Skip to content
CFCozy
Fishing
HomeWikiChangelogRankingsPlayers
Login

Privacy Notice · Last updated 1 September 2026

Privacy,
plainly put.

Cozy Fishing is a non-commercial hobby project: a Discord game bot with a public companion website and Discord-authenticated player and admin areas. This notice explains the data used to run the game and how to request access, correction or deletion.

On this page

OperatorData we processWhy we process itPublic companionRetentionRecipientsYour rightsSecurity

01

Operator and contact

Controller
Tom Lange
Service address
c/o Autorenglück #65559
Albert-Einstein-Straße 47
02977 Hoyerswerda
Germany
Privacy email
privacy@cozyfish.ing

The controller above operates the Cozy Fishing bot and companion website as a private, non-commercial hobby project. Discord independently controls the processing required to provide the Discord platform; consult Discord's own privacy notice for that processing.

02

Data we process

Discord account reference

Your Discord user ID and current username. Cozy Fishing does not use your display name or server nickname as the account name and does not receive or store your Discord password, Discord account email, phone number, date of birth or direct messages.

Discord context

Server, channel, thread and session IDs, plus the user ID of an administrator who changes server settings, where needed for sessions, channel rules and audit history.

Game account

Level, XP, coins, Pearls, owned equipment and cosmetics, bait, boosts, capacities, settings, tutorial progress, quests, achievements and derived gameplay statistics.

Catches and game history

Species or junk item, rarity, color, quality, size, value, saved chance, time, loadout, ownership, basket, lock and showcase status, and the original player reference.

Events and support records

Game events, timestamps, technical correlation IDs and administrative actions. Cozy Fishing does not store free-form Discord message content as gameplay data.

Website requests

The web server or hosting layer may process IP address, request time, URL, browser user agent and HTTP status in security and error logs.

03

Purposes and legal bases

We use account references, Discord context and game state to provide the game you request, keep global progress and respond to commands. This is based on Article 6(1)(b) GDPR where processing is necessary to provide the requested service and, where that basis does not apply, on the controller's legitimate interest under Article 6(1)(f) in operating the requested hobby game.

Security logs, abuse prevention, error diagnosis, administrative audits and economy integrity rely on the legitimate interest in keeping the service safe, traceable and fair. Access and retention are limited to what is necessary for those purposes.

Cozy Fishing has no advertising, does not sell personal data and does not make decisions that produce legal or similarly significant effects.

04

Public companion website and Discord login

Public player profiles continue to show Discord username, level, XP, coins, Pearls, loadout, statistics, rankings, achievement timestamps, current inventory, catch art, catch details and the selected Pixel People character. Discord user, server and channel IDs are not displayed publicly. Friends, Crew and the character editor are available only inside the signed-in player's My Profile.

Starting Cozy Fishing creates the public game profile as part of the service. Avoid using a real name as your Discord username if you do not want it shown here. You can request correction or deletion at any time.

For sign-in, the website redirects to Discord OAuth with the identify permission. Discord returns the account ID and username; no email address, server list or contacts are requested. The short-lived Discord access token is used only to load that identity and is not stored. The account ID links the browser session to the existing game account. Discord therefore receives the login request and the configured callback address under Discord's own privacy terms.

cozy_web_session is a signed, HttpOnly, SameSite-Lax cookie for up to 12 hours. It protects My Profile, Friends, Crew, character changes and Pearl purchases with an additional CSRF token. The same session grants the Admin area only when its Discord account ID equals GAME_ADMIN_DISCORD_ID; all other visitors receive a 404 response. Signing out or expiry ends the session.

Discord OAuthidentify only

Account ID and username are processed for authentication. OAuth state is single-use, stored in Redis for at most ten minutes, and prevents login-request substitution.

Web session12 hours

cozy_web_session is signed, HttpOnly and used for authentication and CSRF protection. It is not used for advertising or visitor analytics.

Browser profile storage0 keys

No username is stored in localStorage or a preference cookie. My Profile is resolved exclusively from the current Discord login.

Tracking0

No advertising networks, visitor analytics or remotely loaded web fonts.

05

Retention and deletion

  • Account and active game state: kept while the game account exists and the data is needed to provide its requested progression.
  • Catch and transaction history: kept while needed for ownership, records, rankings and economy integrity. On a valid deletion request, identifying links are deleted or anonymised unless a legal obligation or overriding reason requires limited retention.
  • Game events and admin audits: kept only as long as needed for security, support and traceability; personal links are reduced where they are no longer necessary.
  • Redis state: short-lived locks, cooldowns and cache entries expire or are replaced; Redis is not used as permanent game storage.
  • Web and container logs: retained until rotation or until the relevant error or security investigation is complete.
  • Browser profile choice: stays in your browser until you replace it or clear the site's local storage.

06

Recipients and transfers

The bot communicates through Discord, so Discord receives interactions and bot responses under its own terms. The website, database, cache and supporting infrastructure are hosted by the provider named below. As a processor, the provider may process request metadata, technical logs, Discord account references and game data stored on the hosted systems on our behalf.

Hosting provider
netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany; processor for hosting and infrastructure services
Other recipients
No advertising, analytics or data-broker services. Data is disclosed only to necessary service providers, where legally required, or when you explicitly direct it.

Discord may process data outside the EEA. Details about its responsible entities and transfer safeguards are available in the Discord Privacy Policy. Any hosting transfer outside the EEA must use an applicable GDPR transfer mechanism.

07

Your rights and requests

Depending on the applicable conditions, you may request access, correction, deletion, restriction and portability, and object to processing based on legitimate interests. Send the request to privacy@cozyfish.ing and include your Discord user ID. We may ask you to confirm control of that Discord account before disclosing or changing data.

Deletion requests cover the API data and identifying game data Cozy Fishing controls. Discord account data controlled by Discord must be requested from Discord separately. You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement.

08

Security and changes

Public production traffic must use HTTPS. Database and cache services remain inside the application network. Administrative functions are access-controlled, technical logs are separated from game events, and credentials and tokens are not committed to the repository.

This notice is updated when data categories, purposes, providers or public features change. The current date appears at the top.

Reference texts

EU General Data Protection Regulation
Discord Developer Terms — User Privacy and Security
Discord Developer Policy — Handle Data with Care

CFCozy Fishing

This is a pixel companion for a cozy Discord fishing game.

ExploreGame wikiChangelogRankingsPlayer finderArt credits
TrustTerms of ServicePrivacy noticeImprintNo ads · no trackers

© 2026 Cozy Fishing · Gameplay lives in Discord.