Account Data
If you create an account, the site stores your email address, internal user ID, password
hash, account creation time, last login time, authentication state, and account or security
metadata created by ASP.NET Identity. Passwords are not stored as plain text.
Steam Login Data
If you choose to sign in with Steam, the site redirects you to Steam and stores the
external login provider and Steam provider key needed to recognize your account later.
Steam may process your data separately during authentication. See the
Steam Privacy Policy.
Account Email
If you create an email-and-password account or request a password reset, the site sends your
email address and a temporary confirmation or reset link through OVHcloud Zimbra. The link
contains a single-use security token. Confirmation links expire after 48 hours and password-reset
links expire after two hours. OVHcloud may process message
and delivery metadata under its own privacy terms. Generic resend and password-reset responses
do not reveal whether an account exists for an address.
Private Marker Data
If you add private markers, the site stores their titles, descriptions, coordinates,
the associated public map, owner user ID, and created or updated timestamps. Marker
categories, groups, and visibility settings may also be retained with existing markers.
We also store whether you have marked each private marker as found.
Your markers are private to your account and cannot be shared with other users.
Uploaded Save Files
Some tools, such as the Skyrim and Baldur's Gate 3 save inspectors, upload a save file
to the server, validate it, temporarily store it outside the public web root, parse it,
return the result to you, and then delete the temporary file. The uploaded file may contain
player or character names, save names, in-game screenshots, mod or plugin lists, quest or
story progress, save timestamps, game version or platform, party data, and in-game
locations. These files are not intentionally retained as account records.
Browser Storage
When signed out, marker "found" progress is stored only in your browser's local storage
under an AllGameMaps key. When signed in, we instead store found-marker progress with your
account using your user ID and the marker IDs, so it is available across devices when
you load a map. Browser-only progress is not imported into your account or merged with it.
Cookies
The site uses an authentication cookie named AllGameMaps.Auth, ASP.NET
antiforgery and external-login cookies, and the standard ASP.NET culture cookie used for
language handling. The authentication cookie is configured for up to 30 days with sliding
expiration. The culture cookie is configured for up to 365 days.
When you select List or Grid in the catalogue, the functional cookie
agm.catalogView remembers that choice for up to 365 days. It contains only
list or grid, is not used for tracking or advertising, and does
not depend on optional-cookie consent. If cookies are blocked, your choice applies
only to the current page; without a saved preference, the catalogue defaults to Grid.
In production, Google and selected advertising partners may place or read cookies and use
similar technologies such as local storage, web beacons or pixel tags. Requests to those
services may include the page URL, IP address, browser or device information, consent state,
advertising or analytics identifiers, and information about ad impressions and interactions.
These technologies are used for analytics, ad delivery, personalization where permitted,
measurement, frequency capping, reporting, fraud prevention, and security.
Google Analytics
In production, the site uses Google Analytics to measure site usage, traffic, and
page interaction. Google may receive the page URL, IP address, browser or device information,
consent state, analytics identifiers, and interaction data. In the European Economic Area,
the United Kingdom, and Switzerland, analytics storage starts denied until consent allows it.
Google explains how data is used on sites using Google services in
How Google uses information from sites or apps that use our services.
Google AdSense
In production, the site uses Google AdSense.
Google uses advertising cookies and similar technologies to serve, render, and measure ads.
Where permitted by your consent and settings, ads may be personalized using information from
prior visits to AllGameMaps or other websites and apps. Google and selected ad technology
partners may process IP addresses, page URLs, browser or device information, consent signals,
advertising identifiers, and ad impressions or interactions for personalization, measurement,
fraud prevention, frequency capping, and aggregated reporting. Non-personalized or limited ads
may still use cookies, local storage, IP addresses, or other identifiers for purposes such as
fraud prevention, frequency capping, security, and reporting.
When Google's consent interface is displayed, the selected partners and their purposes can
be reviewed through Manage options. Google also publishes information about
AdSense ad technology partners
and
how Google uses cookies and similar technologies.
Google Consent Mode And Consent Management
In the European Economic Area, the United Kingdom, and Switzerland, the site defaults
analytics_storage, ad_storage, ad_user_data, and
ad_personalization to denied before loading Google scripts. The Google consent
management platform is intended to collect and communicate your choices. When displayed, you
can review or withdraw those choices through the site's Privacy and cookie settings
control or the Google consent interface. Outside those regions, the site does not supply
these denied regional defaults; Google services still operate according to applicable law,
Google settings, browser controls, and the advertising configuration in use.
You can manage personalized Google advertising through
My Ad Center
and
Google partner ad settings.
You can also use industry controls such as
Your Online Choices
or manage cookies and similar storage in your browser. Opting out of personalized advertising
does not necessarily stop all advertising or storage needed for security, fraud prevention,
frequency capping, or other permitted purposes.
Technical And Server Data
The web server, reverse proxy, application framework, Docker runtime, and hosting
infrastructure may process technical data such as IP address, request URL, timestamps,
browser or user-agent details, diagnostic information, and security-relevant events. This
data is used to operate the site, investigate errors, protect accounts, and prevent abuse.
Hosting And Storage
The web application is hosted on a Hetzner virtual private server in Germany. Application
data is stored in PostgreSQL. Image and map assets are served from server storage mounted
into the application. Data Protection keys used for authentication and antiforgery
protection are persisted on the server so user sessions are not invalidated on every
deployment.
Database And Backups
Account data, private marker data, and account-saved found-marker progress are stored in PostgreSQL until deleted, the account is
deleted, or retention is no longer needed. Hetzner-managed server backups are enabled.
Deleted data may remain inside backup copies until those backups expire, with
a maximum intended retention period of 90 days.