Scrum Energizers
Privacy
How Scrum Energizers handles data when you use an interactive team activity.
Who is responsible for your data?
Benjamin FleischmannFort-Skelly-Str. 36, 93053 Regensburg, Germany
[email protected]
Interactive room data
To provide the selected real-time activity, the application processes your display name, avatar, room code, game choices, submissions, drawings, votes or guesses, and other actions you take in an activity.
Temporary reconnect data
The current tab stores your player ID, rejoin token, and room code in browser sessionStorage under the key scrum-games-session. Choosing Leave removes that stored session. The browser controls the remaining tab-session lifecycle.
Live connection
The interactive application uses a same-origin WebSocket connection at /ws for live room and game communication.
Server storage and retention
Room and game state exists only in the application server’s process memory. Disconnected players normally have a 60 seconds rejoin grace period. Empty rooms are deleted after five minutes, or can disappear immediately after the final player explicitly leaves. Restarting or redeploying the application clears all rooms.
Cookieless reach measurement
We use self-hosted Umami for aggregate reach measurement and product improvement. It may process page paths and titles, the external referrer, browser, operating system and device category, screen size, language, approximate country, region and city, timestamps, and the public activity slug sent with a game-started event. URL query strings and fragments are excluded.
We do not intentionally send Umami any participant name, avatar, room code, rejoin token, activity submission, drawing, vote, guess, or other free-text room content. The tracker sets no analytics cookies. Raw IP addresses and full user-agent strings are used transiently to derive technical and session information, but Umami does not store those raw values. Daily rotating session salts are used, so the resulting identifiers are pseudonymous rather than anonymous.
Analytics data is hosted on infrastructure controlled by the publisher and delivered through the existing Cloudflare infrastructure. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in privacy-conscious reach measurement and improving the service. You may object by contacting [email protected]. Analytics data is retained only for as long as needed for these purposes and can be deleted by the publisher.
Infrastructure services
The application server runs on self-hosted infrastructure controlled by the publisher. Network and security delivery may process technical connection metadata through the project’s confirmed Cloudflare services.
Privacy questions and requests
Send privacy questions or requests to [email protected]. Messages sent to this address are handled through Proton Mail.