RunMyGame Privacy Policy
RunMyGame keeps score for your board and card games. Playing requires no account and no connection: without an account, your games, your players and your settings stay on your device.
1. In short
Without an account or live sharing, none of your game data leaves your phone. The only information we then receive are the usage events described in section 4: they tell us which games are being played — never by whom, never with whom, never where. The account is optional; what it keeps, if you create one, is described in section 9.
The free version shows Google AdMob advertising banners, described in section 10. Premium shows none; it is bought through Google Play and RevenueCat (section 12).
Sharing a game live sends its progress through our servers, for the length of the session only (section 11).
2. Who is responsible for this data
Data controller: Gaëtan Gouhier, sole trader (entrepreneur individuel), SIREN 820549798, SIRET 82054979800040, EU VAT number FR90820549798, 1469 rue de Las Sorbes, 34070 Montpellier, France. Trading name: GGO Labs.
Contact: contact@ggolabs.com. There is no data protection officer: the organisation is not required to appoint one.
3. What stays on your device
Everything you enter: your games and how they unfolded, the names and avatars of the players you save, your settings, your history and your personal statistics. This data is stored in a local database, protected by your operating system's encryption.
Without an account or live sharing, it is never sent to us and we have no way of accessing it; uninstalling the app deletes it permanently. With an account, our servers also keep a copy of it: section 9 says exactly what. A game shared live goes through our servers for the length of the session: see section 11.
4. Usage events
To know which games deserve to be added or improved, the app sends us pseudonymous usage events. They are not statistics yet: aggregation happens on our side, after they arrive. They contain none of your game content, none of your player names, and none of your scores.
What an event contains
| Data | Example | Precision |
|---|---|---|
| Installation identifier | a randomly drawn number | see below |
| Event type | "game finished" | ten types sent by this version, listed below; the format allows for one more, not active |
| Game and player count | Belote, 4 players | never player names |
| Suggested term | "Twilight Imperium" | only when you tap "Suggest this game", see below |
| App version, language | 1.0.0, French | — |
| Platform and device | Android 16, phone | major version only, two device categories |
| Date | 6 September 2026 | the stored event holds the day only, not the time |
The ten event types: app opened; game created, finished or abandoned; championship created; table saved; catalogue search with no result; sharing session opened by the scorer; session joined by a guest; game suggested. The two sharing events hold nothing but their type: not the game, not the role, not the number of guests.
The installation identifier
It is drawn at random by the app, kept on your device, and its value is sent to us with every event — that is what lets us know ten games came from the same installation. This is precisely why this data is pseudonymous and not anonymous.
What we undertake never to do with it:
- It is never linked to an account, to your identity, or to an email address.
- It is never your device's advertising identifier, nor an identifier shared with another app.
- It is used for this measurement only: no targeting, no profiling, no customer support.
- It is renewed after 13 months, and you can reset it whenever you like.
It counts installations, not people. Two phones in a household are two installations; two players on the same device are one. We do not know how many people use RunMyGame, and we do not try to find out.
No free text is ever sent automatically
When a catalogue search returns nothing, we receive the bare count — not the word you typed. Under "No game matches", the Suggest this game button sends us the term exactly as you searched it, capped at 80 characters: only if you tap it yourself, and it is the only free text in the whole usage measurement. A message gives you 5 seconds to cancel; the same term is sent only once per device. The term travels with your usage statistics, under the same installation identifier, and is deleted with them. The button does not appear when usage measurement is switched off. Type nothing there but a game name.
How to opt out
In the settings, the Usage statistics section holds three controls: the Share usage statistics switch, which turns measurement off; Reset my statistics identifier; and Delete my statistics, which requests erasure of the events already sent on our servers, not just on your device. If the device is offline when you ask, the request is recorded and leaves as soon as the network is back. Events are sent in batches, at most once a day, and wait for a network connection: the app remains fully usable offline.
