Legal

Privacy Policy

Updated 28 September 2026

This policy explains what personal data Beyond the Quest processes when you visit beyondthe.quest, play the game in a browser or in the iPhone and iPad app, or play online. The short version: you can play without giving us anything, the game keeps your saves on your own device, we use no advertising or tracking, and the game itself has no analytics.

1. Who is responsible

Hauke Jung, Hauptstr. 41, 79199 Kirchzarten, Germany. Email: mail@haukejung.de. This is also the address for every privacy request.

2. Visiting this website

When you open beyondthe.quest or the game, your browser sends technical data that every web server receives: IP address, date and time, the requested page, referrer, and browser and operating system. We use it only to deliver the pages and to protect the servers from abuse. The website sets no cookies and serves its fonts from our own server. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in running a secure website.

To see how many people visit beyondthe.quest and which pages they read, we use Umami, running on our own server in Germany. Umami sets no cookies and stores nothing on your device. A visit is counted with a hash of the IP address, the browser and a salt that changes daily, so you cannot be recognised on another day or on another site, and the IP address itself is not stored. The statistics are not shared with anyone. This applies to the website only; the game in the browser and in the app sends no analytics. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in understanding how the website is used.

3. Playing without an account

Solo and pass-and-play expeditions, settings, sound preferences and awards are stored on your device only: in your browser's local storage, or in the app's own storage on iPhone and iPad. They are not sent to us. The browser version also caches the game's files so it can start offline. You delete all of this by clearing the site's data in your browser or by uninstalling the app. Save backups you export are files under your control.

4. Online rooms

When you create or join an online room, our server stores the room code, the game state, the explorer names you enter, and when each seat was last connected. Your device receives a secret seat credential; the server keeps only a hash of it. To prevent abuse, the server counts requests per IP address for short time windows. This data is needed to run the game you asked to play (Art. 6 (1) (b) GDPR) and to protect the service (Art. 6 (1) (f) GDPR). Rooms and their data are deleted 30 days after the last move. Request counters expire with their time window.

5. Optional account and friends

You only need an account for a friends list that follows you across devices. For an account we store your email address, a display name, a friend code, your friendships and pending friend requests, the version of the terms you accepted, and, if you enroll one, the public key of a passkey. The private key never leaves your device. Sign-in works with a six-digit code sent to your email; each code expires after 15 minutes. While you are signed in, a strictly necessary session cookie keeps you signed in. Friends see your display name and friend code, never your email address. Legal basis: Art. 6 (1) (b) GDPR.

You can delete your account at any time in the game under Play online → Friends → Delete account. This removes your account, friend code, friendships and passkeys immediately. During the beta, your invitation is kept, so you can create a new account later; ask us if you want it removed too.

6. Beta invitations and waitlist

During the beta, accounts are by invitation. If you ask to join the waitlist, we store your email address and the time you asked, only to invite you later. When you are invited, the address moves from the waitlist to an invitation. You can ask us to remove it at any time. Legal basis: Art. 6 (1) (b) GDPR, steps taken at your request.

7. Error reports

When the game crashes or hits an error, it sends a technical report so we can fix it: the error message and stack trace, the game version, the platform (browser, iOS) and the browser or system version. The reporting library is configured not to send IP addresses, cookies or other personal data, and room codes and map seeds are removed from addresses before sending. Reports go to Thermite, our own error-tracking service on our servers in Germany, and are not shared with anyone. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a working game.

8. Email

Sign-in codes and account emails are delivered through Scaleway Transactional Email, operated by Scaleway SAS in France, which processes your email address on our behalf under a data processing agreement. If you write to us, we use your message and address only to answer you.

9. Hosting and recipients

The website, the game and all its data run on servers we operate, rented from Contabo GmbH in Germany, which acts as our processor. Apart from Contabo and Scaleway, no one receives your data. We do not sell data, show ads, or use tracking tools. If you use the iPhone and iPad app, Apple handles the download under its own privacy policy; the app itself contains no tracking.

10. Children

The game is suitable for all ages and can be played without any personal data. Accounts are intended for people aged 16 and over. Younger players should play without an account or with a parent's consent.

11. Your rights

You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16), deleted (Art. 17) or restricted (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on legitimate interests (Art. 21). Email us to use any of them. You also have the right to complain to a data protection supervisory authority. Ours is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.

12. Changes

If the game starts processing data in a new way, for example with in-app purchases, we will update this policy first and note the date above.