This Policy explains what personal data we process when you use Hoard, why, who we share it with, how long we keep it and what rights you have. The data controller is Raimundo León Oliva, a natural person resident in Spain, whose full identification details are published in the Legal Notice, contactable at [email protected]. We are not required to appoint a Data Protection Officer; enquiries are handled at that same address.
This Policy applies to the managed service at hoard.services. If you self-host Hoard on your own server, you are the controller and none of that data reaches us.
1. What data we process
1.1. Account data
Your email address, a unique account identifier, the sign-up date and, if you sign in with Google, the associated Google identifier. We do not collect your real name unless you enter it yourself.
1.2. Your content and its metadata
The save snapshots you upload, game names and slugs, any labels you add, and per version: size, SHA-256 hash, timestamp and the name and identifier of the device it was created on, so your history can tell you which machine each copy came from. Save folder paths stay on your machine; the server only receives a path where it is needed to restore, and segments identifying your user profile are replaced before they leave.
1.3. Playtime
If you use the statistics features, the application records seconds played per game and local day, per device, and syncs them with your account so the history survives a machine change and your yearly recap can be built. It is activity data: you can stop syncing it or erase it by deleting your account.
1.4. Diagnostics and product telemetry (switchable)
If you keep the "Share anonymous diagnostics" setting on — it is on by default and you can turn it off at any time, with immediate effect — the application sends us:
- Diagnostic events at info level or above (never debug), carrying your device name and a stable identifier generated by the app, to diagnose sync failures.
- Detection corrections: when automatic detection got it wrong and what you did to fix it (the verdict, the game and the shape of the path, with personal segments replaced before leaving your machine). This is what lets us improve detection without relying on people writing in on Discord.
- Hoard Screen usage: when the overlay opens and closes, how long the session lasted and what type of panels were mounted and how many. No window title, application name or thumbnail is ever sent: the content of your screen does not leave your machine.
With the setting off, none of the above is sent and the Service works exactly the same.
1.5. Technical data
IP address, user agent and application version when you contact the API, logged for diagnostics, security and abuse prevention.
1.6. Billing data
Handled entirely by our Merchant of Record, Polar Software Inc. We only receive subscription status (plan, period, next renewal, cancellation) and a customer identifier. We never see or store your card, tax name or postal address.
1.7. Service notices by email
We write to you when something affects your saves and is not in front of you in the app: when automatic cleanup deletes old versions to make room, when a backup does not fit in your space, when a game goes over the per-game size limit, when an archived game is about to be deleted, when your account is using all its devices, and when an export you asked for is ready. Pro accounts only receive the export one.
So as not to repeat ourselves we keep a record of which notice we sent you and when. The cleanup notice repeats at most once a day while it lasts and carries a link to stop it; that link does not identify your account, and it lapses after two weeks without a cleanup.
Some of those notices include an offer to move to Pro. You can refuse them when you sign up or at any time from the link at the foot of each one: the offers stop and the notices about your saves keep coming. We never send email that is only advertising.
2. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, authenticating you | Performance of contract (art. 6(1)(b) GDPR) |
| Storing, versioning and syncing your saves | Performance of contract |
| Recording your playtime and building your recap | Performance of contract |
| Managing your subscription and enforcing plan limits | Performance of contract |
| Recording the date and version of the terms you accepted | Legal obligation and legitimate interest (proof of agreement) |
| Security, abuse prevention and sign-in captcha | Legitimate interest (art. 6(1)(f)) |
| Diagnostics and product telemetry | Legitimate interest, with an off switch (section 1.4) |
| Service communications and critical notices | Performance of contract |
| Offers for Pro inside service notices | Legitimate interest and art. 21.2 LSSI (existing customer, similar own service), with a refusal in every message |
| Tax obligations and requests from authorities | Legal obligation (art. 6(1)(c)) |
You may object at any time to processing based on legitimate interest. For telemetry, the objection is immediate and you exercise it yourself from the application settings.
