AltiGamesAltiGames
Jouer
Nos jeuxPourquoiFAQContact
Jouer

Legal document

Privacy Policy

Last updated: 2026-05-14

How AltiGames collects, uses and protects your personal data.

This policy applies to all AltiGames Games (mobile and web) and complies with the EU General Data Protection Regulation ("GDPR", regulation EU 2016/679) and the French Data Protection Act no. 78-17 of 6 January 1978 as amended.

Some Games may add an annex specifying the specific data they collect in addition to the elements described here. In case of conflict, the Game-specific annex prevails for what it governs.

Get in touch
  • Legalcontact@altigames.fr
  • Privacycontact@altigames.fr
  • Supportcontact@altigames.fr

1. Definitions

Under the GDPR: "Personal data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on personal data. "Controller" means the entity that determines the purposes and means of the processing (here, AltiGames). "Processor" means the entity that processes data on behalf of the Controller. "Profiling" means any automated processing to evaluate certain personal aspects. "Data subject" means the Player whose data is processed.

2. Data Controller

AltiGames

contact@altigames.fr

3. Categories of data processed

Identification and authentication data: unique identifier (UUID), display name, email for full Accounts, password stored as Argon2id hash, Apple/Google social sign-in identifiers as opaque tokens ("sub"). Session data: HS256-signed JWT, refresh token, device identifier for silent re-login in guest mode.

Usage and gameplay data: game history, tiles placed, scores, duration, opponents, aggregated statistics, ELO ranking where applicable, preferences (theme, light/dark mode, dictionary options), friendship links and player invites. Technical data: app version, OS version, device model, language, time zone, error identifiers (Firebase Crashlytics), push notification token (FCM).

Transaction data (only in case of purchase): Platform transaction ID, type of offer, currency, date, status. No payment card data is processed by the Publisher. Reporting and moderation data (where applicable): reported content, reason, date, decision. Each Game may detail additional categories in its annex.

4. Purposes and legal bases

Service delivery (Account creation and maintenance, authentication, progression backup, cross-device sync, multiplayer features): legal basis = performance of the contract (article 6.1.b GDPR). Security and anti-fraud (bot detection, anti-cheat, chargeback prevention, access audit): legal basis = legitimate interest (article 6.1.f GDPR).

Service improvement (anonymous usage analytics via Firebase Analytics, bug detection via Firebase Crashlytics, satisfaction measurement): legal basis = legitimate interest, with right to object in the app settings. Essential communication (turn notifications, password reset emails, purchase confirmation): legal basis = performance of the contract and legal obligation.

Legal and tax compliance (retention of transaction data, response to judicial requests, anti-fraud): legal basis = legal obligation (article 6.1.c GDPR). Optional push notifications (challenges, editorial events, news): legal basis = consent (article 6.1.a GDPR), revocable at any time in system or application settings.

5. Profiling and automated decisions

The Publisher does not implement any fully automated decision producing legal effects on the Player or affecting them significantly within the meaning of article 22 of the GDPR. ELO rankings, matchmaking or Game recommendations are purely contextual automated processings with no substantial legal or material impact.

Any automatic sanctions (temporary block following automatic detection of cheating or abusive behaviour) are always subject to human appeal: the Player may contest the decision by writing to support, which carries out a manual re-examination within a reasonable time.

6. Recipients and processors

Data is accessible, strictly on a need-to-know basis, to the AltiGames team (development, support, security) under individual authorizations. No transfer to commercial partners for prospecting purposes takes place.

Technical processors used: Google LLC (Firebase Crashlytics, Firebase Cloud Messaging, Firebase Analytics) — servers in the European Union and the United States; backend hosting provider listed in the Legal Notice — servers mainly in France or the EEA; Apple Inc. and Google LLC for mobile app distribution; payment providers (Apple, Google, optionally Stripe or equivalent) for transaction processing.

Each of these processors is bound by a contract compliant with article 28 of the GDPR, ensuring a level of protection at least equivalent to the one provided by the Publisher. No data is ever sold, rented or transferred to a third party for commercial purposes. The Publisher does not display targeted advertising.

7. International data transfers

Some Firebase services may transfer data to the United States. These transfers are covered by the EU Standard Contractual Clauses ("SCCs") adopted by the European Commission (decision 2021/914) and by the EU-US Data Privacy Framework ("DPF"): Google LLC is DPF-certified.

No other international transfer takes place outside this scope. The main game and Account servers are located in France or the EEA. The Player may obtain, on request to the privacy email, a copy of the contractual safeguards applicable to each processor involved in an international transfer.

