OPTRIX
Home FAQ Anleitung
DE · EN

OPTRIX OPTRIX OPTRIX

Datenschutz · Privacy Policy

Deutsch · English

Optrix — Datenschutzerklärung

Stand: 8. August 2026 · Gültige Fassung: 1.1

Optrix ist ein Singleplayer-Puzzle mit einer Online-Account- Schicht: Zum Spielen brauchst du ein Konto, weil Levels vom Server geladen werden und dein Fortschritt mit deinem Konto verknüpft ist. Diese Seite sagt dir genau, welche Daten wir speichern, wo sie liegen, wer sie sehen kann und wie du sie löschen lässt.

1. Wer Optrix betreibt

Optrix wird betrieben von Robin Glave, unabhängiger Entwickler. Kontakt für jede Frage zum Datenschutz oder Auskunfts-/Lösch-Wunsch: [email protected].

2. Was wir erheben, und wozu

2.1 Beim Anlegen eines Kontos

  • Name — von dir gewählt. Wird als Anzeigename in der Spieloberfläche verwendet.
  • E-Mail-Adresse — für Anmeldung, Versand des 6-stelligen Verifizierungscodes und Passwort-Reset. Wird in Kleinbuchstaben gespeichert, um Duplikate zu erkennen.
  • Passwort — wird nur als Einweg-Hash gespeichert. Wir können dein Passwort nicht lesen und nicht zurücksenden. Wenn du es vergisst, kannst du es per E-Mail zurücksetzen.

2.2 Wenn du dich mit Apple oder Google anmeldest

Statt E-Mail und Passwort kannst du dich mit Mit Apple anmelden oder Mit Google anmelden registrieren und einloggen. Dabei gilt:

  • Du meldest dich direkt bei Apple bzw. Google an — dein dortiges Passwort sehen wir zu keinem Zeitpunkt.
  • Wir erhalten von dem Anbieter eine dauerhafte Nutzerkennung, deine E-Mail-Adresse und, sofern du sie freigibst, deinen Namen. Mehr nicht. Diese Daten legen wir genauso an wie bei einem E-Mail-Konto (§2.1).
  • Wenn du bei Apple E-Mail-Adresse verbergen wählst, bekommen wir nur die anonyme Weiterleitungsadresse von Apple (@privaterelay.appleid.com) und speichern ausschließlich diese. Deine echte Adresse erfahren wir nicht.
  • Apple bzw. Google erfahren durch die Anmeldung, dass du Optrix nutzt. Was sie damit tun, richtet sich nach ihren eigenen Datenschutzerklärungen — siehe §5.

2.3 Beim Spielen

  • Spielstanddaten, verknüpft mit deinem Konto: welche Levelpakete und Levels du gespielt hast, deine Lösungen und Zeitstempel. Gespeichert auf unseren eigenen Servern (siehe §4).
  • Lokale Einstellungen — Ton an/aus, Musiklautstärke, Sprachwahl und Ähnliches werden lokal auf deinem Gerät gehalten (im localStorage des Browsers, in der iOS-App zusätzlich über den Einstellungsspeicher des Systems). Sie verlassen dein Gerät nicht.
  • Offline-Modus (nur iOS-App) — wenn du Levelpakete für das Offline-Spielen herunterlädst, werden die Leveldaten im Dokumentenordner der App auf deinem Gerät abgelegt. Level, die du offline löst, werden dort zwischengespeichert und beim nächsten Wechsel in den Online-Modus an unsere Server übertragen. Löschst du die App, sind diese lokalen Daten weg.
  • Vorschaubilder — die kleinen Level-Vorschauen in der Levelliste werden in der IndexedDB deines Geräts zwischengespeichert, damit sie nicht bei jedem Öffnen neu gerendert werden müssen.

2.4 Bewegungsdaten (nur iOS-App)

Der Hintergrund in Menü und Level wandert leicht mit, wenn du das Gerät neigst. Dafür fragt die App einmalig die Bewegungs-Berechtigung von iOS ab und liest die Lagesensoren aus. Diese Werte werden ausschließlich auf deinem Gerät im Arbeitsspeicher verarbeitet, um das Bild zu verschieben. Sie werden nicht gespeichert und nicht an uns oder Dritte übertragen. Du kannst die Funktion jederzeit unter Einstellungen → „Neige-Parallaxe Hintergrund“ abschalten oder die Berechtigung in den iOS-Systemeinstellungen verweigern; das Spiel funktioniert dann unverändert weiter.

