Plain-language privacy notice
Privacy at Nimori
Last updated 22 August 2026
Nimori is designed without advertising trackers. We process only what is needed to run accounts, deliver games and memberships, secure the service, and understand broad usage.
What we process
- Your email address, password hash, email-verification state, account settings, sessions, game access, scores, and subscription status.
- Country-level location derived briefly from your connection address. Raw IP addresses are not stored in product analytics; a rotating one-way value supports approximate counts and abuse prevention.
- Browser information used to identify obvious automated traffic and protect authentication.
Email and account security
Resend delivers essential messages such as email confirmation and password resets from noreply@nimori.games. These messages are required to secure and recover your account; Nimori does not use them for advertising. Verification and reset links expire and can be used only once.
Payments
Paddle acts as merchant of record for Nimori memberships. Paddle collects and processes checkout details, payment method information, billing country, taxes, invoices, cancellations, and refunds under its own privacy terms. Nimori receives identifiers, transaction totals, and subscription state needed to unlock games and support your account. Nimori does not receive or store full card details.
Why and how long
We process this information to provide the service and membership you request, secure accounts, meet legal obligations, and improve game balance and reliability. Live presence expires within minutes. Account, payment, and operational records are kept while needed to provide the service and for applicable tax, accounting, security, or legal periods.
Providers and location
Hosting is provided by Hetzner in Germany. Resend delivers service email, and Paddle processes memberships and payments. Each provider receives only the information needed for its role and may process data in countries described in its own privacy documentation.
Your choices
You may ask to access, correct, export, restrict, object to processing of, or delete your account data where applicable. Contact nimori@mind27.com. You may also complain to your local data-protection authority.
Security
Sessions use secure, HTTP-only cookies; passwords are salted and hashed; payment webhooks are signature-verified; and administrative access is restricted and audited. No internet service can promise absolute security, but Nimori minimizes data and layers safeguards.