← Home

Privacy policy

Last updated October 7, 2026 · version 1

In short

  • We do not sell any data and we do not show ads.
  • You can play without an account. The name you choose is shown to the others in the lobby.
  • The database and the games are stored with Cloudflare within the EU.
  • We use no cookies for statistics or tracking, only one that keeps you logged in.
  • You can get a copy of your data or have it deleted at any time.

This is a translation of the Swedish privacy policy. In case of discrepancy the Swedish version applies.

Who is responsible for your data?

HowFarOff is run by Patrik Björklund, a sole trader in Sweden, who is the data controller. This means he is responsible for handling your data in line with the General Data Protection Regulation (GDPR). Send questions about your data to hej@howfaroff.com. You will find more answers on the contact page.

What we store and why

Here is everything we store about you, why, what part of the General Data Protection Regulation allows it and for how long. That part is called the legal basis. You do not need an account to play, only a name in the lobby.

Account

What we store
Your player name, your PIN, how many failed login attempts have been made in a row, any temporary lock, when the account was created and when you last logged in. The PIN is never stored as it is, only as a salted hash, so nobody can read it, not even us.
Why
So that you can log in and collect your stats, and so that the account is locked for a while after too many failed attempts.
Legal basis
Contract (Article 6(1)(b) of the General Data Protection Regulation): the account is part of the service you asked for. The lock is based on legitimate interest (Article 6(1)(f)) in protecting the account against guessing.
How long
Until the account is deleted. Email us if you want us to delete it.

Login

What we store
A random code in the cookie gm_session in your browser. In the database we only store a hash of the code, which account it belongs to and when it was created and expires.
Why
So that you are still logged in the next time you open the game.
Legal basis
Contract (Article 6(1)(b) of the General Data Protection Regulation)
How long
365 days, or until you log out. Expired logins are deleted the following night.

Games and stats

What we store

For each game: mode, settings, lobby code and when the game started and ended. For each player: team, place and points, and depending on the mode the number of sips taken and handed out (Sips 18+) or the number of reps (Workout). For each question: the guess, how far off it was, the place and how quickly the answer came in.

If you are logged in, the results are linked to your account, as are your achievements. Sips can be taken with any drink, so the number says nothing about what you drank.

Why
To show the result to everyone who played, and to build your profile with stats and achievements.
Legal basis
Contract (Article 6(1)(b) of the General Data Protection Regulation)
How long
As long as the account exists. If the account is deleted, your placings remain under the name "Raderad spelare" (Swedish for "deleted player"), so that the other players' results do not change, but they can no longer be linked to you.

Host pass

What we store
If your account has been given a host pass: which pass it is, when it starts and ends, and when it was created. Today we only hand out passes manually, for example in support cases or as a gift. We do not store any email address or payment details.
Why
To give you what the pass includes and to help you if something goes wrong.
Legal basis
Contract (Article 6(1)(b) of the General Data Protection Regulation)
How long
As long as the account exists. If the account is deleted, the link to you is removed, and what remains about the pass cannot be linked to you.

If you play as a guest

What we store
The name you enter and a one-time code that lets the game be saved to an account afterwards. The results are stored as above, but under the name instead of an account.
Why
To show the result to everyone who played, and so that you can save the game to an account afterwards.
Legal basis
Contract (Article 6(1)(b) of the General Data Protection Regulation) during the game. Keeping the name and the code afterwards is based on legitimate interest (Article 6(1)(f)): letting you save the game.
How long
30 days after the game. Then the name and the code are deleted automatically, and what remains cannot be linked to anyone.

During the game

What we store
What is needed while the game is running: the names in the lobby, who is logged in and whether they have a host pass, teams, guesses, points and which players the host has removed. If someone unlocks the lobby with their host pass, everyone in the lobby can see who it was and how long the unlock lasts.
Why
To run the game and show it to everyone in the lobby.
Legal basis
Contract (Article 6(1)(b) of the General Data Protection Regulation)
How long
The lobby is deleted automatically 2 hours after the last activity. A finished game is stored as above.

Feedback

What we store
What you write and what it is about, a reply address if you leave one, your account if you are logged in, language, the page you were on, the app version, screen size and browser. During a game also the lobby code, phase, mode and question number, and if you report a question: which question and what was wrong. We do not store your IP address.
Why
To read what you write, fix mistakes and reply to you if you want a reply. The reply address is only used to reply to that message, never for newsletters.
Legal basis
Legitimate interest (Article 6(1)(f)) in improving the service and answering questions.
How long
Deleted automatically 365 days after it was sent. You can ask us to delete it sooner.

Emails to us

What we store
Your email address, what you write and our reply. If it is about your account, also the details that show the account is yours.
Why
To reply and help you, for example with a forgotten PIN or a request about your data.
Legal basis
Legitimate interest (Article 6(1)(f)) in being able to reply. When you exercise your rights, we keep a record of the request and our reply because the General Data Protection Regulation requires it (legal obligation, Article 6(1)(c)).
How long
While the matter is open and at most 12 months after it was closed.

Error reports

What we store
If the app crashes, it sends an error report: the error message, where in the code it happened, which page it was on (without the lobby code), the app version and the browser. No names, login details or IP addresses.
Why
To find and fix bugs.
Legal basis
Legitimate interest (Article 6(1)(f)) in a service that works.
How long
At most 7 days in Cloudflare's log.

