Last updated: August 21, 2026
1. Introduction
We don't sell your data. Pinky promise. Actually, a legally binding one. This Privacy Policy explains how GAMOSY ("Gamosy," "we," "us," or "our") collects, uses, shares, and protects your personal data when you use our platform at www.gamosy.com (the "Platform"), including our integrated tools and services such as Gamosy Social Publisher, Gamosy KeyVault, and Gamosy Media Monitoring.
This policy is written to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws. If legal documents were boss fights, this one is designed to be fair - no surprise mechanics, no hidden phases.
2. Who We Are (Data Controller)
The data controller responsible for your personal data is:
- Company: Gamosy Sp. z o.o.
- Tax identification number (NIP): 1182331268
- Registered seat: Warsaw, Poland, European Union
- Privacy contact: privacy@gamosy.com
- General contact: info@gamosy.com
We do not currently have a Data Protection Officer (DPO). For all privacy-related inquiries, please contact us at privacy@gamosy.com.
3. What Data We Collect
Here's the full inventory - no hidden loot tables:
3.1 Account Data
When you create an account, we collect:
- Email address
- Display name
- Avatar (if provided or imported from OAuth)
- Account type (personal or team)
- Password (stored as a secure hash - we never see your actual password)
- Registration metadata (authentication provider used, registration timestamp, onboarding completion status)
3.2 OAuth Platform Data
When you connect third-party accounts - including via Gamosy Social Publisher (X/Twitter, LinkedIn, Facebook, Instagram, Threads, Pinterest, TikTok, YouTube, Discord, Reddit, Bluesky, Telegram, Mastodon, Tumblr, WordPress, Slack, Microsoft Teams, VK, Weibo) and other integrations (Twitch, Steam) - we collect:
- Platform username and profile URL
- Platform avatar
- Follower/subscriber count
- Total view count and content count
- Average views per content
- Content categories
- Platform-specific metadata (e.g., channel description, upload frequency, channel creation date) stored in a flexible format
- OAuth tokens (access token, refresh token) - for creator platform accounts (YouTube, Twitch), these are encrypted at rest using pgcrypto symmetric encryption with the key managed in Supabase Vault. For other integrations, tokens are protected by row-level security access controls.
We do not access your private messages, watch history, or any data beyond what is necessary for the Platform's features. We only ask for the minimum OAuth scopes required.
3.3 Developer Profile Data
If you register as a game developer, we additionally collect:
- Steam ID, username and avatar (optional, collected only if you link a Steam account so your Steam name shows on your public page)
- Publisher API key (optional, encrypted at rest using pgcrypto) - used for game ownership verification
- Verification status
3.4 Campaign & Key Data
When you create or participate in campaigns:
- Campaign details (title, description, requirements)
- Game keys (stored in KeyVault with row-level security restricting access to campaign owners and approved creators)
- Application details and status
- Content submission links
3.5 Media Monitoring Data
If you use the Media Monitoring feature, we additionally collect:
- Monitored phrases and their configuration (required and excluded terms, selected sources, linked game)
- Publicly available mentions matching your phrases from Steam reviews and news, Twitch streams and clips, Reddit, YouTube, Bluesky, Threads, and Hacker News: a short excerpt of the public post, its title, URL, the author's public handle and platform identifier, engagement counts, and publication date. We never collect private messages, emails, or non-public content, and we store only an excerpt rather than full post bodies.
- A sentiment classification (positive, negative, neutral) computed for each collected mention
- Alert events (mention volume spikes, negative review surges)
We process these public third-party mentions on the basis of our and our customers' legitimate interest in monitoring public reception of their games and brands (Art. 6(1)(f) GDPR), supported by a documented legitimate interest assessment. Collected mentions are automatically deleted after 90 days. Authors of public posts may request erasure of their data at any time via privacy@gamosy.com. Unlike our publishing tools, Media Monitoring collects no OAuth tokens for these public sources and never posts on your behalf.
