Privacy policy.

Last updated: 27 August 2026Effective from: 26 September 2026

BoardMatey (ABN [32 117 029 184]) (we, us, our) operates BoardMatey, a board game tracking and group play-planning service (the Service). This Privacy Policy explains what personal information we collect, how we use and protect it, and the choices and rights you have.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). A copy of the APPs is available from the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au/.


1. The short version

  • We collect only what we need to run BoardMatey.
  • We don't sell your personal information.
  • We use a small number of trusted service providers (listed in section 6) to host the platform and deliver core features.
  • If you scan a photo of your shelf, it goes to Google's Gemini API to have the game titles read off the boxes, and it's deleted once the scan has worked out — see section 7 for the times we keep one.
  • To delete your account, email support@boardmatey.com — there's no delete button in your Settings yet, so we do it by hand. Some of your data you can download yourself; for the rest, ask us. Section 9 has the detail.
  • When you delete your account we remove most of what we hold, cut your name off a few records we keep for other people, and keep one entry proving the deletion happened. Section 7 says which is which.
  • If you have a privacy concern, email support@boardmatey.com and we'll respond.

2. What personal information we collect

We collect personal information in four main ways: when you give it to us, as records the Service writes while you use it, automatically as you browse, and from third parties (only when you've connected them).

2.1 Information you give us

  • Account details — name, email address, password (stored hashed), avatar, country/region, time zone, and any preferences you set.
  • Profile information — display name, bio, favourite games, and similar information you choose to share.
  • Content you submit — play logs, scores, photos, comments, group details, vote choices, calendar events, gift ideas you note against a friend, and other content you create in BoardMatey.
  • AI scan photos — the shelf or box photos you upload when you scan games into your collection. Your browser resizes and re-encodes every photo before any of it is sent, which strips the file's embedded metadata, including any GPS coordinates your camera recorded — so the location of the photo never leaves your device. What happens to the photo itself is set out in section 7.
  • Communications — messages you send us by email or via in-app forms (including support requests and bug reports). A bug report or feature request you send from inside the app becomes a ticket in our issue tracker on GitHub, along with the page you were on, your browser and screen size, your time zone and language, the app version and which plan you're on. Your name and email don't go with it: the ticket carries a scrambled code instead, so we can tell two reports came from the same person without GitHub knowing who that is.
  • Billing details — if you subscribe to a paid plan, our payment processor Polar (which uses Stripe as its underlying payment infrastructure) collects and processes your payment details. We don't store full card numbers; we receive a token, the last four digits, the card brand, your billing country, and the status of each transaction.

2.2 Records we create as you use the Service

These aren't things you type in. They're records BoardMatey writes about what you've done, so the Service can work and so we can improve it.

  • Progress and activity — achievements you've unlocked, milestones, rewards, your position on leaderboards over time, and the entries in your activity feed.
  • Social records — which groups you belong to and in what role, your friendships, blocks, invites you've sent or accepted, and referrals.
  • The scan correction record — when you scan a shelf, we keep a short written record of each box the AI found: the title it read, how sure it was, any other text it read off the box, the title you typed if you corrected it, the game you picked, and whether you kept that row, added it yourself or removed it. This is what tells us where the scanner is going wrong. It's text only — the photos are covered separately above and in section 7 — and how long we keep it is in section 7.
  • Subscription records — your plan, changes to it, renewals, cancellations and scheduled downgrades.
  • Notification records — the notifications we've sent you and the preferences you've set for them.
  • Legal acceptance records — which version of this Policy and our Terms you accepted, and when.
  • Security and account-protection records — your MFA setup, recovery codes and trusted devices.
  • Admin records — a log of actions our team takes on an account, so we can show what was done and by whom. This includes an entry recording an account deletion; section 7 explains what that entry keeps.

2.3 Information we collect automatically

  • Device and usage data — IP address, browser type, operating system, language, referring URL, pages visited, features used, timestamps and crash logs.
  • Cookies and similar technologies — see our Cookies notice for details. We use a small set of cookies to keep you signed in, remember your preferences, and understand how the Service is used.
  • Security logs — sign-in activity, MFA events and rate-limiting signals to detect and prevent abuse.

