Legal
Privacy Policy
Dusted Blocks is a free, 150-second block puzzle duel you play in your browser or in our iOS app. You can play without an account. This policy explains what we process, why, where, and for how long.
1. Controller
The controller within the meaning of the GDPR is:
Forward Systems GmbH
operating under the brand Dusted
Auguststraße 47A
10119 Berlin
Germany
Email: hello@forwardsystems.ai
Managing Director: Markus Imanuel Maier. Further details are in our imprint.
2. Description of the Service
Dusted Blocks (“Dusted”, the “Game”) is a two-player block puzzle game available at dusted.fun and as an iOS app. You can practise alone, invite a friend with a link, and, if you both choose to, see and hear each other during a match. Match results are decided by our game server, not by your device.
3. Data Processed
a) Access and server data
- IP address, date and time of the request, requested address, browser and operating system type
- Short technical and error logs of our game server, web server and media server
We use IP addresses only transiently to deliver the page, to protect the service (for example, per-address rate limits against abuse) and to find errors. We do not use them to identify or profile players. Our reverse proxy does not write access logs, and our web server only sees the proxy’s internal address, not yours.
Purpose: operation, security and stability of the Game. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working service).
b) Guest identity and display name
- A random player ID that our server creates for your first online session, and a long random device key that the Game keeps in your browser storage (or app storage on iOS) so that you stay the same player next time. Our server stores only a one-way hash (SHA-256) of the device key, never the key itself.
- A server-signed guest session that is valid for 24 hours; the Game then gets a new one with your device key
- The display name you choose. If you do not choose one, the Game suggests a random name such as “Swift Otter”
- A pseudonymous player reference derived on our server from your player ID
You do not need to give us your name, email address or phone number to play. Your display name is shown to the other player and, if you allow broadcasting, to spectators.
Purpose: letting you play, reconnect to a running match and see who you are playing. Legal basis: Art. 6(1)(b) GDPR (providing the Game you asked for).
c) Friend invitations
When you invite a friend, our server creates an invitation link containing a random single-use token of at least 128 bits, plus a short six-character code. The invitation can be redeemed once and expires after 10 minutes. We store it only in the server’s memory until it is used or expires. We do not see how or with whom you share the link.
Legal basis: Art. 6(1)(b) GDPR.
d) Gameplay, results and replays
- Match state, your moves and their timing, scores, clock, result and how the match ended (for example, a forfeit or disconnect)
- A replay of each online match that lets us reconstruct it move by move, linked to the pseudonymous player references and display names of both players
Our game server is authoritative: it checks every move and decides the result. Replays are stored on our servers at Hetzner in Germany.
Purpose: running the match, verifying results, detecting cheating and resolving disputes. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in fair play).
e) Video and voice calls during a match
During a match you can talk to and see the other player, like a video call. Camera and microphone are switched on when a match starts, but only after your browser or device has asked you for permission and you have allowed it. When you join through an invitation link, you first see your own camera image and can switch camera and microphone off before joining. You can switch them off, mute the other player or leave at any time. Both stop when you leave or the match ends.
- Audio and video are sent from your device to our media server and from there to the other player (WebRTC, using the open-source LiveKit software that we run ourselves on Hetzner servers in Germany at livekit.dusted.fun).
- Media is encrypted in transit, but it is not end-to-end encrypted: it passes through our media server so it can be forwarded.
- The call itself is not recorded or stored. Only if both players have allowed their face and voice to be broadcast (see f) may they be shown to spectators.
- Only the two players of a match receive short-lived access to its call.
Legal basis: Art. 6(1)(b) GDPR (providing the video call you use during the match) and Art. 6(1)(a) GDPR (your consent, given through your browser’s or device’s camera and microphone permission). You can withdraw it at any time by switching camera or microphone off or revoking the permission.
f) Broadcasts, spectator view and highlight clips
Under “Share on stream” – on the Play a friend screen when you invite, and on the Ready to join? screen when you are invited – you choose separately whether your board, your face and your voice may be shown to spectators. Face and voice are only ever shown while your camera or microphone is actually on.
These switches are on unless you switch them off; you see them before every invitation you create or accept, and your choice is remembered on your device. Nothing is shared unless both players allow it.
- Both players must agree. The server applies the more private of the two players’ choices. If either player shares nothing, no spectator view is created.
- The spectator view is reached through an unguessable link that expires shortly after the match. It shows both boards, display names, scores and the clock, but never the pieces waiting in your tray.
