Privacy Policy
Last updated: 20 September 2026
1. Privacy at a glance
General information
The following information provides a straightforward overview of what happens to your personal data when you visit this website and play We Meme. Personal data is any data by which you can be personally identified. For detailed information, please read the full privacy policy below.
Who is responsible for collecting data on this website?
Data on this website is processed by the site operator. You will find their contact details under “Information on the controller” in this policy and in the imprint.
How do we collect your data?
Some data is collected because you give it to us – for example the username you choose, the captions you write and the votes you cast while playing, or an e-mail you send us.
Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data such as your browser, operating system or the time of the page view.
What do we use your data for?
Part of the data is collected to ensure the website is delivered without errors and that a multiplayer game round works – rooms, scores and the sequence of phases all depend on it. Other data is used to understand how the website is used so that we can improve it, and to finance the site through advertising.
What rights do you have regarding your data?
You have the right to obtain information about the origin, recipients and purpose of your stored personal data free of charge at any time. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you can withdraw that consent at any time with effect for the future. You also have the right to request that the processing of your personal data be restricted under certain circumstances, and the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this and any other questions about data protection using the address given in the imprint.
2. Hosting
Hetzner
This website is hosted on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (“Hetzner”).
When you access this website, Hetzner processes the technical data required to deliver the pages. This may include your IP address, browser type and version, operating system, referrer URL and the time of access.
Hetzner is used on the basis of Art. 6 (1) (f) GDPR. We have a legitimate interest in this website being presented reliably, securely and quickly. Where consent has been requested, processing takes place exclusively on the basis of Art. 6 (1) (a) GDPR and § 25 (1) TDDDG; consent can be withdrawn at any time.
We have concluded a data processing agreement with Hetzner. This is a contract required by data protection law which ensures that Hetzner processes the personal data of our visitors only in accordance with our instructions and in compliance with the GDPR. You can find details in Hetzner’s privacy policy: hetzner.com/legal/privacy-policy
Supabase
The game database is operated with Supabase, a service provided by Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992 (“Supabase”). All game data described in section 4 – usernames, rooms, captions, votes and scores – is stored there and synchronised between players in real time.
Supabase is used on the basis of Art. 6 (1) (b) GDPR: without a database there is no multiplayer game. We have concluded a data processing agreement with Supabase. You can find details in Supabase’s privacy policy: supabase.com/privacy
3. General information and mandatory disclosures
Data protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
Please note that data transmission over the internet – for example when communicating by e-mail – can have security gaps. Complete protection of data against access by third parties is not possible.
Information on the controller
The controller for data processing on this website is:
Jonas Bayer (bavajo)
Wertachtalstr. 45
86517 Wehringen
Germany
Phone: +49 159 08636471
E-mail: mail@jonas-bayer.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data remains with us until the purpose for processing it no longer applies. If you submit a justified request for deletion or withdraw your consent, your data will be deleted unless we have other legally permissible reasons for storing it – such as retention periods under tax or commercial law. In the latter case, the data will be deleted once those reasons cease to apply.
General notes on the legal bases for processing
Where you have consented to processing, we process your personal data on the basis of Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR if special categories of data are processed. In the case of explicit consent to the transfer of personal data to third countries, processing is also based on Art. 49 (1) (a) GDPR. If you have consented to the storage of cookies or to access to information on your device, processing additionally takes place on the basis of § 25 (1) TDDDG. Consent can be withdrawn at any time.
If data is required to fulfil a contract or to carry out pre-contractual measures, we process it on the basis of Art. 6 (1) (b) GDPR. We also process data where it is necessary to fulfil a legal obligation under Art. 6 (1) (c) GDPR, or on the basis of our legitimate interests under Art. 6 (1) (f) GDPR. The legal basis that applies in each individual case is stated in the relevant sections of this privacy policy.
Recipients of personal data
In the course of our activities we work with various external parties. In some cases this requires personal data to be passed on to them. We only pass on personal data where this is necessary to fulfil a contract, where we are legally obliged to do so, where we have your consent, or where we have a legitimate interest under Art. 6 (1) (f) GDPR and no overriding interests of yours stand in the way. Where we commission processors, we conclude a data processing agreement with them in accordance with Art. 28 GDPR.
