Privacy Policy
This overview describes the processing implemented in FormFieber. Google AdSense Auto ads is integrated on the website.
1. Who is responsible?
- Operator
- Tobias Heri
- Status
- Private individual
- Country
- Switzerland
- tobi.heri@icloud.com
- Postal address
- No public postal address is currently provided.
Contact Tobias Heri for privacy requests. Further details are in the Legal Notice. This information does not claim a conclusive legal review.
2. Information used in the game
- Player name and technical player ID
- A name you choose and a random ID identify your session. Other players in the room see your name, score and connection status. No account is required; a nickname is recommended.
- Room codes and invitation links
- A random code assigns connections to a room. It appears in the game, invitation links and the URL query. It may also appear in browser history or technical web-server data. Share it only with intended players.
- Chat and guesses
- Messages go to the server, which checks guesses and, where applicable, shares them with the room. Correct answers are replaced by a success message during guessing. The room keeps at most the last 80 chat entries in memory; starting a new game resets the chat.
- Temporary game state and models
- Shapes, positions, colors, rounds, timers, the chosen word, scores and roles are processed temporarily in server memory to run the shared game. Guessers receive the secret word only at the reveal. The project has no database for permanent game histories.
Quick Play assigns you to a public room with other players, including strangers from other countries. Public rooms use English words. Your interface language does not limit matchmaking. Practice runs locally without a multiplayer room.
3. Connections and technical server data
Socket.IO connects your browser to the game server through WebSocket or, if necessary, HTTP polling. IP addresses, connection identifiers, request times and HTTP headers are technically processed for transmission, reconnection and server operation. Application code does not write permanent access or chat logs.
A hosting provider, reverse proxy or server environment may produce additional technical logs. Specific details about the hosting provider, log scope, retention, recipients and hosting country are not documented here at present. Please contact Tobias Heri at tobi.heri@icloud.com with questions. We do not make an unverified promise that no infrastructure component stores data.
4. Browser storage and session tokens
- Local Storage:
formfieber-name - Remembers your most recently used player name for the next visit, until you or your browser delete it.
- Session Storage:
formfieber - Contains the room code, player ID, name and a random session token for reconnection. The token is sent to the game server, not to other players. It is removed when you deliberately leave or reconnection fails. Otherwise it belongs to the browser tab session; restoring a browser session may preserve it.
- Local Storage:
formfieber-practice - If you choose Save when leaving Practice, your model is saved on this device until replaced or deleted through your browser settings. Practice models are not sent to the game server.
- Local Storage:
formfieber-language - Remembers your chosen interface language, English or German, until you or your browser delete it. English is used when no choice is stored. This preference is not advertising consent.
- Cookies and other preferences
- The current application code does not set its own cookies. The configured Socket.IO connection does not set a session cookie. No home-made advertising consent is stored.
You can delete website data in your browser settings. This may prevent reconnection with the same identity. A session token is an access credential: do not share it.
5. How long is game data retained?
A disconnected player is normally retained for up to 30 seconds for reconnection. Deliberately leaving removes the player immediately. Empty rooms are deleted; restarting the server discards all rooms. Chat or round results already in a room may remain visible until that room is reset or deleted. Other players can independently make screenshots or copies.
6. Libraries and fonts
Three.js and the Socket.IO client are served by the game server. The stylesheet currently requests DM Sans and Space Grotesk from Google Fonts (fonts.googleapis.com and possibly fonts.gstatic.com). Google receives technical request information such as the IP address. System fonts are used if the request fails. These font requests are separate from AdSense. See Google’s font privacy information.
7. Google AdSense Auto ads
FormFieber loads the Google AdSense script on its public pages using publisher ID ca-pub-9565277777173762. Google controls automatic ad placement according to the settings in the operator’s AdSense account. Actual delivery may vary by region, consent status and availability.
Google and advertising partners may process IP addresses, browser and device information, cookies or similar identifiers for ad delivery, measurement and, where permitted, personalization. Non-personalized advertising is not automatically free of cookies or consent requirements. See Google’s advertising information and Google’s Privacy Policy for processing, retention and international transfers.
Privacy Settings opens an available consent platform. If the platform is unavailable or blocked, a notice is shown; this notice does not collect consent. Playing or closing a notice does not grant consent. For questions about the account’s advertising partners or applicable settings, contact Tobias Heri at tobi.heri@icloud.com.
8. Purposes, rights and questions
Game data supports your requested multiplayer session, reconnection and technical protection of gameplay. The operator is Tobias Heri, a private individual in Switzerland. The data-protection rules applicable to the actual operation govern; this description does not claim a conclusive legal assessment. Any necessary future advertising consent is separate.
Depending on applicable law, you may have rights of access, correction, deletion, restriction, objection, portability and a complaint to a competent data-protection authority. Consent can be withdrawn for the future. Contact the operator with requests and do not send session tokens. This information makes no claim of a conclusive legal review.
Last updated: 17 September 2026.