Privacy
Raredle collects as little as a game with accounts can. This page says what that is in plain terms, including the parts that are unusual.
Who is responsible
Raredle is operated by Smol Apps, a sole proprietorship of Marc Wustrack, Gerhart-Hauptmann-Str. 18a, 49163 Bohmte, Deutschland. That is the controller for everything described on this page. Questions about your data go to mail@smol-apps.de, and the full provider details are in the imprint.
What is stored
Your email address, because signing in is a link sent to it. There is no password to store. Your Username, which you choose and which is public. Your rolls: six face values a day, the badges they matched, and the score they earned. Nothing else. There are no avatars, no uploads, and nowhere in Raredle to write free text except your Username.
Your email is never copied into the game's own tables, so no page and no query in Raredle can reach it. It stays inside the authentication system, which uses it for one thing: sending you a link.
Where it lives
In the European Union. The database runs in AWS eu-central-1, Frankfurt, so your email address and account record are stored in the EU. The sign-in emails are sent from Paris. The application itself is served from edge locations worldwide, but the data sits in Frankfurt.
Who else handles it
Raredle runs on three services, each acting on our instructions and for no purpose of their own:
- Neon holds the database and runs the authentication system: your email address, your Username, your rolls and your sign-in sessions. The database is in AWS
eu-central-1, Frankfurt. - Scaleway delivers the sign-in emails. It gets the address the link goes to and the message, nothing else: no Username, no roll, no history. Scaleway is a French company and sends from its Paris region, so this step stays in the EU.
- Vercel serves the application and counts page views. It sees the requests your browser makes, including your IP address, as any web host does.
All three are bound by a data processing agreement under Art. 28 GDPR, which in each case forms part of the terms that apply to using the service.
Nobody else is in the chain. No mailing list, no marketing tool, and nobody is sent your address for any purpose other than delivering the link you asked for.
The company behind it is American
The database region is Frankfurt, and that is where your account record sits. But Neon is a US company, and it operates the authentication system your address is stored in, so we cannot rule out that the address is accessed from outside the EU while Neon runs that system.
Sending the link no longer leaves the EU: that runs through Scaleway in Paris. Nothing beyond the address and the message is involved at any point: no roll, no Username, no history.
Why we are allowed to
- Your account, your email, your Username and your rolls: Art. 6(1)(b) GDPR. You asked for an account and these are what one is made of. Without them there is no service to provide.
- The visitor cookie for rolling without an account: Art. 6(1)(b) GDPR. It exists so the roll you were shown survives a reload, which is the thing you asked for by rolling.
- Sign-in IP addresses and user agents, and inspecting them for leaderboard farming: Art. 6(1)(f) GDPR. Our legitimate interest is a leaderboard that means something, and the records already exist as a by-product of signing in.
- Counting page views: Art. 6(1)(f) GDPR. Our legitimate interest is knowing which pages are used. It sets no cookies and identifies nobody.
- The Username hash kept after deletion: Art. 6(1)(f) GDPR. The interest is preventing a name from silently resolving to a different person, and it is explained in full below.
How long it is kept
Your email address and login are kept while your account exists and are removed when you delete it. Your rolls are kept indefinitely: they are the game's history, they appear in past leaderboards, and after a deletion they stay attributed to "a deleted player" rather than to you. The hash of a released Username is kept forever, on purpose. Sign-in session records are kept by the authentication system for as long as the session is valid.
Sharing a roll makes your past rolls recomputable
Read this before you share anything.
Raredle's dice are provably fair: each day's faces are derived from that day's secret and your player id, and once a day is over its secret is published so anybody can check the maths. A roll's public page publishes your player id so that check is possible.
So anyone holding a link to one of your rolls can recompute your faces for every closed day in Raredle's history, including days you never claimed. They cannot learn your email, your address or anything else, and they cannot compute anything about today until today is over. We chose this deliberately, because a fairness check only you could run would prove nothing to anyone else. The algorithm is published in full.
Sign-in records, and leaderboard farming
The authentication system records the IP address and browser user agent of each sign-in session. We may inspect those records to detect leaderboard farming, meaning one person running many accounts. We do not use them for advertising, we do not sell them, and we do not build profiles from them.
Raredle sets four cookies of its own and no third-party cookies. One holds your session. One holds a visitor identifier, so that a stranger who rolls without an account sees the same roll if they reload. The third remembers whether you have turned the sound off, and it is read before any sound plays, so a muted browser stays muted. The fourth remembers which changelog notice you have closed, so that a notice you have dismissed stays closed and a later one can still reach you.
Counting visits
One third-party script runs on the site: Vercel Web Analytics, which counts page views. It sets no cookies, and it does not follow you from here to anywhere else.
It is told the kind of page you are on rather than its address. An invite link is counted as "/i/[token]", a shared roll as "/r/[code]", and a profile as "/u/[username]". The invite token, the roll code and the username are removed before anything is sent, so the link somebody gave you is never handed on. There is no advertising script anywhere on the site.
Deleting your account
Deleting your account removes your email address and your login. Three things then happen to what is left:
- Your rolls stay, with their scores and their place in past Leaderboards, attributed to "a deleted player" rather than to you.
- Your follows are dropped, in both directions.
- Your Username is removed, and a peppered hash of it is kept forever. This is a deliberate exception to erasure. The hash cannot be read back into your name; its only purpose is to make sure nobody else is ever given that name. Otherwise every old link and message pointing at it would start resolving to a different person with no sign that anything changed. The cost is that if you come back later, you cannot take your old name again.
Your rights
Under the GDPR you may ask for a copy of your data (Art. 15), ask for it to be corrected (Art. 16), ask for it to be deleted (Art. 17, subject to the Username exception above), ask us to restrict what we do with it (Art. 18), ask for it in a portable form (Art. 20), and object to the processing we run on legitimate interest (Art. 21), which is the farming checks and the page counting. Raredle holds so little that a copy is short: your email, your Username, and your rolls.
Write to mail@smol-apps.de for any of it.
You can also complain to a data protection authority without asking us first. Ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, and you may equally go to the authority where you live or work.
Last updated 13 August 2026. Provider details are in the imprint.