English Complete version

This is a complete English translation. If wording differs, the German original controls.

Privacy at Tixagy

In short: Tixagy works without your real name, email address or telephone number. We do not use advertising identifiers or cross-service tracking and we do not sell personal data. We still need a pseudonymous account and technical usage data to provide games, rankings, social features and security.

Last updated: 26 August 2026

1. Controller and contact

The controller for the Tixagy app, Tixagy online service and this privacy website is:

Tridots UG (haftungsbeschränkt)
Rothenbaumchaussee 31
20148 Hamburg
Germany
represented by Michael Trippel

Email: service@tixagy.com

2. Scope of this policy

This policy applies to the Tixagy app for iOS and Android, the associated online service and the privacy website at tridots.de.

Apple or Google processes data under its own responsibility when you install Tixagy through the Apple App Store or Google Play. The privacy information of the relevant store applies to that processing.

3. Data processed by Tixagy

Pseudonymous account and device connection

On first launch, the app creates random technical identifiers for the installation and Tixagy account. The account is tied to the app installation; no traditional account with an email address and password is required.

We process, in particular:

Please avoid using your real name or other directly identifying information as your username.

Games, progress and social features

Depending on the features you use, we process moves, results, scores, game times and modes; Elo rating, rank, experience points, streaks, rewards and game history; matchmaking searches, invitations, challenges and rematches; friendships and friend requests; and selected profile settings.

Your username, Elo rating, rank and online status may be visible to other Tixagy users. Game-related statistics may also appear in rankings and profile views.

Chat, blocking and reports

For match chat, we process the messages you enter together with sender, recipient, game reference and timestamp. Chat is limited to participants in the relevant game.

If you block or report another user, we store the account identifiers involved, the stated reason, review status and, where needed, a reference to the relevant game or message. We use this information to prevent abuse, review reports and protect the community.

Optional push notifications

If you allow push notifications in your device settings, we process a push token, language, device platform, delivery status and time. Notifications may concern invitations, game events or optional reminders.

You can withdraw notification permission at any time in iOS or Android settings. The operating system will then prevent display or delivery. To also have the stored Tixagy push token removed, deactivate your account or contact service@tixagy.com.

First-party usage analytics

Tixagy records a limited set of in-app events such as first launch, starting or completing the tutorial, and use of core game and invitation functions. An event may contain its type, time, a random event identifier and a small number of feature-related properties.

This analysis takes place within the Tixagy service. We do not use an advertising platform, cross-service tracking or profiles for personalised advertising.

Technical connection data and local storage

Connections to the Tixagy service and visits to this website necessarily transmit technical data. This may include IP address, time, requested address, response status, browser or app version and operating system. Hosting providers may process this information in security and server logs.

The app locally stores settings, language, a cached profile, active bot games and events awaiting transmission. Authentication information is kept in the operating system’s protected storage. Removing the app deletes local data but does not automatically delete server-side account data.

We process data for the following purposes:

Elo ratings, rankings and game suggestions are calculated using rules. Tixagy does not make solely automated decisions producing legal or similarly significant effects within Article 22 GDPR.

5. Recipients and service providers

We use the following providers where necessary for operation, storage, delivery or security:

Where required, processors act under a data processing agreement. We may also disclose data where legally required or necessary to establish, exercise or defend legal claims.

The optional “Buy me a coffee” link opens an external service. Its own privacy policy applies after you follow the link. Payment data is not entered in the Tixagy app and is not processed by the Tixagy service.

We do not sell personal data or disclose it for personalised advertising.

6. International transfers

Some providers are US companies or use subprocessors outside the European Economic Area. Technical data, push tokens or support information may therefore be processed outside the EEA.

Where no adequacy decision applies, necessary transfers rely in particular on European Commission Standard Contractual Clauses and supplementary safeguards under Article 46 GDPR. The primary Tixagy service region is Frankfurt, but this does not completely exclude technical access or subprocessors in other countries.

7. Retention and deletion

Legal retention duties or evidence preservation may require longer storage in individual cases. Processing is then restricted to that purpose.

Account deactivation and permanent deletion

The app’s “delete account” function first deactivates the account, hides it and revokes active sessions. Reactivation using the proof stored on the device is possible for up to 30 days. After that, the proof is invalid and the account is scheduled for permanent deletion through the separate database-cleanup process, unless legal grounds require retention.

You can request permanent deletion without the app through our public account-deletion page or by emailing service@tixagy.com.

8. Privacy on this website

We do not set analytics, marketing or advertising cookies. Your selected language is stored only in your browser’s local storage. GitHub Pages may process technical access data for delivery and security as described in GitHub’s privacy statement linked above.

9. Security

We use appropriate technical and organisational measures, including HTTPS encryption in transit, short-lived access tokens, hashed server-side authentication credentials, access restrictions and regular cleanup of time-limited data. No system can guarantee protection against every risk.

10. Your rights and local information

Subject to applicable law, you have rights of access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests, and withdrawal of consent for the future. Send requests to service@tixagy.com. We may request proportionate proof that the relevant Tixagy account belongs to you.

The controller is established in Germany, and the EU GDPR is the primary legal framework. You may complain to a data-protection authority, particularly in the country where you live or work. The controller’s lead authority is the Hamburg Commissioner for Data Protection and Freedom of Information.

United Kingdom: Where UK data-protection law applies, references to the GDPR should also be read as references to the UK GDPR, supplemented by the Data Protection Act 2018. UK users may complain to the Information Commissioner’s Office.

11. Changes

We update this policy when Tixagy, its providers or applicable law changes materially. The current version is available at tridots.de.