Privacy
What this portal stores, why, who else sees it, and how long it stays. Written against what the software actually does, not against what a portal like this usually does.
Who is responsible
PH Productions, owner Paul Hammer, Anton-Burger-Weg 35, 60599 Frankfurt am Main, Germany · webmaster@playmations.com
There is no data protection officer. A one-person operation of this size is not required to appoint one.
You can read without an account
Browsing the catalogue, watching a preview and downloading a public clip as FBX or GLB need no
account and no sign-in. For those requests the server stores nothing about you: the web server
keeps no access log (see “How long”). Opening a clip and downloading it add one to that
clip’s view and download counts – a number, not a record of who (see the table). Taking the .awclip file for the
Animation Workbench does need an account, because it is recorded which account took which clip
(see the table).
What is stored
| Data | Why | Legal basis |
|---|---|---|
| Account: the user ID and display name from the account you sign in with (Discord, GitHub or Google) – one ID for each sign-in you connect, and when each was last used | So an upload has an owner and you can come back to it | Art. 6(1)(b) GDPR – performing the agreement you enter by signing in |
Uploads: the .awclip file, title, description, tags, the sharing choice |
The point of the service | Art. 6(1)(b) GDPR |
| Upload declaration: the exact wording you confirmed, the time, and your IP address | Evidence of who claimed the rights to a clip, if someone later disputes it | Art. 6(1)(f) GDPR – defending against rights claims |
| Comments: the text, who wrote it, when, and any edit | Showing the conversation under a clip, on the portal and in the Animation Workbench | Art. 6(1)(b) GDPR |
| Reports: what was reported, by whom, when | Moderation, and recognising repeated false reports | Art. 6(1)(c) and (f) GDPR – obligations under the Digital Services Act |
| Takedown requests: name, email, the claim, time, IP address | Answering the notice and documenting the decision | Art. 6(1)(c) GDPR |
| Audit log of uploads, removals and moderation decisions | Being able to reconstruct what happened | Art. 6(1)(f) GDPR |
| Profile and activity: your handle and bio, the clips you like, your collections with their titles and descriptions, who you follow, and the messages the portal sends you | The community features you use; what of this everyone sees is listed below | Art. 6(1)(b) GDPR |
Clips you take: which account took which clip as .awclip – on this site or
through Subscribe/Import in the Workbench – and when |
Counting how often a clip is used, and showing you which clips you already have | Art. 6(1)(b) GDPR |
| Views and downloads of a clip: only a number on the clip. Every opening of a clip page counts as a view, and so does every import in the Animation Workbench; for a view nothing about you is kept at all. So that an FBX or GLB download counts once a day per visitor, the server keeps a checksum of your account or IP address together with the clip in its memory until midnight (UTC). It is never written to disk, and the random value it is made with is discarded at midnight, after which the checksum cannot be traced back to anyone | Showing how often a clip is looked at and downloaded | Art. 6(1)(f) GDPR – showing members how their clips are received |
| Workbench sign-in: a token, of which only a SHA-256 hash is kept | Letting the Animation Workbench act for you without holding a password | Art. 6(1)(b) GDPR |
| Browser sign-in: a random value in a cookie, of which only a SHA-256 hash is kept, with when it was created and last used | Keeping you signed in on this browser, so you do not have to sign in on every visit | Art. 6(1)(b) GDPR |
| Operating log of the application: errors and warnings | Keeping the service running | Art. 6(1)(f) GDPR |
Each provider is asked for the least it offers, and none of them for your email address:
- Discord: the
identifyscope – your user ID, display name and picture. Not your servers, not your messages. - GitHub: no scope at all, which is GitHub’s public profile – user ID, username, name and picture. If your email is public on GitHub, GitHub sends it along anyway; it is dropped on arrival and never stored.
- Google: the
profilescope – your Google ID, name and picture. Not your email, not your contacts, nothing from other Google services.
Your display name and picture come from the account you first signed in with. Connecting another one later does not change them – so connecting Google does not put the name on your Google account onto your profile. You can choose another connected account for them yourself, with Use for profile on your account page; you confirm it with that provider once, and only then does its name and picture replace the old ones. Keep in mind that a Google name is usually your real name: if you sign up with Google, or choose it for your profile, that is the name everyone sees.
What your profile shows everyone
Signing in gives you a public profile at /u.html?u=<handle>. Anyone can open it,
with or without an account. It shows:
- your display name from the account you signed up with (or the one you chose for it), and your handle (the address; you can change it on your profile),
- the day you first signed in,
- anything you write in your bio,
- your profile picture, if that account has one,
- your public clips and public collections, and how often they were liked, saved and used,
- who you follow, and who follows you.
Profiles, public clips, public collections and comments are public web pages, and search engines may list them.
Following someone is therefore not private: it appears on your profile and on theirs, and the person you follow gets a message with your name. The same goes for a few other things you do with someone else’s clip: when you like it, add it to a public collection, or comment on it, its creator gets a message with your name, and a comment also tells the others who commented there. Adding a clip to an unlisted collection tells nobody. If you would rather not be seen doing it, do not follow - there is no hidden mode, because a half-public list would be the worst of both.
