Legal
Privacy Policy
Last updated: October 9, 2026
Learn how GAMESLIKE handles website, account, Steam sign-in, Google sign-in, and optional analytics data, plus your privacy choices and rights.
Controller
Burlis Management GmbH, Philippstraße 27, 52349 Düren, Germany
Contact: legalnotice@paraspeech.com
GamesLike in ChatGPT
When you invoke the GamesLike plugin in ChatGPT, OpenAI sends the selected tool inputs to GAMESLIKE: a game-title query or Steam app ID, result count, catalog preferences, or a library recommendation mode. Public catalog tools work without a GAMESLIKE account. The plugin does not request your ChatGPT conversation history or access a payment account.
You can optionally authorize ChatGPT to read your GAMESLIKE wishlist, brief and Steam-based recommendations. We use imported games, recorded playtime and Loved/Not for me preferences to rank games, and return bounded picks and snapshot freshness. Separate authorization lets ChatGPT save or remove wishlist entries and change game preferences when you ask, or read recommendations for groups you belong to. Existing read grants do not gain those permissions. We do not return your email, Steam ID, credentials, full library, other members' private preferences or embedding vectors. Steam login does not expose private game details. Imports require an explicit website action or your separate recurring-refresh choice below.
We retain hashed authorization credentials and consent in the existing account database to provide this requested connection. Access credentials expire; refresh credentials follow their expiry or revocation. Disconnect ChatGPT on the GamesLike connection page to revoke access immediately. Disconnection retains your GamesLike account and imported library; account deletion removes them and the authorization records. Personalized account access requires age 18 under these Terms.
The plugin processes tool inputs and results for the request without storing a search or conversation history. Request limits use hashed network identifiers in process memory for a one-minute admission window; counters are cleared on the first request in a subsequent window or when the process restarts. Hosting and security providers process network request metadata, and sanitized operational error reports follow the provider and retention descriptions below. Tool inputs and recommendation content are not attached to those error reports.
The requested inputs are processed to provide the game-discovery service you invoke. Service security and abuse prevention use the existing security purposes described below. Catalog results are returned to OpenAI for use in your ChatGPT conversation. OpenAI handles ChatGPT content under its own privacy policy and your ChatGPT settings; using this plugin does not change those settings. Following a GamesLike link opens our website, where the website practices described in this policy apply.
Current Processing
GAMESLIKE processes request data to deliver the website, protect the service, operate accounts, support Steam sign-in, show recommendations, and answer messages sent to the contact address.
Account and authentication data is stored by GAMESLIKE on its Hetzner-hosted infrastructure. Steam sign-in uses the verified Steam account identifier and public display name; Google sign-in uses the basic profile data returned by Google to create and access the account. GAMESLIKE never asks for a Steam or Google password.
Account setup and sign-in rely on GDPR Article 6(1)(b) because they are needed to take the account step you request and, after you accept the Terms of Use, to operate your account. Service security and abuse prevention rely on GAMESLIKE's legitimate interests under GDPR Article 6(1)(f); legally required records rely on GDPR Article 6(1)(c) where applicable.
Agreeing to the Terms of Use and acknowledging this Privacy Policy are not treated as GDPR consent. Optional marketing emails always require their own choice. Optional analytics requires its own choice where we ask first and is otherwise on by default with an easy opt-out, as described below.
When Google or Steam confirms a new identity, GAMESLIKE creates a short-lived pending local account and session. Account features remain unavailable until the Terms of Use are accepted. Choosing Not now deletes that unfinished account and its local session.
Game catalog, price, review, recommendation, and metadata pages rely on Steam and other public game data. Recommendation interactions may be processed to operate the account and improve the product.
The public Play Together tool works without an account. Temporary rooms store your chosen nickname, three favourite game IDs, membership and votes. An essential room cookie keeps your browser connected to the room you join. Anyone holding an active invitation can join; members see nicknames, readiness, shared recommendations and votes, but not another member's favourite list or Steam library. Room access expires after 24 hours, and expired records are removed during subsequent room activity. Signing in can attach your participation to your account; using your Steam library is a separate choice. Deleting that account removes its room participation.