3.6 Billing Data
When you subscribe to a paid plan:
- Stripe customer ID
- Subscription plan and status
- Billing history (invoices, amounts)
We do not store your credit card number. All payment processing is handled by Stripe. We never see, store, or have access to your full card details. Stripe is PCI DSS Level 1 certified - the highest level of payment security.
3.7 Usage Data
We automatically collect:
- IP address
- Browser type and version
- Operating system
- Pages visited and time spent
- Referring URL
- Device information
3.8 Cookie Data
We use cookies and similar technologies as described in our Cookie Policy.
4. How We Collect Your Data
- Directly from you: When you create an account, fill out your profile, create campaigns, configure Media Monitoring phrases, or contact us.
- From OAuth providers and API integrations: When you connect your social accounts (including YouTube, Twitch, TikTok, Steam, Reddit, X/Twitter, LinkedIn, Facebook, Instagram, Threads, Pinterest, Bluesky, Discord, Telegram, Mastodon, Tumblr, Slack, Microsoft Teams, VK, Weibo, and WordPress), we receive data from those platforms via their APIs.
- Automatically: Through cookies, analytics tools, and server logs when you use the Platform.
5. Why We Process Your Data (Legal Basis)
Under GDPR, we need a legal basis for each type of processing. Here's the breakdown - think of it as a skill tree, but for legal compliance:
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Providing the Platform (account, campaigns, keys) | Performance of contract (Art. 6(1)(b)) |
| Processing payments via Stripe | Performance of contract (Art. 6(1)(b)) |
| Syncing OAuth platform metrics | Performance of contract (Art. 6(1)(b)) |
| Media Monitoring configuration and alerts (your phrases, alert delivery) | Performance of contract (Art. 6(1)(b)) |
| Collecting and classifying public third-party mentions (Media Monitoring) | Legitimate interest (Art. 6(1)(f)) - monitoring public reception of customer games and brands |
| Calculating Campaign Completion Rate (CCR) | Legitimate interest (Art. 6(1)(f)) - trust & marketplace quality |
| Preventing fraud and key resale | Legitimate interest (Art. 6(1)(f)) - platform security |
| Creator Discovery (finding relevant YouTube creators for developer outreach) | Legitimate interest (Art. 6(1)(f)) - connecting developers with relevant creators (see Section 20) |
| Analytics (Google Analytics 4 on marketing pages, PostHog inside the authenticated app) and error tracking (Sentry) | Legitimate interest (Art. 6(1)(f)) - service improvement |
| Sending transactional emails (key received, etc.) | Performance of contract (Art. 6(1)(b)) |
| Sending marketing emails | Consent (Art. 6(1)(a)) - you can opt out anytime |
| Complying with legal obligations (tax, accounting) | Legal obligation (Art. 6(1)(c)) |
6. Who We Share Your Data With
We share your data only with trusted service providers who need it to help us run the Platform and, for assigned business leads only, with the individual Gamosy Partner working that lead (see Section 21). No selling. No shady data brokers. No loot box mechanics with your personal info.
| Service Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase | Database hosting, authentication | All account and platform data | EU (Frankfurt) |
| Vercel | Application hosting, CDN | IP address, usage data | Global (US primary) |
| Stripe | Payment processing | Billing data, email | US (EU-US DPF) |
| Resend | Transactional emails | Email address, name | US |
| PostHog | Product analytics (authenticated app, /home) | Usage data, anonymized events | EU |
| Google LLC (Google Analytics 4) | Marketing analytics (public pages only) | Anonymized IP, pseudonymous device ID, page views; no advertising signals | US (EU-US DPF + SCCs) |
| Sentry | Error monitoring | Error logs, IP address | US |
| YouTube API | Creator metrics sync | OAuth tokens (encrypted) | US |
| YouTube Data API | Creator Discovery (see Section 20) | Public channel/video metadata (no account connection required) | US |
| Twitch API | Creator metrics sync | OAuth tokens (encrypted) | US |
| TikTok API | Creator metrics sync | OAuth tokens | US |
| Steam API | Game import and ownership verification | Publisher key, Steam ID (only if you link a Steam account) | US |
| Reddit API | Media Monitoring (public post search) | Search queries (no user tokens) | US |
| Anthropic | Social Publisher content generation; Media Monitoring sentiment classification | Game data you submit for generation; public mention excerpts (no account data) | US |
| Individual Gamosy Partners | Contacting assigned business leads on our behalf (see Section 21) | The assigned lead's contact record | Partner's own country |
Public Marketplace Data: If you opt to be listed in the creator or developer marketplace, certain non-sensitive profile data (username, avatar, platform metrics, verification status) will be visible to other authenticated users of the Platform.
