Legal
Privacy Policy
Last updated: September 18, 2026
Learn how GAMESLIKE handles website, account, Steam sign-in, Google sign-in, and optional analytics data, plus your privacy choices and rights.
Controller
Burlis Management GmbH, Philippstraße 27, 52349 Düren, Germany
Contact: legalnotice@paraspeech.com
Current Processing
GAMESLIKE processes request data to deliver the website, protect the service, operate accounts, support Steam sign-in, show recommendations, and answer messages sent to the contact address.
Account and authentication data is stored by GAMESLIKE on its Hetzner-hosted infrastructure. Steam sign-in uses the verified Steam account identifier and public display name; Google sign-in uses the basic profile data returned by Google to create and access the account. GAMESLIKE never asks for a Steam or Google password.
Account setup and sign-in rely on GDPR Article 6(1)(b) because they are needed to take the account step you request and, after you accept the Terms of Use, to operate your account. Service security and abuse prevention rely on GAMESLIKE's legitimate interests under GDPR Article 6(1)(f); legally required records rely on GDPR Article 6(1)(c) where applicable.
Agreeing to the Terms of Use and acknowledging this Privacy Policy are not treated as GDPR consent. Optional analytics and optional marketing emails each require their own choice as described below.
When Google or Steam confirms a new identity, GAMESLIKE creates a short-lived pending local account and session. Account features remain unavailable until the Terms of Use are accepted. Choosing Not now deletes that unfinished account and its local session.
Game catalog, price, review, recommendation, and metadata pages rely on Steam and other public game data. Recommendation interactions may be processed to operate the account and improve the product.
- Website delivery and security logs: IP address, request metadata, user agent, timestamps, and error events for operational and security purposes.
- Account data: email or provider account identifiers, sign-in metadata, consent timestamps, and account deletion requests.
- Steam sign-in: the verified Steam ID, sign-in metadata, and public display name retrieved from Steam's API. The display name is stored with your account and refreshed when you sign in through Steam.
- Steam library import: when you sign in with Steam, GAMESLIKE reads the games your Steam account owns and the games on its wishlist from Valve's Web API, and stores their Steam app IDs in your GAMESLIKE library together with the date they were read. For games you own it also stores your lifetime playtime, your playtime in the trailing two weeks, and how many of that game's achievements you have unlocked against how many exist. It does not store Steam's game names or artwork, individual achievement names or unlock times, purchase dates, prices paid, wishlist priorities, friends, or any review you have written. These lists and figures are only readable while the matching parts of your Steam profile are public. The import runs once for a new Steam account, and after that only when you choose Sync Steam library in Account; each sync replaces the stored playtime and achievement figures rather than keeping a history of them. Games you bookmarked on GAMESLIKE yourself are never changed by a sync. Deleting your account removes the imported library and these figures with it.
- Search and recommendations: queries, filters, selected game pages, and account preferences when a signed-in user chooses to save them.
- Contact: email address, message content, and the metadata needed to respond.
Optional GamesLike Emails
The optional GamesLike newsletter includes game news, recommendations and price drops, tailored to your saved games. Choose ‘Yes, sign me up’ and confirm your email to subscribe, or ‘Not now’ to continue without subscribing. You can also subscribe in Account → Email preferences. We use your existing delivery or account email and ask for one only if no usable address is available. This permission covers GamesLike only—not our other products, analytics or third-party advertising.
We process your email address, subscription choice, accepted wording and version, and request, confirmation and withdrawal times under GDPR Article 6(1)(a) and section 7 UWG. We use saved games to select relevant newsletter content, not for decisions with legal or similarly significant effects, and do not send your saved-game list to the email provider. Earlier category-specific permissions retain their original scope; we do not expand them automatically. Subscription does not guarantee a sending schedule or automated price-drop alerts.
We send a neutral confirmation email to verify your address. Its link expires after 24 hours; opening it alone does not subscribe you. Unconfirmed addresses and links are removed within seven days, with an hourly cleanup window. Failed or expired requests do not cancel existing confirmed subscriptions. If an unusable address is replaced, email to the old address stops until you confirm the new one.
Amazon Web Services is our email-delivery processor for these messages. We use Amazon Simple Email Service in the AWS Europe (Stockholm) region, eu-north-1. It receives the delivery address, the message content and technical delivery information, processed under the AWS Data Processing Addendum. We use a GamesLike-specific sending domain, an isolated sending tenant and a restricted credential limited to that domain. Your subscription status, unsubscribe choices and delivery restrictions are kept in GamesLike rather than in a shared provider contact list. Amazon Simple Email Service retains delivery, bounce and complaint events, and keeps a provider-side suppression record of addresses that bounced permanently or complained, so that unwanted delivery is not repeated. Email open and click tracking are disabled, and signup, account and confirmation pages are excluded from optional analytics and session replay.
