Privacy policy
Last updated: October 1, 2026
1. Who is responsible
The controller within the meaning of the General Data Protection Regulation (GDPR) is: Sven Gerlach, Alpenrosenweg 64, 22523 Hamburg, Germany, email: hello@aigamecritic.com. See also our legal notice.
2. The short version
- No passwords: you log in with a one-time link we email you.
- No analytics or tracking tools. All fonts and icons are served from our own server.
- Game images are stored on our server, so visiting a game page does not contact Steam or GOG.
- We show ads through Google AdSense — only with your consent where required (see section 9).
- You can delete your account at any time in your account settings.
3. Hosting and server logs
This website is hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, on servers in Germany. When you visit the site, the web server processes: IP address, date and time, requested page, referrer URL, browser and operating system. This is technically necessary to deliver the website and to keep it secure (Art. 6 (1) (f) GDPR — legitimate interest in a secure, working website). Server log files are deleted after [NUMBER] days. We have concluded a data processing agreement with our host (Art. 28 GDPR).
4. Account and magic-link login
To comment, share takes, claim or submit a game you need an account. We process your email address, your chosen username, your role (member, developer), the time of your last login and the number of your approved posts. We send you login and confirmation links by email; each link can be used once and expires after 30 minutes (submission confirmations: 3 days). Legal basis: Art. 6 (1) (b) GDPR (providing the service you signed up for). We keep your data until you delete your account. Unused login links are deleted regularly.
Sign in through Steam: if you use it, Steam (Valve Corporation, USA) confirms your Steam account to us; you enter your Steam password only on Steam's own website, and Valve's privacy policy applies there. We receive and store your public Steam ID. If our Steam Web API access is set up, our server also reads your public persona name (as a username suggestion) and — if your Steam game details are public — the list of games you own with their playtime. We store this list and refresh it at most once a day; when you comment on a game, the playtime of that game is saved with the comment and shown next to it (e.g. “Played 12 h on Steam”). If we know the achievement that marks a game's ending, we also check whether your public profile has it and show “Finished it” next to your comment. You can disconnect Steam in your account at any time; we then delete your Steam ID and game list. Legal basis: Art. 6 (1) (b) GDPR.
5. Game submissions and developer accounts
If you submit a game, we process the information you provide (texts, images, links, AI disclosure, behind-the-scenes story) and your email address. We check whether your email domain matches the game's website to award the “Verified dev” badge. The game information is published on the website after our review. Legal basis: Art. 6 (1) (b) GDPR. If you delete your account, the game page stays online without your name; ask us if you want it removed completely.
Insert Coin builds: if you post a playtest build, we process the same kind of information (title, short texts, link, version, screenshot, AI disclosure) plus your email address, which we use for your developer account and for a short digest email when testers send you feedback. Our server opens the link of each live build about once a day to check that it still exists; this request does not contain personal data. If you delete your account, your builds are taken offline. Legal basis: Art. 6 (1) (b) GDPR.
6. Comments, takes and ratings
Comments and takes are published with your username and the date. If you share an external link, our server fetches the public preview of that page (for X posts through X's official oEmbed service) so you can use it as a summary; this request comes from our server, not your browser, and does not transmit your data. Your first posts are reviewed manually before publication.
Keeping comments human: while you write a comment, our own script counts keystrokes and the length of pasted text, and the form notes when it was opened. These numbers are sent with the comment and are only used to decide whether a person should check it before it is published; we store at most a short reason (e.g. “posted 2s after opening the page”), never the numbers or your keystrokes themselves. If you tick “translated with AI” or “written with AI”, this note is published with your comment. Each username gets a small pixel avatar that is calculated from the name — no image is uploaded or loaded from elsewhere.
Playtest feedback (Insert Coin): feedback answers are stored with your username, the build version and the date. They are not published: only the developer of the build and we can read them. If you report a bug, the same applies to your description and up to two screenshots; the screenshots are stored outside the public website and can only be opened by the developer, by us and by you. Please do not include personal data in screenshots. The number of feedback answers a build received is shown publicly. The developer can additionally show up to three answers to “What was fun?” on the build page — anonymously, only with the build version, never with your username. The developer can delete feedback; its content and screenshots are then erased. The developer can mark your feedback as helpful; after several helpful marks your username shows a “Playtester” badge to developers. If you delete your account, your feedback is deleted. Reactions on builds work like ratings (keyed hash of the agc_voter cookie, and for visitors without an account a keyed hash of the IP address combined with the build). Builds themselves run on external platforms; when you open one, that platform's privacy policy applies. Legal basis: Art. 6 (1) (b) and (f) GDPR.
You can rate games without an account. To prevent the same person from rating many times, we store a random ID in a cookie (“agc_voter”, 12 months) and keep only a keyed hash of it together with your rating. To stop abuse (spam, rating floods) we store keyed hashes of IP addresses for up to 24 hours (rate limiting). Together with each rating we store a keyed hash of your IP address combined with the game, so that each network can submit only one anonymous rating per game; this value cannot be reversed and cannot be linked across games. We never store your IP address in plain text. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in fair ratings and protection against abuse); the cookie is strictly necessary for the rating function you use (§ 25 (2) no. 2 TDDDG).
7. Reports
If you report content, we process your report, your email address and the reported content to handle the report and to inform you of our decision, as required by the Digital Services Act (Art. 6 (1) (c) and (f) GDPR). We keep reports for up to 12 months after they are closed.
8. Cookies
- agc — session cookie that keeps you logged in and protects forms against forgery (up to 30 days). Strictly necessary.
- agc_voter — see section 6. Strictly necessary for ratings.
- Your sound preference for the rating button is stored in your browser's local storage and never sent to us.
- Advertising cookies from Google — only with your consent, see section 9.
9. Advertising with Google AdSense
We use Google AdSense, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), to show ads. Google uses cookies and similar technologies to show ads, measure them and — if you agree — personalise them. For this, data such as your IP address, device information and your interactions with ads may be processed and transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework. Before any of this happens, we ask for your consent through Google's certified consent tool (legal basis: Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). You can change or withdraw your consent at any time via the “Privacy settings” link at the bottom of every page. More information: policies.google.com/technologies/ads and Google's privacy policy.
10. Store data (Steam and GOG)
Game data and review scores are loaded by our server from the public interfaces of Steam (Valve Corporation) and GOG (GOG sp. z o.o.). No data about you is transmitted. When you click a store link, you leave our website and the privacy policy of that store applies.
11. Emails
We send emails through the mail server of our host (see section 3). We only send emails you triggered (login links, confirmations, decisions on your submissions, claims or reports). No newsletter.
12. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7 (3)). Just email us. You also have the right to lodge a complaint with a data protection supervisory authority, for example the one responsible for us: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit der Freien und Hansestadt Hamburg, Herr Thomas Fuchs Kontakt: Ludwig-Erhard-Str 22, 7. OG.
13. Security
This website uses TLS encryption. Login links are stored only as cryptographic hashes.