7. International Data Transfers
Our primary database (Supabase) is hosted in the EU (Frankfurt, Germany). However, some of our service providers are located outside the EU/EEA, primarily in the United States.
For transfers to the US, we rely on:
- EU-US Data Privacy Framework (DPF): For providers certified under the DPF (Stripe, Sentry).
- Standard Contractual Clauses (SCCs): For providers not certified under the DPF.
We ensure that all transfers provide an adequate level of data protection as required by GDPR Chapter V. You can request copies of the relevant safeguards by contacting privacy@gamosy.com.
8. Data Retention
We keep your data only as long as necessary. No hoarding - we're not digital pack rats:
| Data Category | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| OAuth tokens | Until platform disconnected or account deleted |
| Campaign data | 3 years after campaign ends (for analytics) |
| Game keys | 3 years after distribution (audit trail) |
| Media Monitoring mentions (public third-party posts) | 90 days (automatic rolling deletion) |
| Media Monitoring alert history | 6 months |
| Media Monitoring phrases and configuration | Until you delete them or your account |
| CRM contact records (business contacts held in a Gamosy workspace) | Until the workspace deletes them, until you object or request erasure, or until they are no longer needed for outreach |
| Partner leads and lead assignments | A lead is protected for one partner for 90 days, counted from submission for a lead the partner registered and from acceptance for a lead we assigned. The assignment record itself (who was assigned which contact, and when access started and ended) is kept afterwards as an audit trail |
| Partner profile, commission and payout records | Until the partner profile is closed; commission and payout records are kept for 7 years under the Polish tax law requirement stated below for billing data |
| Billing data | 7 years (Polish tax law requirement) |
| Usage/analytics data | 26 months (then anonymized) |
| Server logs | 90 days |
| Error logs (Sentry) | 90 days |
After retention periods expire, data is permanently deleted or irreversibly anonymized. When you delete your account, we remove your personal data within 30 days, except for data we are legally required to retain (e.g., billing records for tax compliance).
9. Your Rights (EU/EEA Residents)
Under GDPR, you have the following rights. Think of them as your inventory of data powers:
- Right of Access (Art. 15): Request a copy of all personal data we hold about you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten"). Subject to legal retention requirements.
- Right to Restriction (Art. 18): Request that we limit processing of your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON or CSV).
- Right to Object (Art. 21): Object to processing based on legitimate interest (including profiling for CCR scoring).
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent (e.g., marketing emails), you can withdraw at any time.
To exercise any of these rights, email privacy@gamosy.com. We will respond within 30 days (extendable by 60 days for complex requests, with notification). No fee is required unless requests are manifestly unfounded or excessive.
10. Your Rights (California / US Residents)
Under the California Consumer Privacy Act (CCPA) as amended by the CPRA, California residents have additional rights:
- Right to Know: Request what personal information we collect, use, disclose, and sell.
- Right to Delete: Request deletion of your personal information.
- Right to Opt-Out of Sale: We do not sell your personal information. We do not share personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Right to Correct: Request correction of inaccurate personal information.
To exercise these rights, email privacy@gamosy.com. We will verify your identity before processing your request.