Play-together groups store opaque group membership, explicit game preferences, attendance, nominations, temporary votes and a confirmed choice in the account database. Group pages are private and no group IDs, invite tokens, game lists, playtime or preference details are sent to optional browser or account analytics. Leaving a group stops future access; it cannot recall information another participant already saw.
- Website delivery and security logs: IP address, request metadata, user agent, timestamps, and error events for operational and security purposes.
- Account data: email or provider account identifiers, sign-in metadata, consent timestamps, and account deletion requests.
- Steam sign-in: the verified Steam ID, sign-in metadata, and public display name retrieved from Steam's API. The display name is stored with your account and refreshed when you sign in through Steam.
- Steam library import: when you sign in with Steam, GAMESLIKE reads the games your Steam account owns and the games on its wishlist from Valve's Web API, and stores their Steam app IDs in your GAMESLIKE library together with the date they were read. For games you own it also stores your lifetime playtime, your playtime in the trailing two weeks, and how many of that game's achievements you have unlocked against how many exist. It does not store Steam's game names or artwork, individual achievement names or unlock times, purchase dates, prices paid, wishlist priorities, friends, or any review you have written. These lists and figures are only readable while the matching parts of your Steam profile are public. The import runs once for a new Steam account, and after that only when you choose Sync Steam library in Account; each sync replaces the stored playtime and achievement figures rather than keeping a history of them. Games you bookmarked on GAMESLIKE yourself are never changed by a sync. Deleting your account removes the imported library and these figures with it.
- Search and recommendations: queries, filters, selected game pages, and account preferences when a signed-in user chooses to save them.
- Play-together: group names, membership, invite digests with expiry, explicit Loved or Not for me choices, session attendance, nominations, ballot votes and chosen game IDs. These records are deleted by the relevant account or group cascade; closed session history is lazily removed after 90 days.
- Contact: email address, message content, and the metadata needed to respond.
Optional GamesLike Emails
Personal brief emails are a separate optional choice on the signed-in Brief page. Choose daily when there is something new, or weekly on Mondays, at 09:00 in your selected IANA time zone, and confirm the new request by email. Existing newsletter subscribers are not enrolled automatically. Mailwerk owns this schedule, consent and delivery. It keeps a bounded baseline of up to 100 wishlist release facts and 100 previously recommended game IDs to avoid repeated picks, plus delivery-period claims. The profile and baseline are removed on account deletion; limited pseudonymous period and send evidence follows the retention rules below. You can separately request a refresh of your public Steam wishlist and library for each brief. That choice starts off and stops when you turn off brief emails. Without it, picks use visibly dated stored snapshots. This choice does not grant permission to edit your Steam wishlist.
The optional GamesLike newsletter includes game news, recommendations and price drops, tailored to your saved games. Choose ‘Yes, sign me up’ and confirm your email to subscribe, or ‘Not now’ to continue without subscribing. You can also subscribe in Account → Email preferences. We use your existing delivery or account email and ask for one only if no usable address is available. This permission covers GamesLike only—not our other products, analytics or third-party advertising.
We process your email address, subscription choice, accepted wording and version, and request, confirmation and withdrawal times under GDPR Article 6(1)(a) and section 7 UWG. We use saved games to select relevant newsletter content, not for decisions with legal or similarly significant effects, and do not send your saved-game list to the email provider. Earlier category-specific permissions retain their original scope; we do not expand them automatically. Subscription does not guarantee a sending schedule or automated price-drop alerts.
We send a neutral confirmation email to verify your address. Its link expires after seven days and opens a confirmation page; opening the link alone does not subscribe you, and nothing is sent to you until you confirm there. We remove unconfirmed request records during routine cleanup after a further seven days; the delivery address remains in Mailwerk until the contact is erased, including when you delete your account. Failed or expired requests do not cancel existing confirmed subscriptions. If an unusable address is replaced, email to the old address stops until you confirm the new one.
