Privacy Policy
Last updated: September 28, 2026
You can read PixelHeat without a reader account. Page-view statistics are currently disabled. We do not use advertising trackers. External video players stay blocked until you choose to allow them.
You can reject optional services or withdraw an earlier choice at any time. Reading our articles does not depend on accepting them.
1. Who Is Responsible?
The controller responsible for personal data on pixelheat.news is:
Sascha Asendorfc/o IP-Management #12127
Ludwig-Erhard-Straße 18
20459 Hamburg
Germany
Email: kontakt@pixelheat.news. Further contact information is in our Legal Notice.
2. Visiting the Website and Hosting
When your browser connects to us, the server processes your IP address, the requested address, time of the request, browser and protocol information, and cookies sent for this website. This delivers pages, images and requested features, helps diagnose failures and protects the service against misuse.
The website and database run on a Hostinger VPS in Frankfurt, Germany. Hostinger and its infrastructure providers process technical data to provide hosting and security. See Hostinger’s privacy information and data processing terms for its processing and subprocessors. Hosting in Germany does not mean every provider support or security operation is limited to Germany.
Our reverse proxy does not keep a routine access log of every page view. Application errors and security events can contain request details, including IP addresses. Application and proxy logs rotate within size limits of three files of 10 MB per service. Security logs follow the server’s rotation limits. Evidence needed to investigate an incident may be retained until the incident and related claims are resolved.
The legal basis is Article 6(1)(f) GDPR: our legitimate interest in delivering a functioning, secure website. Where a specific legal obligation requires processing, Article 6(1)(c) GDPR applies.
3. Cookies and Browser Storage
We use the following first-party storage. Feature-specific entries are created when you request that feature, not simply because you read an article.
| Name | Purpose | Lifetime |
|---|---|---|
ph_consent | Your video-provider choices, policy version and the time you saved them. No advertising identifier. | 180 days from saving |
ph_article_reactions | Lets this browser change or remove a like or dislike after you vote. | Up to one year after your latest vote |
ph_reveal_*, ph_gallery_*, ph_game_gallery_* | Remembers a requested 18+ image or gallery reveal where regional rules allow it. This is not identity or age verification. | Browser session |
pixelheat-news-filter-once (session storage) | Carries the topic filter you selected to the News page. | Removed when read, otherwise until the tab session ends |
payload-token | CMS access for authorized staff. Not set for ordinary readers. | Two hours; renewed during authenticated use |
Storage strictly necessary for a feature you expressly request is used under Section 25(2)(2) TDDDG. Associated processing relies on Article 6(1)(f) GDPR, including our interest in remembering your privacy choices and providing those features. Optional players use your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.
Acceptance and rejection are equally accessible. All optional providers start disabled. Your choice applies to this browser and is requested again after expiry or a material consent-policy change. If your browser blocks storage, the choice lasts only while the page stays open. Session cookies may survive a restart if your browser restores the previous session.
4. External Videos
You can load an approved trailer once or allow its provider in Cookie Settings. A one-time choice lasts while that player remains on the current page; it does not enable other videos. Provider-wide choices can allow players on later pages. RedGifs still requires a separate 18+ confirmation. Privacy consent cannot override content or country restrictions.
- YouTube: Google / YouTube video players. Google may receive your IP address, device data and viewing activity, use storage for personalization and advertising, and associate activity with your Google account. Provider privacy information ↗
- X: Videos and posts from X. X may receive your IP address, device data and viewing activity, use cookies for personalization and advertising, and associate activity with your X account. Provider privacy information ↗
- RedGifs: Adult video players from RedGifs. RedGifs may receive your IP address, device data and viewing activity and use browser storage for its own services, analytics and advertising. A separate 18+ confirmation and regional access rules still apply. Provider privacy information ↗
YouTube uses its privacy-enhanced player domain, which still sends technical information to Google when loaded. Providers may combine activity with an account you have with them and process data outside the EU/EEA, including in the United States. Their notices explain their legal entities, retention, transfer safeguards and controls. We do not control their subsequent processing or set a single retention period for their cookies.
Use to withdraw permission. Rejecting optional services removes active players and stops future automatic loads; a new explicit one-time click can load a player again. Withdrawal does not change the lawfulness of earlier consent-based processing, undo data already sent, or erase another provider’s cookies. Those can be removed in your browser’s settings.
Ordinary links to Steam, itch.io, sources and other websites do not embed those websites. If you follow a link, the destination handles your visit under its own privacy policy.
5. Likes and Dislikes
If you vote, we store the article, selection, timestamps and a pseudonymous identifier specific to that article. The reaction database does not store your raw cookie token or IP address. Its identifiers differ between articles; this feature does not create a reader profile across the site. Technical connection data is still processed as described above.
Click your selected reaction again to remove it or choose the opposite reaction. Votes remain while the article exists unless removed or deleted following a request. Losing the cookie prevents the feature from recognizing your earlier vote. The legal basis is Article 6(1)(f) GDPR, our interest in providing requested feedback and preventing duplicate votes.
6. Page-View Statistics
Page-view statistics are currently disabled. Your browser does not send counting requests, and we do not add new page-view totals while this setting is off.
Any previously collected daily totals remain subject to the 25-month cleanup period. These totals contain no visitor identifiers, IP addresses, browser identifiers, referrers or search terms. The technical processing needed to deliver and protect the website still takes place as described in section 2.
