Skip to content

Privacy policy

1. Controller

Heinrich Janzen Business name: Sahle Höhenweg 16, 49124 Georgsmarienhütte, Germany Email: kontakt@rigmint.de Phone: +49 163 5106212 RigMint is a product name used by this business.

2. Overview of processing

Rigmint processes personal data in particular in the following cases:

  • Registration and login (email address and password)
  • Storage of profile data, in-game IDs and privacy settings
  • Use of the Squadfinder matching system
  • Reports about content (report function for squad posts, themes and builds)
  • Published builds, themes and calculator setups together with who created them, and for builds the indication of which account adopted a build
  • Paired devices and measurement sessions of the Windows application, if you have consented there
  • Price alerts by email and optionally by browser push
  • Sending system emails and correspondence via the contact mailbox
  • Participation in giveaways including a separate consent to name publication
  • Publishing in the workshop gallery (build name, preview image, hearts) including a separate consent to name publication
  • Entries on the workshop leaderboard including a separate consent to name publication
  • Workshop progress (rank, showcase of built parts, badges, deco coins), first in the browser, and additionally on the account when signed in
  • Warnings, account suspensions and the admin log of moderation decisions
  • Technically necessary cookies and entries in the browser's local storage

3. Hosting and infrastructure

Web hosting and DNS: We use Cloudflare Workers and Cloudflare DNS provided by Cloudflare, Inc. (USA). Accessing and using the website involves processing your IP address, time, requested address, browser and connection information, and the request and response content needed for the feature you use. Depending on your use, this also includes session cookies, login and form submissions, and data the Windows application sends to our API. Data that remains exclusively on your device is not thereby sent to Cloudflare. The legal basis for secure and stable operation is Art. 6(1)(f) GDPR; individual account and application features follow the purposes and legal bases stated in their respective sections of this policy.

Cloudflare processes our application content and customer logs as a processor under the applicable Data Processing Addendum: https://www.cloudflare.com/cloudflare-customer-dpa/. For its own network data, Cloudflare acts as a controller under its privacy policy: https://www.cloudflare.com/privacypolicy/. Its subprocessors are listed at https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/. Processing outside the EU, particularly in the USA, is possible. Cloudflare identifies the EU-US Data Privacy Framework and EU Standard Contractual Clauses for further safeguards where required. The relevant safeguards are available in the linked contractual and privacy information; you can request further information through our contact address.

The application database remains with Neon (PostgreSQL). It holds in particular the account, profile and application data described in this policy. The Cloudflare application reads and writes this data to provide the respective feature. Current Neon contractual information is available at https://neon.com/platform-terms/ and refers to Databricks and its data processing agreement at https://www.databricks.com/legal/dpa. Selecting a database region does not mean all data is processed exclusively within the EU. The data processing agreement provides in particular for EU Standard Contractual Clauses where safeguards for international transfers are required.

To deliver public content, we also use Cloudflare KV for caching and D1 for cache tags and update timestamps. Public content may include published names or contributions. Cloudflare Durable Objects process page requests, coordinate cache updates, and calculate or verify password hashes. Password calculation and page processing do not themselves write data to these computing instances' persistent storage; technical cache update data may be stored. For password storage, see section 4.

Caches and logs are separate from live account data. Cached copies may remain until replaced or specifically deleted; there is no single short expiry period for them. Technical error and security data serves troubleshooting and abuse prevention. Cloudflare retains its own network data according to the relevant purpose and legal obligations. Storage and deletion rules for individual application features are set out in the following sections. Vercel Web Analytics is disabled; no measurement script is included in the application code.

3a. Email delivery and contact mailbox

The site sends email only when there is a reason to: confirming your email address, resetting your password, price alerts, the reply to a content report and the notice about a warning. There is no newsletter and no promotional email. The legal basis is Art. 6(1)(b) GDPR where sending is part of providing your account, and otherwise Art. 6(1)(f) GDPR.

