Privacy Policy
Last updated: July 15, 2026
We collect only whatβs needed to run the game. We donβt track you, we donβt sell your data, and we donβt use third-party analytics. You can delete your account and all associated data at any time. This policy is governed by our Terms of Service.
Data Controller
NBacking is operated by Franklin Gonzalez, based in Bogota DC, Colombia.
For any privacy-related inquiries, contact us at: dualnbackproject@gmail.com
Personal Data We Collect
We collect the following categories of personal data:
- Account data β username, email address, password (hashed with Argon2), and country. Collected for authentication and account management.
- Game data β scores, confusion matrices, streaks, points, and tier. Collected to provide the core game service and track your progress.
- Social data β friends list, community messages, and notifications. Collected to enable social features.
- Technical data β IP address (held in memory only, never persisted to disk) and session cookie. Collected for security and rate limiting.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract (Art 6(1)(b) GDPR) β Processing of account and game data is necessary to provide the service you signed up for.
- Legitimate Interest (Art 6(1)(f) GDPR) β Processing of technical data (IP addresses, sessions) is necessary for security and rate limiting to protect the service and its users.
- Consent β Community messages are published based on your voluntary action and consent.
Data Recipients
We do not share your personal data with any third parties.
The only external service that receives limited data is our SMTP provider, which processes transactional emails (account verification and password reset) on our behalf. No game data, profile information, or usage data is shared with any external party.
Data Retention
We retain your data according to the following schedule:
- Account and game data β retained while your account is active.
- Notifications β retained while your account is active.
- Session data β expires per session timeout.
- Password reset tokens β valid for 1 hour only, single-use, then deleted.
- IP addresses β not persisted to disk. Held in memory for rate limiting only and discarded when the server restarts.
- Inactive accounts β accounts with no login activity for 24 months may be deleted. We will attempt to send a warning email before deletion.
Your Rights
Under GDPR Articles 15-22, you have the following rights regarding your personal data:
- Right of Access β You may request a copy of all personal data we hold about you.
- Right to Rectification β You can correct your data at any time via the Edit Profile page in your account settings.
- Right to Erasure β You can delete your account via the Delete Account page. Deletion is immediate and irreversible.
- Right to Data Portability β You may request a copy of your data in a structured, machine-readable format by emailing us.
- Right to Object β You may object to processing based on legitimate interest.
- Right to Withdraw Consent β Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email dualnbackproject@gmail.com or use the relevant in-app features. We will respond within 30 days.
Automated Decision-Making
NBacking uses automated systems for Auto-N adjustment (which adapts difficulty based on your performance) and tier placement (which assigns a rank based on accumulated points). These are game mechanics only and produce no legal or similarly significant effects on you.
Children
NBacking is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If we discover that a child under 16 has provided us with personal data, we will delete that data promptly.
International Transfers
Your data is processed and stored in the location where our hosting infrastructure operates. By using NBacking, you acknowledge that your data may be processed in this location.
Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority.
Data Security
We implement appropriate technical measures to protect your personal data:
- Passwords are hashed using Argon2 (a memory-hard algorithm) and never stored in plaintext.
- Session cookies are configured with HttpOnly, Secure, and SameSite attributes.
- Rate limiting and proof-of-work CAPTCHA protect against automated attacks.
- All connections are encrypted via HTTPS in production.
No method of transmission over the Internet is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights, we will notify affected users via email and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users. The last-updated date at the top of this page reflects the most recent revision.