These emails are prepared and sent by Mailwerk, our own email service. Mailwerk is operated by Burlis Management GmbH, the same company behind GamesLike, on the same Hetzner-hosted infrastructure in Germany; it is not a third-party service and your address is not passed to another controller. Mailwerk holds the permission record, the confirmation page and the unsubscribe page reached from every message, all served from api.mailwerk.io. Links in email we sent before this change still open on gameslike.co and hand the same request to Mailwerk. The GamesLike website itself no longer stores your subscription address.
Amazon Web Services is our email-delivery processor for these messages. We use Amazon Simple Email Service in the AWS Europe (Stockholm) region, eu-north-1. It receives the delivery address, the message content and technical delivery information, processed under the AWS Data Processing Addendum. We use a GamesLike-specific sending domain, an isolated sending tenant and a restricted credential limited to that domain. Your subscription status, unsubscribe choices and delivery restrictions are kept in GamesLike’s own Mailwerk service rather than in a shared provider contact list. Amazon Simple Email Service retains delivery, bounce and complaint events, and keeps a provider-side suppression record of addresses that bounced permanently or complained, so that unwanted delivery is not repeated. Marketing, confirmation and transactional emails do not use open pixels or tracked-link redirects. Routine cleanup removes delivery, bounce and complaint event records older than 720 days (about 24 months). Limited send records with an unresolved delivery outcome may be retained for investigation. Signup, account and confirmation pages are excluded from optional analytics and session replay.
Our contract is with Amazon Web Services EMEA SARL (Luxembourg); the AWS Data Processing Addendum includes Standard Contractual Clauses for transfers outside the EU/EEA. Amazon Simple Email Service is the only delivery route for these messages. Resend, Inc. is no longer a processor for them: that route and its rollback option were retired with this change. Confirmation messages Resend delivered before the move to Amazon Simple Email Service on September 18, 2026, and their delivery logs, age out under its published 30-day retention; it receives nothing further from us. See the provider DPA and subprocessor information below for current recipients and safeguards.
To unsubscribe, choose Unsubscribe in Account → Email preferences, or use the unsubscribe link in any email, which needs no sign-in and takes one click. You can cancel an unconfirmed signup in Email preferences too. Withdrawal stops future sending eligibility immediately and does not affect earlier lawful processing; an email already handed to the provider may still arrive. We remember your decision. Declining does not limit your account.
Active subscription data is kept while the permission applies. After withdrawal, we retain the minimum consent and withdrawal evidence needed to demonstrate compliance and defend legal claims under GDPR Article 6(1)(f). Account deletion erases the delivery address and contact properties; limited pseudonymous consent and send evidence may remain for those purposes. Contact us to exercise your rights concerning these records. Deleting your account erases your Mailwerk delivery address and contact properties, cancels anything scheduled for you, and removes the GamesLike record that you were asked. We retain a keyed, non-plaintext address suppression record for complaints or permanent bounces while email sending remains in use, to avoid repeated unwanted delivery; a new signup does not remove that protection. To prevent confirmation-email abuse, we count requests within the previous 24 hours using the request records retained for the periods above. Backup copies are restricted to recovery and must not be used to revive withdrawn permissions.
Sign-in Security
GAMESLIKE uses Cloudflare Turnstile to protect Google and Steam sign-in from automated abuse. The check runs invisibly when you choose a provider and processes technical browser and connection information to verify the request. This security check is separate from optional analytics and does not require accepting analytics.
Cloudflare processes this information under its Turnstile Privacy Addendum.
Public Steam Review Analysis
GAMESLIKE also calculates rough completion estimates locally from completed-run times mentioned in retained public English Steam reviews. We publish a median time and contributing review count only when at least ten distinct reviews supply usable reports, together with the calculation date. Steam's individual tracked playtime, copied review text, reviewer identifiers and individual review links are not published by this feature. Review text stays in the existing private source store and is not sent to a model provider for this calculation. Existing source-retention and objection/suppression rules apply; retained source removals and matched objections withdraw affected estimates before recalculation.
GAMESLIKE's current compact review-discussion analysis obtains recent public English user reviews from Steam's documented review endpoint and automatically summarizes recurring topics and opinions. Its public output is limited to aggregate topic and sentiment information, sample size, review-window date, last-updated date, and applied filters. It does not publish copied review text, recommendation IDs, Steam IDs, reviewer names, profiles, playtime, avatars, or individual review links.