If you write to kontakt@rigmint.de, your message arrives in a mailbox that is read and answered from this site's admin area. Everything contained in your email is processed: sender address, subject, body, attachments and time. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in answering enquiries), or Art. 6(1)(b) GDPR where the enquiry relates to a contract.

Incoming email is always displayed as plain text in the admin area and never executed as HTML, and images it contains are not loaded. As a result, whoever writes to us does not learn whether or when their email was opened.

On retention: your message stays in the mailbox until it is deleted there. This site's interface can only read email, mark it as read and reply to it; it cannot delete it, deletion happens in the mail client. If you want your correspondence with us removed, write to kontakt@rigmint.de and it will be deleted.

4. Registration with email and password

For a user account we store your email address, optionally a display name of your choice, and your password exclusively in hashed form (method: scrypt with a random salt). The plaintext password itself is never stored. The login state is managed via an encrypted session cookie (JWT). The legal basis is Art. 6(1)(b) GDPR (performance of a contract to provide the user account).

During registration and password reset, our server also checks the chosen password against known breaches using Have I Been Pwned’s Pwned Passwords service. It sends only the first five characters of the SHA-1 hash over an encrypted connection to api.pwnedpasswords.com; the password, complete hash and your email address are not transmitted. Our server compares the returned hash suffixes locally. The service receives the technical request, including our server’s IP address, rather than a direct request from your browser. The purpose is to protect your account against passwords already exposed in breaches. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in account security). A temporary outage of the service does not block registration or password reset.

5. In-game IDs and visibility

In-game IDs (e.g. Steam, Epic, Riot ID) are not shown publicly by default (isPublic: false). They become visible to another user only after a mutual squad request has been accepted by both sides. The legal basis is the user's consent or Art. 6(1)(b) GDPR.

6. Reports about content

When you report a squad post, we store the reported content ID, your user ID, the selected report reason, an optional short note of at most 300 characters and the time of the report, in order to prevent abuse and to meet the legal obligation to handle reports (Art. 16 Digital Services Act). The legal basis is Art. 6(1)(c) GDPR (legal obligation) in conjunction with (f) (legitimate interest in a platform free from abuse).

For reports about themes and builds we store no report reason, only the reported content ID, your user ID and the time. We do not ask for a reason there, because an additional free-text field would be another channel for user content. Exactly one report is possible per account and piece of content. The legal basis is, as above, Art. 6(1)(c) in conjunction with (f) GDPR.

6a. Price alert and browser push

When you set a price alert, we store your user ID, the product key, optionally a target price, and whether the notification should go by email and/or browser push. An alert email is sent only after you have clicked the confirmation link in the email. The legal basis for the alert itself is Art. 6(1)(b) GDPR (service requested by you); sending to your address is based on your consent under Art. 6(1)(a) GDPR, which you give with the confirmation link and can withdraw at any time with one click in the email.

For browser push we store the endpoint address supplied by the browser and the related keys, linked to your account if you are signed in. Delivery goes to your browser's push service (including Google, Mozilla, Microsoft or Apple). These services are partly located outside the EU; transferring the technical address is necessary for delivery. You can end the subscription in the browser settings or via the site; we remove invalid endpoints automatically.

6b. Giveaways

When you take part in a giveaway, we store your user ID, the time of participation and acceptance of the terms of participation. The separate consent to publish your display name if you win is stored separately (timestamp of consent and, where applicable, of withdrawal). Without this consent you still take part; if you win, only a ticket number is shown. The legal basis for participation is Art. 6(1)(b) GDPR, for name publication Art. 6(1)(a) GDPR. You can withdraw name publication on the giveaway page while the giveaway is running.

