←

Klebster

Privacy Policy

1. Who is responsible

The controller responsible for processing your data under the General Data Protection Regulation (GDPR) is:

We have not appointed a data protection officer, as we do not meet the legal thresholds requiring one. For any privacy question, contact us at the email address above.

2. What Klebster is, and our basic approach to your data

Klebster is a game in which physical stickers are placed in the real world and found by other people. The app shows a map, records your location when you explicitly ask it to, and lets you upload photos of stickers.

Core principles:

3. What data we process

3.1 Device identifier (game ID)

On your first visit, your browser generates a random identifier (e.g. u_3f2a…) and stores it in your device's local storage (localStorage). The identifier contains no personal details in itself, but it links your game progress (stickers found and placed) to your device. Because it allows you to be singled out, we treat it as pseudonymous personal data.

3.2 Location data (GPS)

The features "I found a sticker", "Centre on my location" and "Plant new seed" request your position through your browser's location service. This happens only after you press the corresponding button, and only if you have granted location permission in your browser.

We store:

The proximity check ("are you close enough to the sticker?") happens on our server. A find is only recorded if you are within roughly 15 metres of an active sticker.

3.3 Photos

When you place a sticker or create a sticker series, you can take a photo or choose one from your device's gallery. You always make that selection yourself — the app never accesses your camera or gallery on its own or in the background.

Metadata removal: before a photo is stored, we strip its embedded metadata on the server (including EXIF GPS coordinates, device model and capture timestamp in JPEGs, and text/time chunks in PNGs). Only the orientation flag is preserved, so the image is not displayed rotated. If a file cannot be parsed with confidence, the upload is rejected rather than stored unchecked. Maximum file size is 8 MB.

Visibility: the verification photo of a placed sticker is only retrievable by people who have found that sticker themselves. The reference photo of a series (showing what people are looking for) is publicly retrievable.

3.4 Free text

When placing a sticker you can optionally add a description and a hint ("where is it hidden?"); when creating a series, a name and description. These texts are stored and shown to other users — the hiding-place hint only after that sticker has been found. Do not enter personal data or sensitive information here.

3.5 Signing in with Google (optional)

Some features — creating your own sticker series, joining a series as a placer ("seeder"), and placing stickers — require signing in with a Google account. Simply searching for and finding stickers does not.

If you sign in, we receive and store from Google:

We do not store any long-lived Google access or refresh token. Your Google profile is fetched once during sign-in and then discarded. We then issue our own signed session token, valid for 30 days, which is stored in your browser.

During sign-in, data is transmitted to and processed by Google (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); transfer to the USA cannot be excluded. See Google's privacy policy. You can revoke Klebster's access to your Google account at any time at myaccount.google.com/permissions.

3.6 Map tiles (OpenStreetMap)

Map imagery is loaded from servers operated by the OpenStreetMap Foundation (St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom). Loading map tiles necessarily transmits your IP address and the requested map area to OpenStreetMap. We have no control over that processing. See the OpenStreetMap Foundation privacy policy.

3.7 Server logs and hosting

The website and API run on Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, and Cloudflare Germany GmbH). Accessing the service processes technically necessary connection data, in particular IP address, request time, requested URL, data volume, browser type and operating system. Cloudflare also processes this data to mitigate attacks and maintain operational security.

Your game data is stored in a Cloudflare D1 database and photos in Cloudflare R2 storage. A data processing agreement is in place; for transfers to third countries, Cloudflare relies on the European Commission's Standard Contractual Clauses. See Cloudflare's privacy policy.

3.8 Your browser's local storage

We use no cookies for analytics or advertising. Information required to operate the service is kept in your browser's local storage:

You can clear this data at any time in your browser settings. Doing so loses the link to your previous finds on that device, unless you have linked a Google account.

4. Recipients and disclosure

Your data is shared only with the service providers named above (Cloudflare as our processor, Google when you sign in, OpenStreetMap when map tiles load) and — as part of the game — with other users:

We do not sell data. We disclose data to authorities only where legally required to do so.

5. Retention

6. Deleting your account

You can permanently delete your account yourself on the Account page. When you do:

Once anonymised, this information is no longer personal data under the GDPR. Deleting your Klebster account does not affect your Google account itself; you can additionally revoke the link at Google as described in section 3.5.

If you would like deletion beyond this, contact us at the address in section 1.

7. Your rights

You have the right to:

An informal message to the address in section 1 is enough to exercise any of these.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in the country of your habitual residence, place of work, or the place of the alleged infringement. The authority responsible for us is:

8. Minors

Klebster is not directed at children. Use requires a minimum age of 16. People under 16 may use the service only with the consent of a parent or guardian. If we learn that we are processing a younger person's data without the required consent, we will delete it.

9. No automated decision-making

We do not carry out automated decision-making or profiling within the meaning of Art. 22 GDPR.

10. Data security

All traffic is encrypted over HTTPS. Session tokens are cryptographically signed. Additional browser-side protections are active, including a Content Security Policy, HSTS, and protection against the site being embedded in third-party pages.

11. Changes to this policy

We update this policy when app features or the legal situation change. The version published on this page applies. The date at the top shows the current status.