Privacy Policy
Last updated · 21 September 2026
English translation. The German original is legally binding.
1. Controller
This privacy policy covers middiff.gg, the middiff web app and the associated account and product services. The controller is BlueBottle GmbH, Rübezahlweg 8A, 83052 Bruckmühl, Germany (see Legal Notice). Contact: contact@bluebottle.gg.
2. What we process
Account data: email address, internal account and sign-in identifiers, sign-in provider, and creation and update timestamps. Sign-in is available through Google or with an email address and password. For email sign-in, the password is sent over an encrypted connection to our account service and forwarded to Amazon Cognito without being logged or stored by BlueBottle; Amazon Cognito manages the credentials.
Product data: linked Riot accounts with Riot ID, player identifier (PUUID), platform and game profile, game and replay data, analysis results, coaching answers, feedback, sharing links and device pairings. We process these data to analyse games and provide the coaching and sharing features you use. They come from your use of the product and connected game services, not your Google account. Other people can access shared game and report data through a sharing link you create.
Subscription and transaction data: product, plan, billing status and Paddle customer, transaction and subscription identifiers; we do not store full card details. Operational and security data: time, request path, status code, bytes transferred, referrer, user agent, IP address, account or Cognito identifier and technical error data where generated in web-server, API or function logs.
2a. Google sign-in: access and use
When you choose “Sign in with Google”, authentication takes place through Google and our identity service, Amazon Cognito. We request the openid, email and profile permissions. These cover your identity, email address and basic profile information, such as your name and profile picture, which Google may provide to the authentication service. middiff reads the email address and a stable account identifier (sub) from the identity token issued by Cognito; the middiff application does not currently use your name or profile picture.
We use the email address and account identifier to authenticate you, create an account or link you to an existing BlueBottle account with the same email address, maintain your session, and provide access to your account data and subscribed features. We store your email address, internal account identifier, mapping to the Cognito identifier, Google as the sign-in provider, and account timestamps.
This sign-in does not give middiff access to your Google password, Gmail messages, Google Drive files, calendars or contacts. Google sign-in is optional; you can instead use an account with an email address and password.
Google sign-in data are not sold or used for personalised advertising. Amazon Cognito processes authentication; middiff services store the account and session data they need as described in section 7. When you make a purchase, your account email address, including one obtained from Google, and your internal account identifier are shared with Paddle to associate the payment with you. Usage analytics may use the internal middiff account identifier; your Google email address, name and profile picture are not sent as analytics fields.
2b. Limited use of Google user data
middiff uses and transfers Google user data only for the user-facing functions described in this policy and in accordance with the Google API Services User Data Policy, including its Limited Use requirements. We do not use or transfer these data for data brokerage, creditworthiness assessments or personalised advertising, or to develop, improve or train general-purpose or non-personalised AI or machine-learning models. middiff does not access Google Workspace APIs; our game analyses do not use data obtained through Google sign-in as model inputs.
2c. Sessions and protection of your data
We use encrypted HTTPS connections for sign-in. Your browser receives a technically necessary session cookie (bb_session), which is sent only over secure connections in production and cannot be accessed by JavaScript (Secure and HttpOnly). A short-lived cookie (bb_oauth, up to ten minutes) protects the sign-in process.
On the server, we store a hash of the session identifier together with the associated account and Cognito identifiers, email address, sign-in provider and session timestamps. A refresh token issued by Cognito is stored encrypted on the server to maintain authentication. This is a Cognito token; the middiff application does not receive Google access or Google refresh tokens. These tokens are not passed to the browser.
3. Optional product analytics
Our desktop products use an analytics service operated by BlueBottle on Hetzner infrastructure in Germany to understand feature usage and improve the products. Pseudonymous usage and session identifiers are used. We do not use third-party analytics, advertising or tracking services on the public websites.
Optional usage-data collection can be disabled under “Usage data” in the relevant product. The setting does not cover necessary account and security processing, technical server logs or the separate error diagnostics in section 4. We do not use cookies for product analytics.
4. Error diagnostics
Release builds of the desktop products may send technical reports about unhandled crashes to our AWS storage in Frankfurt. This error diagnosis can include a limited extract of the local product log and operates separately from usage analytics.
5. Legal bases (Art. 6 GDPR)
Performance of a contract (Art. 6(1)(b)) for accounts and authentication including Google sign-in, product features, subscriptions, purchases and downloads. Legitimate interests (Art. 6(1)(f)) for operational security, error diagnosis, abuse prevention and improving the product through usage analytics, unless your competing interests or rights override those interests. Consent (Art. 6(1)(a)) where legally required.
6. Payments — Paddle
Purchases are handled by Paddle.com Market Ltd as Merchant of Record. We share your account email address and internal account identifier to associate the customer and checkout with you. Paddle processes your billing and payment data under its own privacy policy and acts as an independent controller for payment processing and tax.
7. Hosting, recipients and transfers
The middiff website, API, product database, session data and self-hosted analytics service run on Hetzner infrastructure in Germany. Identity and account services use Amazon Web Services in the EU (Frankfurt region, eu-central-1), particularly Amazon Cognito and DynamoDB; download and crash storage also use AWS.
If you select Google sign-in, Google processes authentication and provides the authorised identity information to Amazon Cognito. Google also processes data under its own privacy policy. Paddle receives purchase-related data as described in section 6. Disclosure may also be necessary to comply with legal obligations or lawful requests from authorities. Where a recipient processes data outside the EU/EEA, its privacy information and appropriate safeguards such as EU Standard Contractual Clauses apply.
8. Your rights, deletion and Google connection
You have the right to access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time with effect for the future. To exercise these rights or request deletion of your middiff account and associated personal data, including data obtained through Google sign-in, email contact@bluebottle.gg and identify the account email address. We may ask you to verify that you own the account. Statutory retention duties and legitimate grounds for limited further storage remain applicable.
You can remove the middiff connection in your Google Account under connections to third-party apps and services. Google explains this at https://support.google.com/accounts/answer/13533235. Removing the connection does not automatically delete your middiff account or previously stored data, and does not necessarily end an existing middiff session. Also sign out of middiff and send us a deletion request if you want your account data erased.
9. Right to complain
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence, place of work or place of the alleged infringement.
10. Retention
Account data, including the email address and identity mapping obtained through Google sign-in, are kept for as long as needed for your account and the provision of services. Account, product, subscription, transaction and operational data are deleted when their purpose ends unless commercial, tax or other statutory retention duties or legitimate grounds require further storage. Account deletion does not automatically remove shared game and analysis data; we review remaining personal associations as part of your deletion request.
A middiff session becomes invalid after 14 days of inactivity or at most 30 days after creation. Signing out deletes the current server-side session, including its stored Cognito refresh token. Expired session records are cleaned up when accessed again; expiry is not a guaranteed automatic physical deletion deadline.
Usage events are retained server-side for up to 400 days. Technical identity mappings, function logs and crash reports currently do not share one fixed automatic deletion period. Erasure requests can be sent to contact@bluebottle.gg.
11. Changes to this privacy policy
We keep this privacy policy current and identify revisions by the update date above. If we change how middiff accesses, uses, stores or shares Google user data, we will notify affected users by email or a prominent in-app notice before the change takes effect. Where required, we will obtain renewed consent before the changed processing begins.