6c. Warnings, suspensions and admin log

When a post is removed, we store a warning with the removed text, the reason, an explanation to you and the time. This implements Art. 17 and Art. 20 of the Digital Services Act: without the text and the explanation there would be no path to contest. Three open warnings can lead to an account suspension; the suspension carries a reason and an end date. In addition, every moderation decision by an admin writes a line to the admin log (who, what, when). The log is currently not deleted automatically.

6d. Workshop gallery

If you publish a build in the workshop gallery, we store your user ID, the build name and the build configuration. From that, the site generates a preview image for the public detail page and for link previews on social networks. The build name, the preview image and the heart count are publicly visible. Setting a heart stores your user ID against that entry. The separate consent to show your display name with the entry is stored separately (timestamp of consent and, where applicable, of withdrawal). Without that consent an anonymous code is shown instead of your name. The legal basis for publishing the build is Art. 6(1)(b) GDPR; for name publication it is Art. 6(1)(a) GDPR. You can withdraw name publication in the same place where you gave consent. You can delete your entry yourself at any time; deletion is hard removal, not hiding. Retention: the entry remains until you delete it or delete your account; deleting the account removes it as well.

6e. Workshop leaderboard

If you submit a workshop daily challenge, we store your user ID, the calendar date, the score achieved and the related build. Showing your name on the public leaderboard is based on Art. 6(1)(a) GDPR and needs separate consent. Withdrawal is available in the same place as giving consent (Art. 7(3) GDPR). The record of consent (timestamp) is kept even after withdrawal; what is removed is the effect, not the proof. Without consent an anonymous code is shown, never your real name. The legal basis for storing the entry itself is Art. 6(1)(b) GDPR.

6f. Workshop progress

In the workshop we store your progress: the rank reached (apprentice, journeyman, master), the list of parts you have ever fitted (showcase), unlocked badges and the deco-coin balance. At first this lives only in your browser's local storage (bh.werkbank.fortschritt, bh.werkbank.muenzen and related keys). When you are signed in, the same values may also be bound to your account so they reappear on another device. None of this is public unless you publish a build or submit a daily challenge (then 6d and 6e apply). Legal basis: Art. 6(1)(b) GDPR. Retention: locally until you clear browser storage; on the account until you reset progress or delete the account.

6g. Homepage feedback

On the studio homepage terminal you can leave feedback without signing in. We store the text, the time and the page language. We do not run the text through a language model or summarise it automatically; it only appears in our admin area. A reply is not promised. We do not keep your IP address in plain form, only at most a one-way hash for spam defence, and that hash is dropped within 48 hours. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the product and stopping spam). Retention of the text: at most 12 months, then deletion unless a legal duty requires keeping it longer.

7. Cookies and local storage

Technically necessary cookies and storage entries:

  • NEXT_LOCALE: your language choice. No personal reference, required for multilingual output.
  • Login session cookies (JWT): keep you signed in. Legal basis Art. 6(1)(b) GDPR.
  • battlehub-theme: chosen colour scheme, so the page does not briefly flash another theme after loading.

The browser's localStorage may also hold the arrangement of the home page, local drafts and workshop progress (see 6f). These entries do not leave your computer by themselves; they only control what this site does on your device. The optional audience measurement described in section 3 is disabled.

8. Live monitoring in the Windows application

The Rigmint application for Windows (still named BattleHub in older installations) can, at your express request, measure performance values of your computer: load of processor and graphics card, the processor clock, temperature, clock, power draw and fan speed of the graphics card, the occupied and the total system and graphics memory, the refresh rate of the display in use, the game process name, width and height of the visible game-window area and, where measurable, frames per second together with frame time, the 95th and 99th percentile frame times, the number of conspicuous frame-time spikes and the number of frames measured for them. CPU temperature is not collected in this version. The game-window area is not a screen capture and may differ from the internal render resolution due to upscaling or dynamic resolution; that source is stored with the value. For games whose configuration file we verified on a real installation, the application additionally reads only predefined keys for resolution, render scale and graphics quality; arbitrary file contents are not collected. For automatic game recognition it periodically reads the locally installed Steam, Epic and Riot library data as well as the names, process identifiers and executable paths of running programs. For the upgrade planner it additionally reads each drive's model, type, connection, size, free space and drive letters, but no serial numbers. It locally associates detected game paths with a drive and adds the file sizes inside detected game folders for the space check without opening their contents. The full installation path does not leave the main process. These details are compared on the device only with verified game folders and executable names; non-matching programs are discarded immediately and are neither stored nor transmitted. Screen contents, keyboard or mouse input, other file contents or browsing history are not collected.

