Website and Account Privacy Notice

How FishyStuff processes personal data for its website, accounts, eligibility checks, saved work, optional diagnostics, and contact.

1. Scope, controller, and contact

Document informationApproved publication
Effective fromSeptember 7, 2026
Publication versionsha256-olOEFyMsDfj7obB8thTR6Di-xjNpohZYLvhFjiIUFYk

This notice covers the FishyStuff website, registration and sign-in, account settings and saved work, eligibility checks, optional browser functions, community participation, and contact. It is available without an account.

The Desktop and Dataset Contribution Privacy Notice applies to FishyStuff Desktop. The Crio Privacy Policy applies to Crio.

The controller is:

Jannik Höfler
c/o IP-Management #11515
Ludwig-Erhard-Straße 18
20459 Hamburg
Germany
privacy@fishystuff.fish

2. Website, services, and data on the device

Each activity below states what data are used, for what purpose, and on which legal basis. GDPR means the General Data Protection Regulation; TDDDG is the German law governing, among other things, storage and access on your device. Sections 6 to 8 explain recipients, transfers abroad, retention, and rights.

Website and service requests

Data and source
When a page or function is requested, FishyStuff receives the IP address, requested address, and basic browser or app information. It records the time, whether the request succeeded, data volume and duration, and a short identifier for investigating errors. General access logs do not keep URL query text or the referring page.
Purpose
Provide the page or function requested, investigate errors, manage capacity, prevent abuse, and keep the service secure.
Legal basis and interests
Article 6(1)(f) GDPR for processing necessary to voluntarily provide the account functions you request. The legitimate interest is making those functions available to requesting individuals on an account-specific basis. Article 6(1)(f) GDPR for delivering public content and for technical logs, error diagnosis, capacity management, and abuse prevention. The legitimate interests are keeping the service available, reliable, and secure.
Necessity and retention
FishyStuff needs the request data to deliver the requested content. Technical logs have a seven-day retention period; deletion completes within eight days.

Storage on the user's device

Data and location
The browser uses cookies and other device storage for preferences, saved work, imported data, privacy choices, and sign-in. Locally saved calculator work may also be sent to FishyStuff as model and scenario settings, including supplied author details and comments, for server validation and model resolution even without saving to an account. Sign-in information is sent as needed; account-backed settings and privacy choices are also stored with the account.
Purpose
Provide the chosen function, remember its state, validate calculator settings and resolve the calculation model, store privacy or diagnostics choices, and protect sign-in.
Legal basis and interests
Storage or access strictly necessary for a service expressly requested by the user is permitted by section 25(2)(2) TDDDG; other device access requires consent under section 25(1). For personal data, Article 6(1)(f) GDPR applies insofar as processing is necessary for voluntarily provided account functions you request; Article 6(1)(a) applies to optional processing with consent; and Article 6(1)(f) applies to public tools, including server validation and model resolution, and to sign-in protection. The legitimate interests are account-specific provision of requested functions, useful and reliable tools without an account requirement, and protection against unauthorized access.
Choice and retention
Non-essential device access requires prior consent. Local copies remain until deleted by the user or browser, or cleared by the relevant reset function. Calculator settings sent for validation or model resolution remain in server memory while preparing and delivering the response; this does not save them as account work. Technical logs follow the retention above. Sign-in and other temporary data may expire earlier.

3. Accounts, sign-in, and private data

Public content is available without an account.

Accounts and sign-in

Data and source
Depending on the sign-in method: account identifiers, username and optional display name, email address, a protected password verifier or passkey information, linked sign-in methods, and session and security data. FishyStuff also stores selected settings and saved work, account-backed privacy choices, and the version, time, language and context of Terms acceptance. Access permissions associated with the account determine eligibility for restricted functions. Discord sign-in supplies the Discord ID and public profile; FishyStuff does not request the Discord email address, server list, or roles.
Purpose
Create and secure the account, sign the user in, provide verification or recovery, keep selected settings and saved work available across devices, record Terms acceptance and privacy choices, and check access to restricted functions before granting it.
Legal basis and interests
Article 6(1)(f) GDPR for processing necessary for account creation and association, sign-in, the chosen recovery method and requested account storage. The legitimate interest is voluntarily making personal account access and the selected recovery and storage functions available at users' request. Article 6(1)(f) GDPR for preventing unauthorized access and abuse, checking eligibility and documenting the agreed Terms; the legitimate interests are secure access to the intended users and evidence of the contract. Records needed to demonstrate consent are based on Article 6(1)(c), together with Articles 5(2) and 7(1) GDPR.
Necessity and recipients
Creating an account is voluntary. Necessary identifiers and sign-in or recovery data associate the request with the correct account and enable the selected access method; saved settings and work support the requested later use. Optional details can be omitted. Discord receives request and sign-in data when its sign-in is selected; Scaleway receives the address and message needed for account email.

4. Optional external content and diagnostics

External profile images

Data and recipients
After separate approval, the browser loads Discord profile images. The provider receives the IP address, basic browser information, requested user image, and referring information allowed by the browser.
Purpose
Display the separately selected Discord image.
Legal basis
Consent under Article 6(1)(a) GDPR and, where the device is accessed, section 25(1) TDDDG.
Choice and withdrawal
This feature is off until approved and can be disabled in its privacy settings. Withdrawal stops future loads; it does not itself erase provider-held data or limit deletion rights.