2.4 Information from third parties (only when you connect them)

  • Google sign-in. If you choose to sign in with Google, we receive your name, email address, Google account ID and profile picture. We don't receive your Google password, and we don't access your Gmail, Drive or other Google services.
  • BoardGameGeek (BGG). BoardMatey uses BGG's public game catalogue to show game details. If you link your BGG username, we use it to fetch your public collection from BGG. We don't receive your BGG password.

2.5 Sensitive information

We don't ask for sensitive information (as defined in the Privacy Act, e.g. health, racial or ethnic origin, political or religious views). Please don't share sensitive information with us. If you do — for example, in a play log comment — you consent to us holding it for the purpose for which you provided it.

2.6 Children

BoardMatey is intended for people aged 16 and over. We don't knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please email support@boardmatey.com and we'll delete it.

3. Why we collect and use your personal information

We use personal information for the following purposes:

PurposeExamples
Provide the ServiceAuthenticate sign-ins, sync your collection, run group voting, record play sessions, award achievements.
Personalise your experienceShow your stats, recommend games, surface activity from your groups.
Communicate with youSend transactional emails (account, security, billing, group invites), respond to support requests.
BillingProcess subscription payments, manage renewals and cancellations, issue tax invoices.
Identify games from your photosSend the photos you upload to an AI scan to our AI provider so the game titles can be read off the boxes, and keep the photos of scans that went wrong so we can test improvements to the scanner against real examples.
Make the scanner betterKeep the written record of what the AI read off each box and what you corrected it to, and score changes to the scanner against those real answers before we ship them.
Improve and secure the ServiceDiagnose bugs, analyse aggregated usage, prevent abuse, comply with security obligations.
Marketing (optional)Send occasional product updates if you've opted in. You can unsubscribe at any time.
Advertising on free plansIf we introduce advertising on the free plan in the future, we may use limited, non-sensitive information (for example, the page you're on or your broad region) to choose which ad to show. Paid plans are ad-free. We don't currently show ads, and we won't share your personal information with advertisers for them to build their own profile of you.
Legal obligationsRespond to lawful requests, meet record-keeping requirements, enforce our Terms.

We only send marketing messages where allowed under the Spam Act 2003 (Cth). Every marketing email includes an unsubscribe link.

We don't make decisions about you using solely automated processing in a way that produces legal or similarly significant effects. From 10 December 2026, the Privacy Act will require us to include extra information in this Policy if we ever start using a computer program to make (or do something substantially related to making) a decision that could significantly affect your rights or interests. If that ever changes, we'll update this Policy first.

4. How we share your information

We never sell your personal information.

We share personal information only:

  • With other users you choose to share with — for example, members of a group you join can see your display name, avatar, votes, play logs in shared sessions and comments. You control what you post.
  • With our service providers (see section 6) — strictly to help us deliver the Service.
  • When required or authorised by law — for example, in response to a subpoena, court order or lawful request from a regulator.
  • In a business transfer — if we restructure, merge, sell or transfer part of our business, personal information may be part of that transfer. We'll let you know if this happens and your rights under this Policy will continue to apply.
  • To prevent harm — to investigate suspected fraud, security incidents, or threats to a person's life or safety.

5. International data transfers

We're based in Australia, but some of our service providers store or process data overseas (for example, in the United States or the European Union). When personal information leaves Australia, we take reasonable steps under APP 8 to ensure it's handled in line with this Policy.

By using the Service, you consent to your personal information being transferred to and stored in the locations described in section 6. Please note that, in line with APP 8.2, if you consent to an overseas disclosure we may not be required to take steps to ensure the overseas recipient handles your information in accordance with the APPs.

6. Service providers we use

We share personal information with the following providers, only to the extent needed to deliver the Service:

ProviderWhat they do for usWhere data is processed
SupabaseDatabase, authentication and file storageUnited States and other Supabase regions
VercelWeb application hosting and CDNGlobal edge network (primary region: configurable)
Polar (using Stripe)Payment processing for paid plansUnited States and other Stripe regions
Google (sign-in)Optional Google sign-in (OAuth)United States and global Google regions
Google (Gemini API)Reads the game titles off the photos you upload to an AI scanUnited States and global Google regions
BoardGameGeekPublic game catalogue and (if you link it) your public BGG collectionUnited States
ResendSending transactional and (if you opt in) marketing emailUnited States and EU regions
GitHubHolds bug reports and feature requests you send from inside the app, as tickets. We don't send your name or email — see section 2.1United States

We review our service providers and update this list as it changes.