IP address and protection against abuse

What we store
Your IP address, which your browser always sends.
Why
Cloudflare needs it to deliver the site and protect it against attacks. We also use it to limit how many attempts can be made per minute, for example logins.
Legal basis
Legitimate interest (Article 6(1)(f)) in a secure service that is not overloaded.
How long
We do not store your IP address. Attempts are only counted in memory for one minute.

Usage statistics

What we store
When a lobby is created, a game starts or is abandoned, a TV connects, a game is saved to an account or a lobby reaches a limit of the free version, we store what happened and which hour. Depending on the event, we also store the mode, number of players, whether it is a team game, the language, the game's number in the lobby (1 for the first, 2 after Play again, and so on) and which limit was reached. No names, accounts, lobby codes or IP addresses.
Why
To see how many lobbies turn into games, how many games are abandoned and what needs to get better. We only look at totals, such as the number of games per week, not at individual games or people.
Legal basis
Legitimate interest (Article 6(1)(f)) in understanding how the service is used and making it better. The rows have no names or accounts, but because they include the hour they can sometimes be matched to a saved game and so to its players. That is why we treat them as personal data.
How long
Until further notice, so that we can compare over time. The rows can only be linked to you while other data about you is stored with us, such as your account, your guest name in a game or your feedback. Once that is deleted, the rows can no longer be linked to you.

Deleted data can remain in our backups for up to 30 days before it is deleted: at Cloudflare and in copies of the database that we keep ourselves on an encrypted computer.

Cookies and browser storage

We use a single cookie and a few small values in your browser's storage. They are all needed for the service to work the way you ask it to, so no consent is required under Chapter 9, Section 28 of the Swedish Electronic Communications Act. That is why there is no cookie banner. We use no cookies for statistics, advertising or tracking.

  • gm_session: A cookie that keeps you logged in. It is only set when you log in or create an account, and it goes away after 365 days or when you log out.
  • gm-token-<code> and gm-name-<code>: Let you get back into the lobby with the same name if the page reloads. Kept until the tab is closed (sessionStorage).
  • gm-hostkey-<code>: Lets the big screen keep running the game after a reload. Kept until the tab is closed (sessionStorage).
  • gm-adult-<code>: Remembers that the host has confirmed 18+ for Sips 18+ in the lobby. Kept until the tab is closed (sessionStorage).
  • gm-reported-<code>-<question>: Remembers that you have already reported a question in the lobby. Kept until the tab is closed (sessionStorage).
  • gm-lang: Remembers the language you picked. Kept until you clear your browser data (localStorage).

After a game as a guest, the one-time code for saving the game is kept in the tab's history, never in the address, so that it does not end up in links or statistics.

Who sees your data?

  • The others in the lobby see your name, your team, your guesses, points, placings and sips while you play. Only you can see your profile and stats.
  • Anyone who gets a results image: after a game, a player can share an image of the final standings with the names, placings and results of the top five and of the player sharing it. The image is created on the player's phone and is not sent to us. The player decides who gets it.
  • Cloudflare is our data processor. The site, the database, the lobbies and the logs run on Cloudflare, which may only process the data on our behalf under its data processing agreement.
  • Our email provider receives the emails you send us.
  • Anthropic: when we go through feedback, we sometimes use the AI assistant Claude, which then processes the text on our behalf.

We never sell data and we do not share it with anyone else unless the law requires it, for example after a decision by a public authority.

Where the data is stored

The database and the lobbies are in Cloudflare's EU jurisdiction and are stored only within the EU. The logs may be processed outside the EU, including in the United States, and so may feedback that we go through with Claude. Cloudflare may also need to access data from countries outside the EU for operations and support.

These transfers are protected by the European Commission's standard contractual clauses in Cloudflare's and Anthropic's data processing agreements, and for Cloudflare also by the EU–US Data Privacy Framework, under which Cloudflare is certified.

How we protect the data

All traffic is encrypted. In our database, PINs and login codes are only stored as hashes, never as they are. Only we have access to the database and the logs. If something happens that affects your data anyway, we report it to the Swedish Authority for Privacy Protection and tell you when the law requires it.

Age limits

You need to be at least 13 years old to create an account. Sips 18+ is for adults: everyone who drinks alcohol must be at least 18. There is more about this in the terms of use.

Your rights

You have the right to:

  • find out what data we have about you and get a copy of it
  • have incorrect data corrected
  • have your data deleted
  • restrict how we use the data while something is being looked into
  • get the data in a machine-readable format and move it to another service
  • object to what we do based on legitimate interest

Email hej@howfaroff.com. Accounts have no email address, so we need to check that the account is yours before we hand out or delete anything. How that works is described on the contact page. You will get an answer within one month, and it costs nothing. Guest names can rarely be linked to a specific person, but they are deleted automatically after 30 days.

We make no automated decisions about you that have legal effects or affect you in a similar way.

If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (IMY), imy.se. Feel free to contact us first, and we will try to sort it out.

Changes

Today you cannot buy anything in HowFarOff or log in with email. Before that becomes possible, we will update this policy. With the plans we have today, this means that:

  • when email login is introduced, your email address will be stored on the account, and one-time codes will be sent with the email service Resend
  • when payments are introduced, payments will be handled by Stripe, and details of the purchase will be kept for 7 years, because Swedish accounting law requires it
  • if we turn on Cloudflare Turnstile against bots in the forms, a check is loaded from challenges.cloudflare.com that decides whether a human is sending
  • if we turn on a daily operations email to ourselves, it will be sent with the email service Resend and contain the first 100 characters of new feedback, but never your reply address or your account

The date at the top shows when the policy last changed in substance. Before larger changes take effect, we will tell you about them on the website.