Privacy statement
Last updated: 30 August 2026
This is a translation. The German version is the authoritative one — if the two differ, the text at /datenschutz applies. References to German law are kept in German, because they name specific provisions rather than concepts that translate: GDPR articles are cited as the regulation is known in Germany (DSGVO), and § 25 TDDDG is the German implementation of the ePrivacy rules on storing information on your device.
1. Controller
Johnna Golly, Golly Softwareentwicklung
Wentruper Weg 17, 48268 Greven, Germany
Telephone: +49 151 18695357
E-mail: info@golly-software.de
The full provider details are in the imprint. No data protection officer has been appointed; the legal requirements for appointing one are not met.
There is no automated decision-making in individual cases, and no profiling.
2. The basics
dueligo can be played without an account, without an e-mail address and without giving any personal data. There is no sign-up, no password, no age check and no connection to social networks.
If you only play, you are not recognised again. A persistent identifier is created only when you explicitly ask for one (section 5). Without that step, every visit starts from scratch.
When the pages load, no content is fetched from anyone else's servers — no external fonts, no maps, no social networks, no content delivery networks. Your IP address is therefore not passed to any third party.
No advertising is currently served. While that remains the case, no request is sent to Google or to any other advertising network. If advertising is introduced, it will happen only with your explicit consent, and this statement will be extended accordingly beforehand (section 12).
Techniques for recognising you across devices — fingerprinting via screen, fonts, time zone or behaviour — are not used.
3. Visiting the website
Brief technical processing. In order to deliver a page to your browser, the server has to process your IP address for the duration of the connection. That is technically unavoidable. This processing ends when the page has been delivered.
- Purpose: transmitting the page you requested
- Legal basis: Art. 6(1)(f) GDPR (DSGVO). Legitimate interest: making the website technically available
- Storage period: only for the duration of the connection
- Recipient: Hetzner as a processor (section 13)
Visits to dueligo.com are not logged. The upstream server is configured so that no access logs are written for this website. Opening a page leaves no line in a log file.
Faults and runtime events — such as the renewal of encryption certificates or failed connection attempts — are stored by the upstream server in a shared log file with addresses removed. IP addresses, headers and browser identifiers are stripped before an entry is written.
- Purpose: detecting faults and keeping the service secure
- Content: the time and the kind of event; no IP addresses, no browser identifiers
- Legal basis: Art. 6(1)(f) GDPR (DSGVO), to the extent personal data is involved at all. Legitimate interest: a working and secure service
- Storage period: rotated files are deleted after seven days at most
- Recipient: Hetzner as a processor (section 13)
The application itself does not process your IP address. The upstream server does hand it over, but nothing in the application reads it, evaluates it or stores it.
4. The session key while a game is running
So that a run you have started survives a page change or a reload, the application puts a
random identifier in your browser's session storage
(sessionStorage). The server uses it to match your answers to the game
currently being played.
This identifier expires as soon as you close the browser tab. It does not recognise you on a later visit, and it is used for nothing else — not for analysis, not for advertising, and not as the basis for any further identifier.
- Purpose: matching your input to the game currently being played
- Legal basis for storing it on your device: § 25(2) no. 2 TDDDG — strictly necessary for a game you have started to be continued, which is why there is no consent banner
- Legal basis for the processing: Art. 6(1)(f) GDPR (DSGVO). Legitimate interest: providing the game without an account
- Storage period: until the end of the browser session; the corresponding data on the server is deleted at the latest 24 hours after the last activity
- If you do not provide it: without session storage, a run cannot be continued after a reload
No cookies are used.
5. A persistent identifier — only if you want one
If you would like your best times, streak and progress to be kept beyond the session, you
can switch that on explicitly (“save progress”). Only then is a randomly
generated identifier stored persistently in your browser
(localStorage).
Merely opening the site or playing does not set it. Before you switch it on, you are told what it is for.
The identifier is pseudonymous: it contains no information about you as a person, but it points to your stored runs and therefore remains personal data.
It is used for this purpose only — not for evaluating how difficult the puzzles are (section 8), not for advertising, and it appears in no web address.
- Purpose: recognising this browser again, for progress, best times and the streak
- Legal basis for storing it on your device: § 25(2) no. 2 TDDDG — the storage is necessary in order to provide precisely the function you have explicitly asked for
- Legal basis for the processing: Art. 6(1)(f) GDPR (DSGVO). Legitimate interest: providing the requested function without an account and without collecting any further data
- Storage period: until you switch the function off or clear your browser storage
- Control: you can switch the function off at any time in the settings. Doing so deletes the identifier in your browser and the corresponding data on the server
- If you do not provide it: every game remains fully playable; the streak, best times, a leaderboard place and duels are then not available
6. Game data
For a run, the following is stored: the puzzles played, your answers, solving times, wrong attempts, skipped puzzles, hints taken and the times at which all of this happened. If the identifier is switched on (section 5), the streak, best times and the time of your last run are added.
This data contains no information about you as a person. Through the identifier it is linked to a browser, and it is therefore pseudonymous.
- Purpose: running and scoring the game, best times, streak, leaderboards
- Legal basis: Art. 6(1)(f) GDPR (DSGVO). Legitimate interest: providing the game you asked for
- Storage period: see section 11
7. Display name and leaderboards
Display name. Your name is generated automatically and consists of two words from fixed lists and a number, for example “BronzeKranich638”. You can change it, but only using the same fixed lists — you cannot type free text. That rules out a name containing information about you as a person, or anything offensive.
The leaderboard is a separate decision. Your times appear publicly only if you switch that on separately. The default is off. Saving your progress does not mean appearing in public.