A separate GamesLike Review pipeline has been implemented for local and synthetic validation. It is designed to create an AI-assisted English editorial synthesis from a sample of multilingual Steam reviews, with summaries of player opinions and changes over time. Real Steam review text is not currently submitted to OpenCode/Ox. Activation remains disabled until an applicable data-processing agreement and international-transfer terms are executed, including Standard Contractual Clauses where required, and subprocessor, retention, and training terms are confirmed.
If activated, OpenCode/Ox would act as a US-hosted processor for bounded review text, opaque per-run source identifiers, language, and source timestamps needed for multilingual aspect classification and editorial drafting. Steam recommendation direction would stay local. Raw review text would be restricted to the analysis process.
The current dedicated compact capture projects only the review text and the recommendation ID, game ID, language, review timestamps, and observation/capture timestamps needed for classification, deduplication, retention, and rights-request suppression. It does not persist Steam endpoint author, playtime, vote, engagement, purchase, or developer-response fields for compact aggregate analysis, and no profile or persona lookup is performed. Separately, GAMESLIKE's legacy general review ingestion for existing whole-review signals privately retains broader public Steam review fields, including review and author identifiers, review text, playtime, vote and engagement values, purchase/context flags, developer responses, and timestamps. Those broader fields do not enter the current compact aspect sentiment. Under the proposed GamesLike Review design, only bounded review text, opaque per-run source identifiers, language, and source timestamps would enter the processor payload; recommendation direction and raw recommendation identifiers would stay local.
Public GamesLike Review output would contain GamesLike's own paraphrases and aggregates only. It would not publish individual Steam review links, copied review text, recommendation IDs, reviewer names, avatars, profile summaries, playtime, visible Steam IDs, or source provenance. Public validators reject payloads containing those fields or unsupported claims. A game page may link to the game's general Steam review section, which does not identify any sampled reviewer.
This processing relies on GAMESLIKE's legitimate interest under GDPR Article 6(1)(f) in providing useful, auditable game-discovery information. The internal balancing assessment concluded that aggregate-only analysis is necessary for that purpose and has limited impact because the source reviews are public, the output cannot be traced to a reviewer, obvious contact information, directed allegations or abuse, and unsafe personal material are screened before processor transfer, source data is private and time-limited, and reviewers can object to GamesLike's use of their review. Affiliate relationships do not affect review selection, classification, or sentiment.
Steam is the source. Direct Article 14 notice to each of millions of pseudonymous reviewers is not provided because identifying and contacting each person would require disproportionate effort and GAMESLIKE does not collect contact details for this purpose. Under the dated Article 14(5)(b) assessment, this public notice is the compensating measure and explains the source, purpose, safeguards, retention, recipients, and rights.
Current private source data is available only to authorized GAMESLIKE operations and its Hetzner-hosted infrastructure. It is not shared with affiliate partners or optional analytics providers. If the GamesLike Review pipeline is activated, the bounded processor transfer described above will be added to this current recipient set only after the stated safeguards are confirmed. Public aggregate results are available to website visitors, search engines, and normal website-delivery providers such as Cloudflare, including where those providers process data outside the EEA under the safeguards described above.
For the current compact analysis, a review that remains observed can remain in the private rolling source set. It is deleted within 35 days after it is no longer observed; review-specific raw responses and stale source memberships follow the same limit. Current compact aggregate summaries expire after 35 days. If GamesLike Reviews are activated, a V2 payload and its classification provenance will expire with the snapshot and no later than 100 days after generation. Temporary processing queues will be deleted no later than seven days after a terminal run and, in all cases, no later than 30 days after creation. Expired public payloads fail closed. A canonical Steam source review may remain in the current private source set while the review remains observed and that processing path is active. A minimal suppression record containing the recommendation ID, game ID, bounded reason, and date can be retained while ingestion or analysis could select the review again, then is deleted within 35 days after that processing path is permanently disabled.
