Sylvorama, back to the game

Privacy Policy

In effect from 9 October 2026

Sylvorama is a small browser game at sylvorama.world. One person runs it, privately and not as a business. This policy explains which personal data the game handles, why, for how long, who else processes it, and what rights you have under the EU General Data Protection Regulation (GDPR) and the German Telecommunications Digital Services Data Protection Act (TDDDG). “We” and “us” below mean that one person.

The short version

  • We need your email address to sign you in, and we keep the terrariums you grow. Beyond that we keep only what it takes to run and protect the game, such as short-lived records of sign-in requests to stop abuse.
  • No advertising, no analytics, no tracking, no profiling. We don’t sell or share your data for marketing.
  • The game runs on Cloudflare, which processes data on our behalf; mail you send us is kept at Proton.
  • You can delete your account, and everything in it, at any time under Settings.

1. Who is responsible

The controller under the GDPR is:

Aurel Canciu
Germany
Email: privacy@sylvorama.world

Write in English, German or Romanian. There is no data protection officer; the law does not require one for a project of this size, so all privacy questions go to the address above.

2. What we process and why

2.1 Visiting the site

When your browser loads Sylvorama, it sends what every browser sends to every website: your IP address, the address of the page or file it asks for, the date and time, and technical details such as your browser and operating system (the “user agent”). Cloudflare, which hosts and protects the site, needs these to deliver the game and to fend off attacks such as floods of traffic. The game’s own server does not keep logs of your requests.

Legal basis: our legitimate interest in delivering a working and secure website (Art. 6(1)(f) GDPR).

2.2 Your account

When you sign up, we store:

Each time you sign in, we create a session: a random token stored in your browser and in our database, with the dates it was created, last renewed and expires. Sessions are not linked to your IP address or browser; we don’t record either with them.

The small portrait next to your name is drawn in your browser from your email address. It is not sent to us or to anyone else.

Purpose and legal basis: to sign you in, keep you signed in, and let you change your name or address, sign out and delete your account. This is necessary to provide the game you signed up for (Art. 6(1)(b) GDPR). We record which terms you accepted, and when you last played, because of our legitimate interest in being able to show which terms apply to you and in not keeping accounts nobody uses any more (Art. 6(1)(f) GDPR).

2.3 Sign-in and account emails

Sylvorama has no passwords. To sign you in, we email you a link that works once and lasts 15 minutes; until it is used, we store a token together with the address it was sent to, and we delete both when the link is used. To move your account to a new address, we email a confirmation link to your current address and then a second link to the new one; each lasts 60 minutes. Those two links are signed with a secret key instead of being stored, so we keep nothing about them; each works until it expires.

We also email you when we invite you (section 2.5), a month before we delete an account nobody has signed into for three years (section 6), and before a change to our terms or to this policy that affects you. We send no newsletters or marketing. Our emails contain no tracking pixels and no tracked links. When your mail app shows images, it loads the Sylvorama logo and a picture of a Munkel from our site, like any page would.

The emails are sent through Cloudflare’s email service. Cloudflare keeps a log of each email we send you or you send us (sender, recipient, subject, time and delivery status) for up to 30 days, so that delivery problems can be traced. We keep no copies of the emails we send.

Legal basis: necessary to provide the game and your account (Art. 6(1)(b) GDPR); for the delivery log, our legitimate interest in emails that arrive (Art. 6(1)(f) GDPR).

2.4 Protection against abuse

Anyone can type any email address into the sign-in form, so we guard it against bots and against people sending sign-in emails to someone else’s inbox:

Legal basis: our legitimate interest in protecting the game, its players and other people’s inboxes from abuse (Art. 6(1)(f) GDPR). Passing the bot check’s signals to Cloudflare, which also uses them to improve Turnstile, rests on our legitimate interest in using an effective bot check that doesn’t track you across sites or show you puzzles (Art. 6(1)(f) GDPR). For collecting and passing on the signals, we and Cloudflare are jointly responsible; for what Cloudflare does with them afterwards, Cloudflare alone is. The bot check reads information from your browser; under § 25(2) no. 2 TDDDG this is allowed without consent because it is strictly necessary to provide the sign-in you asked for.