Do Not Sell or Share My Personal Information: Gamosy does not sell your personal information and has not sold personal information in the preceding 12 months.
11. Children's Privacy
Gamosy is not directed at children. We do not knowingly collect personal data from:
- Children under 16 in the EU/EEA (GDPR Art. 8)
- Children under 13 in the United States (COPPA)
If we discover that we have collected personal data from a child below these ages without proper consent, we will delete that data promptly. If you believe a child has provided us with personal data, contact privacy@gamosy.com.
12. Automated Decision-Making & Profiling
Gamosy uses automated systems to calculate the Campaign Completion Rate (CCR) - a score (0-100) that tracks how reliably a creator fulfills their campaign commitments (e.g., publishing content within the agreed timeframe after receiving a game key).
How CCR works:
- CCR is calculated based on your campaign activity within Gamosy - specifically, how many campaigns you completed versus how many keys you received.
- CCR is visible to developers as a trust signal when reviewing campaign applications. It is not the sole basis for acceptance or rejection - developers make final decisions manually.
- CCR does not produce legal effects or similarly significant effects on you (GDPR Art. 22). It's a reliability indicator, not a verdict. Think of it as a reputation system - helpful context, but humans make the call.
You have the right to object to profiling under GDPR Art. 21. Contact privacy@gamosy.com to exercise this right.
13. Security
We take security seriously - like raid-night seriously. Technical and organizational measures we employ include:
- Encryption at rest: Sensitive data (OAuth tokens for creator platform accounts, publisher API keys) is encrypted using pgcrypto symmetric encryption, with the encryption key securely managed in Supabase Vault.
- Encryption in transit: All data transmitted between your browser and our servers is encrypted via TLS 1.2+.
- Row-Level Security (RLS): Database access is controlled at the row level - users can only access data they are authorized to see.
- Column-Level Security: For creator platform accounts and developer profiles, sensitive columns (OAuth tokens, encrypted API keys) are restricted at the database column level, preventing unauthorized access even for authenticated users.
- Secure authentication: Powered by Supabase Auth with support for email/password and OAuth providers.
- Regular updates: Dependencies and infrastructure are kept up to date to patch known vulnerabilities.
No system is 100% secure. If you discover a security vulnerability, please report it responsibly to info@gamosy.com. We appreciate the help - you're basically a white-hat in our dungeon.
14. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:
- We will notify the relevant supervisory authority (UODO) within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
- If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by GDPR Article 34.
- Notification will include the nature of the breach, likely consequences, and measures taken or proposed to address it.
15. Marketing Communications
We may send you marketing emails about new features, campaigns, or promotions - but only if you have opted in. You can opt out at any time by:
- Clicking the "unsubscribe" link in any marketing email.
- Updating your notification preferences in your account settings.
- Contacting privacy@gamosy.com.
We comply with CAN-SPAM (US), GDPR (EU), and applicable anti-spam laws. Transactional emails (account confirmations, key delivery notifications, security alerts) are not marketing and cannot be opted out of, as they are necessary for the service.
16. Complaints & Supervisory Authority
If you believe we have violated your data protection rights, you have the right to lodge a complaint with a supervisory authority.
Our lead supervisory authority is:
- UODO (Urząd Ochrony Danych Osobowych / Personal Data Protection Office)
- ul. Stawki 2, 00-193 Warsaw, Poland
- Website: https://uodo.gov.pl
EU consumers may also use the EU Online Dispute Resolution (ODR) platform: https://ec.europa.eu/consumers/odr
Of course, we'd appreciate it if you contacted us first at privacy@gamosy.com so we can try to resolve the issue directly. We promise to take every complaint seriously.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify you via email or a prominent notice on the Platform at least 30 days before the changes take effect.
- Where required by law, obtain your consent for material changes to how we process your data.
We encourage you to review this policy periodically. Think of it as checking for patch notes - except for your privacy instead of game balance.
