Bright
Privacy Policy for Bright
This is a courtesy translation. The German version is legally binding.
In short: Bright collects nothing about you. There is no account, no analytics, no advertising, no tracking and no cookie banner — because there are no cookies to consent to. The rules engine and the opponent both run entirely in your browser.
This policy covers the game Bright by Deari Software, available at bright.deari.de and as an app for Android and Windows. Our company website is covered by the website privacy policy. Provider details are in the imprint. The product page: Bright.
1. Controller
Deari Software
Festim Deari
Friedrich-Ebert-Straße 55
42103 Wuppertal
Germany
Email: kontakt@deari.de
2. What data the game processes
None. Bright requires no registration, asks for neither a name nor an email address, and creates no identifier by which you could be recognised.
3. Storage on your device
The game writes a single entry to your browser's local storage (on Android and Windows, to the app's own settings). That entry holds:
- which rules you have already used in play,
- which training drills you have solved,
- how much help you want the board to give you.
None of it ever leaves your device. It is not transmitted to us, not synced between your devices, and not visible to us. Technically this is local storage rather than a cookie; as the storage is strictly necessary for a function you explicitly asked for (remembering your progress), it requires no consent under § 25 (2) no. 2 TDDDG.
Clearing site data for this site, or uninstalling the app, erases the entry. The game then starts again from the beginning, with no other effect.
4. The game transmits nothing
Once the page has loaded, Bright makes no further network requests. The rules and the computer opponent are computed in your browser, not on a server. The game works completely without an internet connection.
5. Hosting
The site is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA. Like every web server, Netlify logs the requests it serves. Those server logs typically contain the IP address, date and time, the file requested, the referrer and the user agent. They serve secure and reliable operation and are deleted after a short period.
The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in delivering the service securely and reliably. Netlify is a processor under Art. 28 GDPR; transfers to the USA rest on the EU Standard Contractual Clauses and Netlify's certification under the EU-U.S. Data Privacy Framework.
6. No third parties inside the game
Bright embeds no external fonts, no map services, no ad networks, no analytics tools and no social plug-ins. Every file it needs is served from the same origin as the game itself.
7. SSL/TLS encryption
Transmission is encrypted (HTTPS). You can recognise an encrypted connection by the “https://” prefix in the address bar.
8. Your rights
As a data subject, you have the following rights:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection (Art. 21 GDPR)
- lodging a complaint with a supervisory authority (Art. 77 GDPR)
To exercise these rights, write to kontakt@deari.de. The competent supervisory authority for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.
Because the game stores no personal data of yours, there is in practice nothing for us to hand over or delete beyond the host's server logs.
9. Children
Bright is suitable for any age and collects no data, so it needs no age gate and asks for no consent.
10. Changes to this privacy policy
Last updated: September 2026. Should Bright gain online play against other people, this policy will be updated before that feature ships and will say plainly what has changed. The current version is always available at this address and inside the game.