- We currently do not stream matches to external platforms such as Twitch. If we start doing so, we will update this policy first, and only matches where both players allowed it could be streamed.
- Either player can revoke the spectator view, or withdraw only their face, at any time during or after the match.
- Highlight clips: after a match, we can render a 15-second vertical clip from the replay. Clips show boards, scores and avatars – not your camera image. They are private to the two players of the match and are deleted after 30 days. Withdrawing face consent causes any later clip to be rendered without your face.
- A clip you download or share yourself leaves our control; we cannot recall it from other apps or services.
Players under 18 never have their face or voice shared with spectators or in clips. Before you first play online, the Game asks whether you are 18 or older, 16 or 17, or under 16. If you answer 16 or 17, the Face and Voice switches are locked off and our server refuses to share your face or voice even if they were requested.
Legal basis: Art. 6(1)(a) GDPR (consent). Withdrawal does not affect the lawfulness of processing before the withdrawal.
g) App integrity (iOS app only)
The iOS app uses Apple App Attest to check that requests come from a genuine copy of the app on a genuine Apple device. We store the resulting app-instance key and counters. Currently we only observe the result; it does not block you from playing.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the Game against manipulated clients).
h) Test stakes and wallets (if and when enabled)
Stakes are currently disabled. If and when we enable test stakes, the following applies:
- You sign in with Privy (Privy, Inc.), for example with your email address, Google or Apple account. Privy creates an embedded wallet for you.
- We receive your wallet address and link it to your guest session, and we keep a record of each staked match (amounts, deposits, outcome and transaction IDs) for up to 30 days after it is settled.
- Stakes use test tokens on the Base Sepolia test network. They have no monetary value and cannot be exchanged for money. Real-money play is not offered.
- Transactions on a blockchain, including your wallet address, are public and permanent by design. We cannot delete them.
Legal basis: Art. 6(1)(b) GDPR.
i) Error reports (Sentry)
To find and fix errors, our game server, the web version of the Game and the iOS app send error reports to Sentry (Functional Software, Inc.), stored in Sentry’s EU data region. A report is sent only when something goes wrong, and the web version and the iOS app each send at most 20 per visit or app session. It contains technical data only:
- the type and message of the error and where in our code it occurred (stack trace)
- the version of the Game and of its game content, the time, and whether the error came from the game server, the web page or the game itself
- for the web version: browser and operating system type (user agent), whether it is a mobile device, and the page address without any parameters
- for the iOS app: the operating system and its version, and the device family (for example “iPhone” or “iPad”; not the exact model, the device name or any device identifier)
- for the game server: the kind and address of the request that failed and the browser type that sent it
Before a report leaves our server, your browser or your device, we remove invitation links and tokens, session and access tokens, wallet addresses and email addresses; the web version and the iOS app also remove display names (yours and your opponent’s). We do not attach your guest ID or any other user identifier, your age answer, game settings, moves, request contents, or any camera or microphone data, and we do not use reports to identify or profile you. Your browser or the iOS app sends the report directly to Sentry, so Sentry sees your IP address while receiving it; we have configured reporting so that the IP address is not stored with the report.
Purpose: detecting and fixing errors to keep the Game stable. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a stable, working service).
j) When you contact us
If you email us, we process your email address and message to answer you and keep the correspondence as long as needed for that purpose.
Legal basis: Art. 6(1)(b) or (f) GDPR.
k) Player record, rating and rivals
Once you play online, our server keeps a persistent player record, linked to your player ID (see b):
- the hash of your device key, your current display name, when the record was created and when you last played, and the platform you play on (web, iOS, …);
- your match results: opponent, scores, winner, how the match ended, whether it was a public match or a friend invitation, and when it was played;
- your skill rating (a Glicko-2 rating, deviation and volatility, and the number of rated matches) and how it changed in each rated match;
- your head-to-head record against the players you have met (“You lead 2–1”), worked out from your match results. Your opponents see their own record against you with your display name.
Only public-queue matches between two players change ratings; friend invitations and practice never do. We use the rating to pair you with players of similar skill. Your age answer stays on your device; our server only learns whether a match must keep face and voice private (see f).
