Privacy Policy
Effective Date: February 15, 2026 · Last Updated: February 16, 2026
Leave Your Mark, LLC (“Company,” “we,” “us,” or “our”) operates GoodGames (“Service”), a social game library manager. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
By using GoodGames, you agree to the collection and use of information as described in this policy.
1. Information We Collect
1.1 Information You Provide
- Account Information: Email address and password when you register. Optionally, a username, avatar, and bio for your public profile.
- Library Data: Game ratings, reviews, play status, completion types, and curated game lists you create within the Service.
- Comments: Comments you post on other users’ game lists.
- Bug Reports: When you submit a bug report (e.g., via a broken game link), we collect the relevant URL, browser information, and your user ID to diagnose the issue.
1.2 Information Collected Through Platform Imports
When you import your game library, the following data is retrieved from third-party gaming platforms:
- Steam: Steam ID, game library, playtime, achievement progress, and last played dates (via Steam Web API using your Steam ID). You may optionally provide your own Steam Web API Key to unlock additional data such as “Last Played” timestamps.
- Xbox: Game library, playtime, achievement progress, and last played dates (via Xbox Live APIs using temporarily captured authentication tokens).
- PlayStation: Game library, playtime, trophy progress, and purchase history (via PlayStation Network APIs using temporarily captured authentication tokens).
- Nintendo: Game library, playtime, play history, and digital purchase history (via Nintendo APIs using OAuth session tokens).
How platform credentials are handled:
- Steam: Uses your public Steam ID. No password or token is captured. If you optionally provide a Steam Web API Key, it is encrypted using iron-session and stored solely as an
httpOnlybrowser cookie on your device. Your API key is never stored in our database. The cookie automatically expires after 30 days of inactivity and can be removed at any time from the import page. - Xbox and PlayStation: The browser extension captures authentication tokens from your active browser session. These tokens are used for a single import session, transmitted to our servers over HTTPS, and discarded after the import completes. We do not store your Xbox or PlayStation passwords.
- Nintendo: An OAuth session token is stored in our database to enable re-syncing without re-authentication. You can revoke this at any time by disconnecting Nintendo from your settings. We do not store your Nintendo password.
1.3 Information Collected Automatically
- Usage Data: Pages visited, features used, and import activity within the Service.
- Device Information: Browser type and version, collected via standard HTTP headers.
- Cookies: We use essential cookies to maintain your session and import state. If you provide a Steam Web API Key, it is stored as an encrypted
httpOnlycookie with a 30-day sliding expiration. We do not use advertising or tracking cookies.
1.4 Information We Do NOT Collect
- Passwords for gaming platforms (Steam, Xbox, PlayStation, Nintendo)
- Payment information (GoodGames is free)
- Precise geolocation data
- Contacts or address book data
2. How We Use Your Information
We use your information to:
- Operate the Service: Create and maintain your account, import and display your game library, and sync data across platforms.
- Classify Games Automatically: Apply heuristic algorithms to categorize your games (e.g., playing, completed, backlog) based on playtime, achievements, and other signals. You can override these at any time.
- Enable Social Features: Display your public profile, library, activity, and lists to other users (unless you set your profile to private).
- Improve the Service: Diagnose bugs, analyze usage patterns, and improve features.
- Communicate With You: Send service-related emails (e.g., account verification, security alerts). We do not send marketing emails.
We do not:
- Sell your personal information to third parties
- Use your data for advertising or ad targeting
- Share your data with data brokers
- Use your gaming data for purposes unrelated to the Service
3. How We Share Your Information
3.1 Public Profile Information
If your profile is public (the default), the following is visible to other GoodGames users and visitors:
- Username and avatar
- Game library (titles and statuses)
- Activity feed (games added, status changes, ratings)
- Game lists you have published
You can make your profile private at any time in your settings. Private profiles are not visible to anyone except you and GoodGames administrators (for bug investigation purposes only).
3.2 Service Providers
We use the following third-party services to operate GoodGames:
- Supabase: Database hosting and user authentication (stores your account data, library data, and platform tokens)
- Vercel: Web hosting and serverless functions
- Inngest: Background job processing (processes your library imports)
- IGDB (Twitch/Amazon): Game metadata (titles, cover art, release dates, completion times)
These providers process your data only as necessary to provide their services to us and are bound by their own privacy policies.
3.3 Legal Requirements
We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
3.4 Business Transfers
If Leave Your Mark, LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
4. Data Storage and Security
4.1 Where Your Data Is Stored
Your data is stored on Supabase-hosted PostgreSQL databases. Supabase infrastructure is hosted on AWS in the United States.
4.2 Security Measures
We implement reasonable security measures including:
- Encrypted data transmission (HTTPS/TLS)
- Row-level security (RLS) policies on all database tables ensuring users can only access their own data
- Hashed passwords (bcrypt via Supabase Auth)
- Service role keys restricted to server-side operations only
- Temporary import data deleted after processing
No method of electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
4.3 Data Retention
- Account data: Retained until you delete your account.
- Library and activity data: Retained until you delete your account.
- Import data (temporary): Xbox, PlayStation, and Nintendo import records are deleted immediately after successful import.
- Platform tokens (Nintendo): Retained until you disconnect the platform or delete your account.
- Steam API Key (optional): Stored only as an encrypted browser cookie. Expires automatically after 30 days of inactivity. You can remove it at any time from the import page. It is never written to our database.
- Bug reports: Retained until the issue is resolved, then kept in anonymized form for diagnostic purposes.
5. Your Rights and Choices
5.1 Access and Portability
You can view all data associated with your account through the GoodGames interface, including your library, activity history, and platform connections.
5.2 Correction
You can update your profile information, game statuses, ratings, and reviews at any time through the Service.
5.3 Deletion
You can delete your account, which will remove your profile, library data, activity history, platform tokens, and lists. To request account deletion, use the account settings page.
5.4 Profile Privacy
You can set your profile to private at any time, which hides your library, activity, and lists from all other users.
5.5 Platform Disconnection
You can disconnect any gaming platform from your account at any time. For Nintendo, this revokes the stored session token.
5.6 Hidden Games
You can hide individual games from your library view. Hidden games are excluded from your public profile.
6. Children’s Privacy
GoodGames is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will promptly delete that information.
7. Third-Party Links and Services
GoodGames may contain links to third-party websites (e.g., IGDB, Steam Store). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
8. California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at contact@goodgames.fyi.
9. International Users
GoodGames is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the Service or by email. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: contact@goodgames.fyi