PRIVACY NOTICE
Last updated: 2026-05-10
Who runs Choridy

Choridy is a hobby project run by Alexander Palosaari as a private individual (not a company). For privacy questions, contact palosaaritobias@gmail.com.

For the purposes of the EU General Data Protection Regulation (GDPR), Alexander Palosaari is the data controller for Choridy.

Age limit: 13+

Choridy is intended for people aged 13 and over. We ask you to confirm your age before you can pick a display name. We do not knowingly process the data of children under 13. If you believe someone under 13 has used the service, please contact us so we can delete their data.

What we collect
  • A pseudonymous device ID stored in a cookie (device_id) and used as your account identifier. This is generated locally — we do not ask for your email, phone number, or real name.
  • A display name you choose yourself. This is visible to other Choridy users on leaderboards and in crews. Don’t use your real name.
  • A recovery code you can use to restore your account on another device. We store an HMAC fingerprint of this code, not the code itself, after you have viewed it once.
  • Gameplay data: XP, streaks, completed daily tasks, crew membership, equipped cosmetics.
  • Server logs: temporary technical logs that may include your IP address, kept for up to 30 days for security and debugging.
Why we process your data
  • To provide the game — saving your progress, showing leaderboards, running crews. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
  • To keep the service working and secure — rate-limiting, server logs. Legal basis: legitimate interest (Art. 6(1)(f)).
Who we share your data with

We use the following processors. They process data on our behalf and under contract.

  • Microsoft Azure (EU regions) — hosting, database, container runtime, server logs.
  • GitHub — container image registry for deployment.

We do not sell your data, do not share it with advertisers, and do not transfer it outside the EU/EEA where avoidable.

How long we keep your data
  • Account data: until you delete your account.
  • Server logs: up to 30 days.
  • Database backups: up to 7 days (rolling).
Your rights

Under the GDPR you can:

  • Delete your account and data (right to erasure, Art. 17) — there’s a button in Settings, or email us.
  • Get a copy of your data (right of access, Art. 15 / portability, Art. 20) — email us and we’ll send a JSON export within 30 days.
  • Correct your data (Art. 16) — change your display name in Settings, or email us for other corrections.
  • Complain to a supervisory authority. In Finland that is the Data Protection Ombudsman: tietosuoja.fi.
Cookies
  • device_id (essential, 1 year): your pseudonymous account identifier. Without it the game can’t save your progress.
  • choridy.sid (essential, 24 hours): admin session, only set if you sign in to the admin panel.
Changes to this notice

If we change this notice in a meaningful way, we’ll show an in-app message before the change takes effect. The current version is always available at /privacy.