Optional technical measurements

Data
The user selects measurement categories such as broad page area, software version, type and duration of an operation, result, performance values, and limited error categories. Reports also carry the technical identifiers and times shown in the preview.
Purpose
Diagnose technical problems. The measurements are not used for advertising. Technical request identifiers can connect these diagnostics with account-related server and security records, although the browser measurement payload excludes account identifiers.
Legal basis and choice
Consent under Article 6(1)(a) GDPR and, for non-essential device access, section 25(1) TDDDG. Measurements are available only to signed-in accounts, are off by default, and require separate consent and approval of the selected fields. Consent can be withdrawn in privacy settings without losing the underlying service.
Exclusions, safeguards, and retention
Browser measurement payloads exclude account and session identifiers, page addresses and URL query text, page content, user input, credentials, game locations, and session recordings. Before storage, FishyStuff removes request information that could identify the user's device and rejects data outside the listed categories. The measurements are deleted within eight days; the account-linked consent record remains until account deletion.

Manual diagnostic reports

Data and source
The preview shows the user's description, broad page area, selected problem categories and severity, counts, diagnostic mode and visibility settings, report identifier, and time. The description may contain personal information entered by the user; it is sent as shown.
Purpose
Investigate the reported technical problem and improve the affected function. Sending a report does not open an account-linked support case.
Legal basis
Consent under Article 6(1)(a) GDPR, given by confirming the report after previewing it; section 25(1) TDDDG also applies to non-essential device access for the report.
Choice and retention
Sending a report is optional and each report requires confirmation. It is deleted within eight days. Consent to a sent report can be withdrawn by contacting the privacy address in section 1; include the report identifier if available so it can be located.

5. Contact and community contributions

Contact form, email, Discord messages, and post

Data and source
The contact form receives a subject and message, plus any name, email address, or Discord username included by the sender. Signed-in account details may be prefilled, but each can be edited or removed. Other contact channels supply the message, sender details, time, and any attachments and delivery information.
Abuse prevention
The form uses the request IP address and, where present, the signed-in account to limit requests. Short-lived coded counters expire within one day. The delivered message does not include the request IP address or internal account identifier; it includes the contact details the sender leaves in the form.
Purpose and recipients
Handle and answer the message, prevent abuse, respond to privacy requests, and handle legal claims. Scaleway delivers form messages to the operator's Zoho mailbox. Other messages pass through the chosen email, Discord, or postal provider.
Legal basis
Article 6(1)(b) GDPR for enquiries needed to enter into or perform a contract at the sender's request. Article 6(1)(f) for other enquiries, abuse prevention, and legal claims; the interests are answering messages and protecting users and the operator's rights. Article 6(1)(c), together with Articles 12–22 GDPR, applies to handling statutory privacy requests.
Choice and retention
The message and contact details are voluntary, but FishyStuff cannot handle a matter without the information it needs. Ordinary correspondence is retained for up to six months after completion; security, abuse, or legal cases follow the longer periods in section 7.

Community submissions, proposals, and voting

Purpose and data
Where these features are offered, FishyStuff uses your submitted content, selections or votes, the relevant subject, period and game region, and your account identifier when signed in. This supports community suggestions, assessment and confirmation of information, and prevention of duplicate or abusive participation.
Voting without an account
For signed-out voting, your IP address is used to create a substitute identifier limited to the voting period and region. The voting record keeps that identifier, not the IP address. This is not anonymous processing; technical request logs are covered by section 2.
Legal basis, choice, and visibility
Participation is voluntary; required information is needed to record the contribution and prevent repeat participation. The feature indicates which proposals or results are public. Voting identifiers are not published. Article 6(1)(f) GDPR applies, in the interests of useful community information, reliable results and protection against manipulation. Author credits and publication permissions are covered separately below.
Retention
Private submission records are kept until the relevant proposal review or submission period ends; individual voting records until the voting period ends. They are then deleted, and account-linked records are also removed on account deletion. Public results without participant identifiers may remain. Technical logs and records needed for a specific abuse or legal case follow section 7.

Authors and permission to publish

Data and source
Author names or pseudonyms, published content, publication dates and citations, correspondence with the author or source, and evidence of permission to publish. These come from the author, sender, or cited source. Published content and author credits are visible to the public; private correspondence and permission records are not published.
Purpose
Credit authors correctly, verify where content came from and permission to publish it, make corrections, resolve disputes, and handle legal claims.
Legal basis and interests
Article 6(1)(f) GDPR. The legitimate interests are correct attribution, documenting the source and permission to publish, resolving disputes, and defending legal claims.
Choice and retention
Submission is voluntary; there is no statutory or contractual obligation to submit content. FishyStuff cannot review, attribute, or publish a contribution without required information. Evidence is kept while content remains published and afterward for applicable legal-claim periods as detailed in section 7.