Our contract is with Amazon Web Services EMEA SARL (Luxembourg); the AWS Data Processing Addendum includes Standard Contractual Clauses for transfers outside the EU/EEA. Resend, Inc. remains a processor for a bounded period: for confirmation messages sent before this change, for their delivery feedback, and as the delivery route we would return to if we had to reverse the change. Resend's data-processing agreement forms part of its service terms and includes Standard Contractual Clauses for relevant transfers; Resend states that primary processing is in the United States, and on our Pro plan provider email content and logs are retained for 30 days. We will remove Resend from this notice when that route is retired. See each provider's DPA and subprocessor information below for current recipients and safeguards.
To unsubscribe, choose Unsubscribe in Account → Email preferences, or use the unsubscribe link in any email without signing in. You can cancel an unconfirmed signup in Email preferences too. Withdrawal stops future sending eligibility immediately and does not affect earlier lawful processing; an email already handed to the provider may still arrive. We remember your decision. Declining does not limit your account.
Active subscription data is kept while the permission applies. After withdrawal, minimum consent evidence is kept for up to three years to demonstrate compliance and defend legal claims under GDPR Article 6(1)(f), and is removed when you delete your account. Account deletion also removes your email preferences and grants. We retain a keyed, non-plaintext address suppression record for complaints or permanent bounces while email sending remains in use, to avoid repeated unwanted delivery; a new signup does not remove that protection. To prevent confirmation-email abuse, we count requests within the previous 24 hours using the request records retained for the periods above. Backup copies are restricted to recovery and must not be used to revive withdrawn permissions.
Sign-in Security
GAMESLIKE uses Cloudflare Turnstile to protect Google and Steam sign-in from automated abuse. The check runs invisibly when you choose a provider and processes technical browser and connection information to verify the request. This security check is separate from optional analytics and does not require accepting analytics.
Cloudflare processes this information under its Turnstile Privacy Addendum.
Public Steam Review Analysis
GAMESLIKE's current compact review-discussion analysis obtains recent public English user reviews from Steam's documented review endpoint and automatically summarizes recurring topics and opinions. Its public output is limited to aggregate topic and sentiment information, sample size, review-window date, last-updated date, and applied filters. It does not publish copied review text, recommendation IDs, Steam IDs, reviewer names, profiles, playtime, avatars, or individual review links.
A separate GamesLike Review pipeline has been implemented for local and synthetic validation. It is designed to create an AI-assisted English editorial synthesis from a sample of multilingual Steam reviews, with summaries of player opinions and changes over time. Real Steam review text is not currently submitted to OpenCode/Ox. Activation remains disabled until an applicable data-processing agreement and international-transfer terms are executed, including Standard Contractual Clauses where required, and subprocessor, retention, and training terms are confirmed.
If activated, OpenCode/Ox would act as a US-hosted processor for bounded review text, opaque per-run source identifiers, language, and source timestamps needed for multilingual aspect classification and editorial drafting. Steam recommendation direction would stay local. Raw review text would be restricted to the analysis process.
The current dedicated compact capture projects only the review text and the recommendation ID, game ID, language, review timestamps, and observation/capture timestamps needed for classification, deduplication, retention, and rights-request suppression. It does not persist Steam endpoint author, playtime, vote, engagement, purchase, or developer-response fields for compact aggregate analysis, and no profile or persona lookup is performed. Separately, GAMESLIKE's legacy general review ingestion for existing whole-review signals privately retains broader public Steam review fields, including review and author identifiers, review text, playtime, vote and engagement values, purchase/context flags, developer responses, and timestamps. Those broader fields do not enter the current compact aspect sentiment. Under the proposed GamesLike Review design, only bounded review text, opaque per-run source identifiers, language, and source timestamps would enter the processor payload; recommendation direction and raw recommendation identifiers would stay local.
Public GamesLike Review output would contain GamesLike's own paraphrases and aggregates only. It would not publish individual Steam review links, copied review text, recommendation IDs, reviewer names, avatars, profile summaries, playtime, visible Steam IDs, or source provenance. Public validators reject payloads containing those fields or unsupported claims. A game page may link to the game's general Steam review section, which does not identify any sampled reviewer.