Before a proposed processor transfer, automated screening excludes detected contact details, directed allegations or abuse, and other obviously unsafe personal material from the model payload. Screening cannot guarantee that public review text contains no sensitive or third-party information. Public validators separately reject copied wording, identity fields, recommendation IDs, source links, provenance, and unsupported claims. The output is not used for decisions with legal or similarly significant effects. These safeguards must be revisited before any reviewer attribution, copied quotation, profile enrichment, or materially broader use.
To request access, correction, objection, or suppression of a Steam review from this analysis, send the public Steam review URL to legalnotice@paraspeech.com. GAMESLIKE uses the game and public profile identifiers transiently to locate exactly one private source record; ambiguous or unmatched requests stop without a change. A matched objection excludes the review from future GamesLike analysis and withdraws or recalculates an affected current draft. It does not remove the public source review from Steam. The submitted review URL and profile identifier are not retained in the suppression record or application logs.
Providers and Transfers
GAMESLIKE currently uses Cloudflare for edge delivery/security, Hetzner-hosted infrastructure for application hosting and account/catalog storage, Typesense for search, Google for Google sign-in, and Steam/Valve data for Steam sign-in and catalog data.
OpenCode/Ox is not currently a processor for live Steam review data. The proposed US-hosted processing described above remains disabled pending an executed data-processing agreement and confirmed international-transfer, subprocessor, retention, and training terms; this policy will be updated before activation if the confirmed arrangement differs.
Cloudflare Web Analytics is an optional processor for site-use and performance measurement. It loads only after analytics consent where we ask first, and by default elsewhere unless you object; see Optional Analytics and Affiliate Data.
PostHog, Inc. provides optional, EU-hosted product analytics, heatmaps, and masked session replay. Its browser code loads only after analytics consent where we ask first, and by default elsewhere unless you object, without browser person profiles or browser-to-account identity merging, or advertising profiles. Separately, our server sends anonymous site totals and store-link counts to PostHog as described below.
PostHog stores our product-analytics events in the EU. Service delivery and subprocessors can involve processing outside the EEA, including global edge-network transit. Its data-processing agreement provides EU-US Data Privacy Framework and Standard Contractual Clause safeguards where applicable. PostHog publishes its current subprocessors and processing locations at posthog.com/subprocessors.
Functional Software, Inc. d/b/a Sentry is our error-diagnostics processor under a signed data-processing agreement. Error events and private source maps are stored in Frankfurt, Germany, with backups in the EU. Some account, integration and organization metadata may be stored in the United States. The agreement provides EU-US Data Privacy Framework safeguards where applicable and Standard Contractual Clauses as a fallback.
Cloudflare processing can involve the United States. Its customer DPA uses the EU-US Data Privacy Framework where applicable and Standard Contractual Clauses as a fallback.
Google and Valve process their side of provider sign-in under their own privacy notices. The sign-in request and callback data needed to verify the identity pass between GAMESLIKE and the selected provider. Both providers may process data outside the EEA, including in the United States, and publish EU-US Data Privacy Framework commitments; Google also publishes Standard Contractual Clause coverage where required.
Retention
Operational logs are kept only as long as needed for security, debugging, and service reliability. Completed account data is kept while the account exists and is removed or anonymized after a valid deletion request unless legal retention duties require otherwise.
An unfinished account is deleted after it has been abandoned for more than 24 hours. Cleanup runs during normal account-session maintenance, so deletion occurs on the next maintenance pass after that point. Choosing Not now deletes it immediately.
Contact messages are kept while needed to handle the request and related follow-up. Deletion applies immediately to the live account database. Copies can remain in disaster-recovery backups until the relevant backup is overwritten or deleted under the infrastructure backup schedule; backups are not used for ordinary account access. Security logs may retain limited data for a short operational period.
Cloudflare keeps unsampled Web Analytics data for seven days, then retains aggregated data for up to six months in the dashboard.
