Privacy policy
Last updated: Sep 8, 2026
This is a translation. In case of doubt the German version is authoritative.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
Marco Foof
Joachim-Friedrich-Straße 25
10711 Berlin, Deutschland
E-mail: [email protected]
No data protection officer has been appointed, as the legal requirements for doing so are not met.
2. Overview
SatisfactoryBase is a planning tool for the game Satisfactory (factory planner, interactive map, wiki). You can use all tools without an account; your plans then remain exclusively in your browser (localStorage). With a voluntary, free account you can save worlds, share them and edit them with others. We process only the data required to operate the site and the features you use. Advertising and reach measurement only run if you have consented to them in our cookie settings.
3. Hosting, delivery and server logs
The application runs on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (Falkenstein data centre, Germany), including a Hetzner load balancer for TLS termination. In front of the server sits the content delivery network of Cloudflare (Cloudflare Germany GmbH, Rosental 7, 80331 Munich, on behalf of Cloudflare, Inc., USA), which provides DNS, caching, TLS and protection against attacks (WAF/DDoS). Cloudflare technically processes the IP address of every request; Cloudflare is certified under the EU-US Data Privacy Framework, and standard contractual clauses are additionally in place.
Every request processes the following data in server logs:
- the IP address of the requesting device,
- the date and time of access,
- the URL accessed, HTTP method and status code,
- the amount of data transferred, referrer URL (where sent by the browser),
- browser type/version and operating system (user agent).
Purpose: technical delivery of the site, ensuring stability and security (detecting attacks and errors). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and functioning operation). Retention period: the application logs on our server are rotated by size and are therefore typically overwritten within a few days to at most a few weeks; they are only evaluated on a case-by-case basis.
4. Database
Account data and content data (see sections 5 and 9) are stored in a PostgreSQL database at Neon, Inc. (209 Orange Street, Wilmington, DE 19801, USA). The database is located in the AWS eu-central-1 region (Frankfurt am Main, Germany); backups and restore points are kept by the provider in the same region. A data processing agreement pursuant to Art. 28 GDPR is in place with Neon; standard contractual clauses apply for any support access from the USA.
5. Registration and user account
An account is required to use worlds, saving, sharing and collaboration. When registering with e-mail and password, we process:
- e-mail address (login, verification, password reset, invitations),
- display name,
- password – exclusively as a cryptographic hash; the plain-text password is never stored,
- the time of registration and e-mail verification status,
- session data (session token, creation/expiry time, and the IP address and user agent of the login, to secure the account).
You can optionally extend your profile with a username (@name), avatar image, short bio and website. Username, display name, avatar, bio and website are publicly visible on your profile page; your e-mail address is never public.
Legal basis: Art. 6(1)(b) GDPR (performance of the account usage contract); for the session's security metadata additionally Art. 6(1)(f) GDPR. Retention period: until the account is deleted. You can delete your account yourself at any time in the account settings; this deletes your account data, your worlds and uploads. Sessions expire after 30 days at the latest.
6. Sign-in via Google and Discord
Alternatively, you can sign in using an existing Google or Discord account (OAuth 2.0). You are redirected to the respective provider's site; after your consent there, we receive from the provider:
- a provider-internal user ID,
- e-mail address and display name,
- profile picture URL (avatar),
- an access token, which we use only to confirm the sign-in.
We only request the email and profile permissions (Google) or identify/email (Discord). The provider learns that you are signing in to SatisfactoryBase; what data it processes itself is governed by its own privacy policy:
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland – policies.google.com/privacy
- Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands (for users in the EEA) / Discord Inc., 444 De Haro Street, San Francisco, CA 94107, USA – discord.com/privacy
Legal basis: Art. 6(1)(b) GDPR (providing the sign-in method you chose); the redirect to the provider happens at your own initiative (Art. 6(1)(a) GDPR). Transfers to the USA may occur with Google and Discord; both providers are certified under the EU-US Data Privacy Framework and/or use standard contractual clauses. You can unlink a connected provider account again in the account settings, provided another sign-in method remains for your account.
7. Sending e-mail
We send verification, password-reset, invitation and notification e-mails through the service provider Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). Sending happens through Resend's EU region (eu-west-1, Ireland); account administration and delivery logs (recipient address, subject, delivery status, timestamp) are held by the provider in the USA. Resend is certified under the EU-US Data Privacy Framework; a data processing agreement is in place.
If you invite other people into a world by e-mail, we store the e-mail address you entered together with the invitation token until the invitation is accepted or expires. Legal basis: Art. 6(1)(b) GDPR; for invited people Art. 6(1)(f) GDPR (the inviter's interest in collaboration).
