Back to Game

Privacy Policy

Policy version: 2026-09-08.2
Last updated: 2026-09-08

StillDeck (“we”, “us”, “our”) is a free online Klondike solitaire game operated by MN Media s.r.o. This policy explains what data we collect, why, and what choices you have.

We keep things simple: gameplay and settings are stored locally by default, optional measurement and advertising follow your privacy choices, and we never sell personal data.

What we collect and why

Without an account (default)

Your entire game — cards, moves, score, settings, and statistics — is stored locally in your browser using localStorage. The site may still contact Google for consent management and, subject to your choices in Google Privacy & Messaging and applicable law, Google AdSense may show up to three static display ads to the right of the game, only on sufficiently wide desktop game layouts. No display ad is shown during active play on phones or tablets. We assign a pseudonymous device identifier (a random UUID stored in localStorage) solely so that if you later create an account, we can merge your local stats with the server copy without duplicating them.

With an optional account

If you choose to sign in (email magic-link, no password), we additionally store:

  • Your email address — to authenticate you and send the sign-in link.
  • Game results (win/loss, time, moves, score per game) — to sync statistics across your devices.
  • Settings JSON (theme, draw mode, accessibility preferences) — to sync preferences.
  • Device identifier — linked to your account to prevent duplicate stat merges.

Feedback you choose to send

Feedback is user-triggered and leaves your browser only when you press Send. We process:

  • Your message, optional email address, locale, page path, feedback type, entry point, and game variant.
  • For bug reports only, bounded game, deal, move-count, and display diagnostics, together with the browser user-agent string and application release identifier where available.
  • Before reaching StillDeck, the feedback request passes through Bunny CDN, which uses the client IP address and request path for edge anti-abuse controls and forwards the form fields to the application. StillDeck’s own limiter holds the raw client IP address only in server process memory; scheduled cleanup removes it after the rolling window, or a process restart removes it sooner. The IP address is not included in the delivered email. Bunny edge and request-log retention settings remain pending operator/legal review.
  • The SMTP feedback endpoint forwards the message over an authenticated connection to an operator-configured mailbox and creates no new application database copy. During this rollback-safe transition, older cached application versions can still write to the legacy Supabase feedback table; those rows are readable only by administrators. Public insert access will be revoked in the follow-up release after the SMTP release is live-accepted and no longer retained as the rollback target.

After analytics consent

If you accept analytics cookies, Google Analytics 4 collects:

  • Truncated IP address (last octet zeroed by GA4 default).
  • User-agent string, screen resolution, browser language.
  • Pages visited, feature-usage events (e.g. “started game”, “changed theme”).

After session replay consent

If you accept session replay, Microsoft Clarity collects:

  • Anonymized IP address.
  • Clicks, scrolls, and cursor movements.
  • Page content snapshots with sensitive input fields masked.

Advertising and consent management

Google Privacy & Messaging manages advertising choices. Subject to those choices and applicable law, Google AdSense may show up to three static display ads to the right of the game, only on sufficiently wide desktop game layouts. No display ad is shown during active play on phones or tablets. Google may process:

  • IP address, user-agent string, device information, and browser language.
  • Consent signals and advertising identifiers or cookies where permitted.
  • Ad delivery, interaction, frequency-control, measurement, and fraud-prevention data.

Where your choices and applicable law permit, Google and other advertising vendors use cookies to select ads using your earlier visits to StillDeck or other websites. Google’s advertising cookies allow Google and its partners to personalize ads across these sites.

You can turn off personalized advertising using the controls below. These choices affect personalization; they do not remove all ads.

Other advertising vendors and ad networks may also use advertising cookies. Where Google’s European privacy message is available, open cookie settings to see the partners selected for StillDeck and their privacy links. Google also publishes a broader list of eligible advertising partners and links to their websites; not every listed partner serves ads on StillDeck.

Google advertising partner lists and privacy links

Site delivery and operational logs

Requests pass through Bunny CDN and the Hostinger origin for delivery and security. Bunny request logging and IP anonymisation are enabled; forwarding, permanent log storage and extended logging are disabled. The origin also keeps Caddy access logs containing connection metadata, request URL, method, ordinary headers, response status and timing. Sensitive authentication and cookie headers are masked. Origin access logs are separate from the application rate limiter.

Bunny documents a three-day limit for ordinary raw logs. IP anonymisation does not establish when the original address is erased; separate provider security records remain subject to unverified retention. Caddy access logs rotate at 100 MiB by default, retaining up to ten archives with a 90-day age limit checked during rotation. The active file has no fixed age expiry. Application output enters journald, limited to seven days, 1 GB total and one-day files, and can also enter local syslog, which rotates weekly with four archives, potentially about 35 days. Hostinger platform/network retention and provider-side deletion remain unverified.