18. YouTube API Services - Additional Disclosure
Gamosy uses YouTube API Services. By connecting your YouTube account to Gamosy, you agree to be bound by the YouTube Terms of Service. In addition to our normal data handling procedures described in this Privacy Policy, your use of YouTube data is also governed by the Google Privacy Policy.
You can revoke Gamosy's access to your YouTube data at any time via the Google Security Settings page.
Separately, Gamosy Creator Discovery processes limited public YouTube data about creators who have not connected an account to Gamosy. That distinct data flow is described in Section 20.
19. Gamosy Social Publisher - Additional Disclosure
Gamosy Social Publisher is an integrated feature of the Gamosy platform that allows game developers to create, schedule, and publish social media content across multiple platforms simultaneously. When using Gamosy Social Publisher, the following additional data practices apply:
19.1 BYOK (Bring Your Own Keys) Model
Gamosy Social Publisher uses a Bring Your Own Keys model. This means you provide your own API credentials (Client ID, Client Secret, API keys) from each social media platform. Gamosy stores these credentials securely in your account and uses them exclusively to publish content on your behalf. We do not share your API credentials with any third party.
19.2 Social Platform Connections
Gamosy Social Publisher supports connecting to: X (Twitter), LinkedIn, Facebook, Instagram, Threads, Pinterest, TikTok, YouTube, Discord, Reddit, Bluesky, Telegram, Mastodon, Tumblr, Slack, Microsoft Teams, VK, Weibo, and WordPress. When you connect a platform via OAuth or provide API credentials (BYOK model), we collect and store:
- OAuth access tokens and refresh tokens
- Platform user identity (username, user ID, profile picture)
- Token expiration timestamps
We use these tokens solely to publish content you create or approve, refresh expired tokens, and display your connected account identity in the Gamosy dashboard. We do not read your private messages, browse your feed, or access data beyond the minimum OAuth scopes required for publishing.
19.3 AI Content Generation and Advertising Recommendations
Gamosy Social Publisher uses AI (Anthropic Claude) to generate social media post suggestions based on your game data and input. Your game information (name, genre, reviews, player counts) and any text you provide are sent to the AI service for content generation. We do not use your content to train AI models. Generated content is stored in your Gamosy account and is not shared with other users.
The same AI service also powers advertising recommendations in Gamosy Ads Manager. When you connect an ad account and request recommendations, campaign metadata and daily performance metrics (spend, impressions, clicks, reach) that Gamosy retrieves via the Meta Marketing API for your connected ad accounts are sent to the AI service to generate suggestions. These recommendations are advisory only - Gamosy never executes changes on your ad accounts. We do not use this data to train AI models, and generated recommendations are stored in your Gamosy account and are not shared with other users.
19.4 TikTok Content Posting API
When you connect TikTok via Gamosy Social Publisher, we collect, store, and process the following data received from TikTok's Login Kit and Content Posting API on your behalf:
- Your TikTok
open_id(a stable, app-scoped identifier - never your TikTok email or phone number) - Your TikTok display name (
creator_nickname) and unique username (creator_username) - Your TikTok avatar URL (
creator_avatar_url) - the URL only, not the image bytes - An OAuth access token (24-hour lifetime) and refresh token (365-day sliding window) issued by TikTok, stored encrypted at rest in our database
- The OAuth scopes you granted (
scope) - stored so we can confirm we only ever request the minimum permissions needed (user.info.basic,user.info.profile,video.publish) - The list of privacy options and interaction settings TikTok exposes for your account (
privacy_level_options,comment_disabled,duet_disabled,stitch_disabled,max_video_post_duration_sec) - fetched fresh each time you open the composer
We use this data only to (a) display your TikTok account in the Gamosy composer so you can confirm which account a post will be sent to, (b) call TikTok's /v2/post/publish/video/init/ endpoint with the post you authored, and (c) poll /v2/post/publish/status/fetch/ until your video is published or fails. We do not read your TikTok inbox, comments, follower list, or any video other than the one you actively publish.