PostHog analytics events remain stored until deleted by GAMESLIKE or under PostHog’s account-termination terms; this project does not currently have an automatic event-deletion schedule. Contact us to request deletion where records can be associated with you. This statement concerns unlinked browser events. Consented account events use a separate random subject for at most 180 days from acceptance; withdrawal, expiry or account deletion removes the local event ledger and queues verified remote erasure. A new acceptance after revocation or expiry starts a new unmerged subject. Minimal random-ID erasure records remain through the subject lifetime to detect late ingestion. Provider outages can delay remote deletion; unsuccessful deletion stays pending and is retried.
PostHog keeps session replays for 30 days and product-analytics events, including the anonymous server totals and store-link counts, for up to seven years, the fixed retention of our PostHog plan. Deleting a replay does not delete its analytics events.
Sentry retains individual error events for 90 days under our Team plan and deletes them after that retention period. Copies may remain in Sentry's backups, which are deleted 90 days after creation.
Optional Analytics and Affiliate Data
Where we ask first, Cloudflare Web Analytics and PostHog load only with Usage analytics consent, and Sentry browser diagnostics require separate Error reports consent. We ask first in the European Economic Area (including EU outermost regions and Åland), the United Kingdom, Guernsey, Jersey, the Isle of Man, Gibraltar, Switzerland and Canada, and whenever we cannot tell where you are. Accept all permits both; Reject all refuses both. There, device access relies on consent under section 25(1) TDDDG; subsequent personal-data processing relies on consent under GDPR Article 6(1)(a). Refusing analytics does not limit the site.
Elsewhere, Usage analytics and Error reports are on by default. This relies on our legitimate interest under GDPR Article 6(1)(f) in understanding how the site is used and fixing problems: which pages and features help people find games, where navigation breaks, and which errors occur. We use masked session replay, build no advertising profiles and do not link these browser events to accounts. We do not sell or share personal information for cross-context behavioral advertising. To keep this proportionate, PostHog keeps default-analytics events from about 20% of browsers, chosen at random by its browser identifier, and runs session replay for no more than 10% of browsers, and Sentry keeps about 25% of browser error reports; the rest are discarded in your browser before sending. Cloudflare measurement is not sampled. You can object to default analytics at any time under GDPR Article 21: use Cookie settings and select Reject all, or turn off an individual purpose. A Global Privacy Control or DNT: 1 signal from your browser counts as that objection. Your region comes from the country code Cloudflare derives from your connection; the check stores nothing. Account-linked analytics, marketing email and affiliate or advertising tracking always require consent, wherever you are.
Cloudflare measures page views, page and referrer information, country, browser, operating system, device, navigation timing, and Core Web Vitals. Cloudflare documents that Web Analytics does not use analytics cookies, local storage, or fingerprinting.
PostHog receives pageview and pageleave events, scroll depth, browser and device properties, and Core Web Vitals (CLS, FCP, LCP, and INP). We also send search outcomes and result-count/query-length categories, selected filters, selected game identifiers and positions, recommendation clicks, save attempts and results, sign-in prompts for saving, and clicks to game stores. These help us improve discovery, identify saving friction, and understand store interest; store clicks do not tell us whether a purchase occurred. PostHog custom search events do not include the words you type.
When Usage analytics is on, existing PostHog pageview and pageleave events can also include visible page time in broad intervals. We measure only foreground time on public pages, exclude samples below five seconds, and cap the highest interval at 30 minutes or more. Hidden time, private pages, time before analytics is on, and time after withdrawal or objection are excluded. DNT or Global Privacy Control suppresses these duration samples. This uses the existing browser analytics stream, without additional events, cookies or storage.
PostHog also receives limited browser diagnostics after analytics has initialized: the affected page category, a fixed error category, and whether the error came from a page error screen, browser error, or unhandled rejection. These diagnostic events do not include raw error messages, stack traces, rejection content, form values, or full page paths. This helps us find unreliable parts of the site; errors before initialization or when analytics is blocked are not covered.
Sentry provides error diagnostics. Browser reporting starts only once Error reports is on (after consent where we ask first, by default elsewhere); DNT or Global Privacy Control prevents reporting. Reports send exception types, fixed error descriptions and technical error codes, application and framework source-code locations, application version, page category, browser/operating-system category and runtime. Raw exception messages, form input, account identifiers, request bodies, cookies, query strings and browsing breadcrumbs are omitted. Session replay and performance tracing are disabled. Sentry's data scrubbing is enabled and IP addresses are excluded from stored error events. Sentry receives the network connection needed to deliver an error report; these safeguards do not make that connection anonymous.
