Rudder plays two different roles. For the account you sign in with, we are the controller. For the players in your game, you are the controller and we are only a processor acting on your instructions — see our Data Processing Agreement.
Who we are
Rudder (rudder.build) is a backend for game studios: player accounts, wallets, counters, storage and game-feature modules behind one API. Rudder is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For anything in this policy, or to exercise any right described below, write to hello@rudder.build.
Data we hold about you, the account holder
- Your name and email address. The email is your sign-in identifier.
- Your password, stored only as a bcrypt hash. We never store, log or transmit the password itself.
- Your account status, and the projects you belong to together with your role in each.
- Personal access tokens you create, stored only as a hash. The secret is shown once at creation and never again.
- Email confirmation tokens, deleted once used or expired.
- Your IP address and browser user agent appear in our server request logs. They are not written to the database and are not linked to your account record.
We process this to give you an account, to secure it, to bill your plan and to email you operational notices — for example when a project approaches its monthly active user limit. The legal basis is performance of our contract with you, and our legitimate interest in keeping the service secure.
Data we process about your players
When you integrate Rudder into your game, we store and process the following on your behalf. You decide what the game sends us; we do not decide it for you.
- A player identifier we generate, plus nickname, avatar URL, region and language.
- The identity your game authenticates a player with — a provider name and a subject, both supplied by your game. If your game sends an email address or a device identifier as the subject, that is what we store.
- Free-form player profile data and player storage blobs. The contents are entirely yours: we never inspect, parse or index them.
- Gameplay state: wallets and their audit trail, counters, resource rows created by the modules you install, and module logs.
- Days on which a player was active, used to compute the monthly active users on your plan.
- An audit log of administrative actions taken on players through the admin API, including a before/after diff of the change.
What we do not do
- No AI or machine learning. No personal data, player data or stored content is sent to any AI or machine-learning system, ours or anyone else's, for any purpose — including model training.
- No advertising, no profiling, no sale or sharing of personal data.
- No analytics or tracking. Neither the dashboard nor this website runs an analytics product, a tag manager or an advertising pixel.
- No cookies. The dashboard keeps your session token in the browser's local storage, not in a cookie, and this website sets nothing at all.
Who else touches the data
These are our sub-processors. We use no others.
| Who | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Application and database hosting | Germany |
| Resend | Transactional email (confirmations, plan notices) | United States |
| Google Fonts | Web fonts on this website and in the dashboard | United States |
Google Fonts is loaded from Google's servers, which means your IP address reaches Google when you open a Rudder page. No other data is sent and no cookie is set. Everything else stays inside the European Union.
We give you at least 30 days' notice by email before adding or replacing a sub-processor, so that you can object.
How long we keep things
| What | How long |
|---|---|
| Player records and their gameplay data | Until you delete them. We apply no retention limit of our own. |
| A player you delete through the API | Erased immediately: nickname, avatar and profile data are cleared, login identities and storage blobs are deleted outright. A record marked deleted remains so that the same player identifier is never reissued. |
| Administrative audit log | 90 days, then deleted automatically. |
| Idempotency records for admin operations | 24 hours. |
| A project you delete | Marked deleted and no longer served, but its player data is retained. Write to us to have it erased. |
| Your account, when you delete it | Erased immediately, along with every project where you were the only owner and all of that project's player data. Projects with another owner are kept and you are removed from them. |
| Server request logs | Kept on the host and rotated; not archived. |
| Database backups | Deleted data disappears from backups within 30 days. |
Security
Traffic is TLS-encrypted end to end. Passwords are bcrypt-hashed, API tokens are stored as hashes only. Admin and SDK keys are scoped to a single project and environment. If a breach affects your data, we notify you without undue delay and in any case within 72 hours of becoming aware of it.
Your rights
You may ask for access to your personal data, correction, erasure, a portable export, restriction of processing, or object to processing. Most of it you can do yourself: the dashboard lets you edit your details, revoke tokens, and delete your account outright. For anything else write to hello@rudder.build and we will answer within 30 days. You may also complain to your national data protection authority.
If you are a player in a game, not a Rudder customer: we hold your data only on behalf of that game's studio and we cannot identify you from it. Contact the studio. If you contact us instead, we will pass your request to them without undue delay.
Children
A Rudder account is for professional use and is not intended for anyone under 16. Whether your game may be played by children, and what that requires of you, is your responsibility as the controller of that data.
Changes
If we change this policy we update the date at the top. For changes that materially affect you we email account holders in advance. See also our Terms of Service and Data Processing Agreement.