Legal bases for processing

Under the GDPR we rely on the following legal bases:

  • Consent — Art. 6(1)(a) — Analytics (GA4), session replay (Microsoft Clarity), and advertising storage or personalization where required. You can withdraw consent at any time through the Google privacy message in the footer or Settings panel.
  • Performance of a contract — Art. 6(1)(b) — Storing your game state, settings, and statistics locally; account creation and cross-device sync when you choose to sign in.
  • Legitimate interest — Art. 6(1)(f) — Security logging, fraud prevention, and maintaining service reliability. We balance our interest against your rights by minimizing the data collected and retaining it only as long as necessary.
  • Feedback delivery and abuse prevention — legitimate interests (GDPR Art. 6(1)(f)) — Delivering and handling feedback you choose to send, preventing abuse, and investigating reported problems. We minimize the fields collected and separate bug-only diagnostics from other feedback.

Sub-processors

We share data with the following third-party processors:

Cookies and local storage

StillDeck uses localStorage for essential game data. Google and Microsoft may use cookies or local storage for analytics, session replay, consent management, and advertising according to your privacy choices.

Users in the EEA, UK, and Switzerland choose through Google’s privacy message. Elsewhere, these tools operate according to applicable law and product settings. You can review your choices at any time via Settings → Privacy & data.

International transfers

Essential account data stays within the EU (Supabase, AWS eu-west-1). Google Analytics, Microsoft Clarity, Google Privacy & Messaging, and Google AdSense data may be transferred to the United States under the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914). Declining the relevant choices limits non-essential transfers, although consent, security, and fraud-prevention data may still be processed where necessary.

Feedback requests pass through Bunny CDN before reaching the StillDeck application and are then delivered through the operator-configured SMTP and mailbox provider. Exact processing locations, transfer mechanisms, retention settings, and contract or DPA status for those feedback providers remain pending operator/legal review.

How long we keep your data

We retain data only as long as necessary for the purposes described above.

  • Account email: Retained for the life of your account. Deleted within 30 days of account deletion.
  • Game results (server): Retained for the life of your account. Deleted together with your account.
  • Settings (server): Retained for the life of your account. Deleted together with your account.
  • Device identifier: Tied to account lifetime. Stored locally until you clear browser storage.
  • Google Analytics: Google Analytics default retention: 14 months for user-level data.
  • Session recordings: Session recordings retained up to 13 months by Microsoft Clarity, then auto-deleted.
  • Advertising and consent data: Google retains advertising and consent data according to its product settings and applicable legal requirements.
  • Feedback email (operator mailbox): The SMTP feedback endpoint creates no new application database copy. The delivered email remains in the operator-configured mailbox until the operator deletes it.
  • Legacy feedback database (rollback window): During the rollback-safe transition, feedback submitted by older cached application versions may remain in the legacy Supabase feedback table and is readable only by administrators. Public insert access will be revoked in the follow-up release after the SMTP release is live-accepted and no longer retained as the rollback target; retained rows remain until an administrator deletes them.
  • Feedback abuse-control IP address: StillDeck’s application limiter holds the raw client IP address in server process memory and deletes it by scheduled cleanup after its rolling rate-limit window expires; a process restart removes it sooner. The separate Bunny edge and request-log retention settings remain pending operator/legal review.
  • Local storage (browser): Retained until you clear your browser storage.

Your rights

Under the GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate personal data.
  • Erasure — request deletion of your data (“right to be forgotten”).
  • Restriction — ask us to limit how we process your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interest.

You also have the right to lodge a complaint with your local data protection authority. For users in Czechia, this is the Office for Personal Data Protection (ÚOOU).

Withdrawing consent

In the EEA, UK, and Switzerland, Google’s privacy message lets you change or withdraw applicable consent choices. Outside the message’s scope, the same footer or Settings control opens StillDeck’s on-device opt-out for analytics and session replay; this local control does not manage advertising. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

Children’s privacy

StillDeck is a general-audience card game. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated through a refreshed Google privacy message or another prominent notice. The “Last updated” date at the top of this page always reflects the latest revision.

Contact us

If you have questions about this policy or want to exercise your rights, email us at hello@mnmedia.io. We aim to respond within 30 days.

Data controller

The data controller for StillDeck is:

MN Media s.r.o.
Varšavská 715/36, Vinohrady, 120 00 Praha 2, Czechia
hello@mnmedia.io

Privacy & data

Control analytics and session replay on this device.