Lawful basis (GDPR). Connecting TikTok and authorising posting is processed on the basis of your explicit consent (Art. 6(1)(a)) collected through TikTok's OAuth consent screen and our Connect TikTok confirmation. Once connected, sending a video you compose is processed on the basis of performance of contract (Art. 6(1)(b)). Retention of publication metadata (publish IDs, status, timestamps) for 12 months relies on legitimate interest (Art. 6(1)(f)) in service auditability, abuse prevention, and your ability to review your posting history within Gamosy.
Sub-processor. Video files and metadata are transmitted to TikTok Pte. Ltd. (and its affiliates including TikTok Inc. for US-served accounts) acting as an independent controller for the published content and as a processor for the API call itself. TikTok's privacy policy at tiktok.com/legal/privacy-policy governs their processing.
Retention. We retain TikTok OAuth tokens and identity fields only while the connection is active. When you click Disconnect TikTok in Gamosy we immediately (1) call TikTok's /v2/oauth/revoke/ token-revocation endpoint to invalidate the access and refresh tokens at source, and (2) clear the OAuth tokens and identity fields from the corresponding row in our credentials table. Encrypted database backups are rotated within 30 days, after which the data is unrecoverable from any Gamosy system. Published-post records (publish_id, status, the published post's public URL, any failure reason (fail_reason), and timestamps) are retained for 12 months for analytics and audit; you may request earlier deletion at privacy@gamosy.com.
How to delete your TikTok-tied data. Either (a) click Disconnect TikTok from Platforms → TikTok inside Gamosy, which triggers the revocation + deletion described above, or (b) email privacy@gamosy.com with the subject "Delete TikTok data" - we respond within 30 days. You can additionally revoke Gamosy's access from your TikTok app: Profile → Settings & privacy → Security & permissions → Manage app permissions → Gamosy → Remove.
We comply with TikTok's Terms of Service and the Content Sharing Developer Guidelines.
19.5 Data Deletion
You can disconnect any social media platform from Gamosy Social Publisher at any time. Upon disconnection, we delete your stored OAuth tokens and platform credentials. Published posts remain on the respective social media platforms and must be deleted directly from those platforms.
For Meta platforms (Facebook, Instagram, Threads) you can also remove Gamosy from your Meta account's connected-apps settings. Meta then notifies us through our Deauthorize and Data Deletion callbacks and we automatically deactivate the connection and delete the associated tokens and credentials. Full instructions and the ability to check the status of a deletion request are available on our Data Deletion page.
19.6 TikTok Developer Compliance
Gamosy Social Publisher is registered as a third-party application with TikTok for Developers and is subject to the TikTok Content Sharing Developer Guidelines, the TikTok Branded Content Policy, and the Music Usage Confirmation. The privacy, interaction, AI-generated content, and Branded Content disclosure controls described in those documents are reproduced in the Gamosy composer exactly as required by TikTok. We do not add promotional watermarks, brand logos, links, or text overlays to videos uploaded to TikTok via the Content Posting API.
20. Gamosy Creator Discovery - Additional Disclosure
Gamosy Creator Discovery is a tool for verified game developers that helps them find YouTube content creators relevant to their game (for example, creators who recently covered a similar title) so the developer can invite them to feature the game, typically in exchange for a free game key. This section explains how we process creator data for this feature and applies in addition to the rest of this Privacy Policy.
20.1 What Data We Process and Where It Comes From
Creator Discovery uses the official YouTube Data API v3. For a developer's search we obtain only publicly available channel and video metadata that the API returns, such as:
- YouTube channel ID, title, custom URL (handle), and country
- Public channel and video descriptions, and the title of the video that matched the search
- Public statistics (subscriber count, view count, video count) and the most recent upload date
- Channel thumbnail (avatar) URL
The YouTube Data API does not expose creator email addresses, and we do not attempt to read the login- and CAPTCHA-protected business email on a channel's About page, nor do we use unofficial scrapers. Where a creator has voluntarily published an email address or social media links inside their public channel or video description, we may extract and store those details so a developer can reach out. Many creators publish no contact details; for them we store only the public channel information above and offer in-app contact instead.
