Privacy Policy

Last updated: August 2026

This Privacy Policy explains what information Mathalon (“we”) collects, how we use it, and the choices you have. Mathalon is used mostly by students, so it is written to be readable rather than lawyerly — and to meet Articles 12–14 of the EU General Data Protection Regulation (GDPR).

1. Who is responsible for your data

Mathalon is operated by Peter Christer Andreas Nödtveidt, a private individual based in Sweden. That person is the data controller for everything described here.

A postal address is available on request — we will provide it to you, or to a supervisory authority, if asked.

Privacy contact: [email protected]. We have not appointed a Data Protection Officer, and are not required to: we carry out no large-scale systematic monitoring and process no special categories of data.

2. Information we collect

Account information — your username, email address, a hashed password (never the password itself), and your year of birth. We ask for the year only, never a full date of birth: it is the least precise value that still lets us enforce the age limit in section 4.

Guest sessions — you can try Mathalon without registering. A guest account holds no username, email or password, only the problems attempted and the rating built from them. Registering later upgrades that same account, so nothing you solved is lost.

Activity data — problems you attempt, answers you submit, ratings, matches, Rush and Redline results, streaks, saved lists and similar gameplay telemetry used to power ratings, leaderboards and your progress.

Integrity signals — for rated play we record simple anti-cheat signals on an attempt, such as paste events and how long an answer took. They are used to detect manipulation, nothing else.

Technical data — basic log and device information (IP address, browser type, requested page, timestamp) generated automatically whenever any browser contacts a web server.

3. Why we use it, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Running your account, saving your progress, showing your profileArt. 6(1)(b) — performing the contract you enter into when you register
Calculating ratings, leaderboards and problem difficultyArt. 6(1)(b) — this is the service itself
Detecting cheating, abuse and bot traffic; keeping the platform secureArt. 6(1)(f) — our legitimate interest in a rating that means something
Aggregate, non-identifying statistics about how problems performArt. 6(1)(f) — our legitimate interest in improving the problem library
Newsletters and product updatesArt. 6(1)(a) — your consent, given by opting in and withdrawable at any time
Answering your emails and handling rights requestsArt. 6(1)(c) — our legal obligations under the GDPR

We do not sell personal data, we run no advertising, and we build no profiles beyond the ratings and statistics described above.

4. Young players — and the 13 year minimum

Mathalon is built for students, so we assume many of our users are minors and design for that. Two things follow.

You must be at least 13 to hold a registered account. Under GDPR Art. 8, a service offered directly to a child may rely on the child’s own consent only from a minimum age each member state sets; Sweden sets it at 13. We therefore ask for your year of birth when you register and decline registration below that age.

If we learn that a registered account belongs to someone under 13, we delete it and its data without undue delay. If you are a parent or guardian and believe your child has created an account, write to [email protected] and we will remove it.

For every user who may be a minor, the following apply by default:

  • No advertising, ad tracking or third-party marketing pixels anywhere on the site.
  • We ask for the minimum: a username, an email address and a birth year. Never a real name, a school, a phone number or a photo.
  • Your username is public on leaderboards and profiles. Pick one that does not identify you in real life — we will happily change it if you picked badly.
  • We never publish your email address, your birth year or your age.
  • Deletion requests from a young user are honoured without argument.

5. Cookies and browser storage

We use cookies and similar storage to keep you signed in and to remember preferences such as your language and theme. There is no advertising or analytics cookie and no third-party tracker, so no consent banner is required: these are strictly necessary for a service you asked for. Disabling them signs you out and affects core functionality.

6. Marketing emails

We only send newsletters and occasional product updates if you have opted in — this is never required to use the Service. You can change your mind at any time from your account preferences, and every marketing email includes an unsubscribe option. Account and security messages (such as password or sign-in notices) are not marketing and are sent regardless of this setting.

7. Who else processes your data

We keep this list as short as we can. Each acts as a processor on our instructions, under a data processing agreement.

ProcessorWhat they do
RailwayHosts the application servers and the PostgreSQL database, in the EU (Netherlands, europe-west4).
ResendDelivers transactional email only — verification and password-reset messages. Established in the United States; sees the recipient email address and the message it delivers, nothing else.

That is the complete list. If it grows, it is updated here before the new processor starts handling any data.

Public profile elements — username, rating, leaderboard position — are visible to other users by design. We also disclose data where legally required, for example in response to a valid order from a competent authority.

8. Transfers outside the EU/EEA

Some processors are established in the United States or may process data there. Where that happens the transfer is covered by the European Commission’s Standard Contractual Clauses, and where applicable by the processor’s certification under the EU–US Data Privacy Framework. Ask us and we will tell you which safeguard applies to a specific transfer.

9. How long we keep things

DataRetention
Account information (username, email, password hash, birth year)While the account exists. Erased when you delete the account — see section 10.
Attempts, ratings, matches, streaks and listsWhile the account exists. After deletion they survive only in pseudonymous form, detached from your identity, so opponents' match histories stay intact.
Guest accounts that never solved anythingSwept automatically — an empty guest row is reaped rather than kept.
Telemetry events behind product statistics90 days, then dropped automatically.
Server access logsUp to 30 days, unless a specific log is held longer for a security investigation.
Encrypted database backupsUp to 30 days, after which deleted data disappears from backups too.

10. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, port and object.

You can delete your account yourself at any time under Settings → Delete account. That erases your username, email and password; past matches and ratings are retained pseudonymously so other players’ histories stay intact. For anything else — a copy of your data, a correction, an objection — email [email protected] from the address on your account. We answer within one month, free of charge unless a request is manifestly unfounded or excessive.

Where we rely on your consent — marketing email — you may withdraw it at any time without affecting what came before.

If you think we have handled your data badly, you can complain to your national data protection authority. In Sweden that is Integritetsskyddsmyndigheten (IMY), imy.se.

11. Security

Passwords are stored only as salted hashes. Traffic is encrypted in transit. Access to the production database is limited to the operator of the Service. No system is perfectly secure, and we will notify you and the supervisory authority as required by Articles 33 and 34 if a breach ever puts your data at risk.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes we will update the date above and take reasonable steps to notify you before they take effect. See also our Terms of Service.