Privacy

Updated Aug 31, 2026

What we collect, why, who else sees it, and how to get it deleted. Written to be read.

The short version

  • Browsing sets no cookie. Read the whole site without an account and nothing of ours is written to your device, which is why there is no cookie banner.
  • No passwords. You sign in with a code sent to your email.
  • Your Steam library is never stored. It is read once, compared, shown, and forgotten.
  • No ads, no data selling, no tracking across other sites.
  • Ask us to delete your account and everything in it, and we will.

Who is responsible

Cloudplay (cloudplay.now) is published by Room 46 LLC, 1021 E Lincolnway, #8138, Cheyenne, WY 82001, United States. Under the GDPR that company is the data controller for everything described here. For any question, correction or deletion, write to hello@cloudplay.now. A human reads it.

What we collect

If you only browse: nothing that identifies you. Our host processes your IP address for the seconds it takes to serve the page, as any web server must, and uses it to tell us which country you are in, so we can show prices in your currency and the PlayStation status for your country. The country is used for that request and not kept. Your browser’s time zone is read on the page to guess your nearest server region; it stays in your browser.

If you create an account: your email address, the games you follow, whether alerts are on, and the time of your last sign-in. Nothing else: no name, no password.

If you use My library: the public game list of the Steam profile you paste is read from Steam when you press the button, compared with our catalogue on our server, and shown to you. We store neither the profile nor the list nor the result. The only trace is the profile id in the address bar of your browser.

If you vote on the roadmap: a random identifier is set in a cookie, for a year, so that one browser counts once per idea. It names nobody. Clearing it forgets your votes.

If you report a mistake on a game page: what you picked in the form, anything you wrote in it, and your email address if you gave one. Nothing about your browser. The address is used to answer you about that report, and for nothing else.

Why we are allowed to (legal bases)

  • Performing our agreement with you (Art. 6(1)(b) GDPR): your account, the games you follow, the alerts you asked for.
  • Our legitimate interest (Art. 6(1)(f)): keeping the site up, keeping it free of abuse, and understanding, in aggregate and without identifying you, which pages work.

Analytics, without the tracking

We count page views by page, country and device type. Two tools do it: Vercel Analytics, and Umami, which we run ourselves so that data stays in our own database. Umami also records two things you do: what you type in the search box, and which service you open a game on. The search terms are how we find out which games people look for and do not find here. Neither tool sets a cookie or keeps an identifier on your device, so a visit cannot be linked to a previous one. We use nothing else.

Who else sees your data

A small number of providers, each for one job, each bound to process data only on our instructions:

  • Supabase: the database, the accounts and the analytics data, hosted in its Singapore (ap-southeast-1) region. Supabase also sends the sign-in codes.
  • Vercel: hosting and delivery of the site, and the cookieless analytics (United States).
  • Resend: delivers the alert emails and the mistake reports (United States).
  • Steam: only when you use My library, and only in the sense that we ask Steam for the public game list you pointed us to. Steam sees our request, not you.

Your data leaves Europe, and you should know it. Accounts live on Supabase’s Singapore (ap-southeast-1) servers; Vercel and Resend are in the United States. Singapore has no adequacy decision from the European Commission, so that transfer is covered by the Commission’s Standard Contractual Clauses agreed with Supabase; the American providers also rely on the EU–US Data Privacy Framework where it applies.

We will also disclose data if a law or a court obliges us to. We will not do it quietly if we are allowed to tell you.

Cookies

There is no cookie banner because there is nothing to consent to. The cookies involved are the one that keeps you signed in after you log in, the roadmap vote identifier described above, and the security cookies our host may set to block bots. All are strictly necessary to deliver something you asked for, which is the case the law exempts from consent.

How long we keep it

Your account and the games you follow stay until you delete them. Delete the account, from the account page or by writing to us, and the address, the followed games and the alert setting go with it, at once. Alert emails already sent are kept by Resend for its own log for a short period. A mistake report is kept while we work through it, and deleted once the page it names is fixed. Analytics counts, which are not linked to you, are kept as totals.

Your rights

Under the GDPR you can ask us for a copy of your data, correct it, delete it, take it elsewhere, or object to how we use it. Write to hello@cloudplay.now and we will answer within a month. Most of it you can do yourself from your account page.

If you think we have handled your data badly, you may complain to your national data protection authority, in France the CNIL. We would rather you told us first and gave us the chance to fix it.

Children

Cloudplay is not intended for children under 16. If you believe a child has created an account, tell us and we will remove it.

Changes

If we change how we handle your data, we update this page and move the date at the top. If the change is significant, account holders are told by email.

Who exactly stands behind the site is in the legal notice; the rules for using it are in the terms of use.