LittleShelf

Privacy Policy

Deutsch · English

Last updated: 2026-09-18

1. Controller

The controller for the processing of personal data on this website and in the game LittleShelf is:

Henry Schorradt, Wiesengrund 3, 35091 Cölbe
E-mail: [email protected]

Full details are in our Legal Notice.

2. Data protection officer

n/a

3. What we process

3.1 Player account

To run an account we process your e-mail address, a username and display name of your choosing, and your password. The password is stored only as a cryptographic hash; it never exists in plain text and is not readable by us either.

On top of that comes everything the game itself produces: your shelf, inventory, progress, scores, friendships, group membership, and the timestamps of account creation and last visit.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.2 Signing in with Discord or Google

You can sign in with a Discord or Google account instead. The provider then gives us your identifier and, if you allow it, your e-mail address and display name. For Discord we additionally store your Discord user ID so that we recognise your player account on your next sign-in.

We receive no password from these providers and no access to your content there. If the provider confirms your e-mail address as verified, we link it to an existing account with that address instead of creating a second one.

Legal basis: Art. 6(1)(b) GDPR.

3.3 Server logs

When you open our pages, the web server records technically necessary data (IP address, timestamp, requested resource, status code, amount of data transferred, browser identification). This serves operation and abuse prevention.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

3.4 Payments

Purchases of in-game currency are handled through PayPal. You enter your payment details directly with PayPal; we never receive them. What arises on our side for a purchase is: our own order number, PayPal's transaction number (the order ID, which lets us match the purchase and recognise a refund), your player account, the pack bought, the amount, the currency and the payment status.

What never reaches us and is stored nowhere: your name, your PayPal e-mail address, your payer ID and your means of payment. We neither request these from PayPal nor process them temporarily.

Legal basis: Art. 6(1)(b) GDPR. Recipient: PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg.

3.5 Notifications (web push)

If you enable push notifications, we store the subscription issued by your browser (endpoint URL and keys) so that we can send you messages while the game is closed. Delivery runs through the push service of your browser vendor.

Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw it at any time in the game settings or in your browser; the subscription is then deleted.

3.6 Chat

Chat messages are processed together with your display name and a timestamp so that other players can read them. Retention period: 14 days

Legal basis: Art. 6(1)(b) GDPR.

3.7 Item suggestions you submit

If you submit an item suggestion, we transmit the text you entered to OpenAI (api.openai.com) to have an image generated from it. Please do not enter personal data there. We store the result together with your account as the author of the suggestion.

Legal basis: Art. 6(1)(b) GDPR. Recipient: OpenAI, USA — the transfer relies on Standard Contractual Clauses and/or the EU-US Data Privacy Framework.

3.8 E-mails

We send you e-mails that are necessary to run your account: registration confirmation, password reset, notices about your account.

Legal basis: Art. 6(1)(b) GDPR.

4. Cookies and similar technologies

Purpose What is stored Duration
Session Session identifier, so you stay signed in between requests 30 days
Stay signed in A random token, rotated on every use — never a password until you sign out
Preferences Language, view and filter settings (in your browser's local storage, not on our server) until you clear them

All of these are strictly necessary to run the game, so no consent under § 25(1) TDDG is required (§ 25(2) no. 2 TDDG). There is no third-party tracking and no advertising.

5. Playing through Discord

LittleShelf can also be played as a Discord Activity, inside the Discord client. Content is then delivered through Discord's proxy servers, so Discord learns that and when you use the Activity. Discord is the controller for its own processing; its privacy policy applies to that part.

If you sign in through Discord, we request these permissions ("scopes") from Discord:

  • identify — your Discord user ID and display name
  • email — the e-mail address held at Discord, so that an existing LittleShelf account can be matched
  • rpc.activities.write — so LittleShelf may appear as a running Activity in your Discord status

We use the access token issued in the process once, to fetch those details from Discord; it is not stored. The only thing we keep permanently from the Discord sign-in is your Discord user ID — it links your Discord account to your player account. Name and e-mail address serve to create or match the account.

Legal basis for our own processing in this context: Art. 6(1)(b) GDPR.

6. Using the Android app

LittleShelf is also available as an Android app in the Google Play Store. The app is a shell around the same website (a WebView loading littleshelf.de) — it runs no separate code of its own that collects data.

Permissions: The app requests exactly one permission — INTERNET, network access. Without it, it could not load the game. It requests no other permission, in particular no access to location, contacts, camera, microphone, storage or notifications.

No analytics or crash libraries: The app embeds neither Google Play Services nor Firebase, Firebase Cloud Messaging or Crashlytics — and no advertising or analytics services either. There is no advertising ID and no crash reporting.

Switched off in the app: push notifications (the WebView has no push interface) and purchases via PayPal. Those processing operations therefore do not take place in the app at all.

Independently of this, Google as operator of the Play Store processes data relating to installing and updating the app (such as your Google account and your device). Google is the controller for that; Google's privacy policy applies.

7. Recipients

Beyond the recipients named above for each purpose, we do not share your data. Processors — in particular our hosting provider and our e-mail delivery service — are bound by contract under Art. 28 GDPR.

Hetzner Online GmbH, [email protected]

8. Retention

Account data is stored for as long as your account exists. After deletion we remove it, unless a statutory retention obligation applies — this mainly concerns payment records, which German commercial and tax law requires us to keep. The remaining periods are stated with each purpose above.

8.1 Deleting your account

In the game, Options → Delete account lets you end your access yourself at any time and without giving a reason. The step is final: you will not be able to sign in to this account again, not through Discord or Google either.

Everything you sign in with, or that we could reach you by, is deleted immediately and irreversibly:

  • your e-mail address — it is replaced by an empty placeholder and is not kept as a checksum either, so the same address is free again for a new sign-up straight away
  • your password
  • the link to Discord or Google
  • saved sign-ins on your devices ("stay signed in") and your push registrations

Everything that would leave your name standing in areas belonging to other players is removed straight away as well:

  • your public shelf page including its preview image — the page can no longer be opened afterwards
  • your entries in the rankings, including the publicly available overview
  • your group membership (if you founded the group, it promotes a successor itself) and your friendships in both directions
  • your marketplace listings — they are withdrawn
  • a running placement including the images uploaded for it — the placement is ended
  • any open item submissions — they will not be decided on

Your game data — shelf, collection, progress and the other details named under 3.1 — is not affected by this and remains stored. You can no longer reach it, but that does not mean it has been deleted. If you want it removed as well, an informal message to [email protected] is enough; we will then delete it in full (Art. 17 GDPR), unless a statutory retention obligation applies. You can also request this full deletion without going through the step in the game first.

9. Your rights

You have the following rights in relation to us:

  • Access to the data we hold about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR) — for the way to do this in the game see 8.1
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on a legitimate interest (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
  • Complaint to a data protection supervisory authority (Art. 77 GDPR)

Write to [email protected].

You may lodge a complaint with any supervisory authority, in particular the one where you live. The authority competent for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(Hesse Commissioner for Data Protection and Freedom of Information)
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Germany

10. Obligation to provide data

An e-mail address and a password are required for an account; without them you cannot play LittleShelf. Everything else is voluntary.

11. Automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

12. Changes to this policy

We update this policy when the game or the legal situation changes. The version published on this page applies; the date above shows its revision.

13. Binding version

This page is a translation provided for convenience. In case of any discrepancy, the German version is the legally binding one.

Legal Notice Terms of Service Back to LittleShelf