Privacy Policy
Last updated: August 12, 2026
Pizia S.A.S. is an independent game studio, and is the company responsible for the personal data described here. You can reach us about anything in this policy at contact@pizia.com. This policy covers two different things: this website (pizia.com) and our games and apps. They collect very different information, so they are described separately.
In short: the website has no accounts unless you choose to sign in to leave a comment, we do not sell or share personal data with anyone for advertising, and you can have anything we hold about you deleted by asking us at contact@pizia.com.
Part 1 — This website (pizia.com)
Just reading the site
You do not need an account to read anything here. When you visit, our host (Firebase Hosting, operated by Google) records ordinary server request data, including your IP address, the page requested, the time, and your browser's user agent. This is standard for any web server and is used to deliver the site and to investigate abuse or faults.
We use Google Analytics to understand which posts and pages people read. It sets cookies and reports usage to Google. We look only at aggregate figures — page views, referrers, countries, which links get clicked — and we do not attempt to identify individual visitors. Google retains this data for the period configured on our property. If you would rather not be counted, most browsers and ad blockers can block it, and browsers that send a Do Not Track or global privacy signal are respected by our analytics provider where it honours them.
Some parts of the site load files from other companies, which means those companies receive your IP address and basic request data when the part in question loads:
- Google Fonts — the typeface used across the site.
- Cloudinary — video and images in blog posts are served from Cloudinary rather than from us, so their servers see the request when a clip loads.
- Imgur — some older posts still embed media hosted at Imgur.
- YouTube — game trailers are embedded players. YouTube may set its own cookies when a trailer loads.
- Google Translate — only if you choose a machine translation of a blog post from the language picker. It sets a cookie recording that choice, which is removed when you switch back.
Likes
Some blog posts can be liked. This needs no account. So that the same visitor is counted once, we store a one-way cryptographic hash of your IP address combined with your browser's user agent. That hash cannot be reversed into your IP address, and the IP address itself is not stored. Your browser also remembers locally which posts you liked, so the heart stays filled; clearing your browser storage clears that.
Comments
Leaving a comment requires signing in with Discord or Google. We ask those services for one thing: your display name and profile picture. We do not ask for, and cannot see, your email address, your contacts, your servers, or anything else, and we cannot post or act anywhere on your behalf.
We store, for each person who comments:
- the display name and profile picture from the service you signed in with;
- the identifier that service uses for your account;
- the text of your comments and the time you posted them.
Your profile picture is copied once to our own storage when you first sign in, so that reading a post never causes a request to Discord or Google. Comments are public: anything you write is visible to anyone reading that post.
Signing in sets a single cookie on this site so that you stay signed in. It contains only a signed reference to your account, expires after 30 days, and cannot be read by scripts running in the page. Signing out removes it. This cookie is necessary for commenting and is set only when you choose to sign in.
How long the website keeps things
- Comments and your commenting profile — kept until you delete them or ask us to. You can delete any of your own comments yourself, at any time, from the post it appears on.
- Likes — the hash is kept while the like stands. Removing your like deletes it.
- Server logs — kept for a short period by our host for operational purposes.
- Analytics — kept by Google for the retention period set on our property.
Why we are allowed to do this
For readers in the European Economic Area and the United Kingdom: we rely on your consent when you choose to sign in and comment, and on our legitimate interest in running, securing and understanding our own website for server logs, like counts and analytics. You can withdraw consent at any time by signing out and deleting your comments.
Part 2 — Our games and apps
Some of our games are distributed free and supported by advertising. Those apps use third-party services that may collect information used to identify your device, in order to show ads, measure crashes, and understand how the game is played. This information is handled according to those companies' own policies:
Our apps may also collect diagnostic data when they fail, which can include your device's IP address, device name, operating system version, the configuration of the app, the time of the error and other statistics. On mobile devices you can reset or limit ad personalisation through your system settings.
We do not sell your data
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other United States privacy laws. We have never done so and have no plans to. There is nothing to opt out of, which is why you will not find a "Do Not Sell or Share My Personal Information" link here.
We also do not use your comments, your name, or anything else you give us to train machine learning models, and we do not pass them to anyone who does.