If the leaderboard is switched on, other players see your display name and your time for the day in question. Nothing beyond that — no identifier, no history, no time of your last visit.
- Purpose: comparing one day's results
- Legal basis: Art. 6(1)(a) GDPR (DSGVO) — your consent
- Withdrawal: at any time in the settings, with effect for the future
- Storage period: see section 11
8. Measuring how difficult the puzzles are
In order to judge how difficult a puzzle actually is, the following is recorded for each finished puzzle: the kind and level of the puzzle, how long it took, wrong attempts, whether it was skipped, whether a hint was used, along with the time until the board was first touched and the number of touches. Those last two values are stored rounded into bands, not to the millisecond and not to the individual tap.
These measurements carry no identifier and no link to you. They carry only the characteristics of the puzzle itself, plus two factual entries — whether the introduction had already been completed at that point, and whether it was the first sprint. No conclusion about a person can be drawn from them; the rows remain even when your data is deleted.
- Purpose: calibrating how difficult the puzzles are
- Legal basis: Art. 6(1)(f) GDPR (DSGVO), to the extent personal data is involved at all. Legitimate interest: puzzles that are neither too easy nor too hard
- Storage period: indefinite, as there is no link to a person
9. Challenge links
After a run you can create a link and pass it on. Whoever opens it sees your display name and your time, and can play the same run.
The link contains a randomly generated key. It cannot be derived from your identifier and does not contain it. The page is closed to search engines.
Please bear in mind: anyone who knows the link sees the display name and the time. You decide who you pass it on to.
- Purpose: passing a result to people of your choosing
- Legal basis: Art. 6(1)(f) GDPR (DSGVO). Legitimate interest: providing the function you asked for
- Storage period: see section 11
10. Duels
In a duel, two people solve the same puzzles and compare their times. A duel comes about only through an invitation link, and only once the person invited explicitly accepts it.
This stores a connection between two identifiers. What is stored: the two identifiers, the two display names, the kind and level of the puzzles, the results of the rounds and the times at which they happened.
The other person sees only your display name and the results of this duel. No identifier, no other duels, no time of your last visit. There is no way to exchange messages, and no way to search for other players.
Duel results appear on no public leaderboard.
A duel requires the persistent identifier from section 5, because a duel runs over several days. You are told this before you accept.
- Purpose: running the duel and showing the result
- Legal basis: Art. 6(1)(f) GDPR (DSGVO). Legitimate interest: providing the function both participants asked for
-
Storage period:
- an invitation that is not accepted is deleted after 7 days
- the details of the rounds — times per round, answers — are deleted 30 days after the duel ends
- what remains is one row with both display names, the result and the date
- if one of the two people deletes their data, their name is replaced by a placeholder; if both do, the row disappears entirely
11. Storage periods and deletion
| What | Period |
|---|---|
| Data without the identifier switched on | at the latest 24 hours after the last activity |
| Data with the identifier switched on | until you switch the function off or ask for deletion |
| A duel invitation that was not accepted | 7 days |
| The details of a finished duel | 30 days |
| Difficulty measurements (no link to a person) | indefinite |
| Logs of the upstream server | 7 days at most |
You can delete your data yourself at any time — in the settings, in one step. This removes the identifier in your browser and the corresponding data on the server.
Backups: deleted data does not disappear from technical backups immediately. A backup of the database is made daily and kept for 30 days; only after that is a deleted entry gone from there as well. The same applies when you ask for deletion yourself.
12. Advertising
No advertising is currently served. No advertising scripts are loaded and no requests are sent to advertising networks.
Once advertising is introduced, the following applies: it will be loaded only after you have consented. If you decline, no request is sent to Google or to any other provider — not even one for non-personalised advertising. You can change your decision at any time in the settings. The game remains fully playable either way.
This statement will be extended with the details that then apply before advertising is introduced.
13. Recipients of your data
The application runs on a server operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, in a data centre in Germany. Hetzner processes the data solely on instructions, as a processor, on the basis of a contract under Art. 28 GDPR (DSGVO).
The daily backups of the database are also held at Hetzner, in a second data centre in Germany, and are covered by the same contract.
My e-mail mailbox is operated by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, as a processor on the basis of a contract under Art. 28 GDPR (DSGVO).
Both providers may engage further processors; those are contractually bound to the same level of protection. Processing takes place exclusively within the European Economic Area. No transfer to third countries takes place.
Beyond this, your data is not passed on.
14. Getting in touch
If you contact me by e-mail or telephone, I process what you provide in doing so: your name, your contact details and the content of your message.
- Purpose: handling and answering your enquiry
- Legal basis: Art. 6(1)(f) GDPR (DSGVO), legitimate interest in answering enquiries; where retention obligations apply, Art. 6(1)(c) GDPR (DSGVO)
- Recipient: IONOS SE (section 13)
- Storage period: until the enquiry has been dealt with; beyond that only where statutory retention obligations require it
15. Your rights
You have the right of access (Art. 15 GDPR/DSGVO), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20, where the legal requirements are met). An informal message to info@golly-software.de is enough.
Please note: since dueligo does not know who you are, I can only match your data through the identifier in your browser. Deletion is easiest done yourself in the settings — there it takes effect immediately and without any proof of identity.
16. Right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR (DSGVO) (Art. 21 GDPR/DSGVO). Here this concerns sections 3, 4, 5, 6, 8, 9, 10 and 14.
An informal message to info@golly-software.de is enough.
17. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority. The competent one is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44, 40102 Düsseldorf, Germany
Telephone: +49 211 38424-0
18. Changes
This statement is adjusted when the processing changes. The version available on this page is the one that applies.
Last updated: 30 August 2026