Privacy Policy

Last updated: August 21, 2026

This policy explains how Tools For Games (TFG) processes personal data. TFG does not sell personal data and does not use advertising, audience analytics, or profiling trackers.

Data controller

The data controller is Francis Maestri. For questions or requests concerning personal data, email contact@toolsfor.games or use the contact page.

Accounts and tool data

When you create an account, TFG processes your email address, display name, account identifier, password hash, security tokens, and authentication metadata. It also stores the data you choose to save in the BDO and E7 tools. Passwords themselves are not stored.

This processing is necessary to create and secure your account, authenticate you, and provide the saving and restoration features you request. Its legal basis is performance of the service requested by you (Article 6(1)(b) GDPR), with legitimate interests in preventing abuse and securing the service where applicable (Article 6(1)(f) GDPR).

The registration fields are required. Without them, TFG cannot create an account. Account and saved tool data are retained while your account exists, unless you delete particular tool data sooner or request complete deletion. Accounts whose email address is never confirmed are deleted after six months.

Contact messages and problem reports

TFG processes the email address or account identifier associated with your request, its subject or title, your message, the page address, browser user-agent, date, and processing status. These details are used to answer you and diagnose reported problems. The legal basis is taking steps at your request or performing the requested service (Article 6(1)(b) GDPR), and TFG's legitimate interest in support, security, and reliability (Article 6(1)(f) GDPR).

The email, subject, and message fields shown as required are necessary to process an anonymous contact request. Signed-in support uses the email attached to the account. Without the required information, TFG cannot receive or answer the request. Do not include passwords or sensitive personal information in free-text fields.

Support messages and problem reports are retained for up to 9 months.

Technical and security data

Web-server and application logs may contain an IP address, requested URL, date and time, user-agent, account identifier, and technical error information. Malformed-request diagnostics record the endpoint and error, but not the submitted JSON body. This data is processed for TFG's legitimate interests in operating, securing, debugging, and maintaining the service (Article 6(1)(f) GDPR).

Security and technical logs are retained for up to 9 months.

Cookies and browser storage

TFG uses only storage needed to provide requested features:

  • The authentication cookie keeps you signed in. A persistent sign-in can last up to 30 days.
  • The antiforgery cookie is a session cookie used to protect forms and requests.
  • The tfg-theme cookie remembers the selected visual theme for up to 365 days.
  • Local storage remembers dismissed welcome messages until you clear it in your browser.

These items are strictly functional and are not used for advertising, analytics, or cross-site tracking. They therefore do not require prior consent, and TFG does not display a consent banner. You can remove them through your browser; doing so may sign you out or reset interface preferences.

Recipients and service providers

Personal data is accessible to the publisher only when needed to operate TFG or answer a request, and to the technical providers required for their services:

  • Hetzner Online GmbH, for hosting in Germany and encrypted backups in Finland.
  • OVHcloud, for the TFG mailboxes and delivery of transactional and support email.

Data may also be disclosed where required by law. TFG does not sell or rent personal data. Website assets are served by TFG itself rather than a third-party browser CDN.

International transfers

TFG's server and backups are located in the European Economic Area. When an email is sent to an address whose provider operates outside the EEA, its delivery may necessarily route personal data to that provider under the safeguards applicable to the provider's service.

Retention

  • Account and saved tool data: while the account exists, or until earlier deletion.
  • Accounts whose email address is never confirmed: up to 6 months.
  • Contact messages and problem reports: up to 9 months.
  • Web, application, and malformed-request diagnostic logs: up to 9 months.
  • Authentication cookie: session-only, or up to 30 days when persistent sign-in is requested.
  • Theme cookie: up to 365 days; welcome state: until cleared in the browser.
  • Encrypted disaster-recovery backups: daily copies for 30 days, weekly copies for 12 weeks, and monthly copies for 12 months. Deleted production data can therefore remain isolated in a backup for up to 12 months and is not used for ordinary operations.

Your rights

Under the GDPR, you may request access to and rectification or deletion of your personal data, restriction of processing, and portability where applicable. You may object to processing based on legitimate interests. TFG does not rely on consent for the processing described above, so there is no consent to withdraw.

You can download your account details, contact messages, problem reports, and saved BDO data as JSON, or request complete account deletion, from account management. For another privacy request, email contact@toolsfor.games from your account address or use the contact page. A proportionate identity check may be requested. TFG will normally answer within one month. Data remaining only in disaster-recovery backups expires with the backup cycle and will not be restored to ordinary production use after a deletion request.

You may lodge a complaint with the French data protection authority (CNIL).

Automated decisions

TFG does not use personal data for automated decision-making or profiling.

Changes to this policy

This policy will be updated before introducing advertising, analytics, monetization, or another material change to personal-data processing. The date at the top identifies the current version.