Last changed 11 October 2026
This policy explains what personal data Deskdrift collects, why, how long it is kept, and what rights you have. Plain English wherever the law allows it. If anything is unclear, write to support@deskdrift.eu and it will be explained.
Deskdrift has no sign-up. There is no email address and no password. The first time you drive, the server hands your device a random token, and that token is the whole of your identity here. One thing can put a name of yours in it, and only because you chose to: signing in through a game portal makes the name that portal knows you by your name here too, where this game can show it, which section 2 sets out.
The data controller for personal data processed through Deskdrift is Aliaksandr Palazok, an individual operating from the Republic of Poland. For data-protection enquiries, write to support@deskdrift.eu.
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with a designated supervisory authority, you have the right to lodge a complaint with it — the Urząd Ochrony Danych Osobowych (UODO) in Poland, or your local equivalent.
Identity: a nickname, the normalised form of it used to tell two players apart, a digest of your device token, the colour of your car, and five settings kept so the game works the same on every device you sign in from — which body your car has, which touch control scheme you drive with, how loud you keep the sound, how close the camera follows your car, and whether the camera leans into a corner or looks straight along your car. None of those five describes you, except that a body a reward opens says you earned it: a medal body says no more than the public leaderboards already show, and the van body says you once kept up the daily track seven days in a row, a bought-back day counting (see Return loops). They are kept on your account, so that choosing them once is enough, and also on the device you play on, so that the game starts with them before your account answers and a device with no account still remembers the body, the sound level, the camera distance and whether the camera leans for as long as the game may keep anything there. Which body your car has is the one of those five that anyone who reads a leaderboard can see, and the colour of your car is seen with it: both go out with each of your laps on a leaderboard, which anybody may read without an account, and the podium after a lap stands a track’s three fastest cars, or the day’s three fastest on the daily track, in the bodies and colours their players chose, and a ghost raced on a track can wear the body of the player whose lap it is. The nickname is drawn from a list rather than typed by you — unless you signed in through a game portal, in which case it is the name that portal knows you by, read from the portal again every time you sign in, and this game does not offer you another. The server keeps a digest of the token and never the token itself, so a copy of the database does not let anybody play as you.
Laps that reached a leaderboard: the track, the time, how many ticks it took, which version of the physics ran it, a digest of the inputs you drove, whether the server and your device agreed on the result, and, for a lap the server did not watch all of as it was driven, the reason it did not — that nothing of the lap arrived while it was being driven, say, or that a part of it went missing. The inputs themselves and the path your car took are kept for the laps a leaderboard or a ghost still needs.
Return loops: which days you played, which days you finished the daily track, and any day you bought back with a rewarded advert. Seven of those daily days in a row, a bought-back day counting, open the van body for your car; it is worked out from these records whenever it is read, so it goes when they do. If you choose the van, anyone who sees your car on a leaderboard, a podium or a ghost can tell that you once kept up the daily track seven days in a row, a bought-back day counting; the van itself says nothing about which days. While the daily days you have finished run at least three in a row up to today or yesterday, a bought-back day counting, your car wears stickers that anyone who sees it on a leaderboard, a podium or a ghost can see, and they cannot be turned off: a calendar at three days, two flames added at fourteen and a gold stripe at thirty. They are worked out from the same records whenever they are read and are stored nowhere. A sticker tells others that your run is still going and that you finished the daily track, or bought the day back, on each of the two, thirteen or twenty-nine days before today, including days whose laps are held for review and not shown on a board. Someone who looks day after day can tell the day your run began and how long it has lasted, from the day each sticker appears, the day it broke, and that a missed day was bought back; beside the board of the day, which shows who finished today’s and yesterday’s daily track, they can work out the exact length of your run. They come off at midnight UTC once a day is missed, and come back if that day is bought back. For each day you finished the daily track, the server also keeps your best time on it that day, a digest of the inputs you drove it with, the layout and the physics it was driven on, and whether that time was held for review or judged tool-assisted, which a judgement on your other laps on that track can also set. The board of the day shows that time beside your nickname, your car’s body and its colour; a time held for review or judged tool-assisted is kept but not shown.
