Privacy
Your data at CoopCouch
Last updated . This page describes the data paths implemented in the current service.
Account and sign-in data
A CoopCouch account can link Steam, Discord, and Google identities. We store the verified provider identifier, display name, avatar when available, link timestamps, tracked games, and opaque server-side sessions in Cloudflare D1. We do not request or retain provider email addresses, provider passwords, Steam Guard codes, or OAuth access tokens. Session and authentication secrets are stored as hashes where the service needs to verify them later.
Steam libraries and private planning
Steam library sync is optional. When requested, CoopCouch imports the account's owned-game list from Steam and stores access records, sync state, and privacy-check timestamps in D1. Group membership, invitations, manual access choices, Game Night recommendation contexts and snapshots are private to authorized group members. A Game Night stores the selected game, schedule, optional title and note, invited group members, and their RSVP state. The organizer's browser suggests the event time zone, which is stored with the schedule. Each invitee's local display time is calculated on their own device; CoopCouch does not store participant time zones. Decision Room data can include reactions, ranked ballots, availability, session plans, and RSVP state. Private planning data is not sent to product analytics or placed in ads.
Group get-togethers store proposed games and times, an optional plan name, each member's response, and the confirmed game, time, and attending members. Active members of that group can see who is interested or unavailable and which games and times each person accepts. Choosing any game also accepts games suggested later. These responses are private to the group and are excluded from analytics, ads, and operational logs.
Independent group votes store a question, game choices or proposed times, and each member's selected options. Collaborative game votes also store members' suggested games, whether each active member has finished suggesting, the current round, and the chosen winner. A time vote also stores the creator's chosen time zone. Authorized group members see suggested games, collection readiness, aggregate results, and their own response; individual ballots from other members are not displayed. Vote contents are excluded from analytics, ads, and operational logs.
Optional analytics and advertising
Product analytics is off until you grant analytics consent. If allowed, explicit, bounded product events can be sent to PostHog EU with pseudonymous identifiers. We do not use autocapture, session replay, contact data, provider identifiers, raw IP addresses, full query strings, or free-form planning answers in those events.
Advertising is a separate choice. Google AdSense can load on registered public content pages and the Groups dashboard after advertising consent is granted and the runtime gates allow it. The rule is the same for signed-in and signed-out visitors and does not require product-analytics consent. AdSense code therefore runs in the browser on the Groups dashboard; CoopCouch does not add group names, membership, or query strings to its ad telemetry. Tracked, individual group pages, Game Night, Decision Room, invite, availability, shared-link, account, admin, and sign-in surfaces do not contain ad slots. Google may present an additional region-specific consent message.
Essential storage, security, and providers
Essential cookies keep signed-in sessions and authentication challenges secure. Browser storage holds privacy choices, your local color-palette preference, and limited session state. The palette preference stays on this device and is not part of your CoopCouch account. Your profile shows a stable public user ID that you can share with support and that may later identify you in social features. It is not a sign-in credential and is separate from the internal account ID used server-side during routine operation. Cloudflare hosts the application and D1 database and provides security and aggregate operational metrics. Steam supplies catalog and opted-in library data; Steam, Discord, and Google verify their respective sign-ins. Operational diagnostics are redacted and bounded; they exclude passwords, tokens, contacts, public or internal account identifiers, provider identifiers, and private planning contents.
Early-access applications
If you submit the separate early-access form, it stores controlled application answers, referral attribution, and the email you explicitly provide for up to 90 days. The email is encrypted in D1 and is not silently linked to a signed-in account or analytics consent. It is therefore outside account export and account deletion.
Retention, export, and deletion
- The profile security panel can export account data and permanently delete the account after recent reauthentication. The export includes your current Free/Pro group entitlement, explicit played-session confirmations, Game Nights you organize, your public user ID, your own internal account ID, and your own invitations and RSVP responses. It also includes a bounded history of game-page review approvals and editorial changes attributed to your account, but never another administrator's audit actions or another member's user ID, internal account ID, or private member handle. The internal ID appears only in this explicit, protected download, not the routine profile UI. Account deletion removes provider links, live sessions, tracked games, imported library data, memberships, played-session confirmations, personal Game Night participation, group-vote responses, and owned groups from the live database. Exports also include votes you created, your game suggestions, your readiness during game collection, and your own responses in the current round. When an account is deleted, retained votes and game suggestions in someone else's group no longer identify that creator or contributor. Get-together exports include plans you started, games and times you suggested, and your own responses. Deletion removes your responses and removes your account link from retained suggestions and plans in other people's groups.
- Imported Steam library data can be exported or deleted separately. Deleting it keeps the Steam sign-in identity and manual access entries.
- Soft-deleted groups are purged after 30 days; live-group audit records are retained for 180 days. Tonight snapshots and Game Nights remain only for the lifetime of their group. If a member deletes their account, their RSVP is removed and retained Game Night audit history no longer identifies them.
- Get-togethers stay open for at most 30 days. Confirmed plans become past plans when their selected start time arrives; this does not assert that anyone played. Cancelled and past plans become eligible for deletion after 180 days. Starting a new plan trims older history to the latest 95 records; the group displays the ten most recent. Leaving or pausing group membership withdraws your responses. A future confirmed plan returns to gathering if fewer than two active members still accept its game and time.
- Independent group votes close after 30 days at the latest; time votes can close sooner after their last proposed time. Closed votes become eligible for deletion after 180 days. Starting a new vote trims older closed history within that vote format to the latest 195 records. Your group shows the 20 most recent closed votes. Each new game-vote round replaces the previous round's individual responses. Readiness records are removed when voting starts, collection is cancelled, or expired collection is cleaned up. Leaving or pausing group participation also removes that member's readiness. Response totals count currently active members and can change when membership changes or an account is deleted; a game already chosen by a finished round remains the recorded winner.
- Terminal Decision workflows become eligible for deletion after 180 days; Decision audit records are retained for 365 days and notification rows for 180 days. Expired poll response data is removed after 30 days when no live session depends on it.
- Game-page review approvals and editorial-change audit records may be retained indefinitely to protect publication integrity. Current original CoopCouch summaries and their historical audit snapshots may remain as operational content history. If the acting administrator deletes their account, retained current and audit records anonymize the actor by removing the account link; the operational record remains but no longer identifies or exports under that account.
- Cloudflare's encrypted recovery history may temporarily contain an older database state for its platform backup window. Independent deletion tombstones are retained for 45 days so a recovery must reapply account deletions before restored data is served.
Your choices and contact
You can reopen Privacy settings in the site footer at any time. Rejecting optional uses does not disable the catalog or private planning features. For privacy questions or a request concerning separately submitted contact data, email:
info@coop-couch.com