Privacy - Cairn

What this site collects, why, and what you can do about it. Nothing here has changed since 1 September 2026.

Who is responsible

Maffin e.U., Brochweg 12, 6100 Mösern, Austria.
Email: admin@dasmaffin.com. Full details on the imprint.

We are not required to appoint a data protection officer and have not appointed one. Write to the address above and you reach the person who runs this.

The site itself

This part applies wherever you are on the site. Last changed 13 August 2026.

Signing in with Steam

What is kept
Your SteamID, which is the public number identifying your Steam account, the moment you first signed in, the moment you last signed in, and which permissions on this site have been granted to you. Signing in happens at Steam: you type your password on Valve's pages, never on ours, and we never see it. Steam tells us the SteamID and nothing else.
What for
To know who you are between pages, and to decide what you are allowed to see.
On what basis
Article 6(1)(b) GDPR - it is what you asked for by signing in. There is nothing on this site you have to sign in to read unless it is somebody's private data.
For how long
Until you ask for it to be removed. Ask and it is removed.
Who can see it
You, and the accounts holding the permission to manage permissions.

Signing in with an email address

What is kept
Your email address, a hash of your password, when the account was made and when it was last used, and a name if you chose to give one. The password itself is never stored and cannot be recovered from what is: it is put through a one-way function with a random salt, and even we cannot read it back.
What for
So that somebody without a Steam account can have one here. The address is used for two letters and nothing else: one asking you to confirm it is yours, and one carrying a link to choose a new password, sent only when somebody asks for it. There is no newsletter, no announcement, and no way to opt in to one.
On what basis
Article 6(1)(b) GDPR - it is what you asked for by making an account.
For how long
Until you ask for it to be removed. Ask and it is removed.
Who can see it
You, and the company that carries the letters, which is the mail provider for this domain. They are handed the address and the letter in order to deliver it and for nothing else. Nobody else is sent it and nothing is shown it.

Two factor authentication, if you turn it on

What is kept
A random secret shared with your authenticator app, when the code was last used, and the one-way hashes of ten recovery codes. The secret is not a hash and cannot be one - working out the same six digits your phone shows means knowing the same number it does. Nothing about your phone is collected: no device name, no push token, and no contact with the app you chose, which never speaks to this site at all.
What for
So that knowing your password is not enough to sign in as you.
On what basis
Article 6(1)(b) GDPR - it is what you asked for by turning it on.
For how long
Until you turn it off, which deletes the secret and every remaining recovery code, or until the account is removed.
Who can see it
Nobody. It is never shown again after the setup screen and is not sent anywhere.

Staying signed in

What is kept
One cookie holding a session identifier. No advertising cookie, no analytics, no tracking pixel, and nothing loaded from another company's servers - every stylesheet, script and font on this site is served from this site.
What for
So that following a link does not sign you out.
On what basis
Strictly necessary for a service you asked for, so no consent banner and nothing to opt out of.
For how long
Until the session ends or you sign out.
Who can see it
Nobody. It is an identifier, not information about you.

Web server logs

What is kept
The ordinary record a web server keeps of each request: the IP address it came from, the time, the address requested, and the browser's own description of itself.
What for
Keeping the site up, and working out what happened when something breaks or somebody attacks it.
On what basis
Article 6(1)(f) GDPR - our interest in a site that works and is not abused.
For how long
By the hosting provider, under their retention. Nothing on this site reads them as a matter of course.
Who can see it
The site's operator and the hosting provider.

Cairn

This part applies to the Cairn pages and to anything that sends data to them. Last changed 1 September 2026.

Reports you send from the game

What is kept
What you typed, which is whatever you chose to put in the box - including a way to reach you, if you decide to leave one. Alongside it the game sends what it knows about the run: its own version, the platform, the device and operating system, and an id the game made on this installation so two reports from the same place can be recognised as such. Anything the game attaches, such as a log or a picture of the screen, is kept with the report.
What for
To work out what went wrong. A report with none of that in it is a sentence somebody has to answer by guessing.
On what basis
Article 6(1)(a) GDPR - your consent, given by sending it. Nothing goes before that, and closing the form sends nothing.
For how long
At most 120 days, and 28 days after it is marked as finished with, whichever comes first. Ask sooner and it goes sooner.
Who can see it
Only the people who work on the game, on this site's own server. It is used to investigate what you reported and for nothing else.

Nothing else, for now

What is kept
Nothing. The game has no account to sign in to, collects no advertising or analytics identifier, and does not ask where you are.
What for
Worth saying plainly rather than leaving to be inferred from a short list.
On what basis
Not processing - a limit on it.
For how long
Not applicable.
Who can see it
Nobody, there being nothing to see. When the game starts doing any of this, these notes say so before it ships rather than afterwards.
Other parts of this site keep their own things:

What you can ask for

Under the GDPR you may ask us to:

For the rest, write to admin@dasmaffin.com from an address we can tie to your account, or include your SteamID. There is no form and no fee, and we answer within a month. Deleting is done by hand today, so ask and it is done rather than pressed.

If you are not happy with the answer

You can complain to the Austrian data protection authority: Osterreichische Datenschutzbehorde, Barichgasse 40-42, 1030 Wien, dsb@dsb.gv.at, dsb.gv.at. If you live in another EU country you may complain to your own authority instead.

Where it is kept

On servers rented from a hosting provider, who processes it on our behalf and under contract and does nothing else with it. Signing in involves Valve Corporation, whose own handling of your Steam account is described in the Steam Privacy Policy. We send Valve nothing about you; you are sent to them, and they tell us the SteamID you signed in with.

Children

Nothing here is aimed at children, and we do not knowingly keep data about anybody under 14. Tell us and it goes.

Changes

When this changes, the date at the top changes with it. There is no mailing list to be dropped from, because there is no mailing list.