Privacy at a glance
- We collect only the data needed to run Uzora.
- Your profile and gaming content are public by default, but sensitive data is never public.
- You can sign in via magic link or connect third-party accounts (Google, Steam, Xbox, Discord).
- OAuth connections are optional and permission-based; passwords are never stored.
- We do not sell your data and do not track you for advertising.
- Analytics and cookies are used only with your consent.
- You can access, delete, or correct your data at any time.
- Your data is processed and stored in the EU.
This Privacy Policy explains how Uzora (“Uzora”, “we”, “us”) collects, uses, and protects personal data when you use the website xcore.gg and related services (the “Platform”).
This policy is drafted in accordance with Regulation (EU) 2016/679 (GDPR) and applies to users worldwide.
Your use of the Platform is also governed by the Terms and Conditions.
Uzora is the current brand of the platform. The operator remains XCORE.GG.
1. Data Controller
Controller: XCORE.GG
Location: Vienna, Austria
Contact email: support@xcore.gg
Data Protection Officer (DPO): CTO (support@xcore.gg)
2. Who This Policy Applies To
The Platform is intended for users aged 13 or older. Users under the age of majority must have permission from a parent or legal guardian.
Uzora does not actively verify user age and does not knowingly target minors.
3. Categories of Personal Data
3.1 Account & Identification Data
- Email address (magic-link authentication)
- OAuth provider user ID and display name
Email addresses provided for magic-link authentication are obfuscated during transmission. The email address of the created account is stored encrypted with AES-GCM-256.
3.2 Profile & Social Data (Optional)
- Username / display name
- Avatar or profile image
- Connected gaming accounts
- Games played and related metadata
- Game highlights and uploaded images
- Genres, platforms, and device preferences
- Connections, connection requests, and reactions
3.3 OAuth & Imported Third-Party Data
- Google: user ID, email
- Google Play Game Services: user ID, username, avatar, friends, games, achievements
- Steam: user ID, username, avatar, friends, games, achievements
- Xbox (Microsoft): user ID, username, avatar, friends, games, achievements
- PlayStation (PSN): data import only (no authentication)
- Discord: user ID, username, avatar
Upon revocation of Steam access, Steam-derived data may be removed or no longer updated.
Uzora's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Uzora does not control and is not responsible for the availability, accuracy, or continued access to data provided by Discord services.
Discord is a trademark of Discord Inc. This application is not affiliated with or endorsed by Discord Inc.
4. Public Information
User profiles and content are public by default. Private or sensitive data (such as email addresses or authentication identifiers) is never made public.
Future controls may allow users to hide selected profile elements.
5. Purposes and Legal Bases
- Account creation & platform use: performance of a contract
- Profile display & social features: user consent
- OAuth connections & data import: user consent
- Emails (magic link): performance of a contract
- Analytics & cookies: user consent
- Security & logging: legitimate interest
7. Emails & Communications
By providing your email address, you consent to receive transactional and service-related emails (e.g., authentication links, notifications). You may withdraw consent at any time through in-app settings.
Currently, Uzora only sends transactional emails (magic-link authentication), which are sent only after the user specifically provides their email address and requests authentication.
Marketing or product emails, if introduced, will require explicit opt-in and will always include an unsubscribe option.
We monitor email delivery and respect bounce and complaint feedback. If your address generates multiple bounces or complaints, we may suspend or modify email delivery.
7.1 Email delivery and abuse prevention
We process technical information related to email delivery, such as delivery failures (bounces) and abuse or spam complaints, in order to maintain the reliability of our communications, prevent misuse of our services, and comply with the requirements of our email service providers.
Email addresses that repeatedly fail delivery or generate abuse complaints may be automatically suppressed from further communications.
8. Logging & Monitoring
Technical logs (session identifiers, timestamps, errors) are collected solely for security and debugging purposes.
- No IP or device fingerprint tracking
- Logs retained for 30 days
- Error monitoring via Sentry
9. Data Sharing & Processors
Personal data may be processed by the following providers:
- Hosting & infrastructure: Vercel, Scalingo (EU)
- Database: Scalingo (EU)
- Email delivery: MailGun (EU configuration)
- Analytics: Google Analytics (EU configuration)
- Media storage: Amazon S3 (EU)
No data is transferred outside the European Union.
10. Data Retention
- Account data: retained until deletion is requested
- Account deletion: immediate
- Logs: 30 days
- Backups: 30 days
11. User Rights (GDPR)
Users have the right to:
- Access their data
- Rectification
- Erasure
- Restriction of processing
- Objection
Requests can be made via email or future in-app tools and will be handled within 30 days.
12. Automated Processing
The Platform may introduce recommendations, matching, rankings, or leaderboards. These features do not produce legal or similarly significant effects.
13. Security Measures
- Encryption in transit and at rest
- Strict access controls
- Role separation
- Incident response and breach notification procedures
14. Changes to This Policy
Changes to this Privacy Policy will be communicated via in-app notice and published on xcore.gg.