← Home

LEGAL

Privacy Policy

What Kridona Games stores about makers and players, why, and how to get it removed.

Last updated: October 6, 2026

Data controller: Kristijan Babić, Straubing, Germany — kridona.official@gmail.com

1. Two kinds of people

Makers have an account and make games. Players play games on their links and never need an account. We store far less about players than about makers.

2. What we store about makers

3. What we store about players

4. How we use it

5. Services we use

ServicePurposeData shared
StripePaymentsEmail, payment details
AnthropicAI that writes and changes gamesYour game requests and the game's code
CloudflareHosting kridona.games and every game, own domainsGame files; players' IP addresses in transit
RailwayOur APIAccount and game data in transit
SupabaseDatabaseAccount, game, play and leaderboard data
ResendEmailsEmail address

Each service works under its own privacy policy. We share only what each one needs to work.

6. Cookies and browser storage

We use no tracking or advertising cookies. The browser keeps a few things locally: your sign-in on kridona.games, and in games the random player number, your leaderboard name and game progress (saves). You can clear them in your browser at any time.

7. How long we keep it

Account data and games are kept while your account is active. Play counts and leaderboard entries are kept while the game exists. Payment records are kept as tax law requires. After you delete your account, your data is removed within 30 days, except where the law says we must keep it.

8. Your rights (GDPR)

You can ask for a copy of your data, its correction or deletion, limit or object to how we use it, and take your data with you. Write to kridona.official@gmail.com — we answer within 30 days. You can also complain to a data protection authority.

9. Children

Making games requires an account, and accounts are for people aged 16 or older. Anyone can play games, but players are never asked for personal data. If you believe a child gave us personal data, write to us and we will delete it.

10. Security

Passwords are hashed (PBKDF2, 600,000 rounds, SHA-512), everything travels over HTTPS, sign-ins use tokens that are blocked on sign-out, sign-in attempts are rate limited, and card data never reaches us.