Privacy
Le Président is an online card game published by Benoit Jolly as a private individual. This page explains what data the website and the game use, why, where it is hosted and how long it is kept.
In short: no account required, no email or password asked for, no ads, no analytics.
Who is responsible?
Benoit Jolly, the game’s publisher, is the data controller.
A dedicated contact address will be published on this page.
This website
Its pages are static. They set no cookies, use no analytics and serve their own fonts. If you pick a language or reduce animations, that choice may be remembered in your browser, as may the animated scenes already played during your visit; nothing is sent anywhere. Like any host, Vercel receives your IP address and technical browser information to deliver the pages.
In the game
- Your guest identity. On your first action, the game creates an anonymous identity with Firebase Authentication, a Google service: a random identifier, with no email or password. It lets you get back to your seat and your history. When you sign in this way, Google processes your IP address and browser type to secure the service and prevent abuse.
- Your nickname. You choose it. Players and spectators at your table can see it; it is stored with the game and shows up in the history of players who shared a game with you.
- Your avatar. If you pick a character in “My avatar”, that choice is saved on your device, even if you have linked an account, and the character’s identifier is sent to the game server when you join a table and when you change your avatar while you are there. Players and spectators at your table see it, and it is stored with the table, like your nickname. The game history does not keep it. All avatars come from the game’s catalogue: you cannot upload a photo.
- Your games. During a game, the table’s state (cards in hand, turns, timer) is saved so the game can resume after a disconnection. Neither the other players nor spectators see your hand. The history keeps the date, mode, rules, participants, places, points and roles of each round, without any cards. It also records any rounds a bot played for you, your departure or removal during a game (the time and, if a round was in progress, which one), and how the game ended, including when the host ended it or an administrator stopped it. The other players in that game can see your departure or removal, and the rounds a bot played for you, in their own history. Your profile builds your stats from your history.
- Reactions are sent live to the table and are not kept in the history.
- Feedback. All players can read feedback. Posting or supporting feedback requires a linked account. If you post feedback, we store its type (bug or suggestion), title, description and, if you allow it, technical details: the page, app version, browser family and screen orientation. The title and description are visible to all players, without your nickname or identifier. Supporting feedback stores your identifier and the date. The publisher can reply publicly to feedback, triage it (status, priority, internal note), hide it or merge it with another entry. Withdrawing your feedback erases its title, description, public reply, internal note and technical details.
- A Google account. This is optional. In your profile, the “Save my progress” button offers to link your guest identity to a Google account: you keep the same identifier, and with it your history and stats, and you can get them back on another device by signing in with the same Google account. When you link it, Firebase associates your identifier with that account and receives its basic information from Google: email address, name and profile photo. Our server only checks that an account is linked; it stores neither your email, nor your name, nor your photo. Recovering an account on another device does not transfer that device’s guest progress and does not merge any accounts. Linking an Apple account is not available yet; this page will be updated before it is.
- Moderation. When an administrator suspends or restores an account, removes a player from a table, closes a table, stops a game or handles feedback, the action is recorded with its reason, who did it and when. The moderation log also keeps the identifier of the suspended or restored account; the identifier, nickname and seat of the removed player; the table code when a table is closed or a game stopped; and, for feedback, changes to its status, priority, visibility or merging, and whether it has a public reply or an internal note, but not their text.
- Your IP address. To limit abuse, the game server counts requests per IP address over one minute. These counters stay in its memory: they are never written to a database or a log, and they are gone by the next server restart at the latest. The game server keeps no request logs.
- The game’s fonts are currently loaded from Google Fonts, so your browser contacts Google’s servers, which receive your IP address.
Voice chat
Voice chat is only offered at tables where the host has turned on the “Voice chat” option, which is off when the table is created; the host can turn it on or off at any time, in the lobby or during a game. Only seated players can then join it, never spectators. Games work without it, and it may be unavailable.
