SEC-06 / Privacy policy

Privacy policy

Gelopard is the trade name of Hedvig Holding AB, which is the controller for the personal data described here.

This policy covers the website at gelopard.com. Apps and games published under the Gelopard name link to this policy from their store listing, and each gets its own section below before it ships. Dibs is the exception: it stays web-only and keeps its practices published where it's played, linked from its section instead of duplicated here.

SEC-06.1 / Controller
EntityHedvig Holding AB
Trade nameGelopard
Reg.no559346-1865
VAT noSE559346186501
Registered officeStockholm, Sweden
SEC-06.2 / What is collected

The contact form is the only part of this site that collects anything. Sending it records six things:

Email addressThe address you type, so the enquiry can be answered.
MessageWhat you wrote.
IP addressUsed to rate limit the form, so it cannot be flooded.
CountryA two-letter code supplied by the network edge. Used to handle abuse.
BrowserThe user-agent string, shortened to 300 characters. Used to handle abuse.
TimeWhen the form was sent.

Nothing else is collected. There is no account, no payment and no profile.

SEC-06.3 / Legal basis

The processing rests on legitimate interest under Article 6(1)(f) of the GDPR: answering enquiries that were sent voluntarily, and keeping the form working for everyone else.

You are not asked for consent, because none of this is separable from the act of sending a message. If you would rather not supply it, write to contact@gelopard.com directly instead of using the form.

SEC-06.4 / How long it is kept
Stored copy30 days in Cloudflare KV, then deleted automatically.
Notification30 days in the mailbox that receives it.

Nothing is archived past those windows.

SEC-06.5 / Who else handles it
Cloudflare, Inc.Hosting, storage and outbound mail. United States. Transfers rest on the European Commission's standard contractual clauses.
Proton AGThe mailbox that receives the notification. Switzerland, which the European Commission recognises as providing adequate protection.

No one else for this site. The apps below name any processor of their own -- RevenueCat, Inc. (United States, standard contractual clauses) handles in-app purchases for Wake Alone, Skugga and Tillsvidare. Nothing anywhere here is sold, shared for advertising, or used to train anything.

SEC-06.6 / Cookies and tracking

This site sets no cookies. There is no analytics, no tag manager, no embedded third-party content and no tracking pixel. Nothing follows you between pages.

SEC-06.7 / Wake Alone

Wake Alone reads episodes from JSON and plays them entirely in your browser or app: there is no server involved in the story itself. What can leave your device is described below; the play data is on by default and can be switched off at any time, the purchase data exists only in the app and only if you buy something.

Device storageEpisode progress and 'scars' (choices that persist across episodes), kept in this browser's or app's local storage. Never leaves the device.
Anonymized play dataOn by default, switched off from the About panel in the app or the footer on the web. Two kinds of message go to wake.gelopard.com, a service Gelopard operates. Finishing a story sends the episode id, ending reached, step count, final sanity, and which rooms and choices were taken (by in-story id); kept 12 months, then deleted automatically. Counters send four short strings: what happened (a first session, a return day bucketed as 1, 2-6, 7-27 or 28+ days since first open, a story started or ended, an error in the page, the pack screen seen, bought or dismissed), which of those, the platform, and the version; kept three months as data points, and indefinitely as weekly totals. No device id, IP address, account identifier or timestamp is included in either, so no individual record exists to look up or delete on request. The only state the counters keep on the device is the date of first open. Turning the switch off stops any further sending.
Purchases (app only)The app sells story packs as one-time in-app purchases, handled by RevenueCat. RevenueCat holds an anonymous, randomly generated app-user id created on your device -- not linked to a name, email or account, since the app has no login -- plus the purchase and entitlement records needed to unlock what you bought and support Restore Purchases. Payment details are handled entirely by Apple or Google; Gelopard never sees them.

No cookies, no ads, no accounts. See RevenueCat's own privacy policy for how it handles the purchase data above.

SEC-06.8 / Dibs

Dibs stays web-only, so its practices are published where it's played rather than duplicated here: dibs.urdr.dev/privacy.html. The controller details above apply there too.

SEC-06.9 / Skugga

Skugga keeps level progress, stars, settings, tutorial state and the thumbs-up or thumbs-down you can give a level in this browser's or app's local storage. That never leaves your device.

The counters go to the game's own address, skugga.gelopard.com, and the feedback form to skugga-curator.urdr.dev; both are services operated by Gelopard (Hedvig Holding AB), the same controller named above, even though the second address sits on the urdr.dev domain rather than gelopard.com. Purchases go to RevenueCat instead, and only in the app.