8. Uploads (avatars, blueprints)
Uploaded files – currently avatar images, in future blueprints and screenshots – are stored in an object store (Cloudflare R2, EU jurisdiction, Cloudflare Germany GmbH / Cloudflare, Inc.) and delivered via files.satisfactorybase.com. Avatars are resized server-side on upload; metadata (e.g. EXIF data containing location) is removed in the process. Public files (avatar, the content of a public world) can be retrieved by anyone who knows the URL. The local development environment uses a MinIO store instead.
Legal basis: Art. 6(1)(b) GDPR. Retention period: until you replace or delete the file, or until the account is deleted.
9. Worlds, factories, likes and profiles (content data)
What you create in your account is stored linked to your account:
- worlds (name, seed, settings, notes), factories and plans (goals, recipes, graphs), positions and routes on the map, stations and vehicles,
- memberships in worlds (viewer/editor role) and invitations,
- likes you give or receive, and coupons derived from them,
- creation and modification timestamps.
Worlds you set to "public" are visible to every visitor, together with their factories, map and statistics; they are shown with your username and avatar and can be copied ("forked") into another user's account – the fork references your world as its origin. Only you and the members you invite can see private worlds. Legal basis: Art. 6(1)(b) GDPR. Retention period: until deleted by you or the account is deleted; other users' forks remain as their own worlds but lose the reference to you.
10. Comments and abuse reports
Comments you write on worlds, factories, blueprints or feature wishes (FactoryJin) are stored linked to your account and are visible to whoever may read that content (on public content, to every visitor). Legal basis: Art. 6(1)(b) GDPR. Retention period: until deleted by you, by the owner of the content or with the account; a deleted comment remains as an empty placeholder with its timestamp so that the replies below it do not lose their context.
If you report a comment using the "Report" function, we additionally process:
- the reason you chose and any free text you added,
- the identifier of the reported comment and an excerpt of its text,
- your user ID and displayed user name, and the time of the report.
We store this in our database (section 4) and at the same time send it as an e-mail to the operator's abuse address ([email protected]); it is sent over the same mail path described in section 7. Your e-mail address, your IP address and your browser type are not included. The author of the reported comment is not shown your report. Legal basis: Art. 6(1)(f) GDPR (interest in a lawful service free of harassment, and in meeting our obligations as a service provider). Retention period: the report record for up to 12 months after the case is closed, then deleted; the e-mail in the operator's mailbox according to its own retention.
11. Cookies and local storage
We set as few cookies as possible and no tracking cookies without your consent.
| Name | Type | Purpose | Duration | Category |
|---|---|---|---|---|
better-auth.session_token |
Cookie (HttpOnly, Secure, SameSite=Lax) | Sign-in / session of an account | 30 days, extended on use | Necessary |
sp_consent |
Cookie | Stores your cookie decision, so the server can later gate scripts accordingly | 180 days | Necessary |
sp_last_world |
Cookie | Holds the address (slug) of the world you were last active in, so that the start page can take you straight back to its map – or the value local if you chose to work without a world |
180 days | Necessary |
sp:consent:v1 |
localStorage | Your cookie decision (advertising yes/no, analytics yes/no, timestamp) | until deleted / 180 days | Necessary |
sp:* (local workspace) |
localStorage | Your local planning without an account (factories, plans), map settings (layers, seed, view), a session salt for ad placeholders (sessionStorage) | until you clear your browser data | Necessary |
Google AdSense cookies (e.g. IDE, __gads) |
Third-party cookies | Serving and measuring advertising | as set by Google, up to 13 months | Advertising – consent required |
We set necessary cookies and storage on the basis of § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act, strictly necessary for the service you requested) and Art. 6(1)(b) or (f) GDPR. For everything else, we obtain your consent via the cookie notice (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You can change your selection at any time: open cookie settings.
12. Advertising (Google AdSense)
To help finance the project, ads from Google AdSense may be shown on some pages, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). AdSense is loaded only after your consent in the cookie settings. Without consent, no Google script is embedded, no data is transmitted to Google, and the reserved area stays empty.
With your consent, your browser loads the AdSense script from Google. Google then processes, among other things, your IP address, device and browser information, the page visited and – via cookies or comparable technologies – advertising identifiers, in order to select and personalise ads, measure clicks/impressions and detect fraud. Data may be transferred to Google LLC in the USA; Google is certified under the EU-US Data Privacy Framework, and standard contractual clauses additionally apply.
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG (consent). Withdrawal: at any time with effect for the future via the cookie settings (link in the footer or "Cookies" in the app views) – no further ads will then be loaded. You can delete any Google cookies already set in your browser. Google's ad settings: adssettings.google.com; information on data use: policies.google.com/technologies/partner-sites.
Note: as long as advertising is not enabled, the page may show only neutral placeholders in the ad slots; these load no external content and process no personal data.
