GDPR transparency
Privacy policy
Last updated: August 4, 2026
1. Controller and privacy contact
Personal contact details are loaded only on your request to reduce automated collection.
Privacy enquiries are answered through the contact method shown there.
2. Website delivery and server logs
The server processes technically necessary connection data such as IP address, time, requested URL, referrer, browser, and operating system to provide and protect the service. The legal basis is Article 6(1)(f) GDPR.
3. Necessary storage
Encrypted session and CSRF cookies and a language preference are used where necessary. Favorites and a limited search cache may be stored locally in your browser and can be deleted using browser controls.
4. Internal usage measurement
Searches, page views, and outbound clicks may be stored as internal events. The session identifier is stored only as an HMAC hash; plaintext IP addresses are not part of analytics events. Processing improves recommendations, data quality, and stability under Article 6(1)(f) GDPR.
5. IGDB game data and images
Game data is retrieved from IGDB server-side. Images may load directly from IGDB, which technically discloses your IP address and browser information to that provider.
6. YouTube trailers
Trailers use youtube-nocookie.com. Loading an embedded video may still establish a connection to Google/YouTube and transmit technical connection data.
7. Store and affiliate links
Opening an offer redirects you to a third party. WhatIsLike may record the outbound click internally and may transmit a technical partner identifier for clearly marked affiliate links.
8. Retention and rights
Data is retained only as long as required for its purpose, legal obligations, or abuse prevention. Subject to legal requirements, you have rights of access, rectification, deletion, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.
9. Changes
This policy is updated when functions, providers, or legal requirements change.