5. Processing summary
| Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|
| Usage measurement: how often games and features are used | Legitimate interest (art. 6(1)(f) GDPR) — improving and developing the app. You may object at any time from the settings. | Identifier 13 months, events 25 months | Us only, and Microsoft Azure as our hosting processor |
| Replying to a message sent to our contact address | Legitimate interest — answering you | For the duration of the exchange, then 12 months | Us only |
| Account (optional): finding your games on your other devices, receiving the games played with you when you accept a link | Performance of the service you request by creating the account (art. 6(1)(b) GDPR) | As long as the account exists; on deletion, immediate erasure from the database, backup copies included within 30 days | Us only, and Microsoft Azure as our hosting processor; nickname and avatar visible to other players |
| Advertising (free version): serving and measuring ads, preventing fraud | Consent collected by Google's form in the EEA, the United Kingdom and Switzerland; legitimate interest relied on by some partners, which you may object to | None on our side; at Google and its partners, under their own policies | Google (Google Ireland Limited) and its advertising partners: see section 10 |
| Live game sharing: showing the game in progress to the players and spectators the scorer invites | Performance of the service you request by opening or joining a session (art. 6(1)(b) GDPR) | The length of the session (6 hours without a new event, 24 hours at most), then automatic erasure no later than 24 hours after the last write | Us only, and Microsoft Azure as our hosting processor; the game is visible to anyone holding the session's code or link: see section 11 |
| Buying Premium: selling Premium, verifying and restoring the purchase | Performance of the purchase contract (art. 6(1)(b) GDPR) | On our side, the premium status only; at Google and RevenueCat, under their own policies | Google, which sells Premium; RevenueCat, Inc. (United States) as our processor: see section 12 |
No data is sold or rented. Apart from our own servers and signing in to the account with Apple or Google, only the advertising in the free version (Google and its partners) and the purchase of Premium (Google and RevenueCat) pass on data, and never game data. No third-party analytics SDK is built into the app; the only advertising SDK is Google's, with its consent module, and the only payment SDK is RevenueCat's.
6. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection. Here, honestly, is what we can do about each.
- While your device holds the current identifier, the app can request deletion of the events attached to it. That is what the "Delete my statistics" button does: it requests erasure on our servers, then clears whatever was still waiting to be sent on your device.
- After that identifier is renewed, reset or lost, nothing can be traced back to you. We keep no mapping table between successive identifiers: keeping one so we could answer a request would create exactly the link this design avoids.
- Without an account, your game data is not concerned: it never left your device, and you delete it by uninstalling the app. A game shared live erases itself from our servers after the session (section 11).
We therefore know no civil identity associated with this data. This is not a way of avoiding our obligations: it is a direct consequence of how the service is built, and the GDPR does not require us to collect additional data for the sole purpose of being able to identify you.
The account, if you have one, has its own controls: exporting your data and deleting the account are described in section 9.
Advertising consent can be withdrawn at any time from Settings → Privacy → Ad choices (section 10).
To exercise a right or ask a question: contact@ggolabs.com. If our answer does not satisfy you, you may lodge a complaint with the French supervisory authority, the CNIL, or with your own national authority.
7. Target audience and minors
RunMyGame is a general-purpose utility intended for adults. It is not designed, presented or marketed to children or teenagers. A minor may nevertheless use it occasionally around a table. The app does not ask for their date of birth or seek to determine their age. Ads in the free version are non-personalised and rated for general audiences (G).
8. Hosting
The endpoint that records events, and their storage, as well as the server and database of the account and of live sharing (api-runmygame.ggolabs.com), are deployed in France on Microsoft Azure (France Central region). This website itself is served by Azure Static Web Apps, whose distribution is worldwide.
As with any request over the Internet, our servers see your device's IP address on arrival, but it is not recorded in the usage measurement database and no country is derived from it. The sharing server uses it only to limit repeated attempts at entering a code, in a scrambled form, kept in memory and never written down. Like any online service, our host keeps its own technical logs with their own lifecycle, which we do not control; we do not use them for statistics.
9. The account
The account is optional: playing does not require one. This section says what it keeps as soon as someone creates one.
What it is for
- finding your games, your players and your settings on your other devices;
- receiving the games a scorekeeper played with you, when you accept that they link one of their players to your account.
How it is created
In one step, with Apple or Google, without a password. Our server checks the signed token Apple or Google gives you, then opens its own session: no third-party identity provider is involved.
What it keeps
- a randomly drawn identifier, which is ours;
- the email address Apple or Google provides — Apple's relay address if you chose to hide yours —, never shown to other players;
- your public nickname and your avatar, chosen from drawings supplied by the app (no photo);
- your synchronised game data: finished games and their snapshots, known players, preferences, premium status;
- the technical identifier of the device that wrote each synchronised object;
- the links you accept: which scorekeeper, which player, and when.
Who sees what
Your nickname and your avatar are visible to other players. Your email address never is.
Where
On Microsoft Azure, in France (France Central region): see section 8.
For how long
As long as the account exists. When it is deleted, its data is erased from the database immediately, and from backup copies within 30 days. Your nickname stays in the games other players have already played, which are theirs. Link records are kept in a form that no longer identifies you. The games saved on your device stay there.
Your rights specific to the account
- Export: in the app, Profile › Account › My data, then Export my data. You get a readable JSON file with everything the account keeps.