7. How long we keep your information

We keep personal information only as long as we need it for the purposes described in this Policy, or as required by law.

  • Active accounts — we keep your information while your account is active.
  • Deleted accounts — once you ask us to delete your account, everything set out below happens within 30 days.
  • Backups — copies in our backup systems are overwritten on a rolling basis (typically within 35 days), so something deleted can sit in a backup for a short while after it's gone from the Service.

What deleting your account actually does

Deletion isn't one thing. Most records go. A few stay but stop being about you. One is kept with your details on purpose. Here's which is which.

Removed

  • Your profile, sign-in details, password or Google link, MFA setup, recovery codes and trusted devices.
  • Your collection — owned games and wishlist — with your ratings and notes.
  • Your play history: solo sessions, and your attendance, votes and proposed games in group sessions.
  • Your achievements, milestones, rewards and leaderboard snapshots.
  • Your group memberships, friendships, blocks, invites, referrals and gift notes.
  • Your notifications and your notification preferences.
  • Your subscription record on our side, and the log of changes to it.
  • The record of which version of our Terms and this Policy you accepted.
  • Your own activity feed entries — the ones recording things you did.
  • Your files: your profile picture, every session photo you uploaded (including ones in group sessions other members could see), and any AI scan photos we were still holding. The image files themselves are deleted, not just the links to them.

Kept, but no longer connected to you

Some records belong to other people, or to the Service itself, and deleting them would take away something that isn't yours. So we cut your name off instead: the record survives, the link to you doesn't.

  • The scan correction record. What the AI read off each box, and what you corrected it to, stays — with the account it came from set to nothing. It's the only measurement we have of whether a change to the scanner makes it better or worse, and once the link is cut it's no longer about a person. It still ages out on its own schedule, below.
  • Groups and sessions you started. A group you created, or a session you set up, keeps working for the people still in it. Your name comes off it.
  • Other people's activity feeds. An entry in someone else's feed that mentions you — you joined their group, you accepted their invite — stays in their feed with your name removed.
  • Team and settings records. If you were on our team, records of settings you changed or membership requests you reviewed keep the change and drop who made it.

Kept, with identifying details, on purpose

  • The record that your account was deleted. Our admin log keeps one entry showing the deletion happened, and that entry holds the email address and the name the account had. It's the deliberate exception to everything above, and the reason is simple: without it we couldn't prove to you, or to a regulator, that we deleted what we said we deleted. We keep the email address and the name on that entry for 7 years, and then take them off it — what's left is the record that a deletion happened, with nothing in it about you. We don't use it to contact you, and there isn't enough in it to rebuild your account.
  • Financial records. Tax and financial law (including the Income Tax Assessment Act) requires us to keep records of payments for at least 7 years. Our payment processor Polar, and Stripe underneath it, also hold their own billing records under their own retention rules. That data sits with them, not with us, and deleting your BoardMatey account doesn't erase it — contact us and we'll tell you how to reach them.
  • Security logs. We may keep sign-in and abuse-prevention logs for up to 12 months so we can investigate fraud or abuse.
  • Bug reports and feature requests you sent from inside the app. These are tickets on GitHub carrying a scrambled code instead of your name (see section 2.1), so they aren't tied back to you once your account is gone. We keep them because they're often about a problem that's still open.

The scan correction record

The written record described in section 2.2 is kept whether or not you ever delete your account, on a timer of its own:

  • A scan where you accepted every game exactly as the AI read it taught us nothing, and its record is deleted after 30 days.
  • A scan where you corrected something, added a box we missed or removed a row is the material we test scanner changes against, and its record is kept for up to 180 days.
  • A scan whose photos we kept (see below) keeps its record for as long as we hold those photos. A photo without the record of what went wrong beside it is no use to us.

AI scan photos

Google doesn't use your photos to improve its own products or train its models. We're on the paid tier of the Gemini API, and its terms say Google doesn't use what we send it — prompts, images and the answers that come back — for its own product development. It may log them for a limited period to check for abuse and keep the service secure.

