Privacy Policy of pabolo GmbH for the Baduz Platform
Status: 9 September 2026
In this Privacy Policy, we explain how pabolo GmbH processes personal data when you visit the Baduz website, play Games, create or use an account, use the AI-assisted creation tools, publish or interact with Games, submit reports, contact us, or purchase a Creator Subscription.
1. Controller
The controller responsible for the processing of personal data described in this Privacy Policy is:
pabolo GmbH
Albert-Nestler-Str. 10
76131 Karlsruhe
Germany
Managing Director: Thomas Hans Willberger
E-mail: [email protected]
Telephone: +49 (0)157 58252145
Privacy contact: [email protected]
2. Scope of this Privacy Policy
This Privacy Policy applies to the website at https://www.baduz.com, the browser-based Baduz platform, public Games made available through Baduz, registered User Accounts, Creator tools and Subscriptions, comments and votes, reporting and complaint functions, and related support communications (collectively, the “Services”).
It applies to anonymous visitors and players, registered Users, Creators, persons who submit reports, and persons who contact us. Separate privacy notices may apply where we introduce a materially different service or processing activity.
The Services are operated from Germany and this Privacy Policy is written to satisfy the GDPR and the German TDDDG. If you access the Services from outside the European Economic Area, the United Kingdom or Switzerland, we apply the same standards; where local law grants you additional rights (for example under US state privacy laws), you may exercise them by contacting [email protected].
3. Categories and sources of personal data
3.1 Device, log and usage data
When you access the Services, our systems and service providers may process technical and usage information such as:
- IP address, date and time of access, requested URL, referring page and response status;
- browser type and version, operating system, device type, language, screen or graphics capabilities and similar technical information;
- session identifiers, security tokens, cookie or local-storage identifiers and consent settings;
- Game pages opened, Game start and completion events, errors, crashes, performance information, clicks and other interactions; and
- security events, abuse signals, failed authentication attempts and rate-limit events.
We receive this information from your browser or device, from our infrastructure, and from the service providers used to operate Baduz.
3.2 Data received through third-party login providers
Baduz does not operate its own password-based login and does not independently send an e-mail verification message. Registration and login take place through approved third-party OAuth/OpenID Connect providers. At present, Baduz supports Sign in with Google.
Depending on the permissions shown during login and the provider response, we may receive:
- a stable provider account identifier (for Google, the OpenID Connect “sub” identifier);
- your e-mail address and the provider’s indication whether that address is verified;
- your name and profile picture, if the profile scope is requested and you authorise it; and
- authentication tokens and technical information necessary to establish and secure the Baduz session.
We do not receive or store the password for your Google or other third-party account. The login provider processes personal data under its own privacy terms. For Google, see the Google Privacy Policy and the information displayed during Sign in with Google.
Google Privacy Policy | Manage third-party connections in your Google Account
OAuth scopes used by Baduz: openid, email and profile (requested through the standard Google sign-in of our authentication provider, Firebase Authentication).
3.3 Account and profile data
We process the information required to create and administer a User Account, including the provider identity described above, a Baduz User ID, username or display name, account status, language, age and parental-consent confirmations, timestamps, accepted Terms and Privacy Policy versions, and security and session records.
Profiles are pseudonymous by default. Your e-mail address and OAuth provider identifier are not displayed publicly. A name or profile image received from a login provider is not made public automatically; it is displayed only if the product expressly lets you select it as public profile information.
3.4 Creator inputs, Game data and AI-assisted content
When you use the Creator tools, we process information generated through your use of the tool, including prompts and instructions, mission descriptions, object selections, texts, dialogues, names, level and object arrangements, settings, edits, version history, generated or AI-assisted elements, Game logic, Game metadata, publication status and technical runtime information.
Creator Inputs may include reference images that you upload as a visual guide for a generation. Such images are transmitted to the AI provider only to produce the requested result; they are not stored by us and do not become part of the Game. The tool does not provide an upload function for audio files, code or external project files. You must not upload images of identifiable persons and must not enter third-party personal data, special-category data, confidential information or other information that you are not entitled to use in prompts or Game content.
AI/inference provider(s) and locations: Creator prompts and AI-assisted generation requests are processed with Google Gemini models via the Google Gemini API (Google LLC, USA). Text embeddings used for asset search are computed with Google Cloud Vertex AI (Google Cloud region us-central1, USA).
3.5 Public Games, profile information, comments and votes
If you publish a Game, the Game, its title and description, the public Creator name, content information and related public metadata can be accessed without a login. If comments or votes are enabled, we process the comment text, author identifier, timestamps, moderation status and vote information. Public content may be viewed, shared or recorded by other internet users.