Sentry server diagnostics report application failures for service reliability without browser identifiers or request content. Reports include fixed failure categories, technical error codes, source-code locations, the reporting mechanism, broad route or worker-job categories, HTTP method or response status where available, and a numeric error reference for matching a website error screen. This processing relies on GAMESLIKE's legitimate interest under GDPR Article 6(1)(f) in diagnosing failures and keeping the service reliable. Browser consent controls browser reporting; server operational diagnostics do not access your browser and are separate from optional browser analytics.
PostHog uses a pseudonymous browser identifier in a first-party cookie lasting up to 180 days from its last update. This lets us measure repeat visits, retention, and journeys from a traffic source through game discovery to a save or store click. Browser identifiers and replay are not merged with account identities. With current analytics consent (a regional default does not count) and a signed-in session, our server separately sends allowlisted discovery and feature-use events under a random account identifier, creating a PostHog person profile for activation and retention analysis. This includes the account creation method, return use, and whether you successfully save or import games. We do not send your name, email, Steam ID, Google account, library contents, browser history, or raw search text. Events sent with consent include its version and timestamp; default-basis browser events carry a legitimate-interest marker and sample rate instead. We do not create advertising profiles.
Traffic attribution includes the referring website origin and domain and campaign labels (UTM source, medium, campaign, content, and term). PostHog derives approximate location (country, region, and city) from the IP address of each event and then discards the address instead of storing it. Campaign labels are limited to 100 characters; values containing email or URL syntax are excluded. General analytics URL properties are stripped to origin and pathname; diagnostic URL and pathname properties are removed. We omit advertising click identifiers, search-engine search text, and raw search input. Campaign labels must not contain personal information.
PostHog measures clicks on links and buttons, repeated clicks, unresponsive clicks, and click positions for heatmaps. Automatic click events keep the visible text of the clicked link or button, structural element information and sanitized link destinations, excluding arbitrary attributes, form interactions, and account controls. Session replays show page content, layout, scrolling, and navigation to help us understand usability problems. Input values are masked; forms, editable controls, account details, and the consent panel are excluded. We do not record console output, network request contents, canvases, or cross-origin frames.
Use Cookie settings to change individual purposes or select Reject all at any time; this withdraws consent or records your objection. Turning off Usage analytics stops new PostHog events and replay and removes its analytics storage; turning off Error reports stops Sentry and optional PostHog error reports. For signed-in users, the server also revokes account analytics and queues erasure before confirming the preference; a failed save is shown with retry. Other signed-in devices reconcile the account preference on focus and every 30 seconds while visible. Signed-out choices apply to that browser and are reconciled with an account on the next sign-in. Requests already sent may finish. Withdrawal does not affect processing that occurred before it. Contact GAMESLIKE for an access or deletion request where provider data can be associated with you.
For PostHog access or deletion requests, the pseudonymous identifier in the PostHog cookie can help us locate records. Your account does not identify unlinked browser records. Signed-in users can export their separate account-linked analytics ledger from Account settings. The export identifies its scope and pagination; it is not an export of all product data. If you have already cleared that cookie, or for providers without a stable identifier, we may be unable to associate records with you.
Referral tracking is a separate, optional choice and is off by default in every region. Only a current acceptance lets a GameBoost store link pass through Impact before reaching the selected product. Impact receives the browser request, including your IP address and browser information, and can attribute qualifying purchases reported by GameBoost. The program uses a 30-day last-click attribution window. GamesLike passes the product URL, not your GamesLike account, email, name or Steam identifier. Earlier analytics acceptance does not grant referral consent. Rejecting or withdrawing referral consent, or sending Global Privacy Control or DNT: 1, uses the ordinary GameBoost product link instead. You can change the choice in Cookie settings. Impact and GameBoost apply their own privacy notices and storage controls on their sites: https://impact.com/privacy-policy/ and https://gameboost.com/legal/privacy.