3. Sub-processors
To operate the Service we rely on the providers listed on our sub-processors page, which we keep current and where we announce additions and removals in advance. All are bound by a processing agreement under art. 28 GDPR.
| Provider | Function | Data hosted in |
|---|---|---|
| Supabase (Supabase Pte Ltd, on AWS) | Authentication | Frankfurt, Germany |
| Cloudflare R2 (Cloudflare, Inc.) | Snapshot storage, encrypted at rest | European Union |
| Cloudflare Turnstile (Cloudflare, Inc.) | Web sign-in captcha | Cloudflare global network |
| Fly.io (Fly.io, Inc.) | API and database hosting | Paris, France |
| GitHub Pages (Microsoft Corp.) | Public site hosting | CDN network |
| Polar Software Inc. | Merchant of Record: charging, VAT, invoicing | United States |
| Resend (Resend, Inc.) | Transactional email | European Union |
4. Location and international transfers
Your account, metadata, playtime and snapshots are stored in the European Union: the database in Paris and the files in Cloudflare R2 storage with EU jurisdiction. Sign-in is served from Frankfurt. We do not replicate that content outside the EU.
Some ancillary processing does involve providers established in the United States: the web sign-in captcha (Cloudflare Turnstile sees your IP address and browser signals), delivery of the public site over CDN, and billing through Polar, which processes your payment data as an independent controller under its own policy. These transfers rely on the EU-U.S. Data Privacy Framework and, in the alternative, on standard contractual clauses approved by the European Commission.
5. How long we keep it
| Data | Retention |
|---|---|
| Account, snapshots, metadata and playtime | While the account is active |
| Account deleted by you | 30-day reversible grace period, then permanent erasure |
| Versions you delete or that automatic cleanup archives | 7 days recoverable, then final purge |
| API technical logs (IP, user agent) | Up to 30 days |
| Application diagnostic events | 14 days |
| Product telemetry (detection and Screen usage) | 180 days |
| Record of email notices sent | Until what caused them is resolved; the cleanup one, 14 days after the last |
| Date you refused offers | For as long as the account exists |
| Record of terms acceptance | For the duration of the relationship plus 5 years |
| Billing | Kept by the Merchant of Record for the applicable tax periods |
6. Automated decisions
We make no automated decisions producing legal effects concerning you, and we do not profile you. One automated process is worth knowing about: storage cleanup, which deletes older versions once your usage crosses a threshold of your quota, always preserving the most recent version, any you have pinned, and a minimum per game. It is described in section 9 of the Terms.
7. Your rights
You have the right to access your data, rectify it, erase it, restrict or object to its processing, and receive it in a portable format. Many of these are automated in the product:
- Access and portability: you can trigger a full export of your data from your account and download it when ready.
- Erasure: you can delete the whole account from the Account section, with 30 days to change your mind.
- Objection to telemetry: a switch in the application settings.
For any other right, write to [email protected]. We reply within one month at the latest. If you believe we have processed your data improperly, you may complain to the Spanish Data Protection Agency at aepd.es or to the supervisory authority of your country of residence.
8. Cookies and browser storage
The public site uses no tracking, advertising or third-party analytics cookies, and shares no data with social networks. We only use:
- browser local storage (localStorage) to keep you signed in;
- local storage to remember your language;
- on the sign-in page, the Cloudflare Turnstile captcha widget, which may store a temporary identifier in your browser for the sole purpose of telling you apart from a bot.
All of it is strictly necessary to provide the service you request, and therefore requires no prior consent.
9. Children
The Service is not directed at anyone under 16, or under the applicable minimum digital-consent age in your country if higher. We do not knowingly collect data from children below that age; if you find such an account, write to us and we will delete it.
10. Security and incidents
Snapshots are encrypted at rest in storage and all communication between the application and the server travels over TLS. We store no plaintext passwords: authentication is delegated to Supabase, which applies strong hashing. API access is logged and service credentials are held in the operating system keyring. We apply least privilege for production access.
Should a security breach occur that poses a risk to your rights, we will notify the Spanish supervisory authority within 72 hours of becoming aware, and inform you without undue delay where the risk is high. No measure is infallible: we recommend not using the Service for legally sensitive data.
11. Changes to this Policy
We may update this Policy. Material changes will be notified by email and in the application at least 30 days in advance. The last-updated date in the header always indicates the version in force.
12. Contact
For any privacy question or to exercise your rights: [email protected].