For Game Developers and Players

Version 4.0. | Effective date: 2 November 2026

This Privacy Notice explains how GameAnalytics collects and uses Personal Data. It is written for two audiences: the game developers, studios, publishers and other businesses who use our platform, our application programming interfaces and our website (our Customers, and the individuals who act for them), and the players whose in-game activity is measured through our technology (Players). Section 2 explains which parts apply to you.

1. Who we are

GameAnalytics ApS is a company registered in Denmark under company number 34043221, with its registered office at Pilestraede 58, 2, 1112 Copenhagen K, Denmark. It is the parent company of the GameAnalytics group, operates the GameAnalytics platform and holds the group's ISO/IEC 27001:2022 certification.

GameAnalytics Limited is a company registered in England and Wales under number 09214168, wholly owned by GameAnalytics ApS, and is the contracting entity for our Customers. It is registered with the Information Commissioner's Office under registration number ZA439557.

In this notice, GameAnalytics, we, us and our refer to GameAnalytics ApS and GameAnalytics Limited together. We are an in-game analytics and market intelligence provider that works with developers worldwide to help them understand and improve their games. For our business relationships described in this notice, GameAnalytics ApS and GameAnalytics Limited act as joint controllers, and our lead supervisory authority in the European Union is the Danish Datatilsynet. The essence of our joint controller arrangement is that GameAnalytics ApS operates the platform and its security, and GameAnalytics Limited manages the contractual and commercial relationship; you may exercise your rights against either of us using the contact details in Section 12.

For residents of Mainland China, please read the GameAnalytics China PIPL Privacy Notice at gameanalytics.com/trust/china-pipl.

2. The two roles we play, and which part applies to you

We handle Personal Data in two distinct capacities, and it is important to understand the difference.

When we act as a controller (this notice governs). For our own business relationships, we decide why and how Personal Data is processed, and we are the controller. This applies if you visit our website, create or administer a GameAnalytics account, sign in to our dashboard, use our application programming interfaces or Model Context Protocol servers, activate or use the Ad Insights API, enquire about or purchase our products, correspond with us, subscribe to our communications, or take part in a programme such as AI Labs, the Startup Program or a partner programme. Sections 3 to 12 explain this processing.

When we act as a processor (a Customer governs). When our software development kit or collection API measures player activity inside a Customer's game, that data is processed on behalf of the Customer under our Data Processing Addendum. In that relationship the Customer, not GameAnalytics, is the controller: the Customer decides what to collect and is responsible for informing players and, where required, obtaining their consent. Section 13 explains, in plain terms, what this means for Players. If you are a Player and have a question about how a particular game uses your data, the game's own developer is your first point of contact.

Market and creative intelligence. Our MarketIQ product and Ad Insights API contain aggregated information about apps, advertising campaigns and creatives compiled from public sources and data partners. That information is about apps and companies, not about individuals, and is not designed to contain Personal Data. Where a Customer submits a search term or uploads material that contains Personal Data, the Customer is responsible for that content.

3. Personal Data we collect as a controller

Personal Data means any information from which a person can be identified, directly or indirectly, for example by a name or an online identifier. Special Category Personal Data is more sensitive data revealing, for example, racial or ethnic origin, health, or sexual orientation. We do not seek or require Special Category Personal Data in our controller relationships.

The Personal Data we collect as a controller depends on our relationship with you. The main categories are:

  • Account and identity data: name, work email address, organisation, studio and game membership, role and permissions, account settings and preferences.
  • Authentication data: sign-in records, session identifiers, authentication tokens and, where you connect an artificial intelligence tool to our Model Context Protocol server, the authorisation grant that lets that tool act on your behalf.
  • Credentials and access records: API keys, game keys and tokens issued to you, and server-side records of the requests made under them, including the time, the user and organisation, the tool or endpoint called, the game concerned, the outcome of the request and the size of the response, together with the internet protocol address from which the request was made. We do not log the content of responses returned through the Model Context Protocol server.
  • Billing and commercial data: invoicing details, order forms, purchase history, credits and discounts applied, and payment status. Card details are collected and stored by our payment provider, not by us.
  • Correspondence and support data: enquiries, support tickets, feedback and the content of your communications with us.
  • Product usage data: how you use the dashboard and platform, for example the features you open and the actions you take, collected through analytics and reporting tooling to help us improve the product.
  • Website data: technical information about your visit to our website, collected through cookies and similar technologies with your consent where required, as described in our Cookie Policy.
  • Marketing data: marketing preferences and engagement with our communications.
  • Programme data: information you provide when you apply for or take part in a programme, for example eligibility information for the Startup Program.

