Privacy Policy

Last updated: 18 August 2026

This policy describes what personal data we process, why, how long we keep it, and your rights when you use PlayGrid in Discord Activity, with the bot, or on this website.

1. Who we are

This Privacy Policy explains how Rafał Szołtysik (sole proprietorship / JDG) ("we", "us", "our") processes personal data when you use the PlayGrid website at www.playgrids.app, Discord Activity, the Discord bot, or store-linking pages (together, the "Services").

Data controller: Rafał Szołtysik (sole proprietorship / JDG)
Address: ul. Wolna 35, 44-187 Wielowieś, Poland
Privacy contact: office@playgrids.app

2. Scope

This policy applies to personal data we process as a controller. It does not cover third-party websites, game stores, or platforms (such as Steam, Epic Games, or Discord) that you connect or link to separately; those services have their own privacy policies.

Account and library features run through Discord Activity and our API. The marketing site may link to authentication and store-linking flows in the browser.

3. Personal data we collect

Depending on how you use the Services, we may process:

  • Account: email address, display name, password (stored hashed, not in plain text) if you register with email, profile avatar if you set one, and account timestamps.
  • Discord:Discord user snowflake, username, global name, avatar, email when the OAuth email scope is granted, guild memberships from the guilds scope, and Activity context (guild and channel) from Discord's token exchange. We also store encrypted Discord access and refresh tokens to keep the link alive.
  • Bot and server setup: guild and channel IDs and names for looking-for-group configuration, plus the content of messages we send (session invite DMs, channel posts, RSVP updates, reminders). We do not scrape your private Discord DMs.
  • Linked platform accounts (optional): identifiers and tokens needed to sync your game libraries (e.g. Steam, Epic Games, GOG, Xbox, EA, Ubisoft) - only if you choose to connect them.
  • Library & gameplay metadata: game titles, ownership, play time, store metadata, and related technical identifiers from connected stores.
  • Game artwork (display only):cover images and similar store-hosted artwork shown in your library and session views. For Steam-linked games we typically load images from Valve's public content delivery network (CDN) using your game's store app identifier - only for titles present in your synced library, not as a game store or resale catalog.
  • Social & planning features: friend relationships, session invitations, votes, messages you send through product features, and scheduling preferences (including optional activity-time patterns you share with friends).
  • Telemetry:play-session start/end, heartbeats, aggregated activity buckets, and limited product analytics events (e.g. library search usage) tied to your account. Discord presence telemetry (inferring play time from Discord "Playing" status) runs only if you opt in.
  • Communications: content of transactional emails (e.g. password reset, friend invites, session reminders), Discord bot DMs and channel posts you enable (session invites, reminders, RSVP updates), and delivery metadata. You control Discord DM types (invites, reminders, RSVP) and email where those settings exist.
  • Technical & security: IP address, device/client type, logs, and similar data needed to operate and secure the Services.

4. Game platform data (including Steam)

When you connect a platform (e.g. Steam via OpenID or other supported login), we retrieve data about your account only when you request it - for example to sync the games you own, play time, and profile identifiers needed to show your library and shared-game overlap in Discord Activity. We do not collect your Steam password; authentication is handled by the platform.

For Steam, we may use the Steam Web API and related store endpoints under Valve's terms. We process that data to operate PlayGrid as a personal library and session-planning tool, not to sell games or to present PlayGrid as endorsed by Valve or Steam.

  • We store platform identifiers, library entries, and metadata needed for sync and social features you enable.
  • Cover art may be referenced by URL (e.g. Steam CDN) or cached briefly on our servers for performance; we do not claim ownership of publisher artwork.
  • You can disconnect a platform from Connect stores or Discord Activity; we stop new sync from that source and remove linked library data as described in the product.
  • Platform data is provided to you in Discord Activity on an "as is" basis, consistent with third-party platform terms.

Where we store data: account and library data are processed primarily in the European Economic Area (including Poland, where our operator is based) and, where our infrastructure providers require it, in other countries with appropriate safeguards (see section 7).

5. How we use data and legal bases (EEA/UK)

We process personal data for the following purposes:

  • Providing the Services (contract / steps before contract): Discord sign-in, Discord Activity, the bot, library sync, friends, and session planning.
  • Product updates (consent or legitimate interest, depending on jurisdiction): emailing you about important product news when you opt in. You can withdraw marketing consent at any time.
  • Security & fraud prevention (legitimate interest / legal obligation): protecting accounts, APIs, and infrastructure.
  • Improvement & analytics (legitimate interest): understanding how features are used to fix bugs and improve UX, using aggregated or pseudonymous data where possible.
  • Legal compliance (legal obligation): responding to lawful requests and enforcing our terms.

