Privacy notice
Tilewake demo and Jutland Forge website · Last updated: 1 October 2026
Who is responsible?
Wolfgang Dallmeyer, operating Jutland ForgeBreslauer Straße 10
24537 Neumünster, Germany
Email: wdallmeyer@gmail.com
Your demo profile and game data
No Steam account, email address or real name is required to play the demo. Please choose an alias that does not reveal personal information.
To recognise your profile, process your games and provide online leaderboards, we store:
- Your chosen alias, a server-assigned player ID, a demo-profile marker, registration time and last-sign-in time.
- Game data linked to your profile: scores, layouts, result times, outcomes, completion times, daily-challenge participation, rewards, token balances and derived statistics.
- A hash of your identity credential, plus hashed session tokens and their validity information.
Your alias and the results, ranks and statistics displayed in online leaderboards are visible to other players. Your authentication credentials are not displayed.
A randomly generated identity credential is saved on your device together with your alias and player ID. This lets the demo recognise you on later launches without a separate account registration or password. Our server stores only a hash of that credential. Deleting the local identity file prevents you from signing in with that identity; it does not delete the server profile or its game results.
This processing is necessary to provide the demo and its online functions that you request (Article 6(1)(b) GDPR). The alias, identity and game data are required to use these functions. The demo has no offline mode.
Website, downloads and access logs
When you visit the website, download the demo or use the online service, your IP address and request information are processed to deliver the content and operate the service. The website and API keep IIS access logs for availability, troubleshooting and prevention of abuse. These operational and security purposes are our legitimate interests under Article 6(1)(f) GDPR.
The logs contain the date and time, client IP address, username field (which may be empty), server IP address and port, HTTP method, requested URL path and query string, HTTP status and substatus, Win32 status, bytes sent and received, processing time, user agent and referrer.
This website does not use analytics, advertising trackers, tracking cookies or embedded third-party media. Its images and styles are served locally.
Hosting and external links
The website and online services are hosted by OuiHeberg SARL, 9 rue des Colonnes, 75002 Paris, France. The server used for this website and the demo service is located in Frankfurt am Main, Germany. The hosting provider processes connection data as needed to operate the infrastructure.
Discord is linked from the website rather than embedded. If you follow the link, Discord processes data under its own privacy policy.
How long we keep data
- Demo profiles and linked game data: deleted once 30 days have elapsed after the end of the demo, during the next hourly cleanup. The demo currently has no scheduled end date. Profile deletion also removes associated results, authentication records, tokens, daily participation and statistics.
- Sessions: session tokens are valid for eight hours. Expired session records are deleted once one day has elapsed after expiry, during the next hourly cleanup. The persistent identity credential hash is removed with the profile.
- IIS access logs: deleted in a daily cleanup once their last modification is more than 14 days old. This period applies to each log file rather than to each individual request.
Your rights and contact
Subject to the conditions in the GDPR, you may request access, correction, deletion, restriction of processing and data portability. You may object to processing based on legitimate interests for reasons relating to your particular situation.
Contact wdallmeyer@gmail.com for privacy enquiries or requests. We may need to verify that a request relates to your demo profile; an alias alone does not prove ownership. Do not send your identity credential or session token by email.
You may complain to a competent data protection supervisory authority, including one in your place of residence, work or the alleged infringement. The authority responsible for our location is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD).
Further information: official text of the General Data Protection Regulation.