Skip to content

Legal · Privacy

Privacy Policy

We make games, not data products. This page explains exactly what we collect when you play or visit, why, where it lives and how to make us delete it.

Last updated 3 October 2026 8 min read

The short version: you can play our games without an account, and when you do, your progress stays in your own browser. If you make an account, we store your name, email, a hashed password and your cloud saves so you can carry on from any computer. We don't run ads, we don't use third-party analytics, and we never sell or rent personal data. Ever.

1. Who we are

Solo Frogs Ltd (“Solo Frogs”, “we”, “us”) is an independent game studio registered in England & Wales. We operate solofrogs.com and the games playable on it, including HUM. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Solo Frogs Ltd is the controller of the personal data described here.

You can reach us about anything in this policy at privacy@solofrogs.com. Because we're a small studio we haven't appointed a formal Data Protection Officer, but every privacy message is read by a director.

2. What we collect

When you just visit or play

  • Local game saves. Your HUM progress, settings (volume, sensitivity, subtitles, graphics) and checkpoints are stored in your browser's localStorage. They never leave your device unless you sign in and choose to sync.
  • Essential cookies. A session cookie and a security token (XSRF-TOKEN) that keep forms safe and let you stay signed in. See our Cookie Policy.
  • Server logs. Like every website, our servers briefly record technical request data — IP address, browser type, the page requested and the time — to keep the service secure and working. These are kept for no more than 30 days.

When you create an account

  • Account details: the display name and email address you give us, and your password stored only as a one-way hash (we can't read it).
  • Cloud saves: the save slots you sync from our games — level, checkpoint, inventory, playtime and the name you gave your wanderer — plus timestamps so we can show you the newest one.

When you contact us

  • Your name, email, the topic, which game (if any) and your message. We also keep a salted hash of your IP address and your browser's user-agent string, purely to stop spam and abuse.

When you join our mailing list

  • Your email address, the page you signed up from and when. That's all — no tracking pixels or open-rate tracking in our emails.

We do not knowingly collect special category data, and we don't ask for your age, location, phone number or payment details. Our games are currently free; if that ever changes, payments will be handled by a dedicated processor and this policy will be updated first.

3. Why we use it, and our lawful basis

PurposeDataLawful basis (UK GDPR Art. 6)
Running your account and syncing your savesAccount details, cloud savesContract — it's the service you asked for
Keeping the site secure, preventing abuse and fraudServer logs, cookies, IP hashLegitimate interests
Answering your support, press or business messagesContact messagesLegitimate interests
Essential service emails (password resets, account notices)Email addressContract
Sending our opt-in newsletter (launches, playtests, devlogs)Email address, sign-up pageConsent — withdraw any time
Meeting legal obligations, responding to lawful requestsAny relevant dataLegal obligation

The only marketing email we send is our newsletter, and only if you've asked for it by entering your email in a “Join the pond” form. Every email has an unsubscribe link, or email privacy@solofrogs.com and we'll remove you.

4. Where your data lives

Our website and database run on DigitalOcean infrastructure. Accounts and cloud saves are stored in a managed PostgreSQL database in DigitalOcean data centres, encrypted in transit (TLS) and at rest. DigitalOcean acts as our processor under a data processing agreement.

Where any provider processes data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Agreement / Addendum to protect it.

5. Who we share it with

Only the providers we need to run the service, and only what they need:

  • DigitalOcean — hosting and database.
  • Google Fonts — our pages load typefaces from Google's servers, which means your browser sends Google your IP address and user-agent when fetching them. Google states that it does not use this data to profile you.
  • Our email provider — to deliver password-reset and account emails.
  • Professional advisers or authorities — only when the law requires it, or to protect our players and the studio from serious harm.

We never sell, rent or trade personal data, and we don't share it with advertisers or data brokers.

6. How long we keep it

DataKept for
Account & cloud savesUntil you delete your account (you can do this yourself any time from your account page — it removes every save immediately), or after 3 years of total inactivity (we'll email you first)
Newsletter subscriptionUntil you unsubscribe; we then keep only a suppression record so we never email you again
Contact messages24 months after the conversation ends
Server logsUp to 30 days
Local saves in your browserUntil you clear them — they're on your device, not ours

7. Your rights

Under UK data protection law you have the right to:

  • Access the personal data we hold about you;
  • Correct anything that's wrong;
  • Erase your data (“right to be forgotten”) — deleting your account removes your cloud saves too;
  • Restrict or object to processing based on legitimate interests;
  • Portability — get your saves and account data in a machine-readable format;
  • Withdraw any consent you've given, at any time.

Email privacy@solofrogs.com from the address on your account and we'll respond within one month. It's free, unless a request is clearly unfounded or excessive.

8. Children

Our site is not directed at children under 13, and we don't knowingly create accounts for them. Some of our games — HUM in particular — are horror games we recommend for players aged 16 and over. If you believe a child has given us personal data, contact us and we'll delete it.

9. Security

We use TLS everywhere, hash passwords with bcrypt, keep database access restricted to the people and systems that need it, and keep our software patched. No system is perfectly secure; if we ever suffer a breach that puts your rights at risk, we'll tell you and the ICO as the law requires.

10. Complaints

If you're unhappy with how we've handled your data, please tell us first so we can put it right. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint or on 0303 123 1113.

11. Changes to this policy

If we change how we use your data we'll update this page and the date at the top. For significant changes affecting account holders, we'll also let you know by email before they take effect.