20.2 Information for Creators (GDPR Art. 14)
If you are a YouTube creator whose channel appears in Creator Discovery, please note that we obtained your information from a public source (YouTube) rather than directly from you. Under GDPR Article 14:
- Controller: GAMOSY (see Section 2).
- Source: The public YouTube Data API and the public information you chose to publish on your channel and videos.
- Categories of data: Public channel identifiers and metrics, and any contact details you self-published in your public descriptions.
- Purpose: To let game developers identify and contact relevant creators about promotional opportunities (B2B outreach).
- Recipients: The developer workspace that ran the search. Discovered data is private to that workspace and is not published or sold.
- Retention: Data we obtain from the YouTube API is cached and refreshed or deleted within 30 days; contact records a developer imports are kept only as long as needed for outreach (see Section 20.4).
- Your rights: You can object at any time and be permanently suppressed and erased, with no need to give a reason (see Section 20.5), in addition to the rights in Section 9.
20.3 Legal Basis
We process creator discovery data on the basis of legitimate interest (GDPR Art. 6(1)(f)) - namely connecting game developers with content creators who are likely to be interested in covering their game. We have carried out and documented a Legitimate Interest Assessment (LIA) weighing this interest against creators' rights and freedoms. We process only data relevant to professional, creator-facing outreach, and no special-category data.
20.4 Retention
In line with the YouTube API Services Terms of Service (and the Google Privacy Policy), statistics and metadata we obtain from the YouTube API are treated as a cache and are refreshed or deleted within 30 days. Durable contact records that a developer imports into their CRM workspace are kept separately and retained until the developer deletes them, until you exercise your right to object or erasure, or until they are no longer needed for outreach.
20.5 Your Right to Object and Be Forgotten
You can object to this processing at any time, with no need to give a reason, by emailing privacy@gamosy.com. When you object we will:
- stop processing your data for Creator Discovery and remove it from developer workspaces;
- add you to a permanent suppression list so your channel is never re-imported or contacted through Creator Discovery again; and
- complete erasure of your discovery-related data from our active systems within 7 days; residual copies in encrypted backups are purged on our normal backup-rotation cycle (within 30 days).
20.6 How Developers Contact You
Where you already have a Gamosy account, developers contact you through Gamosy's in-app messaging, which we treat as the default and lowest-risk channel. Where you do not, a developer may use the public contact details you self-published. Any email a developer sends is the developer's own communication and is subject to applicable e-privacy and anti-spam laws; each message identifies the sender and offers a way to opt out.
21. Gamosy Partner Program - Additional Disclosure
Gamosy Partners is our closed referral program: existing Gamosy users recommend the Platform to studios and creators and earn a commission when a referral subscribes. The rules of the program are set out in the Partner Program Terms. This section describes the two data flows the program creates and applies in addition to the rest of this Privacy Policy.
21.1 If You Are a Partner
When you activate a partner profile, we process your account details, your referral code, your click and referral statistics, your payout addresses (PayPal or Wise), and your commission and payout ledger. We process this to operate the program and pay you (performance of contract, Art. 6(1)(b)) and to meet our accounting and tax duties (legal obligation, Art. 6(1)(c)). Referral attribution uses the first-party cookies described in our Cookie Policy.
A partner profile also processes other people's data: the studios a partner registers as leads, and the assigned leads described below. A partner is bound by the Partner Program Terms in respect of all of it.
21.2 Assigned Leads - When a Partner Contacts You On Our Behalf
We may assign a business contact from our own CRM to an individual partner, who then contacts that person about Gamosy on our behalf. If a Gamosy Partner has contacted you, this section explains where your details came from and what that partner can and cannot do with them.
