tabularium

privacy policy

last updated: 7 august 2026.

at yodidac.com we handle your data transparently and only for the purposes described here, in accordance with regulation (eu) 2016/679 (gdpr) and spanish organic law 3/2018 (lopdgdd).

the short version: this site is designed to work without identifying you. there are no user accounts, no cookies, and the only measurement is cookieless analytics that gives no one a visitor identifier. the little that is stored server-side is pseudonymous — votes and scores tied to random identifiers, never to your name or your ip address in the clear — and the ip pseudonym is deleted after 30 days.

data controller

Dídac Pérez Escrich (a private individual), owner of yodidac.com, based in sant boi de llobregat (barcelona, spain). on the rest of the site he signs as «dídac» (more about the author at didacperezescrich.com). contact, including for data-protection matters: hola@yodidac.com.

contact by email

if you write to hola@yodidac.com, we process your email address and the content of your message for the sole purpose of reading and replying to your enquiry. legal basis: your consent when writing to us and the legitimate interest in replying (art. 6.1.a and 6.1.f gdpr).

community votes (comitia, senatus, oraculum, factiones)

when you take part in a vote, the server stores:

  • your vote (the option you chose) linked to a random identifier that your browser generates and keeps. that identifier contains no personal data: it is a random string whose only purpose is letting you change your vote without it counting twice.
  • a pseudonym of your ip address (ip_hash): the ip is never stored in the clear — it is transformed with a keyed hash (hmac-sha256) using a secret key that exists only on the server. it is used exclusively to limit abuse (preventing mass voting from a single connection), cannot be reversed back into your ip, and is automatically deleted after 30 days without activity by a nightly job.

purpose: recording your vote and protecting the votes against manipulation and duplicates. legal basis: your consent, expressed by the act of voting, for recording the vote (art. 6.1.a gdpr); and the legitimate interest in preventing abuse for the ip pseudonym (art. 6.1.f gdpr).

an honest note: since we cannot know who is behind a random identifier, if you ask us to exercise rights over specific votes we may be unable to link them to you (art. 11 gdpr).

game leaderboard (simulacrum)

if you choose to submit your score to the game's public leaderboard, the server stores the alias you choose (3–20 characters), your score, achievements, completion percentage and playtime, together with a random identifier for your run. the alias and score are displayed publicly on the leaderboard: pick an alias that is not your real name if you don't want to be recognised. your ip address is used only in memory, for a few minutes, to rate-limit submissions, and is not stored. legal basis: your consent, expressed by submitting the score (art. 6.1.a gdpr).

new-episode notifications for the game

at the end of an episode, the game offers you the option of voluntarily leaving your email address so we can let you know when the next one is released. if you leave it, it is sent to this site's own service — protected by bot verification (cloudflare turnstile) and rate limits — and stored, together with the episode you are on, in the cloudflare storage (kv) this site uses. it is not used for anything else and is not shared with third parties. legal basis: your consent (art. 6.1.a gdpr). you can request its deletion at any time by writing to hola@yodidac.com.

bot protection (cloudflare turnstile)

to protect the votes and the episode-notification email submission against automated abuse we use cloudflare turnstile in invisible mode. turnstile processes your ip address and technical browser signals to tell people apart from bots; the result of that verification is not stored on the site. legal basis: the legitimate interest in preventing abuse (art. 6.1.f gdpr).

cloudflare carries out that processing under its turnstile privacy addendum, which we reference here as a condition of running turnstile in invisible mode.

analytics

audience measurement runs on cloudflare web analytics, a cookieless tool: it sets no cookie, writes nothing to your device and issues no visitor identifier, so there is nothing to join up between two visits or between two sites.

what reaches the dashboard is aggregate — page path, the domain you arrived from, country, browser, operating system, device type and load timings. there is no row per person, so no profile is built and you cannot be identified from it. legal basis: the legitimate interest in knowing how the site is used (art. 6.1.f gdpr), with no processing of data that could identify you.

server logs

like any website, the infrastructure serving it (cloudflare) generates technical request logs (ip address, timestamp, requested resource) for security and service-operation purposes, under cloudflare's own policy as provider.

we make no automated decisions and build no profiles with your data.

storage in your browser

the site keeps your preferences and progress on your device (localstorage and cache): your chosen language, your game saves, the votes you have already cast and the random vote identifiers. all of this is strictly necessary for the features you yourself use, stays on your device under your control, and requires neither consent nor a banner (art. 5(3) of the eprivacy directive). the full inventory is in the cookies and storage policy.

tiktok videos (load on demand)

tiktok videos do not load when the page opens: you see a card with an image hosted on this site. only when you click to watch the video does tiktok's official player load, and from that moment tiktok may set its own cookies and process your data as an independent controller, under its own privacy policy (including possible transfers outside the european economic area). clicking to load the video constitutes your consent for that specific load. if you don't click, no data travels to tiktok.

support via ko-fi (outbound link)

the ko-fi link in the author band, the footer and de me is an ordinary link: no script, no cookie, no pixel — nothing from ko-fi loads on this site until you click it. once you are on ko-fi.com you are on their site, under their own privacy policy, and ko-fi and its payment provider handle the transaction end to end as independent controllers. we never see your card details at any point. if you make a contribution we receive the data ko-fi passes to the creator — the name or alias you choose to display, any message you leave and the email address linked to the payment — used only to thank you for it and to meet tax and accounting obligations. legal basis: performance of the contribution you initiate and the legal obligations arising from it (art. 6.1.b and 6.1.c gdpr).

retention periods

  • email messages: for as long as needed to handle your enquiry and, afterwards, for the legally required period to address any liabilities; then deleted.
  • votes: the vote itself (option + random identifier) is kept as a statistical aggregate; the ip pseudonym is automatically deleted after 30 days without activity.
  • leaderboard: your entry (alias, score, achievements) is kept while the leaderboard exists; you can request its deletion at any time.
  • episode-notification emails: until the notification is sent or you request deletion, whichever comes first.

recipients and processors

we do not sell or share your data. the following act as processors or third parties:

  • cloudflare, inc. — site hosting (workers and static assets), the votes and leaderboard database (d1), storage of episode-notification emails (kv), cookieless audience measurement (web analytics) and bot protection (turnstile). cloudflare is certified under the eu-us data privacy framework; failing that, transfers rely on the european commission's standard contractual clauses.
  • tiktok — only if you choose to load an embedded video; it acts as an independent controller under its own policy (see the section above).
  • ko-fi and its payment provider — only if you choose to make a contribution; they act as independent controllers under their own policies (see the section above).

international transfers

to the extent that cloudflare processes data outside the european economic area, those transfers rely on the safeguards provided for by the gdpr (data privacy framework, standard contractual clauses or other valid mechanisms). you can request more information at hola@yodidac.com. any processing tiktok performs after you load a video is governed by its own policy.

your rights

you can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consent at any time (without affecting the lawfulness of prior processing), by writing to hola@yodidac.com. if you believe we have not handled your rights properly, you can lodge a complaint with the spanish data protection agency (www.aepd.es).

security

the site is served entirely over an encrypted connection (https). ip addresses linked to votes are stored only in pseudonymised form (hmac with a server-side secret key) and deleted after 30 days of inactivity, vote identifiers are signed to prevent tampering, and the votes are protected by bot verification and rate limits.

minors

this site is not aimed at children under 14 and does not knowingly collect their data. if you are a parent or guardian and believe a minor has given us data, write to us and we will delete it.

changes to this policy

we may update this policy to reflect regulatory changes or changes to the site itself. the date of the last update will always be indicated.