Counts of what happens in a game, carrying nothing about who it happened to: that a lap started, that one finished or was left unfinished, that you restarted, opened the editor, published a track, raced a ghost, or that an advert was shown or paid out. Nine such things and no others. What the server keeps is a running total — the count, the date, which portal you signed in through, if any, and, for the five of those that happen on a track, which of the game’s own tracks it was. Four of them — starting a lap, finishing one, leaving one unfinished, and restarting — are also counted a second time against which touch control scheme was driving, so that the game can tell whether a scheme is one people finish laps with or one they give up on. That second total is deliberately thinner than the first: it carries the day, the count, the portal and the scheme, and never a track. A dimension makes any total narrower, and the paragraph below already says what a narrow total risks; keeping the track out of this one is what stops it from narrowing further than the totals you have already been told about. A track somebody built and published is never named, because a track has an author and naming it would make the count a record of how one person played. Nothing else rides along: not a time, not a name, not a device. Your token is what lets your device be heard at all, and it is forgotten the moment the count lands, so nothing in these totals names you: no nickname, no token, no device. What they are not is beyond all recovery, and saying otherwise would be the easiest sentence here to get wrong. A total carries the day it happened on, and this policy already records which days you played, so somebody holding the whole database could, on a day when hardly anybody played, narrow a total to a handful of people and sometimes to one. Nothing in the game ever makes that link, and asking to be forgotten removes the record of which days you played — which is the only thing that could have made it.
Things you made or wrote: a track you published — its name, its layout and that you are its author — and the text of any report you filed against somebody else’s track.
A keyed digest of your network address, described in section 5.
How a lap was driven, scored: the server measures the shape of your inputs — how often they change, how long you hold them, how fast you react — into a single number and a board that number puts the lap on. Section 10 says what that is and is not.
When your device first asked for a token and when it was last seen.
Operational logs: the web server and the game server each write a line per request that carries the address it came from, the path and the outcome. They are kept fourteen days and exist to diagnose faults and to answer abuse.
If you arrived through a game portal and signed in: the name of that portal, the identifier that portal uses for you, and the name it knows you by, which becomes your nickname here where this game can show it; where it cannot, you keep the name you hold here, which on your first sign-in is one drawn for you. Nothing else the portal sends is read or stored — your picture there is not.
Performance of a contract (GDPR Art. 6(1)(b)) — to deliver the game you are playing: your identity across sessions, leaderboards, ghosts, the daily track and anything you publish.
Legitimate interest (Art. 6(1)(f)) — for the keyed address digest that stops one machine flooding the leaderboards, for the verification that keeps physically impossible times off a board, for moderating tracks people report, and for reading your token long enough to know that a count in section 2 came from a device this server has met rather than from a script. These are balanced against your privacy by keeping the least that works and erasing it on a fixed schedule.
There is no processing on the basis of consent. The daily counts in section 2 are the nearest thing here to telemetry, and they are not put to you as a choice because nothing in them identifies you — there is no name, no token and no device in a total, and nothing in one that a request could be answered against. What they still are, and what asking to be forgotten does to them, is said in section 2 rather than glossed over here. Everything else is what the game needs in order to be the game. There is no marketing of any kind, and no processing on the basis of legal obligation, because there is no billing and no account.
Hosting: OVH SAS, France (EU). The server and its database run on one machine there. The host also snapshots that machine daily into its own infrastructure, which is what makes losing the machine survivable and which section 6 counts as a backup.
Mail: Porkbun, in the United States, forwards anything sent to the address named below. It is a processor for that mail alone and never sees the database. Write only what a question needs; there is no reason to send a token or anything else that identifies your device, and section 8 says what a request does need.
Game portals: if you play Deskdrift on a portal such as CrazyGames or Poki, that portal serves the game to you and is a separate controller under its own privacy notice. What Deskdrift sends it is nothing about you; what it may send Deskdrift, if you sign in, is the identifier and the name in section 2.
There is no advertising network reading this game, no analytics from anybody else, no data broker, and no other third party with a copy. The counts in section 2 are made and kept by this server alone and are sent nowhere.
When a lap arrives, the server keeps a keyed digest of the address it came from: HMAC-SHA256 under a secret only the server holds, cut to the first eight bytes. It is there so that a flood of laps from one machine can be recognised as one machine, and it is never turned back into an address — that is not possible, and it is not what it is for.
What defends the leaderboards while you play is a separate count held in memory and never written down, keyed the same way. The digest beside a lap is the record of where it came from, kept so a pattern can be seen after the fact rather than only in the moment.
It is erased after thirty days. A sweep inside the server does that every six hours; nothing has to be remembered by hand.
What this digest is not is the whole story of your address, and saying otherwise would be the easiest sentence to get wrong here: the request logs in section 2 do carry the address itself for fourteen days. The digest is the only form kept beside a lap, and the only form kept for thirty days.
Your identity and your laps: kept indefinitely until you ask to be forgotten. Nothing expires an account for inactivity, which is stated plainly rather than dressed as a period.
The address digest: thirty days, then erased.
Your best time on a day’s daily track: kept through the day after, then erased within six hours.
Short-lived records issued while you drive, which bind a lap to the moment it was started, are swept away continuously.
Operational logs: fourteen days, then rotated away.