This processing relies on GAMESLIKE's legitimate interest under GDPR Article 6(1)(f) in providing useful, auditable game-discovery information. The internal balancing assessment concluded that aggregate-only analysis is necessary for that purpose and has limited impact because the source reviews are public, the output cannot be traced to a reviewer, obvious contact information, directed allegations or abuse, and unsafe personal material are screened before processor transfer, source data is private and time-limited, and reviewers can object to GamesLike's use of their review. Affiliate relationships do not affect review selection, classification, or sentiment.
Steam is the source. Direct Article 14 notice to each of millions of pseudonymous reviewers is not provided because identifying and contacting each person would require disproportionate effort and GAMESLIKE does not collect contact details for this purpose. Under the dated Article 14(5)(b) assessment, this public notice is the compensating measure and explains the source, purpose, safeguards, retention, recipients, and rights.
Current private source data is available only to authorized GAMESLIKE operations and its Hetzner-hosted infrastructure. It is not shared with affiliate partners or optional analytics providers. If the GamesLike Review pipeline is activated, the bounded processor transfer described above will be added to this current recipient set only after the stated safeguards are confirmed. Public aggregate results are available to website visitors, search engines, and normal website-delivery providers such as Cloudflare, including where those providers process data outside the EEA under the safeguards described above.
For the current compact analysis, a review that remains observed can remain in the private rolling source set. It is deleted within 35 days after it is no longer observed; review-specific raw responses and stale source memberships follow the same limit. Current compact aggregate summaries expire after 35 days. If GamesLike Reviews are activated, a V2 payload and its classification provenance will expire with the snapshot and no later than 100 days after generation. Temporary processing queues will be deleted no later than seven days after a terminal run and, in all cases, no later than 30 days after creation. Expired public payloads fail closed. A canonical Steam source review may remain in the current private source set while the review remains observed and that processing path is active. A minimal suppression record containing the recommendation ID, game ID, bounded reason, and date can be retained while ingestion or analysis could select the review again, then is deleted within 35 days after that processing path is permanently disabled.
Before a proposed processor transfer, automated screening excludes detected contact details, directed allegations or abuse, and other obviously unsafe personal material from the model payload. Screening cannot guarantee that public review text contains no sensitive or third-party information. Public validators separately reject copied wording, identity fields, recommendation IDs, source links, provenance, and unsupported claims. The output is not used for decisions with legal or similarly significant effects. These safeguards must be revisited before any reviewer attribution, copied quotation, profile enrichment, or materially broader use.
To request access, correction, objection, or suppression of a Steam review from this analysis, send the public Steam review URL to legalnotice@paraspeech.com. GAMESLIKE uses the game and public profile identifiers transiently to locate exactly one private source record; ambiguous or unmatched requests stop without a change. A matched objection excludes the review from future GamesLike analysis and withdraws or recalculates an affected current draft. It does not remove the public source review from Steam. The submitted review URL and profile identifier are not retained in the suppression record or application logs.
Providers and Transfers
GAMESLIKE currently uses Cloudflare for edge delivery/security, Hetzner-hosted infrastructure for application hosting and account/catalog storage, Typesense for search, Google for Google sign-in, and Steam/Valve data for Steam sign-in and catalog data.
OpenCode/Ox is not currently a processor for live Steam review data. The proposed US-hosted processing described above remains disabled pending an executed data-processing agreement and confirmed international-transfer, subprocessor, retention, and training terms; this policy will be updated before activation if the confirmed arrangement differs.
Cloudflare Web Analytics and Ahrefs Web Analytics are optional processors for site-use, interaction, and performance measurement. They load only after analytics consent.
PostHog, Inc. provides optional, EU-hosted product analytics, heatmaps, and masked session replay. Its browser code loads only after analytics consent, without person profiles, account linkage, or advertising profiles. Separately, our server sends anonymous store-link counts to PostHog as described below.
PostHog stores our product-analytics events in the EU. Service delivery and subprocessors can involve processing outside the EEA, including global edge-network transit. Its data-processing agreement provides EU-US Data Privacy Framework and Standard Contractual Clause safeguards where applicable. PostHog publishes its current subprocessors and processing locations at posthog.com/subprocessors.
Functional Software, Inc. d/b/a Sentry is our error-diagnostics processor under a signed data-processing agreement. Error events and private source maps are stored in Frankfurt, Germany, with backups in the EU. Some account, integration and organization metadata may be stored in the United States. The agreement provides EU-US Data Privacy Framework safeguards where applicable and Standard Contractual Clauses as a fallback.
