Privacy
Last updated: 24 August 2026
GeoLeague is a free geography game. This page explains what data it handles and your choices — we keep it minimal, and you can play the whole game without creating an account or providing account or profile details.
Playing without an account
We do not store account or profile data when you play without an account. Your progress, best scores and preferences stay on your device (browser local storage), alongside a small cookie that remembers your language, and we do not send that local progress off your device. Our hosting, cookieless aggregate usage analytics and errors-only monitoring providers may process the limited technical data described below.
When you sign in
Signing in is optional and handled by Supabase using email — either a one-time magic link or a password. If you create an account we store your email address, your chosen username/nickname, your ratings (ELO) and badges, and your multiplayer match history, so we can show your profile, leaderboards, friends and ranked games.
Cookies
We use only two, both necessary: an essential session cookie (set when you are signed in, to keep you logged in) and a functional cookie that remembers your chosen language. We do not use advertising or cross-site tracking cookies. Usage statistics are aggregate and cookieless.
Who processes your data
Supabase (authentication and database), Vercel (hosting and cookieless analytics), and Sentry (errors-only monitoring). We do not sell your data or share it for advertising.
Error monitoring
Sentry provides errors-only monitoring for deployed Preview and Production versions of the web app. We send only a privacy-filtered error event with its deployment release and environment, a fixed error description, safe source-code coordinates and limited aggregate operational context. We do not send account, room or player identifiers, email addresses, request bodies, headers, cookies, query strings, guesses, answers, breadcrumbs or free-form error messages, and we do not add IP-address fields to events. A browser connection to Sentry necessarily reveals its source network IP to Sentry’s infrastructure; that is a transport property, not application event data. Tracing, session replay, logs, profiling, client reports and transaction collection are disabled. PartyKit emits separate identifier-free aggregate console events and does not use Sentry.
Your rights & choices
You can delete your account at any time from Account → Delete account, which removes your stored data. You can also play entirely anonymously. For any access, correction or deletion request, just email us.
Children
GeoLeague is not directed at children under 16, and we do not knowingly collect their personal data.
Changes & contact
We may update this policy; the date above reflects the latest version. Questions? Email contact@kamilpabin.cloud.