Purpose: keeping your identity, rating and history across sessions, fair matchmaking and rivalry records. Legal basis: Art. 6(1)(b) GDPR (providing these features of the Game) and Art. 6(1)(f) GDPR (legitimate interest in fair matchmaking and fair competition).
l) Usage statistics (PostHog)
To see how the Game is used – whether matchmaking finds rivals quickly, where new players get stuck in the lesson, and whether matches end normally – our game server sends pseudonymous usage events to PostHog (PostHog Inc.), stored in PostHog’s EU data region. This happens on our server only:
- No PostHog code runs in your browser or in the app, and no cookies or other data are stored on or read from your device for statistics. The Game only tells our own server about a few moments that happen on your device (see below), using your existing guest session.
- Events are linked only to your pseudonymous player reference (see b), never to your display name, player ID, device key, invitation links, wallet address or IP address. PostHog receives the events from our server, not from you, so it never sees your IP address; we also tell PostHog not to record an IP address or derive a location, and we do not create user profiles.
- Events only contain fixed categories and numbers, never text you type. They are:
- a new player record or a new session (with the platform: web, iOS, …);
- joining, being matched in or leaving the public queue (waiting time, a rough rating difference such as “50–99”, and why you left: cancelled, went to practice, or timed out), creating or accepting a friend invitation, rematches and highlight clips;
- match start and end: mode (public or friend), your platform and your opponent’s platform, your result (win, loss, draw), duration, score, lines cleared, blockers sent and cancelled, crashes, whether the match was rated and your rating change, and whether it ended early or by a forfeit;
- from the Game on your device, only once you have played online: lesson started, lesson steps completed, lesson finished or left (with the step), your answer to the “New here?” offer, practice started and ended (score and duration), and the update notice being shown.
When you delete your player data (see section 6), the link between your device, your player record and the pseudonymous reference is erased. Events already sent stay in PostHog under that reference but can then no longer be connected to you or your device; the only other place the reference appears is the match replays, which are deleted after 90 days. You can object to this processing at any time (Art. 21 GDPR) by writing to us.
Purpose: improving matchmaking, onboarding (the lesson) and the stability of the Game. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in understanding and improving the Game with pseudonymous, minimal data).
m) Fair play and anti-cheat
To keep matches between real people fair, we check online matches for three specific kinds of cheating: automated play by a bot or script, help from a solver program that picks placements for you, and two accounts working together to fix results (win trading, chip dumping). Practice matches against the labelled bot are not checked.
- From the match itself: after an online match, our server replays it and compares each of your placements with the options you had at that moment, together with how long you took and how that changed with difficulty and time pressure. This comes from the match record our server already keeps (see d).
- From your device, only simple summary values per placement: whether you dragged, tapped or used the keyboard; how long the placement took; how many pointer positions were recorded; how straight and how evenly fast the movement was; and whether the browser marked the input as coming from a real device. We never store your movement paths, tap positions, keystrokes, camera or microphone for this. Tapping or using the keyboard instead of dragging is never treated as suspicious.
- Once per session: your platform (web, iOS, …), whether your browser reports that it is being controlled by automation software, and a few similar technical indicators.
- Pairings: how often two players meet and who wins, to spot two accounts feeding each other wins.
- New player records: your device solves a small computing puzzle (“proof of work”, a fraction of a second) before a new player record is created. This makes mass-creating accounts expensive; it sends no data about you.
These checks only flag a player for review. They never ban, suspend, void matches or change ratings on their own. A member of our team looks at the evidence, and before any sanction we tell you what we found and give you the chance to respond. You can ask for a second person to review any decision. We do not use these data to identify you, to build a profile of how you move, or for advertising.
Purpose: detecting and preventing cheating, automated play and collusion in online matches. Legal basis: Art. 6(1)(f) GDPR (our and all players’ legitimate interest in fair matches between real people). You can object at any time (Art. 21 GDPR), for example by email; if you object, you can still play friend matches and practice, but we may not be able to let you play public matches.
4. Cookies and Storage on Your Device
Dusted uses only technically necessary storage on your device:
- your device key (see section 3 b), your guest ID, display name and game settings (sound, colours, sharing, camera and microphone choices, your age answer, tutorial progress), kept in your browser’s storage or in app storage;
- cached game files so the Game loads faster next time.
No tracking or advertising cookies are used, and the usage statistics in section 3 l do not store or read anything on your device. You can delete this data at any time by clearing the site data for dusted.fun in your browser, or by deleting the app; you will then start as a new guest.
Legal basis: § 25(2) no. 2 TDDDG (formerly TTDSG), Art. 6(1)(f) GDPR.