- Your microphone. You join voice chat with your microphone off. It only comes on if you switch it on yourself, with your browser’s permission, and you can mute it or leave voice chat at any time. In voice chat, the table’s host can also mute your microphone for everyone: the game server then asks LiveKit to do so, using the identifiers described below, and only you can turn it back on. Finally, each player can stop listening to someone; that setting only applies on their own device and is not sent to anyone.
- The sound. LiveKit Cloud relays it live to the players at the table who are in voice chat. The game does not record conversations.
- What LiveKit receives. When you join voice chat: an opaque identifier specific to this table, a technical identifier for the table and, like any online service, your IP address and the connection’s technical details. LiveKit receives neither your nickname, nor your guest identity, nor any email.
- Access removal. At a table where the host has turned on the “Voice chat” option, when a player leaves the table or is removed from it, when the host turns the option off, or when the table closes, the game server asks LiveKit to cut the matching voice chat access, using these same identifiers, whether or not the player joined voice chat. To do so, it keeps, together with the table, the identifier of each player seated while the option is on and an admission number, plus the date of each removal and a record of its delivery to LiveKit.
In your browser
The game keeps your nickname, avatar, language, sound and screen settings, a technical counter, a marker so the voice chat tip is only shown once, and your guest session on your device, plus its own files so it works once installed; for the duration of your visit, it also keeps a copy of the avatar catalogue. None of this is advertising or analytics tracking: it runs the game or remembers your preferences, so no consent is needed. Clearing the site’s data removes your guest identity from this device; the history already stored on the server stays, and you can ask us to delete it. If you’ve linked a Google account, you can recover your account by signing in with it again.
Why we may do this
- To run the game you are using: identity, linked account, nickname, avatar, tables, history, profile, feedback and voice chat.
- Our legitimate interest in protecting the service and its players: security, abuse limits, moderation and recovery after an outage.
Who can see it
Players and spectators at your table see your nickname, avatar, seat, the cards you play, your reactions and the results. Published feedback is visible to all players, without its author’s name. The publisher and, where applicable, the people they authorize can access data to run and moderate the game. Our providers process data on our behalf. Your data is never sold or used for advertising. In voice chat, the players at the table who joined it hear you when your microphone is on.
Providers and hosting locations
- Vercel Inc. (United States): hosting for this website, the game app and the admin console.
- Fly.io, Inc. (United States): game server, located in Paris.
- Supabase Pte. Ltd. (Singapore): database, located in Paris.
- Google (Firebase Authentication): guest identity, Google account linking and administrators’ sign-in to their console; this service runs from the United States.
- LiveKit, Inc. (United States): voice chat, through its LiveKit Cloud service.
Some of these providers are based outside the European Union; transfers rely on the European Commission’s standard contractual clauses or the EU–US Data Privacy Framework, depending on the provider.
How long
- Rate-limit counters: in memory only, see above.
- A table in progress: while it is open. A table closes after about ten minutes with no seated player connected (bots and spectators do not count); its cards, shuffles and spectator list are then erased.
- Record of a closed table (code, nicknames, identifiers and avatars of the seats, points, identifiers of players who left or were removed): kept so the history stays consistent. No retention period has been set yet; you can ask for it to be deleted at any time.
- Voice chat: the sound is not recorded. For the identifiers kept to remove access, no retention period has been set yet; you can ask for them to be deleted at any time.
- History, stats, feedback and the moderation log: no retention period has been set yet. It will be stated here; until then, you can ask for your data to be deleted at any time.
- Firebase identity, with the Google account you linked to it: until it is deleted. Google says it keeps sign-in IP addresses for a few weeks.
- Browser data: until you clear it.
Your rights
You can ask to access, correct, erase, restrict or port your data, and object to processing based on our legitimate interest.
A dedicated contact address will be published on this page for these requests. Since the game never asks for an email or password, we may ask for details that help us find your games: your nickname, their approximate dates or a table code. We reply within one month.
You can also lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr), or your local authority.
Security
Traffic is encrypted (HTTPS). The server checks the player’s Firebase identity before letting them play or view their data, and limits abuse. Administrative access requires strong authentication.
Changes
This page changes when the game does, for example when a new feature uses your data. The date at the top shows the latest update.