2.5 Was wir nicht erheben

  • Kein Analytics, kein Verhaltens-Tracking, keine Werbe-IDs.
  • Keine Tracking-Pixel Dritter, kein Google Analytics, kein Facebook-SDK, keine Werbenetzwerke.
  • Kein Zugriff auf Mikrofon, Kamera, Standort, Kontakte oder Foto-Bibliothek. Die iOS-App fordert keine dieser Berechtigungen an — die einzige Berechtigung, die sie überhaupt anfragt, ist die Bewegungs-Berechtigung aus §2.4.

2.6 Rechtsgrundlagen (Art. 6 DSGVO)

  • Konto, Anmeldung, Spielstand und Synchronisation — Art. 6 Abs. 1 lit. b DSGVO (Erfüllung des Nutzungsvertrags). Ohne diese Daten können wir dir das Spiel nicht bereitstellen.
  • E-Mail-Verifizierung und Passwort-Reset — Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung) sowie Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an der Sicherheit der Konten).
  • Server- und Zugriffslogs — Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse am sicheren, stabilen Betrieb und an der Missbrauchsprävention).
  • Bewegungs-Berechtigung — Art. 6 Abs. 1 lit. a DSGVO (Einwilligung), erteilt über den iOS-Systemdialog und jederzeit widerrufbar.

3. Wie lange wir Daten aufbewahren

  • Account-Daten — solange dein Konto existiert. Löschst du dein Konto selbst in der App (siehe §7), werden Konto und Spielstand sofort entfernt. Schreibst du uns stattdessen, erledigen wir es innerhalb von 30 Tagen.
  • E-Mail-Verifizierungscodes — kurzlebig (Minuten); werden nach Verwendung oder Ablauf automatisch gelöscht.
  • Offline-Daten auf deinem Gerät — bleiben, bis du das Levelpaket in der App wieder entfernst oder die App deinstallierst.
  • Server-Zugriffslogs — siehe §6.

4. Wo deine Daten liegen

Die Optrix-Backend-Dienste (Nutzerkonten, Leveldaten, deine Lösungen und Fortschritte) laufen auf einem selbst gehosteten Server-Cluster am Standort des Betreibers — physische Hardware, die wir selbst besitzen und administrieren, keine Public Cloud. Das Cluster ist per HTTPS über das Netzwerk von Cloudflare erreichbar (siehe §5).

Die statischen Teile des Spiels (HTML, JavaScript, Bilder, Audio) werden über Cloudflare Pages aus dem globalen CDN von Cloudflare ausgeliefert.

5. Wer deine Daten sonst noch verarbeitet

5.1 Auftragsverarbeiter

Um den Dienst zu betreiben, setzen wir eine kleine Zahl von Drittanbietern ein. Sie handeln weisungsgebunden in unserem Auftrag:

  • Cloudflare, Inc. — DNS, TLS-Terminierung, CDN und statisches Hosting für optrixgame.net und die zugehörigen API-Subdomains. Cloudflare sieht IP-Adresse und Request-Metadaten jeder HTTPS-Anfrage so lange, wie es zum Routen nötig ist. Siehe die Datenschutzerklärung von Cloudflare.
  • Resend (resend.com) — transaktionaler E-Mail-Versand. Wenn wir dir einen Verifizierungs- oder Passwort-Reset-Code schicken, werden deine E-Mail-Adresse und der Nachrichteninhalt von Resend verarbeitet, um die Nachricht zuzustellen. Siehe die Datenschutzerklärung von Resend.

5.2 Anmelde-Dienste (eigenverantwortliche Anbieter)

Wenn du Mit Apple anmelden oder Mit Google anmelden benutzt, verarbeiten diese Anbieter deine Daten nicht in unserem Auftrag, sondern als eigene Verantwortliche. Wir haben keinen Einfluss darauf, was sie dabei über dich speichern:

  • Apple Inc. — „Mit Apple anmelden“. Apple erfährt, dass du dich bei Optrix anmeldest, und übermittelt uns eine Nutzerkennung, deine (ggf. verborgene) E-Mail-Adresse und optional deinen Namen. Siehe die Datenschutzerklärung von Apple.
  • Google LLC — „Mit Google anmelden“. Google erfährt, dass du dich bei Optrix anmeldest, und übermittelt uns eine Nutzerkennung, deine E-Mail-Adresse und deinen Namen. Siehe die Datenschutzerklärung von Google.

Beide Wege sind freiwillig: Du kannst dich jederzeit stattdessen klassisch mit E-Mail und Passwort registrieren, dann werden weder Apple noch Google eingebunden.