Cloudflare processing can involve the United States. Its customer DPA uses the EU-US Data Privacy Framework where applicable and Standard Contractual Clauses as a fallback.
Ahrefs Pte. Ltd. processes analytics data in Singapore and through its published subprocessors under an executed data-processing agreement and Standard Contractual Clauses. Singapore does not have an EU adequacy decision.
Google and Valve process their side of provider sign-in under their own privacy notices. The sign-in request and callback data needed to verify the identity pass between GAMESLIKE and the selected provider. Both providers may process data outside the EEA, including in the United States, and publish EU-US Data Privacy Framework commitments; Google also publishes Standard Contractual Clause coverage where required.
Retention
Operational logs are kept only as long as needed for security, debugging, and service reliability. Completed account data is kept while the account exists and is removed or anonymized after a valid deletion request unless legal retention duties require otherwise.
An unfinished account is deleted after it has been abandoned for more than 24 hours. Cleanup runs during normal account-session maintenance, so deletion occurs on the next maintenance pass after that point. Choosing Not now deletes it immediately.
Contact messages are kept while needed to handle the request and related follow-up. Deletion applies immediately to the live account database. Copies can remain in disaster-recovery backups until the relevant backup is overwritten or deleted under the infrastructure backup schedule; backups are not used for ordinary account access. Security logs may retain limited data for a short operational period.
Cloudflare keeps unsampled Web Analytics data for seven days, then retains aggregated data for up to six months in the dashboard.
Ahrefs discards raw IP addresses and deletes the salt used for its daily IP-and-user-agent visitor hash every 24 hours. Customer analytics history can remain for the agreement term, operational logs for servers handling customer data are limited to one month, and customer personal data is deleted or returned after service termination. Ahrefs publishes no fixed deletion period for non-personal, de-identified, or aggregated derivative outputs used under its Terms.
PostHog analytics events remain stored until deleted by GAMESLIKE or under PostHog’s account-termination terms; this project does not currently have an automatic event-deletion schedule. Contact us to request deletion where records can be associated with you. GAMESLIKE does not create PostHog person profiles or store an account identifier in PostHog.
PostHog session replay retention is set to 30 days. This recording limit is separate from product-analytics event retention and does not delete the associated analytics events.
Sentry retains individual error events for 90 days under our Team plan and deletes them after that retention period. Copies may remain in Sentry's backups, which are deleted 90 days after creation.
Optional Analytics and Affiliate Data
Cloudflare Web Analytics, Ahrefs Web Analytics, PostHog, and Sentry browser diagnostics load only after you select Accept analytics. Device access relies on consent under section 25(1) TDDDG; subsequent personal-data processing relies on consent under GDPR Article 6(1)(a). Refusing analytics does not limit the site.
Cloudflare measures page views, page and referrer information, country, browser, operating system, device, navigation timing, and Core Web Vitals. Cloudflare documents that Web Analytics does not use analytics cookies, local storage, or fingerprinting.
Ahrefs receives page and origin-only referrer data, browser and device data, approximate location, interaction data, and diagnostics. GAMESLIKE sends pageview locations without query strings or fragments. Automatic interaction events can include complete clicked-link destinations and submitted-form actions, including parameters already present in those targets.
The deployed Ahrefs configuration does not send form controls or values, custom properties, account IDs, or GAMESLIKE user IDs. Ahrefs uses a daily salted IP-and-user-agent hash and may use non-personal, de-identified, or aggregated outputs under its Terms.
PostHog receives pageview and pageleave events, scroll depth, browser and device properties, and Core Web Vitals (CLS, FCP, LCP, and INP). We also send search outcomes and result-count/query-length categories, selected filters, selected game identifiers and positions, recommendation clicks, save attempts and results, sign-in prompts for saving, and clicks to game stores. These help us improve discovery, identify saving friction, and understand store interest; store clicks do not tell us whether a purchase occurred. PostHog custom search events do not include the words you type.
PostHog also receives limited browser diagnostics after analytics has initialized: the affected page category, a fixed error category, and whether the error came from a page error screen, browser error, or unhandled rejection. These diagnostic events do not include raw error messages, stack traces, rejection content, form values, or full page paths. This helps us find unreliable parts of the site; errors before initialization or when analytics is blocked are not covered.