Do not publish personal contact information, private information or personal data of other persons in a Game, profile or comment.
3.6 Reports, moderation, complaints and legal requests
When a Game or comment is reported, we process the reported content and its version, the selected reporting reason, the explanation and evidence submitted, timestamps, relevant account and technical information, moderation notes, decisions, communications, complaints and appeal outcomes. A report may be submitted without an account; contact details are collected only where you provide them or where they are required by law or necessary to respond.
Baduz currently does not use an automated content detector to make publication or moderation decisions. The current process includes the Creator declaration, human review and report-triggered review.
If automated detection is introduced, we will update this Privacy Policy and the relevant product information before it is used for materially significant moderation decisions.
3.7 Subscription and payment information
Payments are processed directly by the payment service provider displayed in the checkout. pabolo GmbH does not receive or store full card numbers, bank account credentials, card security codes, PayPal passwords or comparable payment authentication data.
To conclude and administer the Subscription, handle refunds or chargebacks, and meet accounting obligations, Baduz may receive limited transaction and subscription metadata from the provider, such as the provider customer and subscription references, plan, amount and currency, payment and renewal status, timestamps, invoice or receipt reference, refund or chargeback status, and the minimum billing or tax information returned by the provider.
Payment provider: Payments are processed by Stripe, Inc. and its affiliates (“Stripe”) through Stripe Managed Payments, with Stripe’s affiliate acting as merchant of record. Stripe returns to Baduz the customer and subscription references, plan, amount and currency, payment and renewal status, timestamps, invoice or receipt reference, refund or chargeback status, and the country and tax information required for accounting. Details on Stripe’s own processing are set out in the Stripe Privacy Policy.
The payment service provider is independently responsible for the payment data it collects and processes under its own privacy notice. The payment provider may also carry out fraud prevention, sanctions checks or legally required identity checks under its own responsibility.
3.8 Communications and support
If you contact us by e-mail, through a support form, in relation to a report or complaint, or by another supported channel, we process your contact details, the content of your message, attachments you send through that communication channel, the related account or transaction references and our correspondence with you.
Support/ticketing and transactional e-mail provider(s): support is currently handled directly by e-mail; no external ticketing or transactional-e-mail provider is used.
4. Purposes and legal bases
We process personal data only where a legal basis applies. Depending on the context, the main purposes and legal bases are as follows:
| Processing activity | Purpose | Legal basis |
|---|---|---|
| Providing the public website and public Games | Technical delivery, stability, load balancing, error handling and making requested Game pages available. | Art. 6(1)(f) GDPR; where necessary to provide a requested account service, Art. 6(1)(b) GDPR. |
| Account registration and authentication | Creating and securing the account, linking the OAuth identity, managing sessions and giving access to account functions. | Art. 6(1)(b) GDPR. Technically necessary device storage is based on Section 25(2) no. 2 TDDDG. |
| Creator tools and Game operation | Generating and editing Game elements, storing projects, running Games and providing Creator functions during the Subscription. | Art. 6(1)(b) GDPR. |
| Publication and interaction | Publishing Games and selected profile information, enabling comments, votes and sharing. | Art. 6(1)(b) GDPR; for platform integrity and public operation, Art. 6(1)(f) GDPR. |
| Subscription and payment administration | Checkout, status reconciliation, billing, refunds, chargebacks, customer support and accounting. | Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR for statutory accounting and tax duties; Art. 6(1)(f) GDPR for fraud prevention and legal claims. |
| Reports, moderation and appeals | Receiving and processing notices, enforcing Terms and Community Guidelines, protecting Users and complying with legal obligations. | Art. 6(1)(c) GDPR where processing is required by law, including applicable Digital Services Act duties; otherwise Art. 6(1)(f) GDPR. |
| Security and abuse prevention | Protecting accounts, infrastructure and content; detecting fraud, attacks, scraping and other misuse; incident response. | Art. 6(1)(f) GDPR. |
| Support and communications | Answering requests and administering the contractual relationship. | Art. 6(1)(b) GDPR where related to a contract; otherwise Art. 6(1)(f) GDPR. |
| Consent-based features | Optional analytics, non-essential cookies or other optional processing enabled through a consent interface. | Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time. |
| Legal compliance and claims | Compliance with court or authority orders, statutory retention, establishment and defence of legal claims. | Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. |
5. Cookies, local storage and similar technologies
Baduz uses cookies, browser storage and comparable technologies to provide and secure the Services. These technologies may be session-based or persist for a defined period.
