Privacy Policy
This Privacy Policy explains what information Mathalon (“we”) collects, how we use it, and the choices you have. Mathalon is used mostly by students, so it is written to be readable rather than lawyerly — and to meet Articles 12–14 of the EU General Data Protection Regulation (GDPR).
1. Who is responsible for your data
Mathalon is operated by Peter Christer Andreas Nödtveidt, a private individual based in Sweden. That person is the data controller for everything described here.
A postal address is available on request — we will provide it to you, or to a supervisory authority, if asked.
Privacy contact: [email protected]. We have not appointed a Data Protection Officer, and are not required to: we carry out no large-scale systematic monitoring and process no special categories of data.
2. Information we collect
Account information — your username, email address, a hashed password (never the password itself), and your year of birth. We ask for the year only, never a full date of birth: it is the least precise value that still lets us enforce the age limit in section 4.
Guest sessions — you can try Mathalon without registering. A guest account holds no username, email or password, only the problems attempted and the rating built from them. Registering later upgrades that same account, so nothing you solved is lost.
Activity data — problems you attempt, answers you submit, ratings, matches, Rush and Redline results, streaks, saved lists and similar gameplay telemetry used to power ratings, leaderboards and your progress.
Integrity signals — for rated play we record simple anti-cheat signals on an attempt, such as paste events and how long an answer took. They are used to detect manipulation, nothing else.
Technical data — basic log and device information (IP address, browser type, requested page, timestamp) generated automatically whenever any browser contacts a web server.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Running your account, saving your progress, showing your profile | Art. 6(1)(b) — performing the contract you enter into when you register |
| Calculating ratings, leaderboards and problem difficulty | Art. 6(1)(b) — this is the service itself |
| Detecting cheating, abuse and bot traffic; keeping the platform secure | Art. 6(1)(f) — our legitimate interest in a rating that means something |
| Aggregate, non-identifying statistics about how problems perform | Art. 6(1)(f) — our legitimate interest in improving the problem library |
| Newsletters and product updates | Art. 6(1)(a) — your consent, given by opting in and withdrawable at any time |
| Answering your emails and handling rights requests | Art. 6(1)(c) — our legal obligations under the GDPR |
We do not sell personal data, we run no advertising, and we build no profiles beyond the ratings and statistics described above.
4. Young players — and the 13 year minimum
Mathalon is built for students, so we assume many of our users are minors and design for that. Two things follow.
You must be at least 13 to hold a registered account. Under GDPR Art. 8, a service offered directly to a child may rely on the child’s own consent only from a minimum age each member state sets; Sweden sets it at 13. We therefore ask for your year of birth when you register and decline registration below that age.
If we learn that a registered account belongs to someone under 13, we delete it and its data without undue delay. If you are a parent or guardian and believe your child has created an account, write to [email protected] and we will remove it.
For every user who may be a minor, the following apply by default:
- No advertising, ad tracking or third-party marketing pixels anywhere on the site.
- We ask for the minimum: a username, an email address and a birth year. Never a real name, a school, a phone number or a photo.
- Your username is public on leaderboards and profiles. Pick one that does not identify you in real life — we will happily change it if you picked badly.
- We never publish your email address, your birth year or your age.
- Deletion requests from a young user are honoured without argument.
6. Marketing emails
We only send newsletters and occasional product updates if you have opted in — this is never required to use the Service. You can change your mind at any time from your account preferences, and every marketing email includes an unsubscribe option. Account and security messages (such as password or sign-in notices) are not marketing and are sent regardless of this setting.
8. Transfers outside the EU/EEA
Some processors are established in the United States or may process data there. Where that happens the transfer is covered by the European Commission’s Standard Contractual Clauses, and where applicable by the processor’s certification under the EU–US Data Privacy Framework. Ask us and we will tell you which safeguard applies to a specific transfer.
9. How long we keep things
| Data | Retention |
|---|---|
| Account information (username, email, password hash, birth year) | While the account exists. Erased when you delete the account — see section 10. |
| Attempts, ratings, matches, streaks and lists | While the account exists. After deletion they survive only in pseudonymous form, detached from your identity, so opponents' match histories stay intact. |
| Guest accounts that never solved anything | Swept automatically — an empty guest row is reaped rather than kept. |
| Telemetry events behind product statistics | 90 days, then dropped automatically. |
| Server access logs | Up to 30 days, unless a specific log is held longer for a security investigation. |
| Encrypted database backups | Up to 30 days, after which deleted data disappears from backups too. |
10. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port and object.
You can delete your account yourself at any time under Settings → Delete account. That erases your username, email and password; past matches and ratings are retained pseudonymously so other players’ histories stay intact. For anything else — a copy of your data, a correction, an objection — email [email protected] from the address on your account. We answer within one month, free of charge unless a request is manifestly unfounded or excessive.
Where we rely on your consent — marketing email — you may withdraw it at any time without affecting what came before.
If you think we have handled your data badly, you can complain to your national data protection authority. In Sweden that is Integritetsskyddsmyndigheten (IMY), imy.se.
11. Security
Passwords are stored only as salted hashes. Traffic is encrypted in transit. Access to the production database is limited to the operator of the Service. No system is perfectly secure, and we will notify you and the supervisory authority as required by Articles 33 and 34 if a breach ever puts your data at risk.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes we will update the date above and take reasonable steps to notify you before they take effect. See also our Terms of Service.