Privacy Policy
Last updated:
This policy explains what data GAIO processes, what for, how long it is kept and how you can delete it. It is written to be understood: if anything here is unclear, write to us and we will fix it, because a policy nobody understands protects nobody.
1. Who is responsible for your data
The data controller is BIND SEO & DEVELOPMENT LLC, a company incorporated in Wyoming, United States, operating the product under the GAIO brand.
Registered address: 30 N Gould St, Ste R, Sheridan, Wyoming 82801, Estados Unidos.
For anything concerning your data — access, correction, export or deletion — write to soporte@gaio.gg.
2. What data we process
This list comes from our actual database schema, not from a template. If a table holds data about you, it is listed here.
Your account
- email address and username
- avatar, bio and any social links you add
- your GAIO tag and level
Without this there is no account: it is the minimum needed to sign you in.
Your linked accounts
- the linked platform
- your identifier and username there
- the date it was linked
This is what lets GAIO see your library and launch your games. What each platform requests is detailed below, one section per provider.
Your game library
- which games you own and on which store
- hours played and last time played
- unlocked achievements and rank, where the game exposes them
- the install path on your machine
Your Arsenal, the Play button and recommendations come from here. The install path is stored so the game can be launched; it is never shared.
Your status
- whether you are online, away or offline
- what you are playing right now
So your friends know whether they can invite you. You can appear offline from the app itself.
Your devices
- an identifier derived from your machine, which cannot reconstruct its serial number
- the machine name, Windows version and GAIO version
- when it was last seen
So you can see where your account is open and sign out a machine you no longer use. It is a security measure, not profiling.
3. Telemetry: only with your permission
Three groups of data are not collected unless you turn them on. They are performance and network measurements, and they exist so the Optimizer and Radar can do their job.
Your hardware
- CPU and GPU model
- system RAM and video memory
The Optimizer needs to know what you play on to recommend settings your machine can actually sustain.
Your play sessions
- session length and when it happened
- average frames per second
- peak temperature reached
- average CPU, GPU, RAM and video memory usage
This is what turns «it runs badly» into data: without measuring performance it cannot be improved, nor can your per-game statistics be shown.
Your connection, when you use Radar
- latency, jitter and packet loss against each measured node
Radar compares routes to tell you which one suits you. Without measuring them there is nothing to compare.
Legal basis: your explicit consent. You can withdraw it at any time from Settings, without giving reasons and without losing access to the rest of the product. Once withdrawn we stop collecting this data, and you can ask us to delete what was already collected. This data is not sold, is not shared with advertisers and is not used to train artificial intelligence models.
4. Your linked accounts, platform by platform
Linking an account is always your decision and always reversible. Each section states which permissions we request, what specific data we store, what for, for how long and how it is deleted.
Steam OpenID 2.0
- Permissions we request
- None. GAIO requests no additional permissions from this provider.
- What we store
-
- your Steam identifier (SteamID64)
- your game library and its installation state
- hours played per game
- unlocked achievements, where the game exposes them
- What we use it for
- Build your Arsenal, know which games you already own so we don't recommend them, and compute recommendations from what you actually play.
- How long we keep it
- For as long as the Steam account stays linked. Unlinking deletes the identifier and the library data tied to that link.
- How it is deleted
- Unlink the account from Settings → Connected accounts and the associated data is deleted immediately. Deleting your GAIO account removes it along with everything else, after the 14-day grace period.
Steam uses OpenID 2.0, not OAuth: GAIO never sees your password and never receives a token that could act on your behalf. It only obtains your public identifier.
Discord OAuth 2.0
- Permissions we request
-
-
identify -
sdk.social_layer
-
- What we store
-
- your Discord user ID and username
- your avatar
- the access and refresh tokens required by GAIO Voice
- What we use it for
- Show your Discord identity on your profile, let your friends find you, and enable GAIO Voice rooms through the Discord SDK social layer.
- How long we keep it
- For as long as the account stays linked. Tokens are refreshed and discarded when they expire or when you unlink the account.
- How it is deleted
- Unlink the account from Settings → Connected accounts and the associated data is deleted immediately. Deleting your GAIO account removes it along with everything else, after the 14-day grace period.
The `identify` scope grants no access to your email, your servers or your messages. GAIO does not read Discord conversations.
Twitch OAuth 2.0
- Permissions we request
- None. GAIO requests no additional permissions from this provider.
- What we store
-
- your Twitch user ID and channel name
- whether your channel is currently live, and the game shown on it
- What we use it for
- Show your channel on your profile and let your friends know when you go live, inside GAIO Live.
- How long we keep it
- The identifier and channel name, for as long as the account stays linked. Live status is ephemeral, refreshed rather than kept as history.
- How it is deleted
- Unlink the account from Settings → Connected accounts and the associated data is deleted immediately. Deleting your GAIO account removes it along with everything else, after the 14-day grace period.
GAIO requests **no scopes** from Twitch: it only uses the channel's public identity. It cannot read your email or chat, nor manage your channel.
Kick OAuth 2.0
- Permissions we request
-
-
user:read -
channel:read
-
- What we store
-
- your Kick user ID
- your channel name and status
- What we use it for
- Show your Kick channel on your profile and in GAIO Live.
- How long we keep it
- For as long as the account stays linked.
- How it is deleted
- Unlink the account from Settings → Connected accounts and the associated data is deleted immediately. Deleting your GAIO account removes it along with everything else, after the 14-day grace period.
Both scopes are read-only: `user:read` and `channel:read`. GAIO cannot post to or modify your channel.
