Plain-language privacy notice
Privacy at Nimori
Last updated August 23, 2026
Nimori is designed without advertising trackers. We process only what is needed to run accounts, deliver games and memberships, secure the service, and understand broad usage.
What we process
- Your email address, password hash, email-verification state, account settings including your chosen language, sessions, game access, play counts and durations, scores, and subscription status. While a game is open, Nimori also keeps short-lived board-state diagnostic snapshots—game cells, configuration, score, and level, but not a key-input stream or personal message—for up to 10 minutes so the restricted operator can verify that live games render correctly. The restricted Nimori operator console can associate these service records with your account for support, security, game operations, and business reporting.
- Your connection address and country-level location for service security, abuse and bot diagnosis, and short-term visitor operations. Security metadata can include the protected route or network port targeted, the safeguard applied, and a count of repeated attempts; it never includes submitted passwords, recovery tokens, request bodies, or full browser identifiers. Application connection addresses are encrypted at rest, restricted to the operator, and removed from the live service within 21 days. When a visit includes a valid signed-in session, its daily rotating visitor value is also associated with that account in the restricted operator console; a shared network can therefore list several distinct accounts rather than being attributed to one person. This account association is removed from primary storage within 82 days, and seven-day restricted backup expiry plus a safety margin keeps all recoverable copies within 90 days. Short-lived firewall and ban-service snapshots are read only by the protected operator console and are not copied into the application database. After the association expires, retained visit analytics contain no account ID or email.
- Browser information used to identify obvious automated traffic and protect authentication.
Public profile and Community boards
Leaderboard participation is off by default. You may choose a normalized public name and a unique @player ID, then opt in to show your best qualifying completed run on public Community boards. Boards are separated by game setup. They disclose that scores are not independently verified; Nimori does not use them for prizes, payments, or trusted competitive decisions. Your email address and private account ID never appear. Turning participation off removes you from the next leaderboard response, while the underlying private play history remains with your account under the retention practices described below.
Game saves
For games that support saving, Nimori stores account-synced autosaves and manual slots containing validated game state such as the card or board layout, deterministic deal seed, game, rules and schema versions, revision number, and timestamps. Saves are private and remain until you overwrite or delete them, or delete the account; recoverable copies expire under the restricted backup lifecycle. Private slot labels and full save states never appear on public Community boards or in operator live previews beyond the separately disclosed short-lived board snapshot.
Language choice
On a first visit, Nimori uses the country-level location described above only to suggest a supported language; multilingual or unknown locations default to US English. A language you choose is kept in a secure same-site browser cookie. If you are signed in when you make that choice, it is also saved with your account so the same language follows you across your devices. Your saved account choice takes priority over the browser cookie and automatic country suggestion.
Email and account security
Resend delivers essential messages such as email confirmation and password resets from noreply@nimori.games. These messages are required to secure and recover your account; Nimori does not use them for advertising. Verification and reset links expire and can be used only once.
Payments
The secure payment provider acts as merchant of record for Nimori memberships. Nimori sends a country code—not your connection address—to the secure payment provider when requesting a localized public price preview. At checkout, the secure payment provider collects and processes checkout details, payment method information, billing country, taxes, invoices, cancellations, and refunds under its own privacy terms. Nimori receives identifiers, transaction totals, and subscription state needed to unlock games and support your account. Nimori does not receive or store full card details.
Why and how long
We process this information to provide the service and membership you request, secure accounts, diagnose abuse and automated traffic, meet legal obligations, and improve game balance and reliability. Live presence expires within minutes. Application security events and exact connection addresses leave primary storage within 21 days; host-defense snapshots expire sooner, and all restricted backups containing connection data disappear within 30 days. Visitor-to-account links leave primary storage within 82 days and all recoverable backups within 90 days. Account, payment, de-linked analytics, and other operational records are kept while needed to provide the service and for applicable tax, accounting, security, or legal periods.
Providers and location
Hosting is provided by Hetzner in Germany. Resend delivers service email, and the secure payment provider processes memberships and payments. Each provider receives only the information needed for its role and may process data in countries described in its own privacy documentation.
Your choices
You may ask to access, correct, export, restrict, object to processing of, or delete your account data where applicable. Contact nimori@mind27.com. You may also complain to your local data-protection authority.
Security
Sessions use secure, HTTP-only cookies; passwords are salted and hashed; payment webhooks are signature-verified; administrative access is restricted; and sensitive administrative changes are audited. No internet service can promise absolute security, but Nimori minimizes data and layers safeguards.