CountersOn by default, switched off in the Settings screen. Four short strings per event: what happened (a first session, a return day bucketed as 1, 2-6, 7-27 or 28+ days since first open, a level finished, solved or solved with three stars, or an error in the page), which of those, the platform, and the version. Kept three months as data points, and indefinitely as weekly totals. No device id, session id, IP address, account identifier or timestamp is included, so no individual record exists to look up or delete on request. The only state the counters keep on the device is the date of first open. Turning the switch off stops any further sending.
Feedback formOptional, only if you send one: your message and an email address if you choose to give one, plus the browser's user-agent string, the build environment and the commit the report came from. Checked by Cloudflare Turnstile before it's accepted. Kept 30 days, then deleted automatically.
Purchases (app only)The app sells a one-time 'Unlock Full Game' in-app purchase, handled by RevenueCat. RevenueCat holds an anonymous, randomly generated app-user id created on your device -- not linked to a name, email or account, since the app has no login -- plus the purchase and entitlement records needed to unlock what you bought and support Restore Purchases. Payment details are handled entirely by Apple or Google; Gelopard never sees them. The web version has no purchase path and never contacts RevenueCat.

No accounts, no ads. Turnstile processes your IP transiently at Cloudflare's edge to run that check; Gelopard does not receive or store it. See RevenueCat's own privacy policy for how it handles the purchase data above.

SEC-06.10 / Your rights

Under the GDPR you can ask for a copy of what is held about you, ask for it to be corrected or erased, object to the processing, or ask for it to be restricted. Write to contact@gelopard.com. For erasure specifically, deleting your data sets out what each app can delete, what it cannot, and what to include so a request can be matched.

The 30-day window above only covers the contact form: a request about a message you sent through it will find nothing left after that. Wake Alone's play-data records and RevenueCat's purchase records are never linked to an identity, so there is nothing to look up against a request either. Skugga's counters and feedback follow the separate retention windows stated in its own section. Tillsvidare's synced save can be erased from inside the game, and expires on its own after twelve months without use; its counters are never linked to anyone. Dibs keeps no personal data to request in the first place.

If you believe the processing is unlawful you can complain to the Swedish Authority for Privacy Protection, imy.se.

SEC-06.11 / Changes
Last updated2026-09-23

Changes are published on this page. There is no mailing list to notify.

SEC-06.12 / Universes

Universes is still in development and isn't published anywhere yet. It has no accounts, no ads, no telemetry and nothing to buy. Run progress, permanent unlocks, achievements and the archive are held on your device and never leave it.

One thing does reach a server, and it is the only thing that does.

Update checkOnce per launch the game asks whether a newer build has been published, by requesting a single static file from universes.gelopard.com. It is a plain request with nothing attached: no account, no device id, no session id, and nothing about you or your progress. It gives up after three seconds and stays silent if there is no answer, so the game plays offline either way. Cloudflare serves the file and sees the request the way it sees any web request, including the IP address it came from, under its own standard logging. Gelopard receives no record of who asked.

This section will be revisited before the game ships, and again if it ever gains a purchase path or anything else that leaves the device.

SEC-06.13 / Takapa

Takapa runs in the browser at takapa.gelopard.com and as an app from Google Play, on phones, tablets and Android TV. It collects nothing. There are no accounts, no ads, no telemetry, no purchases, and no saved progress: the game keeps a score for the round being played and forgets it when the round ends.

Once the page has loaded it makes no requests at all, in the browser and in the app alike. It is a game for a small child and whoever is sitting next to them, and it is built so there is nothing to hold.

Cloudflare serves the page and sees the request the way it sees any web request, including the IP address it came from, under its own standard logging. Gelopard keeps no record of who played.

This section is revisited if the game ever gains an update check, a saved high score or anything else that leaves the device.

SEC-06.14 / Deep Drop

Deep Drop is still in development and isn't published anywhere yet. It has no accounts, no ads, no telemetry and nothing to buy. Coins, upgrades, unlocks, the best depth and the settings are held on your device and never leave it.

One thing does reach a server, and it is the only thing that does.

Update checkOnce per launch the game asks whether a newer build has been published: on the web by requesting a single static file from deepdrop.gelopard.com, on Android by asking Google Play through its in-app update service. The web request carries nothing about you or your progress, gives up after three seconds and stays silent if there is no answer, so the game plays offline either way. Cloudflare serves the file and sees the request the way it sees any web request, including the IP address it came from, under its own standard logging. The Play check runs under Google's own terms. Gelopard receives no record of who asked.