On our side, a photo you upload is kept only as long as it is doing something, and what that is depends on how the scan went:

  • The scan came out clean — you accepted every game exactly as the AI read it — and the photos are deleted as soon as you finish. In the rare case that deletion doesn't go through, they are removed by the same sweep described below.
  • The scan didn't — anything at all that didn't match counts: a title you corrected, a box we missed that you added yourself, a row you deleted, one you dismissed or left unticked, even a name whose spelling you only tweaked. We keep that scan's photos so we can test improvements to the scanner against a real shelf. We hold at most 50 scans worth of photos at any one time and delete the oldest first, so a kept photo is on its way out from the moment it is kept. A small number can be held open for longer while we work on the particular problem they show. Our team can look at these photos; the review screen never shows whose scan it was.
  • You didn't finish the scan — the photos are kept so you can pick the scan up where you left off. Finishing it, starting it over, or starting a new scan removes them, and you only ever have one unfinished scan at a time. If you never come back to it, the photos go with the rest of the old scan data once the scan is more than 30 days old.
  • Deleting your account deletes the photos — the kept ones and any unfinished scan's. The image files are removed, not just the records pointing at them.

8. How we keep your information secure

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include:

  • encryption in transit (HTTPS/TLS) and at rest;
  • hashed passwords (we never store your password in plain text);
  • multi-factor authentication for staff and (optionally) for you;
  • least-privilege access controls and audit logging;
  • secure software development practices and dependency monitoring; and
  • regular review of our service providers' security posture.

No system is perfectly secure. If we become aware of a data breach that's likely to result in serious harm, we'll notify you and the OAIC as required by the Notifiable Data Breaches scheme.

9. Your rights and choices

You have the following rights and choices:

  • Access — ask for a copy of the personal information we hold about you.
  • Correction — ask us to correct information that's inaccurate, out of date, incomplete, irrelevant or misleading.
  • Export — some things you can download yourself, from inside the app: your collection as a CSV, a group's game library as a CSV, your session statistics as a CSV, your sessions as calendar files, and your MFA recovery codes. For everything else — your full session logs, achievements, friends, groups, queues, votes and billing history — email support@boardmatey.com and we'll put a copy together and send it to you.
  • Deletion — ask us to delete your account by emailing support@boardmatey.com. There's no delete button in your Settings yet, so we do this by hand: we'll confirm it's really you, confirm you want to go ahead, and then delete the account. Section 7 sets out exactly what that removes and what it doesn't.
  • Opt out of marketing — use the unsubscribe link in any marketing email, or change your preferences in Settings → Notifications.
  • Withdraw consent — where we rely on your consent (for example, optional integrations), you can withdraw it at any time. Withdrawing consent doesn't affect processing already done.
  • Cookies — manage cookies in your browser settings. See our Cookies notice for details.

To exercise any of these rights, email support@boardmatey.com. We'll usually respond within 30 days. We will not charge you a fee for making a request to access or correct your personal information. If giving you access requires us to do something that's reasonably costly (for example, providing a copy in a particular form), we'll tell you about any reasonable charge before we go ahead, and the charge won't be excessive. We may need to verify your identity before acting on a request.

If we refuse a request, we'll explain why in writing and tell you how to complain.

10. Complaints

If you think we've handled your personal information in a way that breaches the Privacy Act or the APPs, please email support@boardmatey.com with the details. We'll acknowledge your complaint promptly and aim to give you a substantive response within 30 days.

If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):

11. Changes to this Policy

We may update this Policy from time to time. How we tell you about a change depends on how much it affects you. The "Last updated" date at the top of this page tells you when we last changed it, and we keep a record of every version.

Minor changes. For a change that doesn't affect your rights or how we handle your information — fixing a typo or clarifying wording without changing its meaning — we may make it without telling you in advance. We'll update the "Last updated" date.

Changes we'll tell you about. For other changes that don't significantly affect you, we'll let you know by email or through an in-app notice before they take effect. You don't need to do anything.

Significant changes. If we make a significant change to how we collect, use or share your personal information — for example, collecting a new kind of information, using it for a new purpose, or sharing it with a new third party — we'll tell you in advance and ask you to review and expressly accept the change before we rely on it, rather than treating your continued use as agreement. This is so your consent stays voluntary, informed, current and specific, in line with the Australian Privacy Principles. Where the law lets us rely on a basis other than your consent, we'll tell you what it is. You can always withdraw consent as described in section 9.

12. How to contact us

For privacy questions, complaints or requests:

We're happy to hear from you.