5.3 App-Distribution

Apple Inc. vertreibt die iOS-App über den App Store. Apples Beziehung zu dir richtet sich nach Apples eigenen Richtlinien; uns teilen sie nur Aggregiertes mit (anonyme Installations- und Nutzungszahlen sowie Absturzberichte, sofern du deren Weitergabe in den iOS-Einstellungen erlaubt hast).

5.4 Übermittlung in Drittländer

Cloudflare, Resend, Apple und Google sind US-Unternehmen; bei der Nutzung ihrer Dienste können Daten in die USA übermittelt werden. Die Übermittlung stützt sich auf die Standardvertragsklauseln der EU-Kommission nach Art. 46 Abs. 2 lit. c DSGVO und, soweit der jeweilige Anbieter dort zertifiziert ist, zusätzlich auf den Angemessenheitsbeschluss zum EU-US Data Privacy Framework nach Art. 45 DSGVO. Die eigentlichen Kontodaten, Leveldaten und deine Lösungen liegen dagegen ausschließlich auf unserer eigenen Hardware in Deutschland (§4).

Wir verkaufen, vermieten oder teilen deine Daten mit keinem weiteren Dritten.

6. Cookies, Tokens und Logs

  • Refresh-Token-Cookie — beim Anmelden setzt der Server ein httpOnly, Secure, SameSite Cookie mit einem langlebigen Refresh-Token (rund zwei Wochen). Es dient ausschließlich dazu, dich über Seiten-Reloads hinweg angemeldet zu halten, ohne dass du dein Passwort erneut eingeben musst. Es wird nicht für Tracking verwendet.
  • Access-Token (im Speicher) — ein kurzlebiges (15 Minuten) JWT zur Autorisierung von API-Aufrufen. Liegt im JavaScript-Speicher und wird über vollständige Seiten-Reloads nicht persistiert.
  • Server-Logs — unser Backend schreibt Standard-Zugriffslogs (Zeitstempel, Request-Pfad, Status-Code, IP-Adresse) und Anwendungs-Logs in einen privaten Log-Speicher. Logs werden bis zu 30 Tage zu Betriebs- und Sicherheitszwecken aufbewahrt (Debugging, Missbrauchsprävention) und danach rotiert. Logs werden nicht für Verhaltensprofile ausgewertet.

7. Deine Rechte

Du kannst von uns jederzeit verlangen,

  • dir zu sagen, welche Daten wir über dich speichern (Auskunft);
  • Falsches zu korrigieren;
  • dein Konto und die zugehörigen Daten zu löschen;
  • die Verarbeitung einschränken zu lassen oder ihr zu widersprechen;
  • dir eine Kopie deiner Daten in einem portablen Format zu geben.

Konto selbst löschen: Du brauchst uns dafür nicht zu schreiben. Tippe im Hauptmenü oben auf deinen Namen, dann auf „Konto löschen“. Konten mit E-Mail und Passwort bestätigen mit ihrem Passwort, Apple- und Google-Konten mit einem 6-stelligen Code, den wir dir per E-Mail schicken. Die Löschung erfolgt sofort und ist endgültig.

Wenn du im Europäischen Wirtschaftsraum, im Vereinigten Königreich oder in der Schweiz wohnst, garantieren dir DSGVO / UK GDPR / DSG dieselben Rechte. Um sie auszuüben, schreib uns von deiner hinterlegten E-Mail-Adresse an [email protected]. Wir antworten binnen 30 Tagen, in aller Regel deutlich schneller. Eine erteilte Einwilligung (etwa für die Bewegungsdaten aus §2.4) kannst du jederzeit mit Wirkung für die Zukunft widerrufen.

Du hast außerdem das Recht, dich bei der für dich zuständigen Datenschutz-Aufsichtsbehörde zu beschweren.

8. Kinder

Optrix ist für alle Altersgruppen geeignet (App-Store-Einstufung 4+). Wir erheben jedoch wissentlich keine personenbezogenen Daten von Kindern unter 13 (in der EU unter 16) ohne nachprüfbare Einwilligung der Eltern. Falls du den Eindruck hast, dass ein Kind ohne Einwilligung ein Konto angelegt hat, schreib uns — wir löschen es.

9. Sicherheit

Passwörter werden vor der Speicherung mit einem modernen Passwort-Hash gehasht. Der gesamte Verkehr zwischen deinem Gerät und unseren Servern ist mit TLS verschlüsselt. Refresh-Token- Cookies sind httpOnly, Secure und SameSite. Tokens werden bei jedem Refresh rotiert; bei einer Passwortänderung werden alle Sitzungen invalidiert.

