Last updated 19 August 2026
This policy explains what wastedpenguinz.com and the Wasted Penguinz mobile and desktop apps collect about you, why, and what you can do about it. It describes what the service actually does — not a generic template.
A username and a password, which is stored only as a bcrypt hash — we cannot read it. Optionally an email address and a phone number, each confirmed before use. If you switch on two-factor authentication we store your authenticator secret and recovery codes in encrypted form. Legal basis: performance of our agreement with you.
Messages in public rooms, private messages, group messages, uploaded images and files, reactions, profile fields (bio, favourite track, country, avatar, banner, links) and any support tickets you open. Message bodies and uploaded files are encrypted at rest on our server. Legal basis: performance of our agreement with you.
Your IP address, browser or app user agent, session identifiers, connection and presence times (including "last seen"), and records of moderation actions taken on your account. IP addresses are used to rate-limit sign-in attempts, to detect and block abuse, and to enforce bans. Legal basis: our legitimate interest in keeping the service secure and usable for everyone.
XP, levels, badges, quests, streaks, game scores, leaderboard positions and event participation. Legal basis: performance of our agreement with you.
If you donate, subscribe to VIP, buy merchandise or order a personal service, we record the transaction: amount, currency, date, what was bought, and the identifiers our payment provider gives us. We never see or store your card number — that goes directly to Stripe. For physical orders we also process the delivery name and address you give us. Legal basis: performance of our agreement with you, and our legal obligation to keep accounting records.
Transactional email (address confirmation, password reset, order confirmations) is sent on the basis of our agreement with you. Newsletters, the weekly digest and streak reminders are sent only if you have opted in, and every one of them carries an unsubscribe link. Legal basis: consent, which you can withdraw at any time.
If you allow notifications, we store the push subscription your browser or device gives us so we can deliver them. Turning notifications off removes it. Legal basis: consent.
Messages written in another language can be translated for you automatically. The translation runs on our own server, on software we host ourselves — the text of your messages is not sent to Google, DeepL or any other translation service. Translations are cached on our server alongside the message so the same text is translated only once. You can turn this off in Settings. Legal basis: our legitimate interest in an international community being able to understand each other.
We do not sell your data and we do not use it for advertising. We use the following providers, each only for the purpose listed:
| Provider | Purpose | Where |
|---|---|---|
| Hetzner Online GmbH | Server hosting — the database and uploaded files live here | Germany |
| Stripe | Card payments, VIP subscriptions, donations, shop checkout | Ireland / USA |
| Resend | Transactional and newsletter email | USA |
| Twilio and 46elks | SMS for phone sign-in and verification | USA / Sweden |
| PostNord | Shipping of merchandise orders — name and delivery address only | Sweden |
| Giphy | GIF search — your search terms reach Giphy when you use the GIF picker | USA |
| Twitch | The embedded stream player, when a stream is shown | USA |
| Cloudflare | DNS for our domain | USA |
Voice and video calls run on our own servers — the media relay (TURN) and the call server (LiveKit) are operated by us in Germany, not by a third party.
Providers outside the EU/EEA receive data under the European Commission's Standard Contractual Clauses, or under the EU–US Data Privacy Framework where they are certified.
We may also disclose data where the law requires it, or where it is necessary to establish, exercise or defend legal claims.
Under the GDPR you can ask us to:
Write to privacy@wastedpenguinz.com and we will answer within one month. If you think we have handled your data wrongly you can complain to the Swedish authority, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy.se.
You can delete your account yourself: open Settings → Delete account, confirm with your password, and type your username. It happens immediately and cannot be undone. Precisely what happens:
If you would rather have your public posts removed as well, email us and we will consider the request.
Passwords are hashed with bcrypt. Message bodies and uploaded files are encrypted at rest. All traffic runs over TLS. Two-factor authentication is available to every account and required for staff. The server is hardened — key-only SSH access, an active firewall, automatic security updates and rate limiting on sign-in.
We set one cookie: your signed-in session. There are no advertising or analytics cookies and no third-party trackers. We use your browser's local storage to remember preferences such as your theme.
The service is not intended for children under 13, and we do not knowingly create accounts for them. If you believe a child has an account here, contact us and we will remove it.
If we change this policy we will update the date at the top and, for anything significant, tell you in the app.