The specific services we use are named in this policy: Hetzner (hosting), Supabase (database), Giphy (meme images) and Google (tag management, analytics and advertising).
Note on data transfers to the USA
Some of the services we use are operated by companies based outside the EU or process data there. Where personal data is transferred to the USA, we base this on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework. Please note that US authorities may, under certain circumstances, be entitled to access this data. We have no influence over such processing.
Withdrawing your consent to data processing
Many data processing operations are only possible with your explicit consent. You can withdraw consent you have already given at any time – either through the “Privacy settings” link in the footer of this page, which reopens the privacy message described in section 4, or by informal notification by e-mail. The lawfulness of the data processing carried out before the withdrawal remains unaffected.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
If data processing is based on Art. 6 (1) (e) or (f) GDPR, you have the right at any time to object to the processing of your personal data on grounds relating to your particular situation; this also applies to profiling based on those provisions. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims (objection under Art. 21 (1) GDPR).
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing. If you object, your personal data will subsequently no longer be used for direct marketing purposes (objection under Art. 21 (2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work or the place of the alleged infringement. This right exists without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place where it is technically feasible.
Information, correction and deletion
Within the framework of the applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of the processing, and, where applicable, a right to have this data corrected or deleted. You can contact us at any time regarding this and any other questions about personal data using the address given in the imprint.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing applies in the following cases:
- If you dispute the accuracy of the personal data we hold about you, we usually need time to verify this. For the duration of that check, you have the right to request the restriction of processing.
- If the processing of your personal data was or is unlawful, you can request the restriction of processing instead of deletion.
- If we no longer need your personal data but you need it to exercise, defend or assert legal claims, you have the right to request restriction of processing instead of deletion.
- If you have lodged an objection under Art. 21 (1) GDPR, a balance must be struck between your interests and ours. As long as it has not been determined whose interests prevail, you have the right to request the restriction of processing.
If the processing of your personal data has been restricted, this data may – apart from being stored – only be processed with your consent, to assert, exercise or defend legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the lock symbol in your browser bar. When SSL or TLS encryption is active, the data you transmit to us cannot be read by third parties.
Objection to promotional e-mails
We hereby object to the use of contact data published as part of our legally required imprint for the purpose of sending unsolicited advertising and information material. We expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam e-mail.
4. Data collection on this website
Consent management
On your first visit from the EEA, the United Kingdom or Switzerland, a privacy message from Google’s consent management platform is displayed. It asks for your consent to analytics and advertising and records your decision as an IAB TCF consent string. Analytics and advertising services are only loaded once that decision is available; without consent they run in a restricted, cookieless mode or not at all.
Your decision is stored by Google’s consent management platform in cookies and local storage on this domain; the Cookie Policy lists the individual entries. You can change or withdraw it at any time with effect for the future using the “Privacy settings” link in the footer of this page, which clears your stored decision and shows the privacy message again. The legal basis is Art. 6 (1) (a) GDPR and § 25 (1) TDDDG.
Cookies, local storage and session storage
Cookies are small text files that are stored on your device; they do no harm. They are stored either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). In addition, this website uses your browser’s local storage and session storage.
The application itself stores exactly three values on your device: your anonymous user ID and your username in local storage, so that you do not have to identify yourself again on every page view, and a pending room action in session storage, which remembers the room you wanted to join while you are choosing a username. These values are technically necessary and are stored on the basis of Art. 6 (1) (f) GDPR; under § 25 (2) no. 2 TDDDG they do not require consent, because they are strictly necessary to provide a service you have expressly requested.
All other storage objects – in particular those of the analytics and advertising services described below – are only set with your consent under Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. A complete list is available in our Cookie Policy.
You can set your browser to inform you when cookies are set, to allow cookies only in individual cases, to exclude them generally, or to delete them automatically when the browser is closed. Disabling cookies may limit the functionality of this website.
Server log files
The provider of these pages automatically collects and stores information in server log files, which your browser transmits automatically. These are:
- Browser type and version
- Operating system used
- Referrer URL
- Host name of the accessing device
- Time of the server request
- IP address
This data is not merged with other data sources. It is collected on the basis of Art. 6 (1) (f) GDPR: we have a legitimate interest in the technically error-free presentation and optimisation of our website, which requires server log files to be recorded.
