prevention). The balancing test is documented internally (necessity: yes; minimal data: IP and timestamps only; user impact: low; not overridden by user rights).
- Optional Google OAuth login: Art. 6(1)(a) GDPR (consent) at the moment you choose this login path; once the account exists, Art. 6(1)(b) GDPR applies.
- Payment and subscription processing (Stripe): Art. 6(1)(b) GDPR (performance of the subscription contract). To take payment, manage your subscription, handle renewals and cancellations, and meet tax and accounting obligations, we process billing data via Stripe (see § 5). Retention of invoice/accounting records follows statutory bookkeeping periods (Art. 6(1)(c) GDPR).
- Transactional email (Resend): Art. 6(1)(b) GDPR: e.g. registration confirmation and password-reset emails required to perform the contract and operate the account. Any purely promotional / marketing email is sent only with your separate consent under Art. 6(1)(a) GDPR and can be withdrawn at any time via the unsubscribe link.
- Server logs (Railway): Art. 6(1)(f) GDPR (security/abuse defense), retained max. 14 days.
- Internal AI usage metering and cost accounting: Art. 6(1)(f) GDPR (legitimate interest in cost control, capacity planning and abuse prevention) and Art. 6(1)(b) GDPR where it serves to enforce the usage quotas of your plan. For each AI generation we record the number of input/output tokens, the model and provider used, the type of generation (e.g. analysis, Research Lab, review tools), its duration, and the requesting account. The balancing test is documented internally (necessity: yes; minimal data: token counts and identifiers only, no prompt or review content; user impact: low; not overridden by user rights).
- Activity monitoring ("last active"): Art. 6(1)(f) GDPR (legitimate interest in operating and securing the service). We store the timestamp of your most recent active session.
4. Categories of personal data
- Email address and bcrypt password hash
- IP address (only inside short-lived rate-limit windows and server logs)
- Analysis history (analyses you triggered)
- Favorites
- Research Lab records (Pro feature)
- OAuth profile data, if you sign in with Google
- Payment / billing data for paid subscriptions: Stripe customer ID, subscription status and plan, billing interval, period and trial dates, and billing metadata. We store Stripe identifiers and subscription status; full card numbers are not stored by us; card data is handled directly by Stripe (see § 5). Billing address and any VAT/tax ID you enter at checkout are processed by Stripe for invoicing.
- Email address and message metadata for transactional (and, with consent, marketing) emails sent via Resend
- AI usage records: per-generation token counts, model/provider, generation type, duration and the requesting account; no prompt or review text is stored in these records
- Timestamp of your most recent active session ("last active")
5. Recipients / processors (Art. 28 GDPR)
- Railway Corp.: hosting and PostgreSQL (EU region)
- Anthropic PBC: Claude API for analysis generation
- OpenAI OpCo LLC: GPT API for analysis generation
- Google LLC: Gemini API and optional OAuth login
- Stripe Payments Europe, Limited (Ireland): payment and subscription processing; the contracting entity for EU merchants. Stripe, Inc. (USA) acts as a sub-processor. Purpose: taking payment, managing subscriptions, renewals, cancellations, and invoicing. We pass Stripe the data needed to bill you (e.g. email, billing address and tax ID entered at checkout); your full card details are entered directly with Stripe and are not received by us.
- Resend, Inc. (USA): sending transactional and (with consent) marketing email, via the EU sender domain
mail.critmap.com. Purpose: delivering account and service emails; data processed is the recipient email address and message metadata.
Art. 28 GDPR processing agreements are in place with all processors.
6. Third-country transfers (Art. 44 ff. GDPR)
The AI providers named above, Google, Resend, Inc. (USA), and Stripe, Inc. (USA, sub-processor to the Irish Stripe Payments Europe, Limited) are US-domiciled or transfer data to the USA. Transfer safeguards are based on the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCC) per Implementing Decision (EU) 2021/914, and/or the published Data Processing Addendum (DPA) terms of the respective provider; the applicable mechanism depends on the currently certified status of each recipient and is maintained internally per recipient. You may request a copy of the safeguards via the contact details above.
