Privacy notice
Last updated: 10 October 2026
Highlighted fields are still to be filled in by the operator.
1. Who is responsible
The controller for the processing of personal data on this website, in the game and in the Chrome extension ("Crazy Berlin") is: Operator: full name, Street and number, Postcode City, Germany. E-mail: privacy e-mail.
We have not appointed a data protection officer because we are not legally required to. For any privacy question, write to the address above.
Full contact details are in the imprint.
2. The short version
- Crazy Berlin is a free, non-commercial hobby project. Nothing is for sale — we don't process any payment data.
- We only process what the game needs to work and to keep it safe.
- No advertising trackers, no analytics cookies, no selling of data. We only set cookies that are strictly necessary.
- The game never uses your real location. Other players only see your avatar when they are near you in the game.
- You can download all your data and delete your account at any time in your profile.
3. Visiting the website and server logs
When you open Crazy Berlin, your browser sends technical data to our servers: IP address, date and time, the page requested, referrer, browser and operating system. Our hosting providers process this data to deliver the pages and keep them secure, and keep it in server logs for a short time (at most 30 days).
Our own application logs contain technical events with a pseudonymous account ID — never message contents, passwords or e-mail addresses. While multiplayer is switched on, connections that our realtime server rejects for security reasons (for example from a foreign website) are logged with the IP address.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in running a secure, working service.
4. Your account and the game
To play we process:
- username, display name, password (only as a scrypt hash — we never store the password itself), language;
- your profile: avatar, bio, interests and, if you upload one, a profile photo;
- game data: level and experience, missions, discoveries, achievements, in-game credit and what you spend it on in the game, items and clothes, tickets, in-game offences and court cases, energy, and your last position in the game;
- settings (privacy, notifications, audio, graphics);
- sessions: a SHA-256 hash of the session token, the browser's user agent and timestamps.
Guest accounts work the same way without a password. Guests that haven't been active for 30 days are deleted automatically.
Legal basis: Art. 6 (1) (b) GDPR — we need this data to provide the game you signed up for.
6. Profile photos
Profile photo uploads are optional and only available while they are switched on. If you upload a profile photo, it is stored with Cloudinary and may be checked automatically before other players can see it. When you replace the photo or delete your account, the old file is deleted.
Legal basis: Art. 6 (1) (b) GDPR; checking uploads: Art. 6 (1) (f) GDPR (protecting other players).
7. Sparks (dating, 18+)
Sparks is optional and off by default. If you turn it on, we process your date of birth (only to confirm that you're at least 18; it is never shown), what you're looking for, your gender, who you'd like to see and your Sparks text, as well as the sparks you send and receive. Your gender and who you'd like to see can reveal your sexual orientation — special category data under Art. 9 GDPR.
Legal basis: your explicit consent, Art. 6 (1) (a) and Art. 9 (2) (a) GDPR, which you give when turning Sparks on. You can withdraw it at any time by turning Sparks off: your Sparks profile, including your date of birth and your sparks, is then deleted.
8. E-mail address (optional)
You can add an e-mail address to your account. We only save it after you've confirmed it through the link we send, and use it only for password resets and important notices about your account. Other players never see it. E-mails are sent through Resend.
Legal basis: Art. 6 (1) (b) GDPR. You can remove the address at any time in your profile.
9. Applications from event hosts
If you apply as an event host, we process your organisation's name, contact e-mail, website, message and the events you submit, to review and publish them. Legal basis: Art. 6 (1) (b) GDPR. The data is deleted with your account.
10. Visitor numbers and performance measurement
To show how many people visit the site, we count each visitor once per day — without cookies and without storing anything on your device. For this we keep a one-way hash of a secret value, the date, your IP address and browser identifier (not the IP address itself) and delete it when the day is over; only the daily total remains.
On our hosting at Vercel we measure page performance (Speed Insights: loading times and similar metrics, the page, browser and device type). This uses no cookies and builds no profiles.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in understanding how many people use the site and keeping it fast.
11. Security and abuse prevention
To stop abuse (for example mass sign-ups or password guessing) we count requests per IP address or account in short time windows. These counters are deleted after 24 hours at the latest. Legal basis: Art. 6 (1) (f) GDPR.
13. Service providers and transfers outside the EU
We use the following providers. Processors work only on our instructions under a data processing agreement (Art. 28 GDPR).
| Provider | Purpose · location and safeguards |
|---|---|
| Vercel Inc. | Hosting of the website and API, server logs, performance measurement (Speed Insights) · Server functions in Frankfurt, content delivery through a worldwide edge network; provider in the USA — EU-US Data Privacy Framework and standard contractual clauses |
| Neon | PostgreSQL database (accounts, game progress, messages) · Database region in the EU (Frankfurt); provider in the USA — standard contractual clauses |
| Fly.io, Inc. | Hosting of the realtime server, only while multiplayer is switched on (positions, nearby chat in transit). While multiplayer is off, no data goes there. · Server region Frankfurt; provider in the USA — standard contractual clauses |
| Cloudinary | Storage, moderation and delivery of profile photos, only while photo uploads are switched on. While they're off, no data goes there. · USA / Israel — EU-US Data Privacy Framework, adequacy decision (Israel), standard contractual clauses |
| Resend | Sending e-mails (address confirmation, password reset) · USA — EU-US Data Privacy Framework and standard contractual clauses |
Where data is transferred to a country outside the EU/EEA, this is based on an adequacy decision of the European Commission (for the USA: the EU-US Data Privacy Framework, for certified companies) or on the EU standard contractual clauses (Art. 46 GDPR). You can ask us for a copy.
Map data © OpenStreetMap contributors (ODbL) is part of the game; no data about you goes to OpenStreetMap.
14. How long we keep data
- Account, profile, progress, messages, friends: until you delete your account. Messages you sent stay in shared conversations without your name and content (anonymised).
- Guest accounts: deleted after 30 days without activity.
- Sessions: 30 days (website) or 90 days (extension); expired sessions are deleted daily.
- Confirmation and password links: valid for 24 hours or 1 hour, then deleted.
- Rate-limit counters: at most 24 hours. Visitor hashes: until the end of the day.
- Reports: until resolved, then up to 6 months.
- Server logs at our hosting providers: at most 30 days.
15. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Where we rely on consent, you can withdraw it at any time with effect for the future (Art. 7 (3)).
Right to object (Art. 21 GDPR): where we process data based on our legitimate interests (Art. 6 (1) (f)), you can object at any time for reasons arising from your particular situation.
Do it yourself: in your profile you can download your data (JSON, machine-readable) and delete your account immediately. For anything else, write to us at the address in section 1.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work, or where the alleged infringement took place (Art. 77 GDPR).
16. Age
Crazy Berlin is for people aged 16 and over; Sparks only for adults (18+). We don't knowingly process data of younger children. If you think a child under 16 has an account, please tell us and we'll delete it.
17. No automated decisions
We don't make decisions with legal or similarly significant effects based solely on automated processing (Art. 22 GDPR). Game rules (for example in-game fines) only affect the game. Sparks only suggests people who match each other's settings.
18. Changes
We update this notice when our services or the law change. The current version is always on this page.
5. Multiplayer, chat, messages and friends
Legal basis: Art. 6 (1) (b) GDPR for the social features; Art. 6 (1) (f) and (c) GDPR for keeping the community safe and handling reports of illegal content (Digital Services Act).