gene

privacy

last updated 2026-09-01

This covers gene.dev and platform.gene.dev. The controller is me, Gene, in Finland, at [email protected]. A product with its own users has its own policy, linked from its project page; GenMail is the first.

gene.dev

Static pages. No analytics, no tracking, no third-party embeds, no cookies of its own. Two scripts load: nav.js, which reads the gene_signed_in cookie described below and changes one word in the navigation, and a Cloudflare script that decodes the email address on the page. Cloudflare keeps standard request logs, including IP address, for delivery and abuse prevention.

platform.gene.dev

Creating an account stores:

  • your email address and a display name. Clerk handles sign-in and holds this record. Signing in through a third party gives Clerk what that provider releases.
  • entitlements: which products the account can use, keys claimed, and tokens issued.
  • two cookies. A signed session cookie on platform.gene.dev keeps you logged in. gene_signed_in, on .gene.dev, holds a yes/no flag and no identifier, so gene.dev can show "account" instead of "sign in". Both are necessary for the service, so neither needs a consent banner.
  • request logs, kept short-term for debugging and abuse prevention.

A game server you register in the public directory is public. No advertising, no profiling, no automated decisions. Nothing is sold or shared for marketing.

legal basis

Account data: the contract you enter by creating an account. Logs and abuse prevention: legitimate interest in keeping the services running and secure.

processors

processorwhat for
CloudflareServes gene.dev, DNS, artifact storage (R2)
Fly.ioRuns platform.gene.dev and its database, in Frankfurt
ClerkSign-in, and the identity record
PurelymailMail for @gene.dev addresses

Some operate outside the EU/EEA and transfer data under standard contractual clauses or an equivalent mechanism.

retention

Account data is kept while the account exists. Requesting deletion starts a 7-day hold you can cancel from the dashboard. After it, the account and its keys are removed, except what the law requires me to keep. Logs are short-lived.

your rights

Under the GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to processing, and receive it in a portable form. Email [email protected] and I answer within a month. You can also complain to your national data protection authority. In Finland that is the Data Protection Ombudsman.

children

Not aimed at children under 13. Do not create accounts for them.

changes

The date at the top is the version in force. Changes that affect account holders are announced on the platform.