Public record

Privacy Policy

Last updated: 31 August 2026

This privacy policy explains how personal data is processed when you use Whydunit at whydunit.dev ("the Service"). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable German data protection law.

1. Controller

The controller responsible for data processing on this website is:

Theo Fuhrmann
Moltkestraße 25
40477 Düsseldorf
Germany

Email: whydunit@avayne.de

2. What Whydunit does

Whydunit is a browser-based debugging game. The Service generates small codebases containing a hidden bug, lets you investigate them in a chat with an AI mentor, and grades your bug reports against the hidden answer key. Chat content is processed by AI providers as described in section 6, but submitted bug reports are graded without an AI call.

3. Hosting and infrastructure

The Service runs on Cloudflare Workers, operated by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare delivers the website, executes the application, and protects it against attacks. When you access the Service, Cloudflare processes connection data — including your IP address, request metadata, and technical browser information — and retains short-lived server logs that we use for operating, securing, and debugging the Service.

The legal basis is our legitimate interest in providing a secure and reliable website (Art. 6 (1) (f) GDPR). We have concluded a data processing agreement with Cloudflare. Transfers to the USA are safeguarded by the EU standard contractual clauses and Cloudflare's certification under the EU–U.S. Data Privacy Framework. See Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/.

Application data is stored in a PostgreSQL database hosted by PlanetScale, accessed through Cloudflare's connection pooling service (Hyperdrive). Uploaded profile pictures are processed by Cloudflare Images and stored in Cloudflare R2.

4. Account and registration data

You can create an account with your name, a username, your email address, and a password. The password is stored only as a cryptographic hash. You can instead sign in with GitHub, Google, or Discord. If you do, we receive your provider account identifier, name, email address, email-verification status, and profile image. We store the provider identifier so you can sign in again, but we do not retain provider access, refresh, or ID tokens after authentication. We request only basic identity and email permissions. We do not request access to your repositories, Google files, Discord servers, or messages.

Social sign-in redirects your browser to the provider, which processes the login under its own privacy terms. See the privacy statements for GitHub, Google, and Discord.

You may optionally upload a profile picture. Before upload, your browser checks the file type, size, and dimensions, crops it to a square, removes embedded source metadata, and converts it to WebP. We validate and re-encode the image again before storage; the original selected file is not sent to us or retained. Replacing or removing the picture triggers a best-effort deletion of the previous managed file. If cleanup fails, the file may remain in managed storage. A profile image received from a social sign-in provider may continue to load from that provider until you replace or remove it. You may also play as an anonymous guest, in which case a temporary account without personal details is created; if you later register or use social sign-in, it is merged into your account.

For each login session we store a session token together with the IP address and browser user agent of the device, which helps secure your account. To prevent abuse, authentication endpoints are rate-limited using your IP address.

The legal basis for processing account data is the performance of our contract with you (Art. 6 (1) (b) GDPR); for session and abuse-prevention data it is additionally our legitimate interest in securing the Service (Art. 6 (1) (f) GDPR).

5. Gameplay data

When you use the Service, we store the data needed to run it: your cases and their generated code, your complete chat history with the AI mentor, your submitted bug reports ("flags") and their deterministic verdicts, your achievements and skill statistics, optional case ratings including any free-text comment you enter, in-app bug reports you submit (title, description, and the page you were on), and per-case token usage for enforcing plan limits. The legal basis is the performance of our contract with you (Art. 6 (1) (b) GDPR).

6. AI processing

The core of the Service is powered by large language models. When you play a case, generate its material, or chat with the mentor, the relevant content — including the messages you type, the case's chat history, and the generated case material — is transmitted to our AI infrastructure provider Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA (AI Gateway), which routes it to the model providers OpenAI (OpenAI, L.L.C., San Francisco, USA) and xAI (X.AI Corp., San Francisco, USA) to generate responses. Prompts may be temporarily cached at the gateway to speed up responses and reduce cost.

These providers process the content to provide the model responses. We use API offerings under terms that do not permit the use of your content for model training. Transfers to the USA are safeguarded by the EU standard contractual clauses and, where the provider is certified, the EU–U.S. Data Privacy Framework.

Please do not enter sensitive personal data (yours or anyone else's) into game chats — the game does not need it, and everything you type in a case is processed by the providers above.

The legal basis is the performance of our contract with you (Art. 6 (1) (b) GDPR), since AI processing is the essential function of the Service.

7. Payments

Paid subscriptions and credit packs are sold through Polar Software Inc., 548 Market St, San Francisco, CA 94104, USA, acting as our merchant of record. When you purchase, Polar collects and processes your billing details, payment information, and country/tax data under its own responsibility; we never receive or store your payment card details. We receive and store only order, subscription, and customer identifiers needed to credit your account. See Polar's privacy policy at https://polar.sh/legal/privacy.

If a billing notification cannot be applied, we retain the failed notification and its provider identifiers so an authorized operator can retry or close it. Operators see only a limited failure summary in the review queue, not the stored notification body or customer identifiers.

The legal basis is the performance of a contract (Art. 6 (1) (b) GDPR).

8. Public content

Your profile is private by default. If you set your profile to public, your username, display name, and avatar become visible to other users. If you set a case to public, it appears in the community browse listing together with your username, display name, and avatar, and other users can view and clone it. You can change the visibility of your profile at any time in the settings.

The legal basis is the performance of our contract with you (Art. 6 (1) (b) GDPR) based on the visibility settings you choose.

9. Cookies and local storage

The Service uses a single, strictly necessary session cookie to keep you logged in (httpOnly, Secure, SameSite=Lax). We do not use any tracking, advertising, or analytics cookies, and we do not embed third-party analytics or tracking scripts, which is why no cookie consent banner is shown. In addition, your browser's local storage holds your theme preference (light/dark) and first-hunt walkthrough step. The walkthrough record contains no account, case, chat, or answer data. Session storage is used for short-lived technical state while you play. Storing this information is strictly necessary to provide the Service you request (§ 25 (2) TDDDG).

10. Storage duration

Account and gameplay data, including your current managed profile picture, are stored for as long as your account exists. We make a best-effort attempt to delete replaced managed profile pictures after publication. Login sessions expire automatically. Authentication abuse-prevention records expire after their active rate-limit window. Server logs and completed workflow histories at our hosting provider follow the provider's limited operational retention periods. Billing-related records are retained as long as required by statutory commercial and tax retention obligations. Failed billing notifications remain available while they need reconciliation. After an operator closes one, we delete its stored notification body after 30 days.

You can permanently delete your account in Account settings. This removes your profile, profile-picture files, credentials, sessions, cases, chats, gameplay records, usage records, and retained chat streams. It also ends active subscriptions and asks Polar to anonymize your customer details. Polar keeps transaction records where commercial or tax law requires it. Copies in provider backups, security logs, and completed workflow histories are isolated from normal use and expire under the provider's retention schedule.

You can also request deletion or ask about retained records by emailing whydunit@avayne.de.

11. Your rights

Under the GDPR you have the right to access your personal data (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). To exercise any of these rights, contact us at whydunit@avayne.de.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular the authority of the German federal state in which you live or in which the controller is established.

12. No profiling, advertising, or analytics

We do not use your data for advertising, we do not sell it, we do not build tracking profiles, and we do not use automated decision-making within the meaning of Art. 22 GDPR. The Service contains no third-party analytics.

13. Changes to this policy

We may update this privacy policy when the Service or the legal situation changes. The current version is always available on this page.