How we collect it. We collect most of this data directly from you, when you contact us, register, sign in, generate a credential, make a request to our services, subscribe or use our website. We also generate some of it ourselves, for example access logs. We may receive limited data from our group company, from service providers who support our website and communications, and from publicly available professional sources.

4. Purposes and legal bases (controller processing)

We use Personal Data only where the law allows. The following table sets out our purposes and the legal bases on which we rely.

Purpose Legal basis
Creating and administering your account and providing the platform, application programming interfaces and Model Context Protocol servers to our Customers Performance of the contract between us, or the taking of steps at your request before entering into a contract.
Authenticating you, enforcing permissions on every request, and letting you delegate access to a tool of your choice Performance of the contract, and our legitimate interest in securing access to our services.
Keeping access and request logs, detecting abuse, enforcing usage limits and investigating security incidents Our legitimate interest in the security and integrity of our services and in protecting our Customers, and compliance with our legal obligations on security and breach handling.
Billing, applying credits and discounts, and managing payments Performance of the contract, and compliance with our legal and accounting obligations.
Responding to your enquiries and correspondence and providing support Our legitimate interest in responding to enquiries and supporting our Customers, and performance of the contract where you are a Customer.
Sending you product and marketing communications that may interest you Your consent, or our legitimate interest in marketing to existing and prospective business customers. You may object or withdraw consent at any time by using the unsubscribe link or by emailing privacy@gameanalytics.com.
Maintaining a record of our contact and relationship with you Our legitimate interest in managing our customer relationships.
Improving and securing our website and platform, including product usage analytics Our legitimate interest in operating, improving and securing our services; and, for non-essential cookies and similar technologies, your consent.
Business management, forecasting and product development Our legitimate interest in understanding and developing our business, using aggregated and non-identifying data where possible.
Operating programmes such as AI Labs, the Startup Program and partner programmes Performance of the programme terms you accept, your consent where we ask for it, and our legitimate interest in developing new features and relationships.
Establishing, exercising or defending legal claims and complying with law Our legitimate interest in protecting our rights, and compliance with our legal obligations.

Where processing is necessary for the performance of a contract, we may be unable to provide the relevant service without the required information. Where we rely on legitimate interests, we have balanced those interests against your rights and you may object as described in Section 10.

5. Sharing your Personal Data

We share Personal Data only where necessary and lawful. We may share it with: our group company; the service providers listed below, who process on our behalf under contracts that restrict their use of the data; professional advisers; and public authorities or regulators where we are under a legal duty, or where necessary to protect the rights, property or safety of GameAnalytics, our users or others. We do not sell Personal Data.

Our main service providers for the processing described in this notice are:

Function Provider Location
Cloud hosting and infrastructure for the platform Amazon Web Services United States
Data warehouse infrastructure Google Cloud United States
Identity and authentication for dashboard, API and Model Context Protocol access WorkOS, Inc. United States
Log management for access and request logs SolarWinds United States
Logging and tracing of AI Agent sessions Langfuse GmbH European Union (Germany)
Product usage analytics and internal reporting Metabase United States
Consent management for our website iubenda European Union
Payments for self-checkout Stripe United States
Customer relationship management, email and marketing HubSpot United States
External data protection support Evalian Limited United Kingdom

Where a Customer connects our data to a tool of its own choosing, including an artificial intelligence client through our Model Context Protocol server, that tool's provider is chosen and controlled by the Customer, not by us, and is not our service provider.

Our website may contain links to third-party sites and services that we do not control. We are not responsible for their privacy practices, and we encourage you to read their notices.

6. AI-powered features and Model Context Protocol servers

We offer several AI-powered features. This section explains how they handle data.

The in-tool AI Agent answers plain-language questions about a Customer's own game data. It processes that data through a managed model hosted by a provider named in our Data Processing Addendum, currently Amazon Web Services, solely to generate a response. Customer game data is not used to train or improve any model, and is not retained by the model provider beyond the transient processing needed to answer. We log and trace AI Agent sessions through an observability provider hosted in the European Union, to operate, debug and improve the quality of the feature. The AI Agent produces informational summaries by automated means and does not make decisions that produce legal or similarly significant effects on any individual.

The Documentation Helper is a publicly available assistant hosted by OpenAI that answers questions about our product documentation. It works on our documentation only and does not process Customer game data or Player data. Your use of it is governed by the hosting provider's terms.

