1. Introduction
This Privacy Policy explains how Svigl ("Svigl," "we," "us," or "our") collects, uses, stores, and handles information when you access or use the Svigl website, applications, gameplay features, and related services (collectively, the "Service").
By using the Service, you acknowledge this Privacy Policy. If you do not agree, please do not use the Service. This Policy should be read together with our Terms & Conditions.
Svigl is a browser-based multiplayer drawing game and related experiences (including galleries, labs, and profile features). This Policy is written to reflect how the Service currently operates.
2. Information you provide
Depending on how you use Svigl, you may provide or cause us to receive the following:
Google authentication
If you sign in with Google, we use Google OAuth / OpenID Connect with the scopes openid, email, and profile. From Google, we receive and process:
- your Google account subject identifier;
- your email address (we require a verified email to complete sign-in);
- your name, which is used as your initial display name; and
- your Google profile picture URL, if provided.
Temporary OAuth tokens used during sign-in are processed to complete authentication and are not stored as long-term application account credentials in our user database. After account creation, later Google sign-ins refresh the stored email; your chosen display name and avatar on Svigl are not automatically overwritten by Google on every login.
Guest authentication
If you play as a guest, we create a guest account linked to a browser-generated device identifier stored in your browser. Guest accounts receive a generated display name and do not require an email address. Returning from the same browser with that identifier may reconnect you to the same guest account.
Profile and account details
We store account information such as:
- an internal user identifier;
- authentication provider type (Google or guest);
- display name / username;
- avatar image URL or an uploaded avatar image (which may be stored as image data);
- email address for Google accounts; and
- aggregate gameplay counters associated with your account (for example, drawings completed and like/dislike totals).
Public profile pages may show your username, avatar, provider type, and aggregate counters. Email addresses are not shown on public profiles.
Gameplay, rooms, and interactions
When you create or join rooms and play, we process information needed to operate multiplayer gameplay, including room membership, ready state, scores, guess status, round participation, and related game-session state.
Chat messages
Chat messages you send during a game are transmitted in real time to other participants as needed for gameplay. Chat message text is not stored in our application database as a persistent chat history. Messages may exist temporarily in active server memory while being processed and in other players' browsers during the current session.
Drawings and canvas activity
Drawing and canvas activity is processed to run the game. Committed canvas state during a round may be stored while the round is active. When a round ends, published drawings (including associated word, drawing document data, replay timeline information, and reaction totals) may be retained and shown in galleries or related features. Reactions such as likes and dislikes are associated with your account.
Labs and other submissions
If you use Labs features, we may store personal-best scores linked to your account. If you submit feedback through the Feedback page, you may optionally provide a name and email address along with your message and feedback category. Feedback submissions are sent through a third-party email delivery service (EmailJS) and are not stored by Svigl's game database as part of that flow.
3. Information collected automatically
When you use the Service, we and our infrastructure may automatically process:
- Session and authentication information, including authentication cookies or tokens, session data used for OAuth sign-in, and related timestamps;
- Usage and gameplay events, such as room creation/joining, round and game lifecycle events, and authentication method events (including through analytics when enabled);
- Technical diagnostics, such as application server logs that may include request method/path, status codes, durations, internal user identifiers, room codes, and error details needed to operate and debug the Service; and
- Browser storage values used for guest identity, room continuity, and onboarding preferences (described below).
Our application code does not currently collect IP addresses or user-agent strings as dedicated product fields. However, hosting providers, reverse proxies, and standard web server access logs may still process network and request metadata (which can include IP address and similar technical information) as part of ordinary internet infrastructure.
4. Analytics
Svigl may use Google Analytics 4 when a Google Analytics measurement ID is configured for the deployment. Google Analytics is a third-party analytics service provided by Google.
When enabled, analytics may collect information about:
- pages or screens viewed;
- interactions with the Service;
- authentication-related events (for example, Google or guest sign-in, and sign-out);
- room creation, joining, and leaving;
- gameplay events such as game/round start and finish, guesses, and drawing turns;
- certain technical events such as WebSocket disconnect reasons and API error statuses;
- approximate location, device, browser, and traffic/referral information as provided by Google Analytics; and
- an application user identifier associated with your Svigl account (including guest accounts) when analytics identification runs after sign-in.
Analytics data is not treated as fully anonymous. Custom events may include values such as room codes, and Google Analytics may associate activity with identifiers under Google's practices. Google's collection and use of information is governed by Google's own terms and privacy documentation.
5. How information is used
We use information to:
- provide, operate, and maintain the Service;
- authenticate users and maintain sessions;
- enable multiplayer rooms, gameplay, galleries, profiles, and Labs features;
- display usernames, avatars, scores, drawings, and related gameplay state;
- prevent abuse, cheating, and security issues where practicable;
- diagnose technical problems and improve reliability, performance, and user experience;
- understand usage of the Service through analytics when enabled;
- respond to feedback and support requests you submit; and
- develop and improve features of the Service.
