← Back to Home

Privacy Policy

Last updated: 2026-07-25

1. Who we are

This privacy policy explains how personal data is processed when you use SupaSnake (the "Game"), available at https://supasnake.com. The controller within the meaning of Art. 4(7) GDPR is:

Insoucience Technologies GmbH
Modecenterstraße 20/1/410
1030 Vienna, Austria
E-mail: support@supasnake.com

Data protection contact (Datenschutzbeauftragter): Josef Bell, support@supasnake.com. You can also use our contact form (category "Privacy / data request").

2. The short version

  • You can play as a guest without giving us your name or e-mail address. Game progress is stored under a pseudonymous account ID.
  • Analytics runs only if you opt in via the cookie banner, and is hosted in the EU.
  • We never sell personal data, and we do not show third-party advertising.
  • Payment card data is handled exclusively by Stripe — it never touches our servers.
  • Our AI features receive only aggregate game statistics — no names, e-mail addresses or account IDs.
  • You can export or delete your data yourself at any time in Settings → Privacy.

3. What we process, why, and on what legal basis

3.1 Account and authentication

The Game uses Supabase Auth. You can play anonymously (a random account ID, no e-mail), register with e-mail and password, or sign in with Google or Apple. If you upgrade a guest account, the e-mail address is attached to your existing account ID so your progress is preserved.

Data: account ID, e-mail address (registered accounts only), password hash, OAuth provider identity (Google/Apple account reference), session tokens, sign-in timestamps.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract — providing your account and saved progress). Retention: until account deletion.

3.2 Game progress and gameplay data

All game state is stored server-side: collected snakes, breeding history, resources (DNA, energy), game sessions (score, duration, DNA earned), achievements, streaks, mastery, records, battle pass and season progress, and economy transactions.

Legal basis: Art. 6(1)(b) GDPR. Retention: until account deletion.

3.3 Public profile, leaderboards and Chronicle

Your public identity in the Game is a self-chosen handle (or an automatically derived placeholder such as "handler-1234"). Leaderboards and your public Chronicle page show your handle, scores, clan tag, titles, badges, avatar and mastery — never your e-mail address or account ID. Handle changes are recorded in an internal audit log.

Legal basis: Art. 6(1)(b) GDPR (leaderboards and public profiles are a core feature of the Game). If you prefer not to be recognisable, choose a handle that does not identify you, or keep the generated placeholder.

3.4 Clans

Clan names, tags and descriptions are user-generated content visible to other players, together with the member list (handles) and clan activity (duels, research, ratings).

Legal basis: Art. 6(1)(b) GDPR. Retention: until deletion.

3.5 Discord integration (optional)

If you actively link your Discord account, we receive your Discord user ID and username via Discord OAuth (scopes: identify, guilds.join, role_connections.write), can add you to our Discord server and assign roles, and push your in-game handle and mastery as "Linked Roles" metadata. Clans can connect a Discord channel; in that case in-game events (duel results, level-ups, member joins, season champions) are posted there with your handle and clan name. OAuth tokens are stored encrypted (AES-256-GCM) and are deleted — and revoked at Discord — when you unlink; stale links are purged after 30 days.

Legal basis: Art. 6(1)(a) GDPR (consent, given by linking). You can withdraw it at any time by unlinking. Discord Inc. is an independent controller for its own platform — see Discord's privacy policy.

3.6 Analytics (PostHog) — only with your consent

If (and only if) you enable the "Analytics" category in the cookie banner, we use PostHog, hosted in the EU (eu.i.posthog.com), to understand how the Game is used. We use a curated event set (page views, gameplay, economy, purchases, engagement and social events) with autocapture and session recording disabled. Its device ID, analytics session, and person properties remain in page memory only and disappear when the page closes; browser storage retains only your analytics opt-in or opt-out choice. After sign-in, transmitted events are linked to your account ID. Revoking consent stops all capture.

Legal basis: Art. 6(1)(a) GDPR and §165(3) TKG 2021 (consent). Manage it any time via Settings → Privacy.

3.6a Attribution (where you came from) — only with your consent

If (and only if) you enable the "Marketing" category in the cookie banner, we record which channel brought you to the Game: the campaign labels contained in the link you followed (utm_source, utm_medium, utm_campaign, utm_content, utm_term) and the host name of the referring site — never the full referring address. It is stored in your browser's session storage for the current tab only and attached, as a channel label, to your analytics profile if you later create an account. We operate no advertising network, buy no advertising, and place no third-party advertising tags or advertising identifiers. With the category off, nothing is stored and your visit is counted as "direct".

Legal basis: Art. 6(1)(a) GDPR and §165(3) TKG 2021 (consent).

3.7 Error tracking (Sentry)

To keep the Game stable we send error reports (stack traces, affected route, browser/OS context) to Sentry. Transmission of personal data is disabled by default (no IP addresses attached) and we do not use session replay.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in detecting and fixing errors).