2.5 Invitations

For now, Sylvorama is open by invitation only. When we invite you, we store your email address, when you were invited, when we told you about it and when you accepted, and sometimes a short note on how the invitation came about (for example, where you asked for it). Usually you gave us your address yourself; sometimes a friend passed it on so we could invite you. Either way, we email you within the hour to tell you about the invitation, with a link to this policy. If you don’t want it, ignore that email and the invitation lapses, or reply and we delete your address at once.

Legal basis: where you asked to be invited, steps taken at your request before an agreement (Art. 6(1)(b) GDPR); otherwise, our legitimate interest in letting in the people we have invited (Art. 6(1)(f) GDPR).

2.6 Your terrariums

For each terrarium, we store:

Names you write, for your terrariums and for yourself, are not shown to anyone else: no other player can see your account or your terrariums.

Purpose and legal basis: to keep your worlds so that you can come back to them on any device. This is necessary to provide the game (Art. 6(1)(b) GDPR).

2.7 When you write to us

If you email us, or reply to an email from us, we process your address, your message and whatever you choose to include, to answer you. Mail to our addresses is received by Cloudflare Email Routing and forwarded to our mailbox at Proton (section 4).

Legal basis: our legitimate interest in answering you (Art. 6(1)(f) GDPR); where you exercise your rights under the GDPR, our legal obligation to handle your request (Art. 6(1)(c) with Art. 12 GDPR).

2.8 What we don’t do

We use no analytics, advertising or social-media tools, and no third-party fonts or scripts besides the bot check above. We don’t build profiles, and we make no decisions about you by automated means that have legal or similarly significant effects (Art. 22 GDPR).

3. What is stored on your device

The game stores a few things in your browser. Each is strictly necessary to provide the game you asked for, so under § 25(2) no. 2 TDDDG no consent is needed, and there is no cookie banner. None of it is used for tracking, analytics or advertising.

Cookie __Secure-better-auth.session_token
Keeps you signed in. Lasts 30 days and is renewed, at most once a day, while you play. Deleted when you sign out.
Local storage (sylvorama… entries)
Your settings on this device: sound and volume, the Lab and pacing switches, and whether you have already seen the welcome, the tour and each hint. While you are moving your account to a new address, it also holds that address, so the game can tell which step you have reached; it is removed when a link for the move is followed in this browser, when you sign out here, or when you delete your account here.
IndexedDB database sylvorama
A copy of each terrarium’s latest save, so your progress survives the page closing before it reached our server. The copy in this browser is removed when you delete or start the terrarium anew here, and all copies in this browser are removed when you delete your account here. Copies in other browsers you have played in stay there until you clear the site’s data in them; signing out leaves them in place too.
Cloudflare Turnstile
On the sign-in form only, the bot check may store strictly necessary data under challenges.cloudflare.com (see section 2.4).

4. Who else processes data

Cloudflare

Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA hosts the whole game: the website, the database, the save files, the bot check, and the sending and receiving of email. It processes personal data on our behalf, under the Cloudflare Data Processing Addendum (Art. 28 GDPR). Our database and save files are currently stored in Cloudflare data centres in Europe, but Cloudflare’s network is global, and your requests are handled by the data centre nearest to you.

For the bot check’s improvement (section 2.4), Cloudflare acts as a controller itself. It also uses data about traffic through its network, as a controller in its own right, to protect its network and its customers from attacks, as described in section 6 of its privacy policy: cloudflare.com/privacypolicy.

Proton
Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland hosts the mailbox our addresses forward to (section 2.7). It processes those emails on our behalf, under its Data Processing Agreement (Art. 28 GDPR).
Your email provider
Receives the emails we send you, as with any email.
Authorities
Only if we are legally obliged to disclose data, and only what that obligation covers.

Nobody else receives your personal data.

