BRAINMAXX.gg

Privacy Policy

1. Who is responsible

Brainmaxx is operated by Breathe IT AS, Norway, which is the data controller for any personal data described here.

Privacy enquiries: privacy@brainmaxx.gg

2. What we collect

Today, playing without an account: no personal data reaches us. Your progress — level, rating, streaks, achievements, chosen theme and nickname — is written to your browser's local storage on your own device. It is not transmitted anywhere, and we cannot see it. Clearing your browser data deletes it permanently, and we cannot restore it.

If you create an account (not yet available), we will collect only:

We do not ask for your real name, date of birth, address, phone number or location. An optional age band may be offered in settings purely so scores can be compared within age groups; it is never required.

3. Why we may process it, and on what legal basis

4. Storage and cookies

Brainmaxx sets no advertising or tracking cookies and uses no analytics that identify you. We use your browser's local storage for things that are strictly necessary for the game to function at all:

Because this storage is strictly necessary to deliver a service you have actively asked for, it does not require consent under the ePrivacy rules. If we ever add analytics or any non-essential storage, we will ask you first.

5. Third parties

We do not sell personal data, and we do not share it with advertisers.

6. How long we keep it

Local device data stays until you clear it. Account data will be kept while the account is active and deleted within 30 days of a deletion request, except where we must retain something to meet a legal obligation.

7. Your rights

Under the GDPR you may request access to your data, correction of it, erasure, a portable copy, restriction of processing, or object to processing based on legitimate interests. You can also withdraw consent at any time.

Write to privacy@brainmaxx.gg and we will respond within 30 days. If you are unhappy with our response you may complain to the Norwegian Data Protection Authority (Datatilsynet) or your local supervisory authority.

8. Children

Brainmaxx is not intended for children under 13, and accounts may not be created by anyone under that age. We do not knowingly collect data from children under 13. If you believe a child has given us data, contact us and we will delete it.

9. Security

The site is served over HTTPS only. Where accounts exist, passwords are stored using a modern one-way hashing algorithm, verification tokens are stored hashed rather than in plain text, and access to production data is restricted to named administrators.

10. Changes

If this policy changes materially we will update the version at the top and, for account holders, tell you before the change takes effect.