Sentry provides error diagnostics. Browser reporting starts only after analytics consent and sends exception types, fixed error descriptions and technical error codes, application and framework source-code locations, application version, page category, browser/operating-system category and runtime. Raw exception messages, form input, account identifiers, request bodies, cookies, query strings and browsing breadcrumbs are omitted. Session replay and performance tracing are disabled. Sentry's data scrubbing is enabled and IP addresses are excluded from stored error events. Sentry receives the network connection needed to deliver an error report; these safeguards do not make that connection anonymous.
Sentry server diagnostics report application failures for service reliability without browser identifiers or request content. Reports include fixed failure categories, technical error codes, source-code locations, the reporting mechanism, broad route or worker-job categories, HTTP method or response status where available, and a numeric error reference for matching a website error screen. This processing relies on GAMESLIKE's legitimate interest under GDPR Article 6(1)(f) in diagnosing failures and keeping the service reliable. Browser consent controls browser reporting; server operational diagnostics do not access your browser and are separate from optional browser analytics.
PostHog uses a pseudonymous browser identifier in a first-party cookie lasting up to 180 days from its last update. This lets us measure repeat visits, retention, and journeys from a traffic source through game discovery to a save or store click. The identifier is not linked to your account. Events include the version and timestamp of your analytics acceptance. We do not create PostHog person profiles or advertising profiles.
Traffic attribution includes the referring website origin and domain and campaign labels (UTM source, medium, campaign, content, and term). Campaign labels are limited to 100 characters; values containing email or URL syntax are excluded. General analytics URL properties are stripped to origin and pathname; diagnostic URL and pathname properties are removed. We omit advertising click identifiers, search-engine search text, and raw search input. Campaign labels must not contain personal information.
PostHog measures clicks on links and buttons, repeated clicks, unresponsive clicks, and click positions for heatmaps. Automatic click events retain structural element information and sanitized link destinations, excluding element text, arbitrary attributes, form interactions, and account controls. Masked session replays show layout, scrolling, and navigation to help us understand usability problems. Replay text and input values are masked; forms, editable controls, account details, and the consent panel are excluded. We do not record console output, network request contents, canvases, or cross-origin frames.
Use Cookie settings to reject analytics or withdraw consent at any time. Withdrawal stops new browser PostHog and Sentry events and replay capture, removes PostHog's analytics storage, and reloads the page to stop the other optional providers. Requests already sent may finish. Withdrawal does not affect processing that occurred before it. Contact GAMESLIKE for an access or deletion request where provider data can be associated with you.
For PostHog access or deletion requests, the pseudonymous identifier in the PostHog cookie can help us locate records. Your account email alone cannot identify them because we do not link analytics to accounts. If you have already cleared that cookie, or for providers without a stable identifier, we may be unable to associate records with you.
Simple Analytics, Google Analytics, advertising tags, affiliate pixels, and affiliate attribution cookies are not loaded by the application.
The consented store-click measurement above is separate from third-party affiliate pixels and attribution cookies, which the application does not load. Paid accounts, Mac apps, customer uploads, or materially broader analytics will be explained here before they launch. Optional GamesLike email choices are explained separately above.
Anonymous Store-Link Counts
When you follow a price link to Steam, Gamesplanet, or Green Man Gaming, our server counts the outgoing store request regardless of whether you accepted, rejected, or have not answered the analytics notice. This measurement uses no analytics cookies, browser storage, visitor identifiers, fingerprinting, or account linkage. It does not load the PostHog browser SDK.
The server sends PostHog the game identifier, store, UTC day, and a random delivery identifier used only to avoid counting retries twice. A shared counter label replaces any visitor identifier. We do not send visitor IP addresses, browser details, session IDs, cookies, referring pages, or URL query strings. IP capture, geolocation enrichment, and person-profile processing are disabled for these events. PostHog receives the connection from our server, not from your browser.
These counts measure outgoing requests, not unique people, confirmed arrival at a store, purchases, or commission. Repeated visits and automated traffic can contribute to them; failed event delivery can leave gaps. Website hosting and security providers still process the network information needed to deliver the website, as described elsewhere in this policy. The anonymous counter does not make all website infrastructure IP-free. External stores and affiliate networks apply their own privacy policies after you leave GAMESLIKE.
Your Rights
You can request access, correction, deletion, restriction, portability, or objection where these rights apply. You can also withdraw consent for consent-based processing without affecting earlier lawful processing.
Send requests to legalnotice@paraspeech.com. You may also complain to a competent data protection supervisory authority. For North Rhine-Westphalia, this is the Landesbeauftragte fuer Datenschutz und Informationsfreiheit Nordrhein-Westfalen, poststelle@ldi.nrw.de.