3.8 AI features (“The Analyst”)

The Analyst generates short narrative summaries of your game performance. The input sent to our AI provider (OpenAI) is a fact sheet of aggregate game statistics only — runs, DNA, extraction rate, League mastery. No handle, e-mail address, account ID or free-text content is transmitted. Generated insights are cached in our database and visible only to you (or your clan, for clan insights). The Analyst involves no automated decision-making with legal or similarly significant effects (Art. 22 GDPR).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing game features); the underlying gameplay data is processed under Art. 6(1)(b).

3.9 E-mail

Transactional e-mail (verification, password reset) is sent via our e-mail provider Resend. The weekly "Analyst digest" (your game stats and narration) is strictly opt-in in Settings and can be disabled there at any time.

The "Dispatch" is a separate opt-in list for occasional product news and the results of the weekly hunt. It uses double opt-in: we store your address with a "pending" status and send exactly one confirmation e-mail. If you do not click the link in it, the address is never used for anything else and never receives another message. We store the address, its status, the timestamps, and a coarse channel label (see 3.6a); we never store the confirmation or unsubscribe token itself, only a hash of it. Every Dispatch message carries a one-click unsubscribe link, and the list is never used for advertising.

Legal basis: Art. 6(1)(b) GDPR for transactional mail; Art. 6(1)(a) (consent) for the digest and the Dispatch. Retention: until you unsubscribe. An entry that is never confirmed stays permanently unusable — it can never receive a Dispatch message — and any address can be erased on request via the contact address above.

3.10 Purchases (Stripe)

Purchases are processed by Stripe via Stripe Checkout. Stripe collects your e-mail, billing and payment card details directly — this data never reaches our servers. We store only the Stripe session and payment-intent IDs, the product, price and purchase status, linked to your account.

Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) (statutory retention duties). Retention: purchase records are kept for 7 years in line with Austrian tax law (§132 BAO), in anonymized form if you delete your account.

3.11 Contact form and support

If you contact us, we process the details you provide (name if given, e-mail address, category, message) to handle your request, including privacy inquiries and content reports.

Legal basis: Art. 6(1)(b) GDPR (contractual/pre-contractual communication) or Art. 6(1)(f) (responding to inquiries); Art. 6(1)(c) where handling the request is legally required. Retention: 24 months after resolution, longer where a legal obligation or dispute requires it.

3.12 Age verification

At registration we ask for your birth year and month to enforce our minimum age of 14. We do not store either value — only a salted hash and the verification result, which expires after 7 days.

Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 8 GDPR and §4(4) DSG.

4. Recipients and processors

We use the following processors (Art. 28 GDPR) and recipients. Where a provider processes data outside the EU/EEA, transfers are safeguarded by an adequacy decision (including the EU–U.S. Data Privacy Framework) and/or EU Standard Contractual Clauses (SCCs):

ProviderPurposeLocation / transfer basis
SupabaseDatabase, authenticationEU-hosted project
VercelHosting, deliveryUSA — DPF / SCCs
PostHogAnalytics (opt-in)EU cloud
SentryError trackingUSA — DPF / SCCs
StripePaymentsUSA — DPF / SCCs
ResendE-mail deliveryUSA — DPF / SCCs
OpenAIAI narration (aggregate stats only)USA — DPF / SCCs
DiscordOptional account link (independent controller)USA — DPF / SCCs

We do not sell personal data and we do not share it with advertisers. Beyond the providers above, data is disclosed only where we are legally required to do so.

5. Your rights

Under the GDPR you have the right to:

  • Access your personal data (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure ("right to be forgotten", Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw any consent at any time, with effect for the future (Art. 7(3))

The fastest way to exercise most rights is self-service: Settings → Privacy lets you export all your data (JSON) and delete your account. Deletion takes effect after a 30-day grace period (sign in again to cancel); purchase records are retained in anonymized form where tax law requires. For anything else, contact support@supasnake.com.

You also have the right to lodge a complaint with a supervisory authority, in particular the Österreichische Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.

6. Children

The Game is not directed at children under 14. In line with Art. 8 GDPR and §4(4) of the Austrian Data Protection Act (DSG), you must be at least 14 years old to create an account. If you believe a child under 14 has provided us personal data, contact us and we will delete it.

7. Cookies and similar technologies

Details on every cookie and localStorage entry we use — and how consent works — are in our Cookie Policy. Non-essential technologies are used only with your consent (§165(3) TKG 2021), which you can change at any time.

8. Security

All traffic is TLS-encrypted. Game state is server-authoritative; database access is protected by row-level security so players can only read their own data. Discord OAuth tokens are stored with app-layer AES-256-GCM encryption. Payment card data is handled only by Stripe (PCI-DSS certified). No system is perfectly secure, but we follow the principle of collecting as little personal data as possible in the first place.

9. Users outside the EEA

We apply the GDPR standard described in this policy to all users worldwide. For California residents: we do not sell or share personal information within the meaning of the CCPA/CPRA, and you may exercise access and deletion rights through the same channels described in section 5.

10. Changes to this policy

We update this policy when the Game or our providers change. The date at the top reflects the latest revision; material changes will be announced in the Game. Earlier versions are available on request.

Privacy Policy | SupaSnake — SupaSnake