Items marked UPDATE REQUIRED still need an operational decision or verified provider detail. This page is excluded from search indexing until those items are resolved.
01
Who controls your data
The controller of personal data processed by Casualer is UPDATE REQUIRED: full name, the creator and operator of Casualer.
For privacy questions or requests, email [email protected].
02
What data we process
Account data
Email address, password hash, internal account ID, account type, roles, verification state, and account timestamps.
Guest identity
A random guest identifier, an internal library owner ID, and timestamps used to restore and expire the guest workspace.
Your library
Games, statuses, ratings, playtime, play dates, hardware, platforms, tags, manual and automatic lists, and their ordering. A library entry that came from a Steam import also records the Steam application ID it was matched from, whether its playtime was reported by Steam or entered by you, and when that import wrote it.
External account identifiers
If you start a Steam import, the Steam ID confirmed by Steam's sign-in is stored on that import, together with the moment it was confirmed. It identifies an account held with Valve, which Casualer does not control. Casualer also asks Valve for that account's public display name and shows it while the import is being set up, so you can see which Steam account you signed in to before anything is added to your library; the name is removed when the import finishes. No Steam password, token, or other Steam account access is received or stored.
Steam import in progress
While a Steam import is running or waiting for your decisions, it holds a copy of the games list Steam reported: application ID, the title Steam uses, the lifetime playtime it reports, and the choices you make about each entry. It also holds the rules you set for that import — which status to give games depending on whether Steam reported playtime for them, and what to do when Steam's playtime disagrees with yours — and, while the import is writing to your library, a record of each game it handled and why any of them could not be added. That per-game record is removed when the import finishes. Stopping an import part-way does not end it - it goes back to waiting for your decisions, keeps what it holds, and can be picked up again. The same is true once it has added the games you selected while entries you have not answered are still waiting: the import goes on waiting for your decisions and keeps what it holds, so you can match or dismiss the rest and add them without signing in to Steam again.
When an import finishes, the copy of the games list is removed except for the entries Casualer could not match to exactly one game — their application ID, the title Steam uses and the lifetime playtime it reports. Those are kept so you can come back to them from your account page, and they are removed when you dismiss them or when you start another Steam import.
When you answer one of those entries — by matching it to a game during an import, or by dismissing it from your account page — the answer itself is kept: the application ID, the title Steam uses, and either the catalogue games you chose or the fact that you chose none. It is kept so later imports do not ask you the same question again, it is shown to you under Your decisions on that page, and it is removed when you undo it there.
Your content
Reviews, notes, uploaded image attachments, original filenames, file types, sizes, creation dates, and rankings you build from your library (their names, descriptions, category labels, and the position each game holds).
Security data
IP address, session identifiers, rate-limit keys derived with HMAC, request paths and non-token query strings, request and error diagnostics, and security-related events.
Support data
Feedback type, title, description, a stable case ID, and the account ID and current email address used to route the submission and its confirmation.
Account operations
Email verification, password-reset and pending email-change tokens, queued transactional messages, and temporary export archives.
Usage analytics
Page views, referrer, browser, operating system, device type, country, and a pseudonymous session identifier produced by Umami.
Passwords are not stored in plain text. Casualer does not request payment details, government identifiers, or precise location. Please do not upload sensitive information such as health data, political or religious beliefs, passwords, financial details, or confidential information about other people, in notes, reviews, attachments, or feedback.
03
Why we process it
| Purpose | Legal basis |
|---|---|
| Provide guest mode, accounts, private libraries, imports, exports, and requested account operations. | Performance of the service or steps you request — Article 6(1)(b) GDPR. |
| Secure the service, limit abuse, diagnose errors, and maintain reliable backups. | Legitimate interests in service security and reliability — Article 6(1)(f) GDPR. |
| Receive and respond to bug reports, ideas, and support messages. | Legitimate interest in maintaining and improving the project — Article 6(1)(f) GDPR. |
| Handle privacy requests and comply with binding legal obligations. | Legal obligation — Article 6(1)(c) GDPR. |
| Measure aggregate product usage through the standard, cookie-free Umami configuration. | Legitimate interest in understanding and improving the project — Article 6(1)(f) GDPR. |
| Establish, exercise, or defend legal claims where necessary. | Legitimate interest in protecting the operator and users — Article 6(1)(f) GDPR. |
Casualer does not sell personal data, run advertising, or use personal data for marketing profiles.