This section will be revisited before the game ships, and again if it ever gains ads, a purchase path or anything else that leaves the device.

SEC-06.15 / Tillsvidare

Tillsvidare runs in the browser at tillsvidare.gelopard.com and as an app from Google Play and the App Store. It has no accounts and no ads. What it keeps stays on your device unless you ask it to travel: the name you type on the start screen, the week in progress, your career (levels, achievements, wardrobe), whether sound is on, a random player id the game made up on first launch, and a few things it remembers you already saw or said no to (the browser's offer to add the game to your home screen; the app's notice that a newer version exists; a pack notice on the start screen; which posters on the office bulletin board you have opened). The browser version also keeps a copy of its own files so the last loaded version plays without a connection. Clearing the site's data, or the app's data, removes all of it.

Three things can leave the device, described below. The counters are on by default and can be switched off; the sync happens only after you link a device yourself; the purchase data exists only in the app.

CountersOn by default, switched off with the checkbox at the foot of the start screen. Four short strings per event go to tillsvidare.gelopard.com, a service Gelopard operates: what happened (a first session, a return day bucketed as 1, 2-6, 7-27 or 28+ days since first open, a workday ended, an error in the page, the pack screen seen, bought or dismissed), which of those, the platform, and the version. Kept three months as data points, and indefinitely as weekly totals. No device id, player id, IP address, account identifier or timestamp is included, so no individual record exists to look up or delete on request. The only state the counters keep on the device is the date of first open. Turning the switch off stops any further sending.
Sync between your devices (only if you link them)From the start screen you can fetch a short code on one device and type it on another, so the week and the career follow you between a phone, a tablet and a browser. Until you do that, nothing about your game is stored anywhere but your device. Once you do, the game keeps a copy at sync.gelopard.com, a service Gelopard operates on Cloudflare with the data held in the European Union: your player id, the save (the name you typed, the week in progress, the career), an entry per linked device (a random device id and when it was created and last used, nothing describing the device), and, if you have bought anything in the app, which packs you own. No email, no password, no name beyond the one you chose for your character. The code is valid for ten minutes and once. The copy is deleted twelve months after the last time any of your devices used it, or at once when you choose 'erase synced data' on the start screen, which also forgets the player id on that device. If you lose every linked device the copy is unreachable and expires on its own. The service rate-limits code attempts by IP address at Cloudflare's edge without storing it, and keeps no logs of who synced.
Purchases (app only)The app is built to sell expansion packs ('Regleringsbrev') as one-time in-app purchases, handled by RevenueCat. Nothing is on sale yet. When the app talks to RevenueCat it identifies you by the same random player id the game made up on your device (not linked to a name, email or account, since there is no login), so a pack bought on one device follows the link above to your others, including the browser, which has no purchase path of its own. RevenueCat holds that id plus the purchase and entitlement records needed to unlock what you bought and support Restore Purchases, and tells the sync service which packs the id owns. Payment details are handled entirely by Apple or Google; Gelopard never sees them. The same id is what the game shows you as a 'support id' to copy if you contact us about a purchase.

The app asks the store once per launch whether a newer version exists, through Google Play's or Apple's own update mechanism, which carries the app's identity and version and nothing about you; the browser version makes no requests beyond loading the page itself. A shared card is a link you paste yourself; it carries only the numbers on the card, and the page behind it is drawn from those numbers by the game's own server code, with no record kept. Cloudflare serves the page and sees the request the way it sees any web request, including the IP address it came from, under its own standard logging. See RevenueCat's own privacy policy for how it handles the purchase data above.

SEC-06.16 / Tussock

Tussock is a toy with nothing to achieve, in the browser at tussock.gelopard.com and as an app on Google Play and the App Store. It has no accounts, no ads, no analytics and nothing to buy. Nothing about you is collected, and nothing about you leaves the device.

Device storageA note that you have seen the start screen, and your sound, vibration and motion settings. In the app, also which update notice you dismissed. Never leaves the device; clearing the site's or the app's data removes it.
Web versionOnce the page has loaded it makes no further requests. It keeps a copy of itself in the browser so it works offline, and refreshes that copy from the server on the next load, as any page load would.
App versionOnce per launch the app asks its store whether a newer version exists: Google Play's in-app update service on Android, Apple's App Store lookup on iOS. That request carries the app's identity and version, nothing about you, and is handled by Google or Apple under their own terms, like an update check in any app. Nothing else is sent.

The server that serves the web version keeps no analytics; it sees the request the way any web server does. This section changes the same day the app gains anything else that leaves the device.