Retroduell is deliberately built to be data-sparing: no cookies, no advertising, no third-party analytics, no sharing of data for advertising purposes.
Last updated: 13 September 2026
Deutsche Fassung: Datenschutzerklärung — the German version is the authoritative one; this translation is provided for convenience.
No data protection officer has been appointed, as the requirements of Art. 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG) are not met.
| Purpose | Data | Legal basis |
|---|---|---|
| Delivering the page | IP address (only for transmission, not stored permanently) | Art. 6(1)(f) GDPR |
| Game account (guest account) | Random identifier, self-chosen display name, time of creation and of last activity | Art. 6(1)(b) GDPR |
| Game content and ratings | Your own levels, maps and tracks; shared workshop content (character, object, track); best times, recordings (“ghosts”), saved games, duel results, rating points; your thumbs-up/down votes and reports on other people’s content | Art. 6(1)(b) GDPR |
| Friends and leagues | Your friends list, your online status for friends (can be switched off), membership and points in leagues, season results | Art. 6(1)(b) GDPR |
| Abuse protection | IP address for rate limiting (in memory only, per minute) | Art. 6(1)(f) GDPR |
| Origin (reach) | Country derived from the IP address — only as a daily total, the IP itself is not stored; type of shared link | Art. 6(1)(f) GDPR |
| Reach measurement | Daily counters without personal reference; per account the days with activity | Art. 6(1)(f) GDPR |
This site sets no cookies. There is no recognition across devices or websites, no fingerprinting, no profiling and no automated decision-making. That is why no consent banner appears.
Your browser’s storage (localStorage) holds information that the game itself
needs: the identifier of your game account, your settings (language, sound, character,
controls), progress, coins and local best times with their recordings, your current level in
the editor, the way you arrived here (only until your account is created), and markers noting
when the game last asked for your opinion — so that it does not ask every time. This is
strictly necessary storage within the meaning of § 25(2) no. 2 of the German Telecommunications
Digital Services Data Protection Act (TDDDG) — without it you could neither save levels nor
keep best times. This information does not leave your browser except where expressly
described below. The identifier of your account is additionally kept in a second storage of
the same browser (IndexedDB) — so that your account is not lost if one of the two
is cleared. You can delete both at any time via your browser settings; doing so loses access
to your guest account unless you have secured it with a passkey or a recovery code (section 5).
The site runs on a server of netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany, data centre in Nuremberg. netcup processes data on our behalf (Art. 28 GDPR); a data processing agreement is in place. netcup uses group-internal sub-processors of the Anexia group in Germany and Austria. No data is transferred to countries outside the European Union. No further service providers are used — in particular no content delivery network, no external fonts and no embedded third-party content.
When you open the page, the server processes your IP address as technically necessary to deliver the response. It is not written to any file or database — not even in truncated or hashed form.
The web server keeps an access log without personal reference. Per request it contains only: time, request method, requested path, response status, response duration and response size. Not logged: IP address, browser identification (user agent), referring page (referer) and cookies. Identifiers in the path — such as those of a level, a league, a challenge or an account — are replaced by a placeholder before the entry is written; your access key is sent in a header anyway, and headers are not logged. The sole purpose is to detect and fix disruptions of the service; the legal basis is Art. 6(1)(f) GDPR. Entries are deleted after 14 days. Who made a request cannot be read from the log, and there is no analysis of usage behaviour.
In addition, technical faults produce system error messages that may contain an IP address; these are automatically overwritten after 14 days at the latest.
A guest account is created automatically for playing. It consists of a random identifier, an access key and a display name (preset e.g. “Gast-1a2b”). There is no registration with an e-mail address or password, and no e-mail address is collected. If you choose your own name, it is visible to other players; so please do not choose a name that identifies you unless you want that.
Devices and sign-in. Each device on which you use your account receives its own access key. For each one we store the time of sign-in, the time of last use and a rough device class (“phone”, “tablet”, “computer”). Under Account & Devices you can see this list and sign out individual devices. The access keys themselves are stored with us only as a hash (SHA-256); in plain text they exist only in your browser.
So that your account survives a change of device, three optional ways are available:
The following is visible to others as soon as you use the respective feature:
You can set shared content back to “private” in the game or delete it. Recordings and best times are deleted together with their entry. Copies remain: whoever copies a shared level receives their own private version whose title names you (“… (after …)”). It then belongs to them and remains even if you withdraw the original.
If you report a piece of content, we store the report with your account and your reason until the content or your account is deleted. Other players do not see it.
To understand whether the service works, we count a few events on our own server — such as “page opened”, “game started” or “duel played”. No third-party analytics service is used. Only daily totals are counted; individual visits cannot be reconstructed from them. Not collected: IP addresses, browser or device identifiers, referring pages and visited page paths.
Two properties of a visit are counted separately: whether the interface was in English, and whether a finger touched the screen during the visit. The second tells us for how many people we have to think of the phone first. Nothing is read out for this — no device model, no screen size, no identifier: only the fact that a touch happened is counted, and that only as a daily total.
Country of origin: when the page is opened, our server determines the country from your IP address and counts it as a daily total (“Germany: 42”). The lookup happens in a file on our own server; your IP address is neither stored nor logged and is not transmitted to anyone. Nothing more precise than the country is determined — no region, town or coordinates. The legal basis is our legitimate interest in knowing which countries we are designing the service for (Art. 6(1)(f) GDPR).
How you got here: links that we generate for sharing (recommendation,
invitation, league table) carry a short suffix such as ?q=empfehlung. It tells
us which kind of link someone opened — not who sent it. This, too, is counted only as
a daily total and additionally noted once on the newly created game account, so that we can
see which routes lead to lasting players. The note is deleted with the account.
In addition, your game account records on which days it was active (only the date, no time of day). From this we determine how many people come back. The legal basis is our legitimate interest in a working service (Art. 6(1)(f) GDPR); you can object at any time (see section 10).
Feedback: after a solo game, the result page asks whether you liked it — and on “meh”, for the reason from a fixed list (such as “too hard” or “controls”). If you abandon a short game midway, the game menu instead asks once for the reason, from the same list. Both are voluntary and can be skipped. Here, too, only totals per day and game are counted, together with outcome, mode and duration class of the game. There is no free-text field, and no link to your account is created.
Error reports: if something breaks in the game, your browser reports the error message together with file, line and build version to our server — so that we can find crashes nobody would otherwise tell us about. These, too, are pure daily totals. Addresses, file paths and longer digit sequences are replaced before anything is stored; no link to your account or device is created.
All transmission is encrypted (HTTPS/TLS). The server is hardened and continuously supplied with security updates.
You have the right to
You can exercise access and erasure yourself: under Account & Devices, “MY DATA” downloads everything stored for your account as a file (Art. 15 and 20), and “DELETE ACCOUNT” removes the account with all its content from the server (Art. 17). Both are tied to your sign-in, so no proof of identity is needed. The account identifier is shown on the same page.
For everything else, an e-mail to nico@hilgert.email is enough. Please state the account identifier from Account & Devices, or your display name together with something only you can know — such as the name of one of your levels, your league or the day of a duel. Display names are not unique; without such details we cannot reliably tell your account apart from another one, and we neither delete nor disclose anything whose attribution is uncertain.
You can also lodge a complaint with a data protection supervisory authority — the authority of your place of residence or the one responsible for us:
Die Landesbeauftragte für den Datenschutz NiedersachsenRetroduell is a private project and is not specifically aimed at children. There is no chat with free text messages.
If the service is extended, we adapt this policy. The date above shows the current version.