While Rigmint is running and you have enabled monitoring, a session starts automatically after an installed game has been detected and confirmed, and ends when the game closes. You may optionally let Rigmint start in the background with Windows; this setting is off initially, remains visible in the Windows notification area and can be disabled at any time. Measurement takes place exclusively on your device. During the session, Rigmint also determines locally the average share of total CPU capacity used by its own Electron processes and their highest private-memory level. These self-usage values are not transmitted; the separate Intel PresentMon process is not included and that limitation is named in the display. After a session ends, Rigmint reads the graphics-driver date and version so that a driver change between two comparable runs can be identified. For a fair before/after comparison, the application stores at most 20 session summaries with game, graphics and driver state locally; the time-related measurement series are not stored locally for this purpose. Measured game-folder sizes are cached locally for no more than seven days together with the measurement time and a hash of the path, not the path itself, and are deleted when consent is withdrawn. Without your separate consent to transmission, no measured value leaves your computer. Drive and game-folder details are not transmitted even when sharing is enabled. The legal basis of the measurement itself is performance of the function you requested; for that purpose it is necessary within the meaning of section 25(2) no. 2 TDDDG.

For an automatically detected game session, the already running Windows reader compares on each measurement tick only whether the verified game process owns the foreground window. This produces one percentage for the whole session, but only if Windows supplied the state for at least 70 percent of measurement points; otherwise the value remains empty. Window titles, keyboard input and mouse input are not read for this. The process identifier and time series of the comparison remain local; only the aggregated percentage is part of a voluntarily shared session. The same percentage is also stored in no more than 20 local session summaries so that a run with frequent Alt-Tab use is not treated as a fair before/after comparison. Withdrawing consent deletes these local summaries.

Transmitting a completed measurement session to us is voluntary and happens only on the basis of your consent under Art. 6(1)(a) GDPR. Without any preselected box, you explicitly choose between “Measure and share data” and “Measure locally only”. Sharing requires fresh explicit permission after each application restart. You can switch it off with one click in the “Messung” tab at any time. Upload starts only after monitoring ends. If Stop is pressed while the game remains open, the short upload can still use network and some processing capacity; Rigmint therefore does not promise guaranteed zero impact or delay. If a short network or server interruption occurs, the application retries no more than twice, only while it remains open and sharing remains enabled. Measurement series are not queued on disk for this. A random, one-time transmission identifier prevents duplicate database records. It is stored with the session, which is linked to your account. The purpose is to improve FPS predictions using suitable measurement sessions. Their usefulness depends on measurement quality and comparability. What is transmitted are the measured values named above, both as the series recorded over the session and as the summary calculated from it (mean, peak and percentile values, conspicuous frame-time spikes per minute, a suspicion of throttling and the aggregated foreground share), the session start, end and duration, the interval between two measurement points in milliseconds, the measurement level from 1 to 3, the refresh rate of the display, your hardware, the game process, game-window size and verified resolution, render-scale and graphics-quality values with their respective sources, a stable Steam, Epic or Riot game identifier, the Rigmint version used, and the text version and time of your voluntary sharing choice as consent evidence, linked to your user account. The consent evidence is not an additional device identifier. The process identifier is used only to associate the local game window and is not transmitted. The graphics-driver version read after the game also remains exclusively in the local comparison and is not transmitted with the session. Non-matching process names and paths are not transmitted. For server-side processing, see also section 3, “Hosting and infrastructure”.

