Privacy
How the Roma Design sign-in service handles your data. Last updated 13 September 2026.
Roma Design runs a small number of hobby games — Prophet, Globalization and others — at romadesign.no. This service, at auth.romadesign.no, does one job: it establishes who you are so those games can recognise you. It is not a commercial product, and nothing here is sold, shared or used for advertising.
Who is responsible
Roma Design is the data controller. Reach us at kontakt@romadesign.no.
What is stored
When you create an account, this service stores:
- your username, first name and last name
- your email address
- a cryptographic hash of your password — never the password itself
- the time the account was created, and counters used to lock the account after repeated failed sign-in attempts
If you sign in with Google, we additionally store the account identifier Google gives us, so we can recognise you next time. Google also tells us your email address, whether Google has verified it, and your first and last name, which we use to fill in your profile. We do not receive or store your Google password, and we do not keep any Google access token — we ask Google who you are once, at sign-in, and then discard the connection.
Each game keeps its own separate records — your predictions, leagues, scores and so on — linked to an identifier issued by this service. Those live with the game, not here.
Cookies
Only cookies that are strictly necessary to sign you in. There is no analytics, no advertising, and no third-party tracking of any kind:
- a session cookie that keeps you signed in, encrypted and readable only by the server
- a short-lived cookie that protects sign-in forms against cross-site request forgery
- a routing cookie set by Microsoft Azure to keep your requests on one server
Where it is kept
The service runs on Microsoft Azure in Norway, and account data is stored in MongoDB Atlas. Both act as processors on our behalf. Server logs — which include IP addresses and request times — are retained by Azure for a short period and used only to diagnose faults and abuse.
How long
Your account is kept for as long as you use it. Ask us to delete it and we will, along with the game records attached to it. One-time sign-in codes are deleted the moment they are used, and in any case expire after sixty seconds.
Your rights
Under the GDPR you may ask for a copy of your data, have it corrected, have it deleted, or object to how it is used. Email kontakt@romadesign.no and we will deal with it. If you are unhappy with the response you can complain to the Norwegian Data Protection Authority, Datatilsynet.
Changes
If this policy changes, the date at the top changes with it. Anything that materially affects how your data is handled will be flagged when you next sign in.