Gamosy remains the controller of the lead record. The partner acts as our processor and may process the data only on our documented instructions, under the data processing terms in Annex B of the Partner Program Terms. Partners may not export, download, copy or store lead details anywhere outside Gamosy, may not use them for their own purposes, and may not contact anyone we did not assign.
What a partner can see. Access is staged:
- Before the partner accepts - preview only. The partner sees the contact's display name, company, country and contact type, together with our briefing. No email address and no phone number are disclosed at this stage. The partner has 48 hours to accept or decline; if they do not respond, the assignment expires and the contact returns to the assignable pool.
- After the partner accepts - the full contact card. The partner sees the contact's name, email address, phone number, role, company, country, preferred contact channel, tags and date of last contact. Alongside these they see a profile picture and a public YouTube handle and subscriber count where we hold them (drawn from the public sources described in Section 20), an internal relationship score, and any sales opportunities linked to the contact. The partner may read and write notes, and must log every contact attempt.
- What a partner never sees. The recorded legal basis for the contact, any custom fields, the internal link between the contact and a Gamosy user account, and the internal relationship owner are excluded from the partner view at every stage.
When access ends. A partner's access is tied to the assignment. When an assignment is declined, expires, is withdrawn by us or is completed, the partner's access to the contact card ends. If we suspend a partner or they leave the program, we withdraw their live assignments, and that is what ends their access. In every case the partner must stop contacting you within 24 hours and must keep no copy of your details, and that duty applies to them whether or not the platform has already closed the door. A lead is protected for one partner for 90 days, counted from the moment the partner submits it if they registered it themselves, or from the moment they accept it if we assigned it. The assignment record itself is retained afterwards as an audit trail, so we can always reconstruct who had access to a contact and when.
21.3 Legal Basis, Source of the Data and Your Right to Object
Legal basis. We process lead records for business to business prospecting on the basis of legitimate interest (GDPR Art. 6(1)(f)) - identifying and contacting studios, publishers and creators who are likely to be interested in Gamosy. We hold a documented assessment weighing that interest against your rights and freedoms. We process business contact details only, and no special-category data. Sending the message is governed separately: electronic commercial communication requires prior consent under Polish law, and partners are instructed accordingly and may use only the channels we provide for the assignment.
Source of the data (GDPR Art. 14(2)(f)). Where we did not receive your details from you directly, a lead record comes from one of the following:
- you, your employer or a colleague giving them to us - for example through a contact form, a demo request, an event, a press list or a Gamosy sign-up;
- publicly available business sources - for example a studio or publisher website, a public press or business contact page, or a public creator profile, including the public YouTube data described in Section 20;
- a Gamosy Partner registering your studio as a lead under the Partner Program Terms.
If you want to know which of these applies to your record, ask us and we will tell you.
When we tell you. Because we did not collect these details from you, the information required by Art. 14 is delivered with the first contact: every partner is required to include this notice, or a link to it together with a statement that Gamosy is the controller and that you may object, in the first message they send you. That requirement is a documented instruction under Annex B of the Partner Program Terms, and a partner may not remove or reword it.
Your right to object. Because this processing relies on legitimate interest, you may object at any time under GDPR Art. 21, with no need to give a reason, and we will stop. You can tell any partner who contacts you to stop - they must stop immediately and report it to us the same day - or write to us directly. On request we will also add you to a suppression list so the record is not re-created. The rights in Section 9 apply here in full, including access, rectification and erasure. Note that notes a partner writes about you form part of your record and may have to be disclosed to you.
Questions, objections and erasure requests relating to this section go to privacy@gamosy.com. Questions about the program itself go to partners@gamosy.com.
Achievement unlocked: "Privacy Policy Completionist." You now know more about how we handle data than most people know about their own phone settings. Questions? Reach out at privacy@gamosy.com.