Pairing with your account and the device name: so that a voluntarily shared session can be attributed to your account, you link the application to your Rigmint account once by means of a code. During that step it transmits a label for this device so that you can tell in your profile which device you are removing. The computer name assigned by Windows is proposed; such names frequently contain your real name. The application therefore shows you the name before it leaves the device, and you either pick the neutral label “Windows-PC” instead or cancel. Without that confirmation nothing is sent for the pairing. You delete the device name by removing the device in your profile.

If a voluntarily shared session is eligible for FPS analysis and its graphics context is unambiguously verified, the application receives only aggregate counts of existing sessions and participating computers for that combination together with the target counts. Names, identifiers belonging to other devices, and individual measurements from other users are not returned. This response exists only to explain your visible contribution to the database.

Clearing measurement series: A cleanup run scheduled daily removes raw measurement series from sessions that started more than 90 days earlier. The process name and exact session duration are reset, and the exact session times are replaced with a month marker for the cleanup run. Hardware and game details, aggregated performance values and the link to your account and, where applicable, device remain. The text version and time of sharing consent are also retained. These records therefore remain personal data; this cleanup is not complete erasure or anonymisation.

Change journal of the Windows application: If you accept one of the offered Windows settings (turn on game mode, set the power plan to high performance) or have a frame rate limit written into a verified game configuration, Rigmint creates an entry for it in the file aenderungs-journal.json in your Windows user folder. It holds the affected setting or the game identifier, the value before and after, the time, the reason for the change, the expected effect, whether Windows accepted the change and whether the way back is still open. The entry is written before the change, so that the way back is known even after a power cut; it is the basis of the display “What Rigmint changed on this computer” and of the button that undoes it. The file stays on your device and is not transmitted; it holds at most 50 entries, older ones drop out. Because it is the record of what was changed on your computer and how it is undone, it also remains after you withdraw consent and is not deleted automatically. You can clear it yourself: the “Measurement” tab holds the button “Delete change history”, which removes all completed entries after a second confirmation. Only entries are removed whose way back is undone, already used or never existed. Entries for changes that are still active on your computer and can still be undone stay, because otherwise you would lose the way back together with the entry; the application tells you how many of them are left. The legal basis is performance of the change you expressly requested.

Finding store of the Windows application: As long as the observer is switched on, Rigmint recalculates on your device after every completed measurement whether your frame rate changed at any of the recorded changes. If it finds a difference larger than the usual fluctuation within the same comparison group, it creates an entry for it in the file beobachter-befunde.json in your Windows user folder. It holds the time, the metric examined, the game identifier, the change concerned together with its time, the number of sessions before and after, their middle values, the difference and the threshold it was measured against, as well as whether you have already noted or put the entry aside. No new measured values are collected for this; the calculation uses only the at most 20 local session summaries and the change journal, both described above. The purpose is to point out a deterioration or the effect of a change. The file stays on your device and is not transmitted; it holds at most 20 entries, older ones drop out. At your express wish, Rigmint names such an entry as a Windows notification, at most once a day and never while a game is running; you can turn these notifications off at any time in the “Messung” tab under “What Rigmint noticed”, and the list then remains available to you in the application. In the same place there is a second switch that turns the observer off entirely: nothing is then calculated after a measurement, no further entry is added, and nothing is reported. Entries that already exist stay where they are; if you switch it back on later, it recalculates the existing session summaries again. Both switches are on to begin with, because the observer collects no new measured value, calculates solely on your device and transmits nothing. Unlike the change journal, the finding store is deleted in full when you withdraw consent, because every entry is derived from the local session summaries that are deleted at the same time. The legal basis is performance of the measurement function you requested.

