Account
SaidWho?← Home

Privacy Policy

1. Data Controller

Noodle Media Menzelstraße 31 12623 Berlin Deutschland Email: [email protected]

2. Website Provision and Server Logs

When the site is accessed, the server processes technically necessary connection data, in particular IP address, timestamp, accessed URL, browser identifier and technical status information. This serves the secure and error-free provision of the service and the prevention of misuse (Art. 6(1)(f) GDPR).

Technical application logs in the SaidWho database are automatically deleted once they are older than 90 days. Logs of the hosting infrastructure are subject to the retention periods defined there.

3. Use of SaidWho

When creating and playing, the room code, display name, optional emoji, game status, answers, votes, points and timestamps of game activity are processed. This data is required to provide the requested multiplayer game (Art. 6(1)(b) GDPR) and to enable stable, abuse-free operation (Art. 6(1)(f) GDPR).

Completed games including rounds, answers, votes and points are automatically and permanently deleted once their end date is more than 356 days in the past.

Answer contents are encrypted in the submitting browser before transmission using a key created for that game. SaidWho stores only ciphertext. During the live game, the key is exchanged between authorised game browsers only in wrapped form; the server and administration area never receive a readable answer key. Answer contents are therefore not available through the database or admin area.

During a game, answers are disclosed only as required by the selected game phase to participating persons and, where enabled, observers. After the game, readable answer contents are available only in the archive of the logged-in account that created the game and only on a browser that still holds the local game key. Other account participants and administrators see only the question used and whether a person submitted an answer. Older unencrypted answer contents were permanently removed when this protection was introduced.

4. Technically Necessary Storage

SaidWho uses technically necessary, random session identifiers in HttpOnly cookies so that hosts and participants can be assigned to their game and admin sessions can be protected. In addition, a random visitor identifier is stored in the browser's local storage to determine anonymous live statistics and connection status. It does not contain a name in itself and can be deleted via the browser data.

If a logged-in person creates a game, its per-game answer key is stored locally in that browser so that encrypted answers can later be read in the creator's archive. The key is not synchronised with SaidWho or the account. Clearing the browser data also deletes this key; SaidWho cannot restore it and the encrypted answer contents then remain unreadable.

5. Submitted Questions and CAPTCHA

When a question is submitted, the question text, chosen category and intensity are saved and made available for moderation. To prevent misuse, SaidWho uses a self-hosted Cap CAPTCHA instance. A computational proof of work is generated in the browser and verified server-side; no Google reCAPTCHA is used.

6. Optional User Accounts

The website can be used fully without a user account. Upon voluntary registration, username, email address, confirmation status, securely hashed password proof, sessions, friendships, game invitations and the timestamp of last activity are processed. The email address is used to confirm and secure the account. Linked completed games are shown in the personal archive. The legal basis is the provision of voluntarily requested account features (Art. 6(1)(b) GDPR).

Confirmation links are time-limited and are only stored server-side in hashed form. Email address changes are only adopted after confirmation of the new address; until then the previous confirmed address remains active. Online status is only visible to confirmed friends and is derived from the last logged-in activity. Passwords are not stored in plain text.

The account can be permanently deleted in account management after re-entering the password. Account data, friendships, sessions, passkeys, own question packs, associated support histories and own participations, answers and votes are removed. Games created by the person can remain in other people's archives without account linkage and with an anonymised host name until the general retention period expires.

Logged-in users can, after a CAPTCHA check, request a machine-readable disclosure of the data associated with their account to their confirmed email address.

When referral links are used, the existing account through which the registration came about is stored. This is used exclusively to calculate the visible pack slot bonus. For community question packs, submitted star ratings and reports are associated with the logged-in account to limit multiple ratings and misuse. Public displays show ratings only in aggregated form; the reporting person is not published.

Analytics in the protected administration area are formed from aggregated game, feature and community counts. For audience landing pages, the accessed page, a rough origin category (for example direct, Google, other search or social media) and if applicable only the domain name of the referring website are additionally stored. Full referral URLs, search terms, IP addresses or personal identifiers are not stored for this purpose. The analysis serves to improve the service and does not show individual answers or personal usage profiles.

7. Support Requests

For a support request, name, email address, subject, message history and processing status are processed. The information is used exclusively for processing and responding to the enquiry. The personal conversation link contains a random access key; server-side, access keys are only stored in hashed form. The link must not be passed on to unauthorised persons.

The specified email address is used via the configured SMTP service to notify about replies. The data is deleted once it is no longer required for processing, abuse prevention or legal evidence.

8. Hosting and Recipients

Technical service providers may process data exclusively to the extent necessary for hosting, database operation and provision. The specific hosting details have not yet been entered.

Data is otherwise only passed on if required by law, necessary for legal enforcement, or if consent has been given.

9. Rights of Data Subjects

Data subjects have, subject to the statutory requirements, the right to access, rectification, erasure, restriction of processing, data portability and objection. Consent given can be withdrawn at any time for the future. There is also a right to lodge a complaint with a data protection supervisory authority.

Requests can be sent to [email protected].

10. Updates to This Policy

This privacy policy is updated when features, services used or legal requirements change.

Last updated: 31/07/2026

How it worksQuestion PacksGame IdeasSystem StatusSupportPrivacy PolicyLegal Notice
© 2026 SaidWho