7. Community Feedback, Messages and Corrections
The Feedback Form
Use “Got a Tip?” to send a private message, report a problem or suggest a game or article. We store the feedback category, message, any URL you submit and the time it arrives. Name and email are optional; you can leave both blank. An email address lets an editor follow up where needed. Sending feedback does not subscribe you to anything.
The form also sends the PixelHeat page path without its query string, the referring website’s hostname without its path or query, and your browser language. These help us understand reports. Please leave out passwords, financial details, information about your sex life or health, and other sensitive personal information. Do not send someone else’s private details.
To prevent spam and repeated submissions, we check request headers and body limits, use a short-lived keyed value derived from the connection address, and keep a keyed version of a random form token. The feedback database does not store your raw IP address. Abuse counters expire after one hour and are removed on a subsequent submission or by the hourly cleanup. The form token is held in page memory, not a tracking cookie, and its stored counterpart is removed when the feedback is anonymized. The ordinary security processing in section 2 still applies. Messages and contact fields are not copied into application audit logs.
Research and Editorial Use
Authorized editors can read the private inbox. Supported Steam and itch.io game links can trigger server-side research of the game’s public store page. Those providers receive our server’s request for that page, not your message, name or email. Unsupported websites are not fetched automatically.
Automation checks the source, avoids duplicate assignments and may create a game record, research task or article draft. Our model-assisted writer uses the researched public source material through OpenAI’s Codex service. It does not receive the reader’s original message, optional name or email, form token or private editorial notes. The worker’s database permissions also prevent it from reading optional contact fields and private notes. OpenAI handles the source material under its service terms and privacy information; provider processing may take place outside the EU/EEA.
Your submission is not a public comment. We do not publish your original message or contact details. An editor may use the suggested topic in an article; community suggestions produce drafts and cannot publish automatically. These are editorial decisions about coverage, not automated decisions with legal or similarly significant effects on you.
How Long Feedback Stays
We keep active feedback while it is genuinely needed to process the request. Closing, resolving, ignoring or rejecting it starts a 90-day retention period. Completed draft creation, duplicate linking and a failed task with no scheduled retry also close the feedback workflow. A link to an article does not extend that period. The hourly retention job anonymizes expired records; it skips work that is still running or queued for active processing.
Anonymization permanently removes the original message, optional name and email, submitted URL, form token, technical context, private notes and other reader-specific details from the active database. Where a suggestion led to editorial work, we retain only a generic community-origin record and the necessary content relationships. This does not require deleting an article. You can ask for earlier erasure at kontakt@pixelheat.news; see section 9. We do not collect extra identity details just to make anonymous submissions identifiable.
This processing relies on Article 6(1)(f) GDPR: our legitimate interests in answering voluntary feedback, correcting problems, researching suggested topics and preventing abuse. Optional contacts, restricted access, short-lived abuse counters and anonymization limit the effect on readers. Providing an email address is not consent to marketing, and the form does not require a newsletter or tracking opt-in.
Email, Phone and Post
If you contact us by email, phone or post, we process your contact details, message and information you send so we can respond. Email delivery involves the sender’s and recipient’s mail providers. Send only information needed for your request. There is no automatic newsletter subscription.
The legal basis is Article 6(1)(f) GDPR for inquiries and editorial or rights concerns, Article 6(1)(b) for a contract or steps you request before a contract, and Article 6(1)(c) for applicable legal duties. Ordinary correspondence is deleted when the matter and necessary follow-up are complete. Messages needed for statutory retention duties or to establish, exercise or defend claims remain for the applicable period.
8. Access, Backups and Retention
Administrative access is limited to authorized staff and providers who need it to operate the website. Staff accounts and editorial audit records support access control, accountability and security. We do not currently offer public reader accounts or comments.
Encrypted backups are kept on the server and copied to the operator’s computer in Germany. Server copies rotate across 30 daily, 12 weekly and 12 monthly snapshots; local copies use 45 daily, 16 weekly and 12 monthly snapshots. Deleted data can remain in older snapshots until rotation removes them. Backups are restricted to recovery, not advertising or reader analysis. This relies on Article 6(1)(f) GDPR, our interest in restoring the service after failure.
These are snapshot counts, not a promise that every backup disappears on a particular calendar date: interrupted backup schedules can leave older recovery points. We do not destroy healthy backups for an individual feedback erasure. Before a recovered feedback database can be used again, our recovery procedure anonymizes its original reader data, including messages that were still open in the backup. Editorial content and anonymous provenance remain. Recovery checks also lock the inbox if its deletion state cannot be verified.
Otherwise, we retain personal data only as long as its stated purpose, applicable legal duties or a specific unresolved claim require. We do not sell reader data or use it for automated decisions producing legal or similarly significant effects under Article 22 GDPR.
9. Your Rights
Subject to the GDPR’s conditions, you may request access, correction, deletion, restriction of processing and data portability. You may withdraw consent at any time. Where processing relies on legitimate interests, you may object for reasons relating to your particular situation; you can object to direct marketing at any time.
Write to kontakt@pixelheat.news. We may request proportionate information to locate your data and verify the request. You can also complain to a supervisory authority, particularly where you live, work or believe a violation occurred. The Data Protection Conference’s directory lists the German supervisory authorities.
10. Adults and Future Changes
PixelHeat is intended for adults aged 18 and over. Current reveal controls do not collect identity documents or dates of birth. If we add advertising, visitor-level analytics, reader accounts or age verification, we will update this policy and request any newly required consent before optional processing begins.