5. Hosting, Processors and Other Recipients
We keep the list of services that receive personal data short:
| Service | Receives | Purpose | Location |
|---|---|---|---|
| Hetzner Online GmbH | All server-side data in section 3 | Server hosting (game server, website, media server, replays, clips) | Germany |
| LiveKit (self-hosted) | Call audio/video in transit | Video and voice calls, spectator media | Our own server at Hetzner, Germany – no third-party provider |
| Apple | App Store and App Attest data (iOS app only) | App distribution, app integrity | EU / USA |
| Sentry (Functional Software, Inc.) | Technical error reports (section 3 i) | Error monitoring | EU data region; US parent company |
| PostHog (PostHog Inc.) | Pseudonymous usage events from our server (section 3 l); no IP addresses | Usage statistics | EU data region; US parent company |
| Privy, Inc. | Sign-in data (e.g. email) and wallet data – only if stakes are enabled and you use them | Sign-in and embedded wallets | USA |
We use no advertising services. The only analytics service is PostHog, which receives pseudonymous usage events from our server only (section 3 l); the only error-reporting service is Sentry, for the technical error reports described in section 3 i. Game voices and sounds were produced in advance with ElevenLabs; no player data is sent to ElevenLabs when you play.
Key principles:
- No advertising use of data, no tracking and no sale of data
- Personal data is minimized or pseudonymized where possible
- Processing by service providers is governed by data processing agreements under Art. 28 GDPR
Where data is transferred to a country outside the EU/EEA (USA), this is based on an adequacy decision (EU-U.S. Data Privacy Framework, where the recipient is certified) or on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
6. Data Retention and Deletion
| Data | Kept for |
|---|---|
| Guest session | 24 hours, then renewed or expired |
| Player record (device-key hash, display name, rating) | Until 12 months after you last played, then deleted automatically; 30 days if you never finished an online match; immediately on request |
| Match results and rating changes per match | 90 days, then deleted automatically (your overall rating stays with your player record) |
| Friend invitations | Until used, at most 10 minutes |
| Live call audio and video | Not stored |
| Replays and match results | 90 days, then deleted automatically; earlier on request |
| Fair-play evidence (match scores, per-placement summary values, session indicators, pairings) | 90 days, then deleted automatically; deleted with your player data on request |
| Spectator view settings | Link expires shortly after the match; settings deleted after 30 days |
| Highlight clips | 30 days |
| Stake records (if enabled) | Up to 30 days after settlement; on-chain transactions are permanent |
| Technical logs | Rotated automatically: at most about 30 MB per service (web, game and media server), overwritten continuously, typically within days |
| Error reports (Sentry) | Deleted automatically by Sentry after the retention period of our plan (30 or 90 days) |
| Usage statistics (PostHog) | Up to 12 months, then deleted automatically by PostHog under our plan’s retention; after you delete your player data they can no longer be linked to you |
| Data on your device | Until you clear site data or delete the app |
You can delete your player record yourself at any time: in the Game, open Settings → Delete my player data. This erases your player record, device-key hash, rating, rating history and rivalry records at once; in other players’ match results your seat is replaced by an anonymous placeholder, so their own results and ratings stay correct but no longer point to you. The Game then starts you as a new player.
Because you play without an account, please include your display name and the approximate date and time of your matches (or the invitation link) when you ask us to delete other data, so we can find it.
7. Age
Dusted is intended for players aged 16 and older in the EU. We do not knowingly process data of younger children. Before you first play online, the Game asks for your age group; under-16s can only use the lesson and practice mode against the bot. Players aged 16 or 17 can play and video-call, but their face and voice are never shared with spectators – the switches are locked and our server enforces it. If you believe a child has used Dusted, contact us and we will delete the data.
8. Your Rights
You have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Not to be subject to a decision based solely on automated processing (Art. 22 GDPR) – our fair-play checks only flag cases; a person always decides, after hearing you
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interest (Art. 21 GDPR)
- Withdraw any consent at any time with effect for the future (Art. 7(3) GDPR) – for example by switching off camera, microphone or sharing in the Game
Contact: hello@forwardsystems.ai
9. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
10. Data Security
We implement appropriate technical and organizational measures, including:
- Encrypted connections (TLS for the website and game server; encrypted WebRTC media)
- Short-lived, match-bound and seat-bound access tokens for gameplay and calls
- Access controls and data minimization
- Separation of gameplay and media data
No method of transmission over the internet is 100% secure.
11. Changes to this Privacy Policy
We may update this Privacy Policy to reflect technical or legal changes, for example when we enable a feature described above as not yet active. The current version is always available at dusted.fun/legal/privacy.html; the date at the top shows when it was last updated.