6. Recipients and international transfers

Depending on the function, data are received by these recipient categories:

  • Hetzner as processor for EU-hosted services, data storage, and backups;
  • Scaleway as processor for account and contact-form email delivery;
  • Zoho for the operator’s email correspondence;
  • Discord as independent controller for sign-in through Discord, approved profile images, or communication;
  • IP-Management for receiving and forwarding mail sent to the c/o address; and
  • authorities, courts or advisers where legally required or needed for legal claims.

We send sign-in and communication data through Discord’s developer API to Discord, Inc. in the United States under the EU-US Data Privacy Framework adequacy decision (Article 45 GDPR). Discord’s certification covers these transfers; see the official register. Discord explains its separate platform processing in its Privacy Policy.

We use Zoho Mail’s EU region for email correspondence. Occasional remote technical-support access from India is protected by Zoho’s EU Standard Contractual Clauses and supplementary measures, as described in its privacy FAQ.

Further information and, where applicable, a copy of the relevant transfer safeguards can be requested through privacy@fishystuff.fish.

7. Retention and account deletion

Temporary account-deletion records

Data
Former account identifiers, deletion status and times, and information needed to revoke desktop access and prevent erased data from returning.
Purpose
Complete and document deletion, revoke desktop access, and prevent erased account data from returning after a backup is restored or source records are processed again.
Legal basis and interests
Article 6(1)(c), together with Articles 5(2) and 17 GDPR, for carrying out and documenting statutory erasure. Article 6(1)(f) for keeping deleted data out of restored accounts and revoking access; the interests are effective deletion and access security. These records do not themselves authorize continued analytical use of gameplay data.
Retention
Until deletion completes, then for up to 101 days.
CategoryRetention
Technical logs that may identify a person or requestseven-day retention; deletion completed within 8 days
Optional browser diagnostics and manual reportsdeleted within 8 days
Browser data stored only on the deviceuntil deletion by the user or browser or the relevant reset; temporary data may expire earlier
Account data, privacy choices, settings, and saved workonly while needed for the selected account functions, and no later than account deletion or earlier deletion of the relevant data
Temporary account-deletion recordsuntil deletion completes, then up to 101 days
Encrypted FishyStuff service backupsup to 90 days; replaced backup versions are deleted within a further 7 days
Ordinary contact and feedback correspondenceup to 6 months after completion
Security, abuse, or legal casesuntil completion and then up to 12 months
Evidence concerning published third-party contentwhile the content remains published and afterward until the limitation period for related claims expires; an existing dispute, correction, or legal claim is kept until it ends

These are maximum periods or purpose-based limits, not a reason to keep data that are no longer needed. The technical-log limit also applies to logs containing account, session, request, or diagnostic information.

During inactivity or a temporary suspension, storage remains limited to data still needed for the selected account functions. If a function is permanently discontinued, its provision no longer justifies retaining its data; any continued storage must serve a separately stated purpose or an applicable legal duty. This does not promise future availability.

Longer restricted storage is limited to data needed for a specific legal duty or an ongoing security, abuse, or legal case. Statutory retention relies on Article 6(1)(c) GDPR and the applicable legal duty; case handling relies on Article 6(1)(f), in the interests of protecting users and pursuing or defending legal claims.

Account deletion removes the account and its saved data, except for the limited copies listed above. The separate Desktop notice explains any continued processing of contributed observations; you can obtain it through the contact above even after account closure. A deletion or objection request is assessed according to what it concerns, not simply treated as a request to stop uploads. Browser-only data must be deleted on the device. Logs, restricted case records, and backups follow the limits above.

8. Rights, changes, and language

Under the statutory conditions, you can request access to and a copy of your personal data, correction, deletion or restriction of processing.

Data portability under Article 20 GDPR applies to personal data you have provided where processing is automated and based on consent or Article 6(1)(b) GDPR. Processing based only on Article 6(1)(f) does not meet that condition. Access, copies and any independently applicable rights to the return of data remain unaffected.

Where processing relies on consent, you can withdraw that consent at any time for future processing; this does not change the lawfulness of processing before withdrawal. This applies, for example, to the optional functions in section 4. You can also complain to a data protection supervisory authority, including in the country where you live or work or where you believe an infringement occurred.

Send requests to privacy@fishystuff.fish. Further identity information is requested only where there are justified doubts and only as necessary. A request for the privacy notice itself does not require proof of an account or participation.

Objection: A data subject may object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them based on Article 6(1)(f) GDPR. FishyStuff will then no longer process those personal data unless it demonstrates compelling legitimate grounds for the processing that override the data subject’s interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims.

This includes processing for account creation, sign-in, the chosen recovery method and requested account storage. An objection is assessed according to the affected data, operations and purposes; it does not automatically mean account deletion or termination of the agreement.

Where the conditions of Article 18 GDPR apply, you can request restriction, including while the grounds for an objection are verified. Any contractual consequences are assessed separately under the Terms and applicable law.

We inform affected people of material processing changes before they take effect. An updated notice does not itself authorize new processing or replace required consent. Changes are also available through an optional RSS feed (Download plain text (.txt)).

These privacy notices are provided in German and English. Your statutory data-protection rights apply regardless of the language version.