The daily counts in section 2: kept for as long as the game runs. They hold no key to delete by, so asking to be forgotten cannot subtract your share from a total. What it does remove, on the same day, is the record of which days you played — and that record is the only thing that could ever have narrowed one of those totals towards you.
Backups: the database is dumped daily and fourteen dumps are kept, and the machine itself is snapshotted daily by the host. So anything deleted survives in a backup for up to fourteen days before ageing out — a deletion reaches the live database at once and the backups by expiry.
A track you published and a report you filed outlive a deletion request — section 8 says exactly why.
Deskdrift sets no cookies at all. Your token is held in your browser’s own local storage, or in the storage a game portal provides when you play there, and it is sent only to Deskdrift’s own server as an authorization header. Deskdrift itself carries no tracker, no advertising identifier and no fingerprinting.
A build published on a game portal loads that portal’s own script, because that is how the portal shows adverts and knows a lap has started. Deskdrift asks for that script itself, so the request tells the portal your address and your browser; what it does after that is the portal’s doing under its own notice, and it runs on the same page as your token. The copy of the game at deskdrift.eu/play/ loads no such script.
A portal hosting the game may set cookies of its own for its own purposes. That is the portal’s doing and its notice covers it.
You can erase everything yourself (Art. 17): open your name in the game and press “forget me”. Your nickname, the colour of your car, the settings you chose — which body your car has, which touch control scheme you drive with, how loud you keep the sound, how close the camera follows your car and whether the camera leans into a corner — and every lap you drove are deleted from the server and cannot be brought back.
Three things outlive that request, and they are named here because a promise that overstates itself is worse than a narrow one. A track you published stays up with its author shown as gone, because taking it down would empty the leaderboards other people raced it on. The text of a report you filed stays, no longer joined to you, because it is the evidence a moderator has to read to judge the decision it caused. And a moderator’s own record of any decision about your content stays, because that record cannot be edited or erased by anyone including us — which is the property that makes it worth keeping at all.
You can rectify your data (Art. 16) in the game: draw a different nickname, change the colour of your car, or change which body your car has, which touch control scheme you drive with, how loud you keep the sound, how close the camera follows your car and whether the camera leans into a corner, whenever you like. If you signed in through a game portal, your nickname is rectified where it comes from — change it on the portal and the next sign-in brings it here, where this game can show it, unless a moderator has replaced it, in which case you may draw one here — and the colour stays yours to change in the game.
For access (Art. 15), restriction (Art. 18), portability (Art. 20) and objection to legitimate-interest processing (Art. 21), write to support@deskdrift.eu. A reply comes within 30 days. Note what the design costs here, because it is a real limit rather than a formality: your identity is a token on your device and nothing else, so there may be no way to tell your data from a stranger’s without something that proves the device is yours — and do not send the token itself, since mail is not a safe place for a credential and anybody holding it could play as you. Say what you are asking for and we will say what is needed.
The game, its database and its backups stay within the EU. One processor sits outside it: the mail forwarding in section 4, in the United States, which carries correspondence and nothing else — no player data reaches it unless a player puts it in an email themselves.
Deskdrift is suitable for all ages and is published on portals whose audience includes children. That is why it is built the way it is: there is no account, no email address, no password and no advertising identifier, so there is nothing here that identifies a child any more than it identifies an adult.
Two things are measured about how the game is played, and both are named here rather than left out of a section about children. The server scores the shape of a lap’s inputs to tell hands from a program, and a high score sends the lap to a board of its own instead of the main one. It reads how the lap was driven and nothing about who drove it, it decides where a time appears and never what a player may do, and a person can ask about any such decision at the address in section 13. The other is the daily counts in section 2, which are totals of things that happened in the game — laps started, laps finished, adverts shown — and carry no name, no token and no device. What a total does carry, and what asking to be forgotten takes away from it, is set out there rather than promised away here.
What a player can put into the game is a nickname — drawn from a fixed list, or the one a game portal already knows them by — a track layout, and the text of a report. Nothing asks for a real name, an age, a school, a photograph or a location, and the game has no chat and no way for one player to send another a message.
Traffic is TLS-only. Tokens are stored as digests and never as themselves; an operator’s credential is compared in constant time, and a player’s token is matched by its digest in an index. The address digest is keyed with a server-held secret so it cannot be reversed by trying addresses. Rate limits and a proof-of-work gate stand in front of the routes that create anything. The operator surface is reachable only with an operator credential and every action on it is written to a record that cannot be edited or erased.
No online service can promise absolute security. If a breach occurs, affected players and the relevant supervisory authority will be notified in line with GDPR Art. 33–34.
This policy is updated when the game starts or stops collecting something, or when a regulation requires it. The date at the top is the date of the version you are reading.
Privacy questions, data-subject requests or formal notices: support@deskdrift.eu.