7. Retention
- Account data: until you delete the account. You can delete your account at any time via Dashboard → Settings → Delete account.
- Analysis history: while the account is active; removed when the account is deleted.
- Rate-limit data: pruned best-effort on next access after window expiry, typically within one hour.
- Server logs: max. 14 days for abuse defense.
- Backups: Postgres backups on Railway operate on a cycle of up to 30 days during which deleted records may still exist. Immediate erasure from immutable backup media is "impossible or would involve disproportionate effort" under Art. 17(3)(b) GDPR; final erasure is guaranteed by the regular backup-cycle expiry.
- Payment / billing data: the Stripe customer ID and subscription status are stored while you have or had a subscription; if you delete your account, the link to your account is removed, while Stripe retains the data it needs as an independent controller/processor for its own legal obligations. Invoice and accounting records are kept for the statutory retention periods under German commercial and tax law (generally up to 10 years, § 257 HGB / § 147 AO).
- Transactional email: message metadata at Resend is retained per Resend's defaults; the underlying email address is retained with your account (see account data above).
- pg-boss job rows (Research Lab background jobs): removed by pg-boss's own retention after completion or failure. Pending jobs of a deleted user are released to fail cleanly.
- AI usage records: retained in identifiable form for up to 18 months, then anonymized (the link to your account is removed) so only aggregate cost statistics remain. Deleting your account removes the link to your account from any not-yet-anonymized records.
- "Last active" timestamp: kept while your account is active; removed when the account is deleted.
8. Data subject rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17, also directly via self-serve account deletion), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). Any consent given can be withdrawn with effect for the future.
9. Right to lodge a complaint with a supervisory authority
Under Art. 77(1) GDPR you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The supervisory authority competent for the controller's seat is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden9a. No solely automated decision-making (Art. 22 GDPR)
The AI analyses generated by CritMap produce no legal effect on the user within the meaning of Art. 22(1) GDPR; no solely automated decision-making process is based on them.
10. Cookies and local storage
- Session cookie (
next-auth.session-token, HttpOnly, SameSite=Lax): strictly necessary under § 25(2)(2) TDDDG. Without it you cannot stay signed in to the service you requested. No consent required. - Theme preference in localStorage (
critmap-theme-style,critmap-color-mode): functional preference you set via a visible toggle. Stored only on your device, never transmitted. - Model and analysis convenience preferences in localStorage (e.g.
critmap.selectedModel.v1): functional preferences; the service works without them. Stored only on your device. Migration to a server-side user preference under Art. 6(1)(b) GDPR for signed-in users is planned as a follow-up. - Server-side rate-limit windows: see retention above.
11. Caching of analysis output
CritMap caches the analysis output per Steam game, keyed on (App ID, model, Pro Insights, Deep Analysis, scope signature). This covers the canonical SWOT and its derived views, including Edges (outlier reviews + divisive themes), which are computed from, and cached alongside, the same analysis. When another user requests an analysis for the same game with the same settings, they receive the same cached output. The input is the public Steam review set; the output contains no personal data of the requester. Your identity as the requester is recorded only in your private analysis history.
Public display (default): By default, the SWOT output for a game you analyze may be shown publicly in our homepage showcase (the recent-analyses carousel and featured slots). This display shows the game and its analysis, not your identity. On paid plans (Indie and above) you can turn this off for all of your analyses with the "Private research" setting in your dashboard; analyses already shown are then withdrawn from the homepage. When you delete your account, your analyses are detached from your account and removed from the public homepage.
12. Server logs
Each request to our website causes our hosting provider Railway to record technical access data (in particular IP address, timestamp, URL, user agent) in server logs, kept according to Railway's defaults. The data is not used for profiling.
13. Security
Communication with our platform is TLS-encrypted throughout. Passwords are stored exclusively as bcrypt hashes. Sessions are managed as signed JWTs and revalidated against the database on each refresh, so that any session cookies remaining after account deletion are invalidated promptly.
14. Changes to this policy
We reserve the right to update this Privacy Policy to reflect changes in applicable law or our services. The current version is always available at this URL.