Privacy - Cairn
What this site collects, why, and what you can do about it. Nothing here has changed since 1 September 2026.
Who is responsible
Maffin e.U., Brochweg 12, 6100 Mösern, Austria.
Email: admin@dasmaffin.com.
Full details on the imprint.
We are not required to appoint a data protection officer and have not appointed one. Write to the address above and you reach the person who runs this.
The site itself
This part applies wherever you are on the site. Last changed 13 August 2026.
Signing in with Steam
- What is kept
- Your SteamID, which is the public number identifying your Steam account, the moment you first signed in, the moment you last signed in, and which permissions on this site have been granted to you. Signing in happens at Steam: you type your password on Valve's pages, never on ours, and we never see it. Steam tells us the SteamID and nothing else.
- What for
- To know who you are between pages, and to decide what you are allowed to see.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by signing in. There is nothing on this site you have to sign in to read unless it is somebody's private data.
- For how long
- Until you ask for it to be removed. Ask and it is removed.
- Who can see it
- You, and the accounts holding the permission to manage permissions.
Signing in with an email address
- What is kept
- Your email address, a hash of your password, when the account was made and when it was last used, and a name if you chose to give one. The password itself is never stored and cannot be recovered from what is: it is put through a one-way function with a random salt, and even we cannot read it back.
- What for
- So that somebody without a Steam account can have one here. The address is used for two letters and nothing else: one asking you to confirm it is yours, and one carrying a link to choose a new password, sent only when somebody asks for it. There is no newsletter, no announcement, and no way to opt in to one.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by making an account.
- For how long
- Until you ask for it to be removed. Ask and it is removed.
- Who can see it
- You, and the company that carries the letters, which is the mail provider for this domain. They are handed the address and the letter in order to deliver it and for nothing else. Nobody else is sent it and nothing is shown it.
Two factor authentication, if you turn it on
- What is kept
- A random secret shared with your authenticator app, when the code was last used, and the one-way hashes of ten recovery codes. The secret is not a hash and cannot be one - working out the same six digits your phone shows means knowing the same number it does. Nothing about your phone is collected: no device name, no push token, and no contact with the app you chose, which never speaks to this site at all.
- What for
- So that knowing your password is not enough to sign in as you.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by turning it on.
- For how long
- Until you turn it off, which deletes the secret and every remaining recovery code, or until the account is removed.
- Who can see it
- Nobody. It is never shown again after the setup screen and is not sent anywhere.
Staying signed in
- What is kept
- One cookie holding a session identifier. No advertising cookie, no analytics, no tracking pixel, and nothing loaded from another company's servers - every stylesheet, script and font on this site is served from this site.
- What for
- So that following a link does not sign you out.
- On what basis
- Strictly necessary for a service you asked for, so no consent banner and nothing to opt out of.
- For how long
- Until the session ends or you sign out.
- Who can see it
- Nobody. It is an identifier, not information about you.
Web server logs
- What is kept
- The ordinary record a web server keeps of each request: the IP address it came from, the time, the address requested, and the browser's own description of itself.
- What for
- Keeping the site up, and working out what happened when something breaks or somebody attacks it.
- On what basis
- Article 6(1)(f) GDPR - our interest in a site that works and is not abused.
- For how long
- By the hosting provider, under their retention. Nothing on this site reads them as a matter of course.
- Who can see it
- The site's operator and the hosting provider.
Cairn
This part applies to the Cairn pages and to anything that sends data to them. Last changed 1 September 2026.
Reports you send from the game
- What is kept
- What you typed, which is whatever you chose to put in the box - including a way to reach you, if you decide to leave one. Alongside it the game sends what it knows about the run: its own version, the platform, the device and operating system, and an id the game made on this installation so two reports from the same place can be recognised as such. Anything the game attaches, such as a log or a picture of the screen, is kept with the report.
- What for
- To work out what went wrong. A report with none of that in it is a sentence somebody has to answer by guessing.
- On what basis
- Article 6(1)(a) GDPR - your consent, given by sending it. Nothing goes before that, and closing the form sends nothing.
- For how long
- At most 120 days, and 28 days after it is marked as finished with, whichever comes first. Ask sooner and it goes sooner.
- Who can see it
- Only the people who work on the game, on this site's own server. It is used to investigate what you reported and for nothing else.
Nothing else, for now
- What is kept
- Nothing. The game has no account to sign in to, collects no advertising or analytics identifier, and does not ask where you are.
- What for
- Worth saying plainly rather than leaving to be inferred from a short list.
- On what basis
- Not processing - a limit on it.
- For how long
- Not applicable.
- Who can see it
- Nobody, there being nothing to see. When the game starts doing any of this, these notes say so before it ships rather than afterwards.
What you can ask for
Under the GDPR you may ask us to:
- Show you what we hold about you (Article 15). You do not have to write to anybody for this one: your profile has a button that gathers it from every part of the site and sends it to you as a file, once a week.
- Correct it if it is wrong (Article 16).
- Delete it (Article 17).
- Stop using it while a disagreement is sorted out (Article 18).
- Hand it over in a form you can take elsewhere (Article 20).
- Object to any use we base on our own legitimate interest (Article 21).
For the rest, write to admin@dasmaffin.com from an address we can tie to your account, or include your SteamID. There is no form and no fee, and we answer within a month. Deleting is done by hand today, so ask and it is done rather than pressed.
If you are not happy with the answer
You can complain to the Austrian data protection authority: Osterreichische Datenschutzbehorde, Barichgasse 40-42, 1030 Wien, dsb@dsb.gv.at, dsb.gv.at. If you live in another EU country you may complain to your own authority instead.
Where it is kept
On servers rented from a hosting provider, who processes it on our behalf and under contract and does nothing else with it. Signing in involves Valve Corporation, whose own handling of your Steam account is described in the Steam Privacy Policy. We send Valve nothing about you; you are sent to them, and they tell us the SteamID you signed in with.
Children
Nothing here is aimed at children, and we do not knowingly keep data about anybody under 14. Tell us and it goes.
Changes
When this changes, the date at the top changes with it. There is no mailing list to be dropped from, because there is no mailing list.