Our Model Context Protocol servers let Customers connect our data and documentation to artificial intelligence tools such as chat assistants. The GameAnalytics-hosted server works as follows: you sign in through our identity provider and authorise your chosen tool to act on your behalf; we check your permissions on every request, so a user removed from an organisation loses access immediately even if the tool still shows a connection; the server currently returns aggregated metrics only, not player-level data; and we log each request as described in Section 3, without logging the content of the response. You choose and control the artificial intelligence tool. Anything the tool has already received stays in that tool's conversation history or storage under the terms of its provider, including after you revoke the connection, and is not something we can retrieve or delete. You can revoke a connection at any time from the tool or through your account settings. The self-hosted open-source server runs in the Customer's own environment and does not send data to us.

7. International transfers

We and our service providers may process Personal Data in countries outside the European Economic Area and the United Kingdom, including the United States and Hong Kong. Where we do so, we ensure a level of protection consistent with European and United Kingdom law by relying on an adequacy decision where one applies; on certification under the EU-US Data Privacy Framework, its United Kingdom Extension or the Swiss-US Data Privacy Framework where the recipient is certified; or otherwise on Standard Contractual Clauses together with the United Kingdom International Data Transfer Addendum, supported by a transfer risk assessment and supplementary measures where needed. Because our contracting entity is in the United Kingdom and our operating entity is in Denmark, both the European Union and United Kingdom transfer rules apply to us. You may request further information about these safeguards using the contact details below.

8. How long we keep data

We keep Personal Data only for as long as necessary for the purposes for which it was collected, and for a reasonable period afterwards to meet our contractual and legal obligations and to deal with any complaints or claims. At the end of the retention period we securely delete or anonymise the data. Our main retention periods are:

Category Retention
Account and identity data For the life of the account, then deleted within ninety days of closure, subject to the periods below. Inactive free accounts may be closed after twelve months of inactivity, with thirty days notice by email, as described in our Terms and Conditions.
Authentication data and authorisation grants Session records for ninety days; authorisation grants until you revoke them or the account is closed.
Model Context Protocol access logs Twelve months.
Ad Insights API request logs at the request layer Seven days; aggregated usage statistics without internet protocol addresses are kept for billing and capacity planning.
Other API and platform access logs Ninety days.
AI Agent session logs and traces Ninety days.
Billing and commercial records The duration of the relationship plus the period required by applicable accounting and tax rules, generally five years under Danish bookkeeping law and six years under United Kingdom rules.
Correspondence and support tickets Five years from closure of the matter.
Product usage data Twentyfour months, after which it is aggregated.
Marketing data Until you unsubscribe or object, and a record of your objection thereafter so that we respect it.
Website data As set out in our Cookie Policy.

For the game analytics data we process on behalf of Customers, retention is governed by the Data Processing Addendum. In summary, interactive access to detailed data is limited to a defined maximum look-back period of up to four years, event-level data is retained for up to twelve months to support analytics, data pipeline and backfill features, player-level aggregated data is retained for up to one year, truncated internet protocol addresses are kept for up to thirty days, daily aggregated data is retained for up to one year, and aggregated statistics that do not identify any individual may be kept on a rolling basis for historical trends. These are maximum periods and data may be deleted sooner.

9. How we protect data

We implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage. GameAnalytics ApS holds ISO/IEC 27001:2022 certification (certificate 122160, issued by Prescient Security LLC and valid subject to annual surveillance audits) covering the information security management system that supports our platform on Amazon Web Services and Google Cloud. GameAnalytics undergoes an annual SOC 2 Type II examination, holds the kidSAFE COPPA certification, has been awarded the ePrivacy seal, which is currently under periodic reassessment, and maintains a real-time trust report. You can review our trust report and raise security questions at security@gameanalytics.com. Our SOC 2 Type II report is available on request under confidentiality.

If we discover a security incident affecting your Personal Data, we will assess it, contain it and, where the law requires, inform you and the relevant supervisory authority. We may also contact you with precautionary advice, for example to watch for phishing, where an incident affects account data even if the law does not require formal notification.

10. Your data protection rights

Depending on where you are located, you have rights over your Personal Data. Where GameAnalytics is the controller, you may exercise these rights with us directly. Where GameAnalytics acts as a processor for a Customer, please contact the relevant game developer, and we will assist them in responding.