13. Reach measurement (Umami)
For anonymous reach measurement we use Umami (Umami Software, Inc., USA, cloud variant). Umami operates without cookies and without a persistent identifier: it records the page visited, referrer, browser type, device type, screen size, language and country (derived from the IP address, which is not stored). Identifying individual people is not intended and, to our knowledge, not possible. The Umami script is nevertheless only loaded after you allow "Analytics" in the cookie settings; without that choice, or after withdrawal, it is not loaded and no measurement takes place. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the cookie settings (section 11).
14. Error logging (Bugsink)
To detect application errors, we operate self-hosted error logging (Bugsink) on our own server at Hetzner (Falkenstein data centre, Germany, see section 3); the error data is held in our database (section 4). No external error service is used, and no data is passed on to third parties. When an error occurs, technical details (error message, affected page, browser type, timestamp, possibly an anonymised user ID) are stored. Legal basis: Art. 6(1)(f) GDPR (interest in error-free operation). Retention period: error events are automatically deleted once the configured retention period has elapsed.
15. Fonts and external content
The site uses the Chakra Petch, IBM Plex Sans and IBM Plex Mono typefaces. We deliver these font files from our own server; no connection to Google Fonts or any other third-party font service is made, and your IP address is not transmitted to anyone for this purpose.
We deliver map tiles, game icons and game data from our own servers (tiles.satisfactorybase.com) or from within the application itself; no third-party map services are loaded. Links to external sites (GitHub, Discord, data sources) lead to third-party offerings for which their own privacy policies apply.
16. Recipients and transfers to third countries
| Recipient | Purpose | Location / place of processing | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server, load balancer | Germany (Falkenstein) | DPA Art. 28 GDPR |
| Cloudflare | CDN, DNS, protection, object storage (R2) | EU/global, R2 EU jurisdiction; group USA | DPA, DPF, standard contractual clauses |
| Neon, Inc. | Database | Germany (AWS Frankfurt); group USA | DPA, standard contractual clauses |
| Resend, Inc. | E-mail sending | Sending EU (Ireland); account/logs USA | DPA, DPF |
| Google Ireland Ltd. | Sign-in (optional), AdSense (consent only) | Ireland / USA | DPF, standard contractual clauses |
| Discord | Sign-in (optional) | Netherlands / USA | DPF, standard contractual clauses |
| Umami Software, Inc. | Reach measurement (consent only, cookieless) | USA/EU | anonymous data, DPA |
Beyond this, we only pass on personal data where we are legally obliged to do so (e.g. to authorities) or where you have consented.
17. Retention period
Unless stated otherwise above, we store personal data only for as long as necessary for the respective purpose: account data and content until the account is deleted, sessions for up to 30 days, invitations until accepted or expired, server logs until rotated, database backups for up to 90 days. After account deletion, your data may still be contained in backup copies for the duration of the backup retention period; these are not used in production.
18. Your rights
You have the following rights against us regarding personal data concerning you:
- Access (Art. 15 GDPR) to the data processed,
- Rectification (Art. 16 GDPR) of inaccurate or incomplete data – you can change most account data yourself in the account settings,
- Erasure (Art. 17 GDPR) – you can delete your account yourself at any time,
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR) – on request we provide your account data and content in a machine-readable format (JSON),
- Objection (Art. 21 GDPR) to processing based on Art. 6(1)(f) GDPR, for reasons arising from your particular situation,
- Withdrawal of consent given (Art. 7(3) GDPR) at any time with effect for the future, e.g. via the cookie settings.
To exercise your rights, an e-mail to [email protected] is sufficient. Please use the e-mail address registered with us for identification.
19. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
E-mail: [email protected]
www.datenschutz-berlin.de
20. Data security
All connections to satisfactorybase.com are encrypted via TLS (HTTPS). Passwords are stored exclusively as a hash using a modern algorithm, and session cookies are HttpOnly and Secure. Access to the server and database is restricted to the operator and only occurs over encrypted connections; database backups are stored encrypted within the EU. We continuously adapt our technical and organisational measures to the state of the art.
21. No automated decision-making
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place. Coupons/likes are a purely visual element with no legal effect.
22. Children
This offering is not directed at children under 16 years of age. An account may only be created by someone who is at least 16 years old or has the consent of a parent or legal guardian.
23. Helper list
When you report a bug through the bug-report button in the app and it becomes a GitHub issue, we record against your account how many times you have done this, and credit your account with coupons for it (section 9). This count is not public by itself. The next time you log in, we ask you once whether we may show your username and profile picture on the public "Supporters & testers" page; without your consent you stay unlisted there. You can change your decision at any time in your account settings. Legal basis: Art. 6(1)(a) GDPR (consent) for showing it on the page; Art. 6(1)(b) GDPR for the count itself. Retention: until consent is withdrawn or the account is deleted.
24. Changes to this privacy policy
We update this policy whenever our processing or the legal situation changes – for example when blueprint uploads or savegame uploads go live. The version published here at any given time applies; the date at the top of this page shows when it was last updated. For material changes affecting your account, we will additionally notify you the next time you log in.