5.1 Technically necessary technologies
Technically necessary technologies may be used for authentication and session management, OAuth state and nonce validation, CSRF protection, security, load balancing, consent storage, language or interface settings, and the operation or restoration of Game sessions expressly requested by the user. Where Section 25 TDDDG applies, these technologies are used under Section 25(2) no. 2 TDDDG because they are strictly necessary to provide the requested digital service. The related processing of personal data is based on Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on the function.
5.2 Optional analytics or other non-essential technologies
Optional analytics, advertising or other non-essential technologies are used only after the required consent has been obtained through our consent banner (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw consent at any time with effect for the future through the Cookie Settings link in the website footer. Withdrawal does not affect processing that occurred before withdrawal. The current providers, purposes and retention periods are shown in the consent interface and in our Cookie Policy.
Consent management: We use the consent management platform Cookiebot, provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, to obtain, store and document your consent choices. Cookiebot stores your choice in your browser and keeps a consent record (including a truncated IP address, browser information, date and time, and the consent state) for up to 12 months as proof of consent. This use is strictly necessary (Section 25(2) no. 2 TDDDG); the related processing is based on Art. 6(1)(c) GDPR in conjunction with our documentation duties under Art. 7(1) GDPR.
Google Analytics 4: With your consent, we use Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure how the website and public Games are used and to improve the Services. Google Analytics sets first-party cookies (_ga and _ga_*, stored for up to 24 months) and processes usage data such as pages viewed, events, approximate location derived from a shortened IP address, and device information. We have configured a data retention period of 14 months and do not use Google Signals. Advertising conversion measurement requires separate marketing consent, as described below. Data may be transferred to Google LLC in the United States; Google LLC is certified under the EU-U.S. Data Privacy Framework. Google Analytics is loaded only after you grant statistics consent; if you decline or withdraw consent, no Google Analytics requests are made and existing analytics cookies are deleted. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG).
Google Ads and YouTube advertising: We advertise Baduz through Google Ads, including campaigns on YouTube. With your marketing consent, we use Google advertising conversion measurement, provided by Google Ireland Limited, to understand whether interactions with our advertisements lead to actions on Baduz, such as starting a Game, opening the editor or creating an account. This helps us attribute conversions to campaigns, assess advertising effectiveness and optimise our campaigns and advertising spend.
For this purpose, advertising click identifiers (such as the gclid URL parameter), campaign and referral information, browser and device information, and conversion events and their timestamps may be processed and shared with Google. First-party advertising cookies (_gcl_*, stored for up to 90 days) may be used to associate an advertising interaction with a later conversion. Conversion events recorded through Google Analytics 4 may be used in Google Ads for campaign measurement and optimisation; this also requires statistics consent. Data may be transferred to Google LLC in the United States, subject to the safeguards described in Section 7. Further information about Google’s processing is available in its Privacy Policy.
We use Google Consent Mode to communicate your consent choices to Google. Our Google Analytics tag is loaded only after statistics consent; advertising consent signals remain denied unless you also grant marketing consent. Declining or withdrawing marketing consent disables the advertising consent signals and deletes existing advertising cookies. With statistics consent alone, we may still measure activity on Baduz for analytics purposes, but advertising consent remains denied. You can change or withdraw either choice through Cookie Settings without losing access to core functions. Withdrawal applies to future processing and does not undo processing already performed. Details of the identifiers and storage durations are provided in our Cookie Policy. The legal basis for optional advertising measurement is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG).
Blocking technically necessary storage may prevent login, checkout or other requested functions from working. Refusing optional technologies does not prevent access to core functions.
6. Recipients and service providers
Within pabolo GmbH, access is limited to persons who need the data for product operation, customer support, moderation, security, finance, legal compliance or management. We may also disclose data to the following categories of recipients where necessary:
- identity and OAuth providers, including Google for Sign in with Google;
- cloud hosting, database, storage, content-delivery and security providers;
- AI model, inference and technical tool providers used to provide Creator functions;
- payment service providers, currently Stripe as merchant of record, and, where necessary, banks, tax advisers and accounting service providers;
- transactional e-mail, customer support and ticketing providers;
- analytics, advertising measurement or consent-management providers, currently Google Ireland Limited (Google Analytics and Google Ads, including YouTube campaign measurement, subject to the relevant consent) and Usercentrics A/S (Cookiebot consent management);
- professional advisers, insurers, auditors and parties involved in the establishment, exercise or defence of legal claims; and
- courts, law-enforcement authorities, regulators and other public bodies where disclosure is required or legally permitted.
Processors acting on our instructions are contractually bound under Art. 28 GDPR. Some providers, especially login and payment providers, may also process data as independent controllers for their own purposes. Their privacy notices apply to that processing.