Kein System ist perfekt sicher. Wenn du eine Schwachstelle findest, schreib uns bitte zuerst an [email protected], bevor du sie öffentlich machst — wir nennen dich dann namentlich als Finder.

10. Änderungen dieser Erklärung

Wenn wir wesentlich ändern, welche Daten wir erheben oder wie wir sie verwenden, aktualisieren wir das Datum oben und benachrichtigen bei substanziellen Änderungen registrierte Nutzer vorab per E-Mail. Die weitere Nutzung von Optrix nach dem Wirksamwerden bedeutet, dass du die aktualisierte Fassung akzeptierst.


Optrix — Privacy Policy

Last updated: 8 August 2026 · Effective version: 1.1

Optrix is a single-player puzzle game with an online account layer: you need an account to play, because levels are loaded from our servers and your progress is tied to your account. This page tells you exactly what data we hold, where it lives, who can see it, and how to get rid of it.

1. Who runs Optrix

Optrix is operated by Robin Glave, an independent developer. Contact for any privacy question or data request: [email protected].

2. What we collect, and why

2.1 When you create an account

  • Name — chosen by you. Used as your display name in the game UI.
  • Email address — used to log you in, send the 6-digit email-verification code, and let you reset a forgotten password. Stored lowercased so we can detect duplicates.
  • Password — stored only as a one-way hash. We cannot read your password, and we cannot send it back to you. If you forget it you can reset it via email.

2.2 If you sign in with Apple or Google

Instead of an email and password you can register and log in with Sign in with Apple or Sign in with Google. In that case:

  • You authenticate directly with Apple or Google — we never see your password for those accounts.
  • The provider gives us a persistent user identifier, your email address and, if you release it, your name. Nothing else. We store those exactly as we would for an email account (§2.1).
  • If you choose Apple's Hide My Email, all we ever receive and store is the anonymous relay address (@privaterelay.appleid.com). Your real address stays unknown to us.
  • Apple or Google learn that you use Optrix when you sign in. What they do with that is governed by their own privacy policies — see §5.

2.3 As you play

  • Game-progress data tied to your account: which level packs and levels you have played, your solutions, and timestamps. Stored on our own servers (see §4).
  • Local settings — sound on/off, music volume, chosen language and similar preferences are kept locally on your device (in the browser's localStorage, and in the iOS app additionally in the system preferences store). They never leave your device.
  • Offline mode (iOS app only) — when you download level packs for offline play, the level data is written to the app's documents folder on your device. Levels you solve offline are queued there and sent to our servers the next time you switch back to online mode. Deleting the app removes all of it.
  • Preview thumbnails — the small level previews in the level list are cached in your device's IndexedDB so they do not have to be re-rendered every time you open the list.

2.4 Motion data (iOS app only)

The menu and level background drift gently as you tilt the device. To do that the app asks once for iOS's motion permission and reads the device's orientation sensors. Those readings are processed purely in memory on your device to offset the image. They are not stored and not transmitted to us or to anyone else. You can switch the feature off any time under Settings → "Tilt parallax background", or deny the permission in iOS system settings; the game works exactly the same either way.

2.5 What we do not collect

  • No analytics, no behavioural tracking, no advertising IDs.
  • No third-party tracking pixels, no Google Analytics, no Facebook SDK, no ad networks.
  • No microphone, camera, location, contacts, or photo-library access. The iOS app does not request any of these permissions — the only permission it ever asks for is the motion permission in §2.4.

2.6 Legal bases (Art. 6 GDPR)

  • Account, sign-in, game progress and sync — Art. 6(1)(b) GDPR (performance of the contract). Without this data we cannot provide the game to you.
  • Email verification and password reset — Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR (legitimate interest in keeping accounts secure).
  • Server and access logs — Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation and abuse prevention).
  • Motion permission — Art. 6(1)(a) GDPR (consent), given through the iOS system dialog and withdrawable at any time.

3. How long we keep it

  • Account data — kept as long as your account exists. If you delete your account yourself in the app (see §7), the account and its progress are removed immediately. If you email us instead, we do it within 30 days.
  • Email-verification codes — short-lived (minutes); discarded automatically once used or expired.
  • Offline data on your device — stays until you remove the level pack in the app or uninstall the app.
  • Server access logs — see §6.

4. Where your data lives

Optrix backend services (user accounts, level data, your solutions and progress) run on a self-hosted server cluster at the operator's location — physical hardware that we own and administer ourselves, not a public cloud. The cluster is reachable via HTTPS through Cloudflare's network (see §5).