If a Player consumer residing outside the EEA wishes to use a Game, their informed consent to a transfer to European servers is implicitly collected by their connection; the safeguards applicable to inbound transfers are equivalent to those described here.

8. Retention periods

Active Account: duration of Service use. Account inactive for more than twenty-four (24) months: automatic anonymization (display name neutralised, email erased, identifier kept for referential integrity of games the Player took part in). Account deleted at the Player's initiative: effective erasure within thirty (30) days, subject to legal retention obligations.

Server technical logs: seven (7) days for routine application logs, thirty (30) days for security logs (authentication attempts, anti-fraud). Firebase Crashlytics crash reports: ninety (90) days under Firebase's default configuration. Analytics events: fourteen (14) months under Firebase Analytics' default configuration.

Transaction data (purchases, subscriptions): ten (10) years pursuant to the French accounting and tax retention obligation (article L123-22 of the Commercial Code). Reporting and moderation data: one (1) year after the report is closed. Once data is anonymized, it may be retained for statistical purposes without enabling re-identification of the Player.

9. Security measures

Technical measures: HTTPS only (TLS 1.2 or above), HSTS enabled, passwords stored as Argon2id hashes, short-lived HS256-signed JWTs paired with rotating refresh tokens, secure on-device storage (Keychain on iOS, EncryptedSharedPreferences on Android), no payment card data stored, regular security updates of dependencies.

Organizational measures: access to production data strictly limited to need-to-know, logged and automatically revoked at end of assignment, staff security training, separation of environments (dev/staging/production), encrypted backups with controlled retention, disaster recovery plan.

Processor controls: preference for providers with recognised certifications (ISO 27001, SOC 2), article 28 GDPR contractual framing, regular audit of service conditions. No measure can guarantee absolute security; the Player is invited to report any suspected incident without delay.

10. Data breach notification

Pursuant to articles 33 and 34 of the GDPR, in case of a personal-data breach likely to result in a risk to the rights and freedoms of the data subjects, the Publisher notifies the relevant supervisory authority within seventy-two (72) hours of becoming aware of it, and keeps an internal register of breaches pursuant to article 33(5).

Where the breach is likely to result in a high risk to the Player's rights and freedoms, the Publisher communicates the breach to them without undue delay, unless the data was encrypted in a way preventing re-identification, or subsequent measures have neutralised the risk. The communication describes the nature of the breach, its probable consequences and the remedial measures taken.

11. Your rights

Active Account: duration of Service use. Account inactive for more than twenty-four (24) months: automatic anonymization (display name neutralised, email erased, identifier kept for referential integrity of games the Player took part in). Account deleted at the Player's initiative: effective erasure within thirty (30) days, subject to legal retention obligations.

contact@altigames.fr

Transaction data (purchases, subscriptions): ten (10) years pursuant to the French accounting and tax retention obligation (article L123-22 of the Commercial Code). Reporting and moderation data: one (1) year after the report is closed. Once data is anonymized, it may be retained for statistical purposes without enabling re-identification of the Player.

12. Protection of minors

Pursuant to article 8 of the GDPR as transposed in French law in article 7-1 of the French Data Protection Act, processing the data of a minor under fifteen (15) years based on consent is lawful only if consent is given jointly by the minor and the holder of parental authority.

Guest mode is accessible to minors under fifteen (15) years without email collection. Creating an email Account by a minor requires the authorization of the holder of parental authority, who may at any time ask the Publisher for the rectification, restriction or erasure of the data processed for their child.

13. Cookies and trackers

AltiGames mobile apps do not use HTTP cookies — only a local JWT token stored in the iOS Keychain or Android EncryptedSharedPreferences, and a Firebase Cloud Messaging token for push notifications. The website uses at most a technical session cookie (strictly necessary within the meaning of article 82 of the French Data Protection Act and therefore exempt from consent) and, if enabled, anonymized audience measurement compliant with CNIL guidelines.

No advertising cookies and no third-party marketing trackers are used on AltiGames Games or website. The Publisher does not display behavioural advertising and does not participate in any real-time bidding (RTB) mechanism.

Push notification consent (where required by the Platform) can be revoked at any time from the device's system settings or the application's settings. Withdrawal of this consent disables turn and challenge notifications, without preventing the Player from continuing to use the Game.

AltiGamesAltiGames

Des jeux de mots et de réflexion gratuits, en français, sur tous vos écrans.

Jeux

AltiScrabbleAltiSolitaireAlti2048AltiBuildAltiDémineur

Légal

Conditions d'utilisationPolitique de confidentialitéContact

© 2026 AltiGames. Tous droits réservés.