- Deletion: on the same screen, Delete my account; or from the page https://ggolabs.com/runmygame/delete-account/en/; or by email to contact@ggolabs.com.
Separate from usage measurement
The account is an entirely separate system from usage measurement: two distinct stores, two distinct deletion mechanisms. Creating an account never links usage events to your identity, retroactively or otherwise.
10. Advertising
The free version of RunMyGame shows advertising banners supplied by the Google AdMob ad network (Google Ireland Limited). They appear in the catalogue, the history, the settings and the spectator screen, never on the home screen or while scores are being entered.
What Google receives
To show an ad, the Google Mobile Ads SDK built into the app sends Google your device's IP address, from which Google derives an approximate location, your interactions with the ads, diagnostic data and a device identifier (the "app set ID"). It never receives your device's advertising identifier, which has been removed from the app, and no game data: no score, no player name, no game.
What this data is used for
It is used to serve and measure ads, and to prevent fraud. In this version, ads are non-personalised and rated for general audiences (G). If personalised advertising is offered later, it will only be enabled in regions where consent is required after an explicit, withdrawable choice; merely using the app will not constitute consent.
Your consent
In the European Economic Area, the United Kingdom and Switzerland, Google's consent form is shown when the app starts, before any ad, and lets you accept, refuse or manage the options. Refusing gives limited ads and removes no feature from the app. Some partners rely on legitimate interest: managing the options lets you object to it.
You can withdraw or change your choice at any time from Settings → Privacy → Ad choices.
Google's partners
The advertising partners presented by the consent form are listed on the Advertising partners page. How Google uses this data is described on How Google uses information from sites or apps that use our services.
Premium
With Premium, the app shows no ads and exchanges nothing with the ad network. Buying Premium itself is described in section 12.
11. Live game sharing
Sharing is optional and requires no account. It is the only case where game data leaves the device without an account: this section says which data, and for how long.
What it is for
The player who keeps the score sheet, the scorer, opens a session; the other players and spectators join it with a short code, a QR code or a link, and follow the game live on their own phone.
What goes through our servers
- the course of the game as recorded by the scorer's phone: game and variant, player names and avatars, scores entered, corrections and undos, with the time of each entry and the technical identifier of the device that wrote it;
- the computed state of the game: current scores and ranking;
- for each guest: the name they choose when joining (their nickname by default), their role, player or spectator, and the technical identifier of their device.
Joining a session sends neither your account nor your email address. Exchanges go over an encrypted connection.
Who sees what
Anyone holding the session's code or link joins it without prior approval, and sees the names and scores of all players, as well as the names of the other guests. So share the code only with the people around the table. The short code is valid for 30 minutes only, and the scorer generates a new one in a single tap; the scorer can also remove a guest at any time. At the end of the game, a guest's device may keep a copy of it in its local history.
Where
On Microsoft Azure, in France (France Central region): see section 8.
For how long
The session closes by itself after 6 hours without a new event, and no later than 24 hours after it was opened. Our servers then erase its data automatically, no later than 24 hours after it was last written. The game stays on the scorer's phone, which keeps its full log.
Usage measurement
Opening a session and joining one each produce a usage event (section 4), which holds nothing but its type: not the game, not the role, not the number of guests, and no game data.
12. Buying Premium
Premium is bought once, for life, in the app, through Google Play. We entrust the verification of the purchase to RevenueCat (RevenueCat, Inc., based in the United States), our processor.
Who does what
- Google takes the payment: for purchases made in the European Economic Area, Google is the merchant of record and applies its own payment, refund and withdrawal terms. We never see your payment method.
- RevenueCat receives the Premium purchase from Google Play and tells us whether Premium is owned, so it can be activated and restored.
What RevenueCat receives
The purchase information (product, date, transaction) and an identifier drawn by its own SDK. The app sends it neither your RunMyGame account, nor your email address, nor the usage measurement identifier, and no game data. As with any request over the Internet, RevenueCat sees your device's IP address.
RevenueCat's SDK is loaded only when you buy or restore Premium, never at start-up: as long as you tap neither Buy nor Restore my purchases, the app does not call it.
What we keep
The premium status only, on your device, and in your account if you have one (section 9). How Google and RevenueCat use this data, including outside the European Union, is described in their policies: Google Privacy Policy and RevenueCat privacy policy.
13. What does not exist yet
Crash reports and performance measurements: the app embeds no such tool and sends us nothing when it closes unexpectedly. This policy will be updated before they are switched on, and no additional data is collected until then.
14. Changes
Any change to this policy will be published on this page, with its date. Changes that widen the collection will be announced in the app.