The static parts of the game (HTML, JavaScript, images, audio) are served by Cloudflare Pages from Cloudflare's global CDN.

5. Who else processes your data

5.1 Data processors

To run the service we use a small number of third parties. They act as data processors on our behalf, on our instructions only:

  • Cloudflare, Inc. — DNS, TLS termination, CDN and static hosting for optrixgame.net and the related API subdomains. Cloudflare sees the IP address and request metadata of every HTTPS request you make to the game for as long as it takes to route the request. See Cloudflare's privacy policy.
  • Resend (resend.com) — transactional email delivery. When we send you an email-verification code or a password-reset code, your email address and the message body are processed by Resend so they can deliver the message. See Resend's privacy policy.

5.2 Sign-in providers (independent controllers)

When you use Sign in with Apple or Sign in with Google, those providers do not process your data on our behalf — they act as controllers in their own right, and we have no influence over what they record about you:

  • Apple Inc. — "Sign in with Apple". Apple learns that you are signing in to Optrix, and passes us a user identifier, your (optionally hidden) email address and, if you allow it, your name. See Apple's privacy policy.
  • Google LLC — "Sign in with Google". Google learns that you are signing in to Optrix, and passes us a user identifier, your email address and your name. See Google's privacy policy.

Both routes are optional: you can always register with an email address and password instead, in which case neither Apple nor Google is involved.

5.3 App distribution

Apple Inc. distributes the iOS app through the App Store. Apple's relationship with you is governed by their own policies; they tell us only aggregate things (anonymous install and usage counts, and crash reports if you have allowed sharing them in your iOS settings).

5.4 Transfers outside the EU

Cloudflare, Resend, Apple and Google are US companies, so using their services can involve transferring data to the United States. Those transfers rely on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where the provider is certified under it, additionally on the adequacy decision for the EU-US Data Privacy Framework under Art. 45 GDPR. Your actual account data, level data and solutions, by contrast, live exclusively on our own hardware in Germany (§4).

We do not sell, rent, or share your data with any other third party.

6. Cookies, tokens and logs

  • Refresh-token cookie — when you log in, the server sets an httpOnly, Secure, SameSite cookie that holds a long-lived refresh token (about two weeks). Its only purpose is to keep you logged in across page reloads without re-asking for your password. It is not used for tracking.
  • Access-token (in memory) — a short-lived (15 minute) JWT used to authorise API calls. It lives in JavaScript memory and is not persisted across full page reloads.
  • Server logs — our backend writes standard access logs (timestamp, request path, response code, IP address) and application logs to a private log store. Logs are kept for up to 30 days for operational and security purposes (debugging, abuse prevention) and then rotated out. Logs are not analysed for behavioural profiling.

7. Your rights

Wherever you live, you can ask us to:

  • tell you what we hold about you (right of access);
  • correct anything that is wrong;
  • delete your account and the data tied to it;
  • restrict or object to the processing;
  • export a copy of your data in a portable format.

Deleting your account yourself: you do not have to email us. Tap your name at the top of the main menu, then "Delete account". Email/password accounts confirm with their password; Apple and Google accounts confirm with a 6-digit code we send you by email. Deletion is immediate and permanent.

If you are in the European Economic Area, the United Kingdom or Switzerland, the same rights are guaranteed by the GDPR / UK GDPR / Swiss FADP. To exercise any of them, email [email protected] from the address on file. We will respond within 30 days and normally much sooner. Where processing rests on consent (such as the motion data in §2.4), you can withdraw it at any time with effect for the future.

You also have the right to lodge a complaint with your local data-protection authority.

8. Children

Optrix is suitable for all ages (App Store rating 4+) but we do not knowingly collect personal information from children under 13 (under 16 in the EU) without verifiable parental consent. If you believe a child has created an account without consent, please email us and we will delete it.

9. Security

Passwords are hashed with a modern password hash before storage. All traffic between your device and our servers is encrypted with TLS. Refresh-token cookies are httpOnly, Secure and SameSite. We rotate tokens on every refresh and revoke all sessions when you change your password.

No system is perfectly secure. If you spot a vulnerability, please email us at [email protected] before disclosing publicly — we will give you credit.

10. Changes to this policy

If we make material changes to what data we collect or how we use it, we will update the "Last updated" date at the top of this page and, for substantive changes, notify registered users by email before the change takes effect. Continued use of Optrix after the effective date means you accept the updated policy.

← Zurück / Back

Kontakt: [email protected]

Impressum · Datenschutz · Nutzungsbedingungen · Open-Source-Hinweise

© 2025–2026 Alexander Gülich & Robin Glave