Withdrawal and deletion: You can withdraw consent to transmission at any time with the switch in the “Messung” tab; no further transmission is started after that and any pending retry attempts stop. A transmission that has already started cannot reliably be recalled. Local monitoring and its comparison summaries remain unaffected. “Withdraw consent” also stops local monitoring and deletes those local summaries. The lawfulness of processing carried out until then remains unaffected. You delete sessions that have already arrived completely in your profile under “My measurements” with a button.

8a. Rig Restore: local reading of installed programs

The Rig Restore tab in the Rigmint application for Windows reads, at your express request, the uninstall entries of the Windows registry on your device: program name, publisher and version, wherever the registry holds them. The sole purpose is building a recovery list with links to the official vendor pages of the programs found, so you can find them again after reinstalling Windows. The legal basis is your consent under Art. 6(1)(a) GDPR. You give it on a dedicated screen before the first read runs, and you can withdraw it at any time with a switch in the same tab; each time you do either, the application keeps a local record of when it happened and which version of this text was in effect. Without consent the application reads nothing.

The recovery list stays on your device. Rig Restore has no network connection to Rigmint, neither for reading nor for export; this is guarded by its own automated checks, and nothing is transmitted to Rigmint. When you export the list as a file or back up chosen savegame folders, you pick the destination and folder yourself through a system dialog each time, for example an OneDrive or Google Drive folder already set up on your computer. Uploading and syncing from there runs exclusively through the cloud client of your own account with that provider; Rigmint itself sends nothing to that provider and is not a data processor in this respect, because it takes no part in the transfer. Your cloud provider's own privacy policy additionally applies to that part of the process.

9. Retention period

Profile data is stored for as long as a user account exists. If you delete your account, it is deleted from live account records unless statutory retention obligations prevent this. This does not mean every backup and cached copy is destroyed immediately. Database backups may contain data within their separate recovery and retention periods; cached copies are replaced or deleted separately (see section 3).

Reports about themes and builds as well as the indication of which account adopted a build are deleted automatically after 12 months. A daily job does this; the period is a single number in the source code that the job and this page both follow. What remains are only the counters, that is how often a piece of content was adopted or reported. They no longer relate to a person.

Reports about squad posts (see section 6) are deleted by the same job 12 months after they are handled. Open reports remain until a person has handled them: deleting an unhandled report after the deadline would mean closing it by lapse of time.

10. Minimum age

Rigmint is aimed at users aged 18 and over. Registration is only permitted with a truthful statement that you are at least 18 years old.

11. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection under Art. 15-21 GDPR. Contact the address given above for this. You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the State Commissioner for Data Protection of Lower Saxony (LfD Niedersachsen), which is competent for Lower Saxony.

12. Rigmint Score and external support

The current portable Rigmint Score preview processes hardware queries and optional memory samples locally. It writes HTML and JSON reports to a folder you choose and does not transmit those reports to Rigmint. It records hardware models, technical states and available measurements, not document contents, passwords or hardware serial numbers. Free-text notes may still contain personal information. Please avoid entering unnecessary personal information. You control storage, deletion and sharing of the report.

The website links to Rigmint’s external Ko-fi page. A normal link loads that payment area only when you open it. Ko-fi and the payment provider you select then process information under their own privacy notices. PayPal is connected according to the current setup. Other payment providers will be described after they have actually been activated.

When you support Rigmint or make a future purchase, Ko-fi or the payment provider may give us information such as your name, email address, amount, payment status, transaction reference and any message you send. We use necessary information to process the transaction, answer related enquiries and fulfil statutory record-keeping duties. Legal bases are Article 6(1)(b) and (c) GDPR where applicable, and Article 6(1)(f) GDPR where necessary for transaction matching and abuse prevention. This does not constitute consent to advertising. Existing information on data subject rights and retention also applies.

Provider notices: Ko-fi: https://more.ko-fi.com/privacy ; PayPal: https://www.paypal.com/de/legalhub/paypal/privacy-full. These explain their independent processing and possible international transfers.