7. International data transfers
Some service providers or their sub-processors may process personal data outside the European Union or European Economic Area. Where a transfer is made to a country without an adequacy decision, we use an appropriate transfer mechanism where required, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate. Transfers to certified United States organisations may also rely on the EU-U.S. Data Privacy Framework where its requirements are met.
You may request further information about the relevant safeguards by contacting us.
8. Storage periods and deletion
We retain personal data only for as long as it is necessary for the relevant purpose, while a legal basis applies, and as required to comply with statutory duties or establish, exercise or defend legal claims. The following rules apply subject to the exact production retention schedule:
| Data category | Typical retention rule |
|---|---|
| Account and OAuth identity data | For the duration of the User Account. After account deletion, active account data is erased or anonymised without undue delay, except for data required by law, security records and legal claims. |
| Creator projects and Games | During the active Subscription. When the Subscription ends, the contractual hosting right ends immediately and active Game and project data may be unpublished and deleted immediately. Any longer retention or availability is voluntary courtesy and is not guaranteed. |
| Backups | Deleted data may remain in protected backups until the backup cycle expires. Backups are not public and are not offered as a Creator restore service. The maximum backup retention period is 60 days, after which backups are overwritten or deleted. |
| Comments and votes | Until deleted, the associated Game or account is removed, or the data is no longer required. Moderation and legal records may be retained longer where necessary. |
| Reports, moderation cases and appeals | For the period needed to process the matter and comply with applicable complaint, transparency, safety and legal-claim requirements. The standard retention period is 12 months after the case is closed, unless a longer period is required by law or for legal claims. |
| Technical and security logs | For a short period necessary for security, diagnostics and abuse prevention. |
| Subscription and accounting records | Transaction and accounting records are retained for the statutory periods. Under German commercial law, booking documents are generally retained for eight years and business correspondence for six years; longer retention may apply in specific cases. |
| Consent and acceptance records | For as long as needed to demonstrate consent or contract acceptance and through the applicable limitation period. |
| Support communications | For the duration of the request and the applicable limitation period, unless earlier deletion is appropriate. |
Technical deletion can be irreversible. Reactivating a Subscription does not create a right to recover a previously deleted Game or project.
9. No general obligation to provide personal data
You are not generally obliged to provide personal data. However, without data required for OAuth authentication, account administration, the Creator tools or the Subscription, we cannot provide the relevant function or conclude or perform the contract. Contact details may also be necessary for us to respond to a request, report or complaint.
10. Your data protection rights
Subject to the legal requirements and limitations, you have the following rights:
- Right of access (Art. 15 GDPR);
- Right to rectification (Art. 16 GDPR);
- Right to erasure (Art. 17 GDPR);
- Right to restriction of processing (Art. 18 GDPR);
- Right to data portability (Art. 20 GDPR), where the statutory requirements are met;
- Right to object to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR); and
- Right to withdraw consent at any time with effect for the future.
The right to data portability concerns qualifying personal data and does not create a right to receive a standalone Game, source code, a project file, Baduz engine components, platform assets or another export that is technically unavailable outside Baduz.
10.1 Right to object
You have the right to object, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or Art. 6(1)(f) GDPR, including related profiling. We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for legal claims. Where data is processed for direct marketing, you may object at any time and we will stop that processing.
To exercise your rights, contact us using the details in Section 1. We may need information necessary to verify your identity. This does not require you to send more information than is reasonably necessary.
11. Complaints to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. For pabolo GmbH, the competent German supervisory authority is generally the data protection authority of Baden-Württemberg, without limiting your right to contact another competent authority.
12. Data security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include encrypted transmission, access controls, least-privilege permissions, secure OAuth and session handling, logging, vulnerability management, backup protections and incident-response procedures, to the extent appropriate to the risk and implemented in the production environment.
No internet service can guarantee absolute security. You should protect access to your third-party login account and promptly remove an unauthorised connection through the provider and contact us if you suspect misuse of your Baduz account.
13. Automated decision-making
Baduz currently does not use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. The AI-assisted Creator tools generate or modify Game elements in response to your instructions but do not make such legal or similarly significant decisions about you.
There is currently no automated content detector used for publication or moderation decisions. If this changes, we will assess the system, update the relevant information and implement human review and other safeguards where required before deployment.
14. Changes to this Privacy Policy
We may update this Privacy Policy when our Services, providers, legal requirements or processing activities change. We will publish the current version with its effective date. If a change materially affects registered Users, we will provide appropriate notice through the Platform or by e-mail where required.
Status: 24 July 2026