Battle.net OAuth 2.0
- Permissions we request
-
-
openid
-
- What we store
-
- your Battle.net account identifier and BattleTag
- What we use it for
- Recognise the Blizzard games you have installed so GAIO can launch them, and show your BattleTag to your friends.
- How long we keep it
- For as long as the account stays linked.
- How it is deleted
- Unlink the account from Settings → Connected accounts and the associated data is deleted immediately. Deleting your GAIO account removes it along with everything else, after the 14-day grace period.
The `openid` scope only identifies you. It grants no access to your purchases, balance or match statistics.
Google / YouTube OAuth 2.0
- Permissions we request
-
-
https://www.googleapis.com/auth/youtube.readonly
-
- What we store
-
- your YouTube channel identifier and name
- whether your channel currently has an active live broadcast
- What we use it for
- Show your channel on your profile and let your friends know when you are streaming, inside GAIO Live. Nothing else.
- How long we keep it
- The channel identifier and name, for as long as the account stays linked. GAIO keeps no copies of your videos, their analytics or your subscribers.
- How it is deleted
- Unlink the account from Settings → Connected accounts and the associated data is deleted immediately. Deleting your GAIO account removes it along with everything else, after the 14-day grace period. You can also revoke access at any time at https://myaccount.google.com/permissions, without going through GAIO.
LIMITED USE: GAIO's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: this data is not sold, is not used for advertising, is not transferred except as needed to provide the service or as required by law, and is **not used to train artificial intelligence models**. The `youtube.readonly` scope is read-only: GAIO cannot upload, edit or delete anything on your channel.
Epic Games SDK nativo Integration pending
- Permissions we request
- None. GAIO requests no additional permissions from this provider.
- What we store
-
- your Epic account identifier and display name, once the integration is enabled
- What we use it for
- Recognise the Epic Games Store titles you have installed so GAIO can launch them.
- How long we keep it
- For as long as the account stays linked.
- How it is deleted
- Unlink the account from Settings → Connected accounts and the associated data is deleted immediately. Deleting your GAIO account removes it along with everything else, after the 14-day grace period.
INTEGRATION PENDING: registration with Epic Account Services is not approved yet, so GAIO receives no data from Epic today. This section describes what will happen once it is enabled, and is published in advance because Epic's own review requires the policy to cover it.
Riot Games OAuth 2.0 Integration pending
- Permissions we request
- None. GAIO requests no additional permissions from this provider.
- What we store
-
- your player identifier (PUUID) and Riot ID, once the integration is enabled
- the match results exposed by Riot's official API
- What we use it for
- Show your per-game statistics and feed recommendations with real matches instead of estimates.
- How long we keep it
- For as long as the account stays linked.
- How it is deleted
- Unlink the account from Settings → Connected accounts and the associated data is deleted immediately. Deleting your GAIO account removes it along with everything else, after the 14-day grace period.
INTEGRATION PENDING: GAIO does not hold Riot Games production credentials yet, so no data is received through this route today.
5. Who we share data with
We do not sell your data. We do not share it with advertisers. The only third parties that process it are the infrastructure providers we need for the product to work, acting on our behalf and under our instructions:
- Supabase — database, authentication and file storage (United States).
- Cloudflare — delivery of this website, the API and the installers (global network).
- Rackspace — domain email (United States).
We may also disclose data where legally compelled by a competent authority. If that happens and the law allows us to tell you, we will.
6. International transfers
BIND SEO & DEVELOPMENT LLC is based in the United States and so is part of its infrastructure. If you write to us from outside that country, your data is processed there. Where your country's law requires additional safeguards for that transfer, we apply them through the relevant contractual clauses with each provider.
7. How long we keep your data
For as long as you have an account. When you delete it, it enters a 14-day grace period during which you can change your mind and recover it; after that, the data is erased. The details are in how to delete your data.
Data from a linked account is deleted as soon as you unlink it, without waiting for the 14 days.
8. Your rights
- Access the data we hold about you.
- Correct anything wrong, from your profile or by writing to us.
- Export your data in a format you can read.
- Delete your account and your data.
- Withdraw telemetry consent without losing the product.
- Object to a specific processing and have us explain why it exists.
To exercise any of them write to soporte@gaio.gg. We respond within 30 days at the latest. If you believe we handled your request poorly, you can complain to your country's data protection authority.
9. Children
GAIO is not directed to children under 13 and we do not knowingly collect data from anyone below that age. If we find an account belonging to someone under 13, we delete it along with their data. If you are a parent or guardian and believe we hold data about a child in your care, write to us and we will sort it out without asking you to justify yourself.
10. Analytics on this website
This site has no analytics today. No measurement cookie is set and no third-party request is sent when you visit it.
When we add analytics, nothing will load until you explicitly accept: a banner with two buttons of equal weight, and without acceptance, zero cookies and zero requests. We will say so here and in the cookie policy before it happens, naming the specific tool and the country where it stores the data.
11. Security
Passwords are stored hashed, never in plain text. Database access is restricted by row-level policies, so a query can only return what belongs to whoever issued it. You can enable two-step verification and review which devices have your session open.
No system is invulnerable. Should a breach affect your data, we will tell you what happened, which data was affected and what we are doing about it.
12. Changes to this policy
When we change something material we will tell you inside the application before it takes effect, not in a footnote. The last update date is at the top of this page.
13. Contact
soporte@gaio.gg — the same address handles privacy, deletion requests and support. You can also reach us from the support page.