The legal basis is Art. 6(1)(b) GDPR: a community where nobody can be found is not the service you signed in for. What you can do about it: unfollow, empty your bio, change your handle, or close the account (below).
Your profile picture does not come from Discord, GitHub or Google
It would have been shorter to point the page straight at Discord, GitHub or Google. Two things speak against it, and both of them are about you rather than about us: the address contains your user ID there, which would then sit in the source of every page showing your picture - and your browser would fetch it from them, so they would learn the IP address of every visitor, including people who have no account there and are only reading.
So this server fetches the picture once and serves it from /avatar/<handle>.png.
It keeps a copy for a day. The provider sees this server, not the people reading the page.
No tracking
No analytics, no advertising, no tracking pixels, no external fonts or scripts. Everything the page loads comes from this server.
Three cookies are set, all of them needed for something you asked for, none of them used to recognise you anywhere else – which is why this site has no cookie banner:
JSESSIONIDholds your session while you use the site.XSRF-TOKENstops a foreign page from acting in your name.aw_signed_inis only set once you sign in. It keeps you signed in on this browser for 30 days after your last visit. Signing out deletes it here and on the server.
A few settings stay in your browser’s own storage and never reach the server: whether you
chose light or dark (aw-theme), and, while you link the Workbench to your account,
the device code (aw-link-code, gone when you close the tab). If you add your own
figures on the Characters page, the files and your choice of figure stay in this browser
(IndexedDB and aw.viewer.*); they are not uploaded.
Who else sees it
- Contabo GmbH, Munich, Germany – the server this runs on, including its backups, on our behalf (Art. 28 GDPR). Data stays in Germany.
- Discord, GitHub or Google – only the one you choose to sign in with, and only when you sign in. Your browser is sent to that provider, and what happens there is the provider’s own responsibility under its own privacy policy; it learns that you are signing in here. It then sends this server your user ID, name and picture, as described above. This server also fetches your picture from that provider, at most once a day (see above).
- Discord, as a tool of the operator – reports and takedown requests are announced in a private Discord channel so they are seen quickly. Such a notice contains the reported clip or comment, the reason given, and for a takedown request the name and email address entered in the form. The reporting account is not named. Legal basis: Art. 6(1)(f) GDPR – dealing with reports without delay, as the Digital Services Act expects.
Transfers to the USA. Discord Inc., GitHub Inc. and Google LLC are US companies; for people in the EU some of them act through a European subsidiary, which their privacy policies name. Where personal data reaches the USA through them, the transfer rests on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). All three companies are certified under it; the list is public at dataprivacyframework.gov.
Nothing is sold, and nothing is passed on for advertising.
How long
- Counting views and downloads: for downloads, the checksum until midnight (UTC), in memory only; the numbers themselves as long as the clip.
- IP addresses in declarations, reports and takedowns: replaced by a keyed pseudonym after 30 days. The record stays, the address does not. Running this is a scheduled job on the server, not a promise for later.
- Your account, uploads and comments: until you delete them or the account. A deleted comment stops being shown at once; the text itself is kept so that a report about it can still be looked at.
- After you close your account: the account row stays, but anonymous - name, handle, bio and picture are replaced, and every connected sign-in (the Discord, GitHub or Google ID) is deleted. Everything that pointed at you points at nobody: comments show “Deleted user”, a report you once filed loses its name. Your collections, likes and follows are deleted outright, and so are the messages you caused in other people’s inboxes (“… follows you now”); your clips are withdrawn from the catalogue. Moderation records stay, because they are what makes a decision about someone else explainable - they no longer name a person.
- Removed clips: the file goes, the record of the decision stays – it is what stops the same clip being uploaded again.
- Audit log and moderation decisions: kept as long as they can still matter for a dispute.
- Browser sign-in: 30 days after your last visit, or until you sign out.
- Logs: the web server keeps no access log. The application’s own operating log holds errors and warnings; it is limited in size, overwritten as it fills, and discarded with every update of the portal.
Your rights
You may ask for access (Art. 15), correction (Art. 16), deletion (Art. 17), restriction (Art. 18), portability (Art. 20), and you may object to processing based on legitimate interests (Art. 21). One email to the address above is enough; no form.
A copy of your data needs no email: Download your data on your
account page gives you one ZIP file with everything the portal keeps about
your account – your profile and sign-ins, your clips as the .awclip files you
uploaded, your collections, comments, likes, follows and messages, in JSON. That covers access
(Art. 15) and portability (Art. 20) for your account. Reports others filed about you are not in it,
because they name the person who reported; ask for those by email.
Deletion needs no email either: the button is on the same page, under “Closing your account”. You reach the page from the menu under your name at the top right. It says what goes and what stays before it does anything.
You may also complain to a supervisory authority. The one responsible for us is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (the Hessian Commissioner for Data Protection and Freedom of Information), Wilhelmstraße 7, 65185 Wiesbaden, Germany – datenschutz.hessen.de. You can also turn to the authority where you live or work.
Changes
If this page changes in a way that affects you, the change is announced on the portal before it takes effect.