Where we rely on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, you may object as described in section 10.

6. Sharing and processors

We do not sell your personal data. We share data only as needed to run the Services:

  • Infrastructure & hosting: cloud providers that host our website, API, and databases (e.g. Vercel for the marketing site).
  • Authentication: our auth provider for email sign-in and password management, and Discord Inc. for Discord OAuth and Activity token exchange.
  • Discord Inc.: we call Discord APIs to sign you in, run Activity, and send DMs or channel posts when you or a server admin enable them.
  • Email delivery: SMTP or transactional email providers to send account and notification emails.
  • Game platforms:when you connect a store account, we exchange data with that platform's APIs according to your authorization (e.g. Steam, Epic, GOG). Cover images may be loaded from those platforms' CDNs when you view your library; that traffic goes between your device (or our API) and the platform, not to other PlayGrid users except where you explicitly share library overlap with friends.
  • Other users: information you choose to share in Discord Activity or on a channel (e.g. shared games, RSVP, session details).
  • Professional advisers & authorities: when required by law or to protect rights and safety.

Processors act on our instructions under data-processing agreements where required by law.

7. International transfers

We may process data in the European Economic Area and in other countries where our providers operate (including the United States). When personal data is transferred outside the EEA/UK, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, unless an adequacy decision applies.

8. Retention

We keep personal data only as long as necessary for the purposes above, including:

  • Account data: for the life of your account and a reasonable period after deletion for backups and legal claims.
  • In-product notifications: typically up to 90 days, then deleted automatically.
  • Telemetry and logs: typically rolling periods (e.g. months), unless longer retention is required for security or law.
  • Legal obligations: longer where statute requires.

9. Security

We use technical and organizational measures appropriate to the risk (encryption in transit, access controls, hashed credentials via our auth provider, and least-privilege access). No method of transmission or storage is 100% secure; please use a strong, unique password and keep platform tokens confidential.

10. Your privacy rights

Depending on your location, you may have rights to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent. You may also lodge a complaint with a supervisory authority.

EEA/UK: contact us at office@playgrids.app. You may complain to President of the Personal Data Protection Office (UODO), Poland (uodo.gov.pl/).

United States (e.g. California): we do not sell personal information. You may request access, deletion, or correction as applicable under state law by emailing office@playgrids.app. We will verify your request as required.

You can unlink Discord, adjust Discord DM opt-ins, and disconnect stores from Connect stores or Discord Activity. For other requests, email us from your account email.

11. Cookies and similar technologies

On the marketing website (www.playgrids.app) we use Vercel Web Analytics and Speed Insights to measure page views and site performance (Core Web Vitals). These services are provided by Vercel Inc. and are configured to avoid third-party advertising trackers. Vercel Web Analytics does not use cookies for visitor counting; Speed Insights may send performance metrics tied to your visit.

With your consent (via the analytics banner), we also use PostHog (PostHog Inc., EU cloud) for optional product analytics on the marketing site: Discord setup funnel events (sign-in, bot, Activity) and Session Replay (scroll and mouse movement on the page, with text masked). PostHog may store an identifier in cookies or local storage after you accept. We do not use advertising cookies on the marketing site. You can withdraw consent by clearing site data or rejecting analytics when prompted.

Inside the PlayGrid Discord Activity (Embedded App), after you accept a separate optional prompt in that iframe, we may send funnel events (for example opening Activity or creating a session) through our API to PostHog, and may record a masked Session Replay of the Activity UI. The analytics identifier is your PlayGrid account id, not your Discord username. You can reject or clear Activity storage to stop this; Discord may also clear that storage on its own.

Some product emails (for example a one-time reminder to connect your game library) may include a 1×1 image used only to see whether the message was opened, and links that pass through our API so we can tell if you clicked the button. We do not use this for advertising.

We may still use cookies or local storage that are strictly necessary to operate the site (e.g. security, load balancing, locale preference).

12. Automated decision-making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Scheduling suggestions use your data and friends' availability to assist planning; you remain in control of accepting session times.

13. Children

The Services are not directed at children under 16 (or the minimum age required in your country). We do not knowingly collect personal data from children. Contact us if you believe a child has provided data and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. Material changes may be notified by email, on this website, or in Discord where appropriate.

15. Contact

Questions or requests: office@playgrids.app
General support: office@playgrids.app