Game data
To play We Meme you choose a username. We do not ask for an e-mail address, a password or any other registration data for this; an anonymous user ID is created for you instead. While playing, the following additional data is processed and stored in our database:
- Your username and your anonymous user ID, together with the number of games played, wins and points
- Which room you joined, when you joined it and when you were last seen there
- The captions you write and the votes you cast per round
- Your score per round and per game
This data is processed on the basis of Art. 6 (1) (b) GDPR: it is required in order to run a game round, determine the winner and display the leaderboard. Please bear in mind that your username, your captions and your scores are visible to the other players in your room, and that usernames and scores also appear on the public leaderboard.
Captions are written by you. Please do not enter any personal data about yourself or others in them.
Enquiries by e-mail
If you contact us by e-mail, your enquiry including all resulting personal data (name, enquiry) will be stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.
This data is processed on the basis of our legitimate interest in effectively handling enquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) where this has been requested. The data you send us remains with us until you ask us to delete it, withdraw your consent to its storage, or the purpose for storing it no longer applies – for example once we have finished dealing with your request. Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
Giphy
The meme images used in the game are provided by Giphy, a service of Giphy, Inc., 416 West 13th Street, New York, NY 10014, USA. The images are loaded directly from Giphy’s servers by your browser, which means that Giphy receives your IP address and technical details of your request and may transfer this data to the USA.
Without meme images there is no game, so Giphy is used on the basis of Art. 6 (1) (b) GDPR. You can find further information in Giphy’s privacy policy: support.giphy.com
Fonts
This website uses the Inter typeface for a consistent presentation. The font is delivered from our own server together with the page. No connection to third-party servers – in particular not to Google Fonts – is established, and no data about you is transmitted to a font provider.
5. Analytics
Google Tag Manager
We use Google Tag Manager, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to embed and manage tracking and analytics tools on this website. Tag Manager itself does not create user profiles, does not set cookies and does not collect personal data on its own account. It only triggers the services integrated through it, which may in turn collect personal data.
When Google Tag Manager is loaded, a connection to Google’s servers is established and your IP address is transmitted to Google; it may be transferred to the USA.
Google Analytics
This website uses the web analytics service Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics allows us to analyse how visitors use the website. It records, among other things, which pages are opened, how long and how intensively they are viewed, how visitors reached the website, and technical details such as device type, browser, operating system and approximate location. Google Analytics uses cookies and comparable recognition technologies that can identify returning visits.
Cookies are only set and data is only linked to them on the basis of your consent under Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. Consent can be withdrawn at any time with effect for the future. If you do not consent, Google Analytics runs in a cookieless mode: no cookies are set and no identifiers are stored on or read from your device. A reduced, aggregated measurement is still transmitted to Google, and like any request to a server it carries your IP address — see the note on IP anonymisation below.
IP anonymisation is enabled by default in Google Analytics 4: your IP address is shortened by Google within the EU or the EEA before any data is transferred to the USA. Data may nevertheless be transferred to Google in the USA; such transfers are based on the European Commission’s standard contractual clauses.
We have concluded a data processing agreement with Google. Data stored at user and event level that is linked to cookies or identifiers is deleted after 14 months at the latest. You can find further information on how Google Analytics handles user data in Google’s privacy policy: policies.google.com/privacy
6. Advertising
Google Ad Manager and Google AdSense
We finance this website through advertising and use Google Ad Manager and Google AdSense, services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google acts as an advertising vendor and may in turn involve further advertising partners.
When an advertisement is requested, your IP address, technical details of your device and browser, the page on which the advertisement appears and your consent string are transmitted to Google, and may be transferred to the USA. If you have given your consent, Google and its partners may also store cookies and similar identifiers on your device in order to measure the delivery of advertising, limit repetition and select personalised advertising.
Personalised advertising, the storage of advertising identifiers and the transmission of advertising data only take place on the basis of your consent under Art. 6 (1) (a) GDPR and § 25 (1) TDDDG, which is obtained through the privacy message described in section 4 and passed on to Google as an IAB TCF consent string. Consent can be withdrawn at any time with effect for the future. If you refuse or withdraw your consent, only non-personalised advertising is delivered.
You can find further information in Google’s advertising privacy notice: policies.google.com/technologies/ads