5. Transfers outside the EU

Cloudflare, Inc. is based in the United States and its network spans the world, so personal data may be processed outside the European Economic Area. Cloudflare, Inc. is certified under the EU–U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR); our transfers to Cloudflare rest on it. If that certification lapsed, the European Commission’s Standard Contractual Clauses in Cloudflare’s Data Processing Addendum would apply instead (Art. 46(2)(c) GDPR). Cloudflare is bound by the same addendum when it uses sub-processors in other countries.

Proton keeps our mailbox in Switzerland, for which the European Commission has also adopted an adequacy decision (Art. 45 GDPR).

You can ask us for a copy of these safeguards.

6. How long we keep data

Account
Until you delete it, or until nobody has signed into it for three years. We email you a month before we delete an unused account; signing in before then keeps it.
Terrariums, saves and pictures
Until you delete the terrarium or your account, or we delete an unused account. Starting a terrarium anew deletes its save and picture at once.
Sessions
Deleted when you sign out (or sign out everywhere else). A session you stop using expires 30 days after it was last renewed and is deleted within a day after that.
Sign-in links
Deleted when used; unused ones expire after 15 minutes and are deleted within a day after that. Address-change links are not stored; they stop working after 60 minutes.
Rate-limit records
Counts per IP address are deleted within 25 hours of your last request, usually much sooner. Records of sign-in links requested for an address are kept for one hour and deleted within 25 hours.
Invitations
An invitation nobody accepts lapses after 90 days. An accepted one is kept while an account with that address exists. Either way it is deleted within a day after it lapses, after the account is deleted, or after the account moves to another address.
Email delivery log
Kept by Cloudflare for up to 30 days (section 2.3).
Emails you send us
We delete your message and our reply one year after our last exchange about it. If you exercise your GDPR rights, we instead keep a record of the request and our answer for three years, to be able to show that we handled it (Art. 5(2) GDPR).
Backups
The database keeps an automatic point-in-time history for up to 30 days, so deleted records leave it entirely within 30 days. We would use it only to recover from a failure, and would then delete again anything deleted after the point we restored to. Save files and pictures have no backup copies: they are gone as soon as they are deleted.
Technical data at Cloudflare
We don’t receive or keep logs of your visits. Cloudflare keeps the connection data of section 2.1 for as long as it needs it to deliver the site and to protect it and its network from attacks, by the criteria in the “Data retention” section of its privacy policy; it publishes no fixed period.

7. Your rights

Under the GDPR you have the right:

Your right to object. Where we process your data on the basis of our legitimate interests (sections 2.1, 2.2, 2.3, 2.4, 2.5, 2.7 and 9), you may object at any time, on grounds relating to your particular situation (Art. 21 GDPR). We then stop, unless we can show compelling legitimate grounds that override your interests, or need the data to establish, exercise or defend legal claims. Write to privacy@sylvorama.world.

To exercise a right, email privacy@sylvorama.world, ideally from the address of your account, so we can tell that the request is yours. If we can’t, we may ask you to confirm it by following a link we send there. We answer within one month (Art. 12(3) GDPR), free of charge.

8. What you have to provide

Playing Sylvorama needs an account, and an account needs an email address, because that is how you sign in. You don’t have to give us your address, but without it you can’t play. A display name is optional. No law obliges you to provide any data.

9. Children

You must be at least 16 to play, or have the permission of a parent or guardian if you are younger. If you are under 18, German law lets you enter into our Terms of Use only with that permission, so please ask before you sign up. If you are under 18 and signed up without it, we process your account and terrarium data on the basis of our legitimate interest in letting you play the game you signed up for (Art. 6(1)(f) GDPR) until a parent or guardian agrees; you can object at any time by deleting your account.

If you are a parent and believe your child under 18 signed up without your permission, write to us and we will delete the account.

10. Security

The site is served only over encrypted connections (HTTPS). There are no passwords to steal: sign-in links work once and expire within minutes. Requests for sign-in links are checked for bots, requests to the game’s server are rate-limited, each account can reach only its own terrariums, and Cloudflare encrypts the database and save files at rest. To report a security problem, see our security policy.

11. Changes to this policy

We update this policy when the way the game handles data changes; the date at the top shows when it took effect. Before a change that affects how we use data you have already given us, we email everyone with an account.