Simple Analytics, Google Analytics, advertising tags and affiliate pixels are not loaded by the application. GamesLike does not install an Impact SDK or attribution cookie; the optional tracking occurs only when you follow a GameBoost store link with referral consent.
The store-click measurement above is separate from optional Impact referral attribution. Paid accounts, Mac apps, customer uploads, or materially broader analytics will be explained here before they launch. Optional GamesLike email choices are explained separately above.
Anonymous Request and Store-Link Counts
You can object at any time under GDPR Article 21 to the counts described in this section. Your browser’s DNT: 1 or Sec-GPC: 1 signal applies that objection automatically to the public page-request, referring-source, device, country, automated-request and outgoing store-request totals; it does not change the separate operational search counts described below. These totals hold no visitor identity, so an objection sent to legalnotice@paraspeech.com cannot be matched to your earlier or later requests; the browser signal is how it takes effect.
We count public page requests, search results and search speed on our server, including when analytics is declined. For page requests, we also count broad referring-source groups (such as Google or Reddit), device types and countries. The country comes from the two-letter code that Cloudflare, our edge delivery provider, derives from the connecting IP address; we record it only as one of 60 fixed countries, “other” or “unknown”. To keep automated traffic out of these totals, the server compares the user agent, client hints and language headers your browser already sends; requests from automated clients are counted separately by type, such as search engine, AI crawler, link preview or HTTP client. These headers are read in memory and discarded without forming an identifier. These are separate totals: we do not build a record of your visit or retain the underlying headers, IP address, search words, URL parameters or account identity in these counters. This limited processing serves our legitimate interest under GDPR Article 6(1)(f) in understanding demand and where it comes from, separating people from automated traffic, improving discovery and keeping search reliable.
Our server keeps these daily totals for 90 days and sends PostHog a summary of the last 30 days once an hour. Country totals are included only for completed UTC days. Only fixed categories and counts leave our server; no visitor identifier is sent and person profiles and PostHog’s IP geolocation are disabled. The summaries remain subject to PostHog’s separate project retention, not the 90-day local cleanup. These totals count requests rather than unique people. Automated requests are counted separately by type and prefetches not at all; disguised automation can remain in page counts, and search workload includes automated requests. Pages served entirely from a cache and failed delivery can leave gaps.
When you follow a price link to Steam, Gamesplanet, or Green Man Gaming, our server counts the outgoing store request regardless of whether you accepted, rejected, or have not answered the analytics notice, unless your browser sends DNT: 1 or Sec-GPC: 1. The same header check skips automated clients before counting. This measurement uses no analytics cookies, browser storage, visitor identifiers, fingerprinting, or account linkage. It does not load the PostHog browser SDK.
The server sends PostHog the game identifier, store, UTC day, and a random delivery identifier used only to avoid counting retries twice. A shared counter label replaces any visitor identifier. We do not send visitor IP addresses, browser details, session IDs, cookies, referring pages, or URL query strings. IP capture, geolocation enrichment, and person-profile processing are disabled for these events. PostHog receives the connection from our server, not from your browser.
These counts measure outgoing requests, not unique people, confirmed arrival at a store, purchases, or commission. Repeated visits and automated traffic can contribute to them; failed event delivery can leave gaps. Website hosting and security providers still process the network information needed to deliver the website, as described elsewhere in this policy. The anonymous counter does not make all website infrastructure IP-free. External stores and affiliate networks apply their own privacy policies after you leave GAMESLIKE.
Your Rights
You can request access, correction, deletion, restriction, portability, or objection where these rights apply. You can also withdraw consent for consent-based processing without affecting earlier lawful processing. You can object to default analytics at any time in Cookie settings, as described under Optional Analytics and Affiliate Data.
Send requests to legalnotice@paraspeech.com. You may also complain to a competent data protection supervisory authority. For North Rhine-Westphalia, this is the Landesbeauftragte fuer Datenschutz und Informationsfreiheit Nordrhein-Westfalen, poststelle@ldi.nrw.de.