04
Guest mode
Guest libraries are stored on the Casualer server, not only in your browser. A random, non-guessable
guest_id cookie connects the browser to its server-side library. Qualifying activity refreshes
the library's rolling retention window, for up to 90 days from the last qualifying activity.
Losing or clearing the guest cookie can make the library inaccessible before the server-side retention window ends. Creating an account from the active guest session upgrades the same library in place.
07
How long data is kept
- Registered account and libraryUntil account deletion
- Queued feedback and confirmation contentUntil successful email delivery; failed queued deliveries are scheduled for deletion after 30 days
- Message headers and content processed by MailgunNo provider retention period after delivery under the current Free plan (0 days); transient processing is still required to deliver the message
- Mailgun delivery logs and events1 day under the current Free plan
- Feedback and privacy-request correspondence in the operator mailboxUPDATE REQUIRED: configure and document mailbox retention
- Active guest libraryRolling window, up to 90 days from last qualifying activity
- Remember-me cookieUp to 90 days
- Password-reset token1 hour
- Pending email change24 hours
- Empty, unverified accountEligible for deletion after 7 days
- Unfinished Steam import, including its copy of the Steam games listUnusable after 30 days from the moment it was started, and scheduled for deletion by an hourly sweep from that point
- Completed Steam importKept as a summary — the Steam ID, its timestamps and the resulting counts — plus the Steam entries that could not be matched, until you dismiss them or start another Steam import. The rest of the copy of the games list is removed
- Your answers about Steam entries Casualer could not matchKept until you undo them from your account page
- Steam application ID to catalogue mappingKept indefinitely as a shared technical cache; contains no account data
- Export download token1 hour
- Generated export archiveScheduled for deletion within 24 hours
- Other failed queued deliveriesScheduled for deletion after 30 days
- Umami analyticsFor the lifetime of the active project; deleted when the analytics instance is retired
- Technical logsScheduled for deletion after 14 days; entries may be removed earlier when the host journal reaches its storage or free-space threshold
Backups
Backups contain the PostgreSQL database, locally stored game covers, and uploaded note attachments. One backup is created daily. The two newest daily copies and one rotating monthly copy are retained; older copies are replaced automatically. Backup archives are encrypted and kept on a private machine controlled by the operator. Data deleted from the live service may therefore remain in a backup until that copy is replaced. Deleted data may remain in an encrypted monthly backup until that backup is replaced at the beginning of the following month, generally for no longer than about one month. A restored backup must be reconciled with deletion requests already completed.
Feedback and privacy-request emails already sent before account deletion remain subject to the mailbox retention period above.
08
Your choices and rights
Depending on the circumstances, you may request:
- access to your personal data;
- correction of inaccurate data;
- deletion of data;
- restriction of processing;
- data portability;
- objection to processing based on legitimate interests.
Registered users can delete their account in account settings and can submit a data-access request through the private feedback form. Anyone, including a guest user, may contact [email protected]. Casualer may request information needed to verify that a request relates to the correct account or guest session.
The library ZIP available in account settings is a product backup, not necessarily a complete response to a GDPR access request. You may lodge a complaint with the Polish President of the Personal Data Protection Office (Prezes UODO).
Casualer does not make solely automated decisions that produce legal or similarly significant effects.
09
Security and user precautions
Casualer uses access controls, password hashing, CSRF protection, rate limiting, signed private-file URLs, encrypted network transport, isolated per-user libraries, and backups. No internet service can guarantee absolute security.
Reviews, notes, lists, and attachments are designed as private library content and are not intentionally published to other users. Avoid uploading secrets or information about other people unless you have a lawful reason to do so.
10
Changes to this policy
This policy may change when Casualer functionality, infrastructure, or legal obligations change. Material changes will be communicated in the application where reasonably possible. The effective date at the top identifies the current version.
The rules for using the service are described separately in the Terms of Service.
Back to Casualer