Gandras is a small game for practising Lithuanian. It keeps as little information as possible, shows no ads, sets no advertising cookies, and never follows you around the web.
Who we are
Gandras (gandras.unbxed.dev) is an independent project by unbxed.dev. We decide how the information described here is used, and you can reach us at gandras@unbxed.dev.
Information we collect
Playing as a guest
If you never create an account, your name, settings, streak, egg, practice history and progress stay only in this browser on this device. Nothing is uploaded to our servers. Clearing your browser storage, or using Reset progress in Settings, removes it.
With an account
Creating an account is optional. It lets Gandras synchronise your progress across your devices.
When you sign in, we store:
- your account identifier;
- your display name;
- your email address;
- your Gandras character and customisations;
- your learning progress, including streaks, eggs and hatchlings, practice history, statistics, settings and achievements.
Google Sign-In
You may choose to sign in with your Google account. Gandras requests only the standard OpenID Connect scopes:
openidemailprofile
From Google we receive only your Google account ID, name, email address and profile picture (if your account provides one).
Gandras itself reads only your account ID, your name (to suggest what Gandras calls you) and your email address (shown in Settings so you know which account you're signed in with). Your profile picture link stays in the sign-in record that Supabase keeps for your account; Gandras doesn't display, copy or use it.
We use this information only to:
- create your Gandras account;
- authenticate you when you sign in;
- synchronise your progress between your devices.
Gandras does not access your Gmail, Google Drive, Google Calendar, Google Photos, Google Contacts or any other Google account data.
Gandras does not sell, rent or use your Google account information for advertising or marketing. It is never shared with other users.
Gandras' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide the features described here, and is never:
- used for advertising, including personalised or retargeted ads;
- sold, or transferred to data brokers or information resellers;
- used to train artificial intelligence or machine-learning models;
- used to determine credit-worthiness or for lending;
- read by a person, except with your permission, to investigate a problem you report, for security, or where the law requires it.
How we share Google user data
We don't share, transfer or disclose your Google user data with anyone, with one exception: Supabase stores your account and progress for us, as our service provider, and may use it only to run that service. We would otherwise disclose it only if the law requires us to. It is never sold or rented, and other players can't see it.
How we use your information
Your information is used only to:
- save your progress;
- synchronise your devices;
- remember your preferences;
- improve the game through anonymous usage statistics;
- fix crashes and bugs.
Anonymous analytics
Gandras measures overall usage using Umami. The information is anonymous and aggregated. We do not use advertising identifiers, tracking cookies or fingerprinting.
Umami records things like:
- page visits;
- rounds completed;
- settings changed;
- whether the app was installed;
- approximate country;
- device type;
- rough lifetime bands such as "3–6 days played".
None of this data identifies you personally or is connected to your Gandras account.
Crash reports
When something goes wrong, Gandras sends an error report to Sentry, hosted in the European Union. Reports include technical information such as the browser, page, app version and stack trace.
Crash reports may include a short replay of the moments before the error. Text is masked, images are blocked, and reports never contain your learning progress, Google account, email address or IP address.
Feedback
If you send feedback or report a mistake from inside the app, the message is stored in Sentry together with technical information needed to investigate it.
If you include your email address, it is used only to reply to your message.
Third-party services
- Supabase stores accounts and synchronised learning progress.
- Google authenticates users who choose Google Sign-In.
- Vercel hosts Gandras and processes standard web server logs, including IP addresses.
- Sentry receives crash reports and feedback.
- Umami provides anonymous, cookieless analytics.
Gandras contains no advertising, advertising cookies or cross-site trackers.
How we protect your data
- Every connection to Gandras, to Supabase and to Google uses HTTPS (TLS encryption).
- Your account and progress are stored in Supabase's database, encrypted at rest.
- The database lets each signed-in account read and change only its own rows (row level security); guests have no access at all.
- Gandras stores no passwords: Google confirms who you are.
- Only the developer can access the database directly, to run and maintain the service.
Data retention
- Your account information and learning progress are kept until you delete your account.
- When you choose Delete my account, they are removed from our database immediately.
- Crash reports and feedback are deleted automatically after 90 days.
- Analytics are only ever kept as anonymous totals, with nothing that identifies you.
- The copy in your browser stays on your device until you reset your progress or clear the site's data.
Deleting your data
In Settings, choose Delete my account to permanently remove your account and all information stored with it.
Any local copy stored in your browser remains on your device until you reset your progress or clear your browser's site data.
You can also request deletion by emailing gandras@unbxed.dev.
Questions
If you have any questions about this policy or how Gandras handles your information, contact gandras@unbxed.dev.