What we collect, by category
Stated in the categories United States privacy laws use, on this website we collect:
- Identifiers — your IP address (server logs), and if you sign in to comment, your display name and the account identifier from Discord or Google. Collected from you and from the service you sign in with.
- Internet and network activity — pages viewed, referring site, links clicked, and general browser and device information, through Google Analytics.
- Approximate location — country or region, inferred from your IP address. We do not collect precise location.
- Audio, visual and similar information — the profile picture from the service you sign in with.
- User-generated content — the comments you choose to write.
We do not collect sensitive personal information: no government identifiers, no financial information, no precise location, no health data, no biometrics, and no information about race, religion, union membership, sexuality or political views. We collect no email addresses through this website.
Your rights
We give the same rights to everyone, wherever you live, rather than only where a law compels us. You can ask us to:
- tell you what we hold about you and where it came from;
- correct anything that is wrong;
- delete it;
- give you a copy in a portable format;
- stop processing that we base on legitimate interest.
Write to contact@pizia.com. We aim to reply within 30 days. It costs nothing, you do not have to explain why, and we will not treat you differently for asking — no degraded service, no different pricing. Most of it you can also do yourself: delete your own comments from the post, remove a like by tapping it again, and sign out to remove the cookie.
If we refuse a request, we will tell you why, and you may ask us to reconsider by replying to that message. If you are still unhappy, you can complain to your data protection authority.
Where you live
The rights above are the same everywhere. This is who regulates us where you are, and anything specific to your region.
- European Economic Area and United Kingdom (GDPR / UK GDPR) — we rely on your consent when you sign in and comment, and on legitimate interest for server logs, like counts and analytics. Withdraw consent by signing out and deleting your comments. You may complain to your national supervisory authority, or to the UK Information Commissioner's Office.
- United States — California (CCPA/CPRA) — you have the rights to know, delete, correct, and to non-discrimination, all listed above. We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes requiring a limitation right. You may complain to the California Privacy Protection Agency.
- United States — other states — the same rights apply if you are in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Kentucky, Nebraska, Minnesota, Maryland, Rhode Island, or any state that has since passed a comparable law. You may also complain to your state Attorney General.
- Brazil (LGPD) — you additionally have the right to confirm we process your data, to anonymisation, and to information about who we share it with. The authority is the Autoridade Nacional de Proteção de Dados (ANPD).
- Canada (PIPEDA) — you may access and correct your information and complain to the Office of the Privacy Commissioner of Canada.
- Japan (APPI) — our purpose of use is set out in this policy: running this website, publishing the comments you choose to write, and understanding readership. The authority is the Personal Information Protection Commission.
- South Korea (PIPA) — signing in to comment is optional and separate from reading the site; you may refuse it and still use everything else. The authority is the Personal Information Protection Commission.
- Australia (Privacy Act / APPs) — you may complain to the Office of the Australian Information Commissioner.
- Argentina (Ley 25.326) — the authority is the Agencia de Acceso a la Información Pública.
International transfers
We operate outside the European Economic Area, and the services we use — Google, Discord, Cloudinary — store and process data outside your country, including in the United States. Argentina is recognised by the European Our providers offer their own transfer safeguards for this, such as the European Commission's standard contractual clauses.
Security
We keep what we collect to a minimum, which is the most reliable protection available to us. Credentials are held in managed secret storage rather than in our code, and the site is served over HTTPS. That said, no method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security.
Children
This website is not directed at children, and we do not knowingly collect personal information from them. Commenting requires a Discord or Google account, both of which have their own minimum ages.
The threshold differs by country — 13 under the United States Children's Online Privacy Protection Act, between 13 and 16 across the European Union depending on the member state, 14 in South Korea, and 18 in Brazil where a parent or guardian must consent. We apply whichever is higher where you are. If you believe a child has given us personal information, contact us and we will delete it without asking anything further.
Links to other sites
This site links to other places — stores, social networks, press coverage. Those sites are not operated by us, and we have no control over their content or their privacy practices.
Changes to this policy
We may update this policy as the site changes. The date at the top always reflects the current version, and changes take effect when posted here.
Contact
Questions, corrections, or a request to delete your data: contact@pizia.com.