Privacy policy

Last updated 9 September 2026 · Ensigner Tech, Poland · hello@openlifesim.com

The short version

1. Who is asking

OpenLifeSim is made and run by Ensigner Tech, a company registered in Poland (registered office: [registered address]). Under the GDPR we are the controller of everything described below. Write to hello@openlifesim.com — it is a person, not a queue.

2. Playing without an account

This is how most people play, and it is the whole answer for them: nothing is collected. The game runs in your browser. Your character, your saves and your settings are written to your browser's own storage on your own device and are never sent anywhere.

If you are curious what is in there: ols.saves.v2 (the shelf of lives), one ols.save.v2.* entry per life, ols.pass.v1 (what the account has paid for, if anything) and ols.skin.v1 (which colour scheme you picked). Clearing your browser's site data deletes them, and us with them.

3. If you sign in

Signing in exists so a life can follow you between devices. We never handle a password — you sign in through Google, Discord or CrazyGames, and they tell us who you are. From them we keep:

That, plus the date the account was created and what it has paid for, is the account. Legal basis: performing the contract you asked for by signing in.

Cloud saves

With the full version, a signed-in life is also stored on our servers: a compressed copy of the save itself, and a short summary — the character's name, age, money and year — so the shelf can list your lives without downloading all of them. Names in a save are names you typed. We do not read them, and nothing in the game asks for your real one.

Things that are public because you chose it

Two features publish something on purpose, and only if you use them. Sharing a life creates a link; anybody holding that link can see and fork that character's snapshot until you delete it. A patron name is a name supporters may opt into having shown in the credits and as a character in other people's games — it is whatever you type, so type what you are happy to see in public.

4. Paying

Payments run through Stripe. Card details are entered on Stripe's own checkout and never touch our servers. What we store is the receipt: the tier you bought, the amount and currency, the time, and Stripe's own ids for the payment and the customer.

Legal basis: performing the contract, and a legal obligation to keep accounting records afterwards.

5. Bug reports

When you send a bug report, the game attaches your entire save to it, along with the game version and the platform you were on. That is deliberate: a bug that cannot be reproduced cannot be fixed. It means the report contains everything that was in your game, the names you typed included.

You can file one without signing in, in which case there is nothing tying it to you. Every report deletes itself 180 days after it is filed.

One honest limitation: there is no index from an account to the reports it filed, on purpose — building one would mean keeping a second pointer to a save you may later ask us to forget. So deleting your account does not reach your reports, and the 180-day expiry is how they go. If you need one gone sooner, tell us roughly when you filed it and what it said, and we will find it.

Legal basis: our legitimate interest in a game that works.

6. The waitlist

If you typed your email into the waitlist box that was on the front page before launch, we keep that address and the date, and use it to send you one message when the game launches. Nothing else, ever, and it goes to nobody else. Legal basis: your consent, which you withdraw by asking us to remove it.

7. The devlog

Reactions and comments

The like/dislike buttons under a post store your vote, your comment if you wrote one, and a random id your own browser generated and keeps — that id is only there so changing your mind replaces your vote instead of adding a second one. We do not log your IP address against it and we do not derive anything from it. This replaced an older scheme that hashed your address and browser together; a hash like that can still be checked against a guess, which is more than a like button has any business knowing.

Counting visits

The site uses GoatCounter, which is cookieless and collects no personal data — just that a page was viewed. That is also why you are not being asked to click a cookie banner: there is no tracking cookie to consent to.

Server logs

Like every web server, our CDN writes an access log: the IP address a request came from, the browser string, the page asked for, the time, and the referring page. We use it to keep the site up and to count visitors in aggregate. Logs are deleted after one year. Legal basis: our legitimate interest in running and securing the service.

8. Where it lives, and who else sees it

Accounts, saves and purchase records are held on Amazon Web Services in Frankfurt, Germany (eu-central-1). The CDN's access logs are held on AWS in the United States, which is a transfer outside the EEA made under the European Commission's standard contractual clauses.

We do not sell or share anything for marketing. These are the only other companies that touch any of it, each doing one job:

If you reached the game through a storefront such as itch.io or CrazyGames, that site is running its own page around ours and has its own privacy policy, which we do not control.

9. How long anything is kept

WhatHow long
Saves in your own browserUntil you clear your browser's site data. We cannot see or delete them.
Account, identities, cloud savesUntil you ask us to delete them, or the account is dormant for three years.
A shared lifeUntil you delete the share or the account.
Purchase recordsFive years after the end of the tax year, as Polish accounting law requires.
Bug reports180 days from filing, automatically.
Waitlist addressUntil the launch email is sent, or until you ask us to remove it.
Devlog reactionsKept while the post is up. There is nothing in them that identifies you.
CDN access logsOne year.

10. Your rights, and how to use them

You have the right to see what we hold about you, to have it corrected, to have it deleted, to restrict or object to what we do with it, to take it elsewhere in a portable form, and to withdraw any consent you gave. One message to hello@openlifesim.com is enough for any of them, and we answer within 30 days.

Deleting your account

You do this yourself, from inside the game: the start screen's account corner has a Delete account button under your name. It shows you this list first and asks you to confirm, and when it is done it tells you exactly what went. If you would rather we ran it, ask.

What it does, exactly:

For the technically inclined, the button is a DELETE /me on our API and it answers with a receipt of exactly what went and what stayed. Deleting the account does not refund a purchase and does not touch the saves in your own browser — those are yours and always were.

If you think we have handled your data badly, please tell us first — and you can complain to the Polish supervisory authority, the Urząd Ochrony Danych Osobowych (uodo.gov.pl), or to the authority where you live.

11. Age

The game is free to play at any age, but you must be 16 or older to create an account, to buy anything, or to send us your email address. We do not knowingly keep data about anybody younger. If a child has signed in, write to us and we will delete the account without asking for anything else.

12. Cookies

We set no advertising or tracking cookies, and there is nothing here to consent to. Signing in keeps a token in your browser's storage so you are not asked to sign in every time you open the game; the game keeps your saves and your settings there too. That is storage on your device for a thing you asked for, and signing out clears the token.

13. When this changes

If we change what we collect, this page changes with it and the date at the top moves. Anything that materially affects you gets said in the devlog as well, rather than quietly edited in.