7. Third-party services
Svigl relies on third-party services to operate. These providers process information under their own terms and privacy practices. Depending on configuration and how you use the Service, relevant providers include:
- Google — Google OAuth / OpenID Connect for authentication, and Google Analytics 4 for analytics when configured;
- EmailJS — delivery of feedback form submissions and automated AI-guesser limit / abuse alerts;
- PostgreSQL database infrastructure — persistent storage of accounts, rooms, gameplay state, drawings, and related data;
- Amazon Web Services (AWS) — backend hosting (EC2) used for the API / realtime server deployment path present in this project; and
- Frontend hosting providers — the Next.js frontend may be deployed on a separate host (for example, a platform such as Vercel). The specific production frontend host may vary by deployment.
If you set an external avatar URL, your browser may request that image from the third-party host you specify. Links to external sites (such as GitHub, LinkedIn, or a personal portfolio) are governed by those sites' own practices once you leave Svigl.
8. Data sharing
Svigl does not sell your personal information.
We may share information in the following circumstances:
- with service and infrastructure providers that help us operate the Service (such as hosting, database, authentication, analytics, and feedback-delivery providers);
- with other users of the Service, to the extent necessary for multiplayer gameplay and public features (for example, usernames, avatars, scores, room participation, chat during a session, and published drawings);
- if required to comply with applicable law, legal process, or lawful requests;
- to protect the security, integrity, or rights of Svigl, our users, or others, including investigating abuse or fraud; and
- in connection with a business transfer, reorganization, or similar transaction, if one occurs in the future, subject to appropriate safeguards.
9. Data retention
We retain information for as long as reasonably necessary to operate the Service, maintain security, resolve disputes, enforce our terms, comply with legal obligations, or for other legitimate business purposes related to the Service.
In practice, retention currently differs by category:
- Account information (including guest accounts linked to a device identifier) is stored until removed through an account/data deletion process or other operational cleanup. Automated self-serve account deletion is not currently available in the product interface.
- Room and live game-session datamay be deleted when rooms become empty or expire under the Service's presence/cleanup logic, though some related records may remain where the application preserves them.
- Chat messages are not retained as a persistent database chat history.
- Published drawings, reactions, Labs scores, and similar content may persist after a room ends so galleries, profiles, and related features can continue to function.
- Logs, analytics, and feedback-delivery recordsmay be retained by us or by the relevant third-party providers according to operational needs and those providers' practices.
We do not currently publish fixed retention schedules for every data category. If you want specific information deleted, see the contact section below.
10. Data security
We use reasonable technical and organizational measures designed to protect information processed by the Service. These measures are intended to reduce risk, but no method of transmission or storage over the internet is completely secure.
We cannot guarantee absolute security of the Service or of information processed through it. Please use strong account practices where applicable and avoid sharing sensitive personal information in chat, drawings, usernames, or feedback unless necessary.
11. Your choices and rights
Depending on how you use Svigl, you may have the following options:
- Guest access — you may choose guest sign-in instead of Google authentication;
- Profile controls — you may update your display name and avatar through available profile features;
- Browser controls — you may clear cookies and site storage, which can sign you out and, for guests, disconnect the browser from a previous guest identity;
- Analytics controls — you may use browser settings, extensions, or other tools that limit analytics cookies or tracking where available; and
- Sign out — signing out clears your active authentication session, but does not by itself delete your account or stored content.
Depending on where you live, applicable law may provide additional rights regarding access, correction, deletion, restriction, or objection to certain processing. Svigl does not currently offer an in-product automated account-deletion or data-export workflow.
To request access to, correction of, or deletion of personal information associated with your account, contact us using the details in the Contact section. We may need to verify your request before acting on it, and some information may need to be retained where required for security, legal, or operational reasons.
12. Children and age
Svigl is a general-audience consumer drawing game and is not specifically directed to very young children. The Service does not currently implement an age-verification gate or parental-consent workflow.
If you are not legally able to consent to the applicable terms or to the processing described in this Policy under the laws that apply to you, you should use the Service only with appropriate parent or guardian involvement where required. If you believe a child has provided personal information in a way that is inconsistent with applicable law, please contact us so we can review the situation.
13. International data processing
Svigl and its service providers may process information in countries other than the country where you live. Those countries may have different data-protection laws than your own.
By using the Service, you understand that your information may be transferred to and processed in such locations as needed to operate hosting, authentication, analytics, feedback delivery, and related infrastructure. This Policy does not claim that any specific cross-border transfer framework has been implemented beyond ordinary use of those providers.
14. Policy changes
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Where changes are material, we may also provide additional notice through the Service or other reasonable means.
Your continued use of the Service after an updated Policy becomes effective means you acknowledge the revised Policy.
15. Contact
For privacy questions, requests about your personal information, or related concerns, contact:
- Email: [PRIVACY CONTACT EMAIL]
- In-product feedback: Feedback page
- Project issues: GitHub Issues
Please note that feedback submitted through the Feedback page is transmitted via EmailJS and is intended for product feedback; privacy or legal requests are best sent to the privacy contact email once it has been configured.