Rights in the European Economic Area, the United Kingdom and Switzerland. You have the right to be informed about our processing; to access your data; to have inaccurate data rectified; to have data erased in certain circumstances; to restrict processing in certain circumstances; to data portability in certain circumstances; and to object to processing based on our legitimate interests. You have an absolute right to object to direct marketing. Where we rely on consent, you may withdraw it at any time without affecting prior processing. You may also lodge a complaint with a supervisory authority.

Rights in the United States. Depending on your state of residence, you may have the right to know what Personal Data we hold about you, to access or delete it, to correct it, to obtain a portable copy, and to opt out of certain processing. We do not sell Personal Data and do not share it for cross-context behavioural advertising, and we do not use Personal Data for profiling that produces legal or similarly significant effects. We will not discriminate against you for exercising these rights. If we deny a request, you may appeal by replying to our decision, and we will respond within the period required by your state's law.

Exercising your rights. You will not usually have to pay a fee. We may charge a reasonable fee, or decline to act, if a request is manifestly unfounded or excessive. To exercise your rights where we are the controller, email privacy@gameanalytics.com. We may need to verify your identity, for example by asking you to respond from the email address associated with your account.

11. Children's privacy

Our platform and website are for businesses and are not directed to children, and we do not knowingly collect Personal Data from a child without the required consent. We design our platform so that data collected from games can be used to support the internal operations of those games rather than to profile or advertise to children.

In the course of providing analytics, the technology may collect persistent identifiers such as device identifiers. For games that a developer has configured as directed to children, these identifiers are used only to support internal operations, which include service delivery and network communication, platform security and integrity, usage and session analytics, retention and funnel reporting, product improvement and experimentation, and detection of invalid traffic and fraud. Persistent identifiers collected from child-directed games are not used to contact a child, to serve targeted advertising, or to build a profile of a child for any other purpose, and data from such games is made available to AI-powered features and external tools only in aggregated form unless the developer instructs otherwise.

We support developers in meeting their obligations to children through role-based access controls and data segregation, training for personnel who handle children's data, contractual commitments from our service providers, review of our providers' practices, and configuration options that restrict the use of identifiers for child-directed games. Our approach reflects the United States Children's Online Privacy Protection Act and its current rule, the United Kingdom Age Appropriate Design Code, and applicable European guidance on children's data. The developer of each game remains responsible for determining whether its game is directed to children and for age assurance.

If you are a parent or guardian and believe a child has provided Personal Data without your consent, please contact us at privacy@gameanalytics.com and we will act, together with the relevant developer, to address it.

12. Cookies, contact and complaints

Cookies. We use cookies and similar technologies on our website and in our platform. Non-essential cookies are used only with your consent, which you can give or withdraw through the consent banner managed by our consent management provider. More information is in our Cookie Policy at gameanalytics.com/trust/cookie-policy.

How to contact us. To exercise your rights or ask a question about how we handle Personal Data, contact us at privacy@gameanalytics.com, marking your message for the attention of the Data Protection Officer. You can also write to GameAnalytics ApS, Pilestraede 58, 2, 1112 Copenhagen K, Denmark, or to GameAnalytics Limited at its registered office.

How to complain. You may lodge a complaint with a supervisory authority. Our lead European authority is the Danish Datatilsynet. In the United Kingdom you may complain to the Information Commissioner's Office. In Switzerland you may contact the Swiss Federal Data Protection and Information Commissioner. If you are elsewhere in the European Economic Area, you may contact your local authority.

Changes to this notice. We may update this notice from time to time. Where we make material changes, we will notify you as required by applicable law, by an in-product notice. Non-material updates take effect when published. Each version states its version number and effective date.

13. Information for Players

This section is for players of games that use GameAnalytics. When you play a game that uses our technology, the game sends us information about how the game is used so that the developer can understand and improve it. This typically includes technical information about your device, a randomly generated identifier that lets the developer measure activity without knowing your name, approximate location (country, region and city), and events describing what happens in the game, such as sessions, progress and purchases. We use your internet protocol address to work out your approximate location and then keep it only in a shortened form for a short period for security reasons.

In this relationship the game's developer decides what is collected and why. GameAnalytics processes this information on the developer's behalf and does not use it to identify you personally, to contact you, or to advertise to you. We do not sell it. Where a developer uses our AI-powered features or connects our platform to its own tools, the information those features see is aggregated, unless the developer configures its account otherwise, and the developer is responsible for the tools it chooses. If you want to know how a particular game uses your data, or if you want to exercise your rights, please contact that game's developer, who can ask us for assistance. You can also read the developer's own privacy policy, which should be available in or alongside the game.

Upcoming Privacy Notice