LEGAL

Privacy

The short version: there is no analytics on this site, no tracking cookie, no advertising and nothing loaded from anybody else's server. Your copy of Final Fantasy VII is read inside your own browser and never uploaded. The one place you hand over personal data deliberately is the early-access form, and you can have it deleted by asking.

This notice covers openmidgar.com and workshop.openmidgar.com, which are published by the same company and described together throughout.

Who is responsible

Controller within the meaning of Article 4(7) GDPR:

GrowForge UG (haftungsbeschränkt)Pädagogenweg 759379 SelmGermanykontakt@growforge.dev

Represented by Timur Dudhasch. The full provider identification, including the register entry, is in the Impressum. No data protection officer has been appointed; there is no obligation to appoint one at this size, and the address above reaches the people who would answer anyway.

When you only look at the site

The site is hosted on Microsoft Azure App Service in the West Europe region. Serving a page produces a server log entry — your IP address, the time, the address requested, the response code, how many bytes went back, the referring page and your browser's user agent — and the platform's own monitoring records request timings and errors alongside it.

This is used to keep the site running, find faults and defend it from abuse, and nothing else. The legal basis is Article 6(1)(f) GDPR: there is no way to operate a public service without it. Those records are kept for 30 days and then deleted automatically.

No cookie is set by looking at this site, and there is no analytics, no tag manager and no advertising network. Typefaces are served from this site's own server rather than a font service, so simply reading a page tells nobody but the host that you were here.

The character creator

The creator at /demo runs entirely in your browser. If you point it at your own install, your game archives are opened where they sit and read a piece at a time; no part of them is uploaded, copied to a server, or written back to. The models in the showcase are served from this site and need nothing from you at all.

The Workshop works the same way, and adds the same promise in the other direction: there is no code path anywhere in it that writes into a game directory.

The early-access form

What the form asks for, and why each field exists:

  • Email address. The only way to tell you a place has opened. It is also the row key, stored as a SHA-256 hash so a second application updates the first rather than leaving a copy.
  • Steam profile. As you typed it — a URL, an ID or a name. Early access is gated on owning the game, and this is how that is checked when the time comes.
  • Which copy of the game you have. So we know which install layouts have to work before you are let in.
  • Whether you have modded before. So the first people through are not all beginners or all veterans.
  • What you want to make. The useful one. It decides what gets finished first.
  • Anything you have made before, and how you heard about this. Both optional, both free text, neither required to be let in.

Legal basis. You send this so that we can consider you for access and reply to you, which is Article 6(1)(b) GDPR — steps taken at your request before a contract. So far as any part of it is not covered by that, it rests on your consent under Article 6(1)(a), which you may withdraw at any time by asking for the row to be deleted.

What is not stored. Your IP address and user agent are not saved with the application. The IP is held in the server's memory for a few minutes to enforce a per-network limit on submissions and is never written to disk. That limit exists because the form has no captcha, and it rests on Article 6(1)(f).

Where it goes. Azure Table Storage, in the same West Europe region as the site. Once a day a scheduled job reads the new applications and emails a summary to the operator through Azure Communication Services; that job runs on GitHub Actions, so what you wrote passes through GitHub's infrastructure at that moment. It goes nowhere else, and it is never sold, shared or used to build a profile.

How long. Until early access ends or you ask for it to be removed, whichever comes first. Ask and the row is deleted — you do not have to give a reason.

The contact form

/contact asks for four things: what the message is about, your email address, your name if you want to give one, and the message itself. The address is required because it is the only way to answer you; the name is optional and the form works without it.

Legal basis. Article 6(1)(f) GDPR — our legitimate interest, and yours, in answering somebody who has written to us. If your message is about becoming or being a customer, Article 6(1)(b) covers it instead.

What is not stored. The same as the form above: no IP address and no user agent are written down. Your IP is held in the server's memory for a few minutes to enforce a per-network limit, because this form has no captcha either.

Where it goes. Azure Table Storage, in the same West Europe region, in a table separate from the applications. Each message is its own row and a second message never overwrites the first. The same daily job that reports applications emails these to the operator through Azure Communication Services, and it runs on GitHub Actions — so what you wrote passes through GitHub's infrastructure at that moment.

How long. As long as the matter it is about is open, and then no longer than is needed to show what was said if it is ever questioned. Ask for it to be deleted and the row goes, unless there is a statutory reason to keep it — a message that is itself a legal notice being the obvious one.

Bugs and feedback from inside the Workshop

The Workshop, at workshop.openmidgar.com, has a “Bugs & feedback” button. Sending one stores what you typed — the kind of report, a one-line summary, what happened, optionally what you expected and how to reproduce it, and an email address if you give one — together with what the page can see about the session:

  • Your SteamID. Taken from the pass that let you through the beta gate, so a report can be tied to an account we have already approved. You do not type it and cannot get it wrong.
  • The build, the open tool, your browser and window size. Which version broke, and where.
  • Whether a game folder and a mod project are open — the file count and the project name you chose. Not the folder's path. It is usually a path with your own name in it, and no bug was ever diagnosed from one.
  • The last few errors that tab caught, with anything that looks like a file path removed before they are sent. This is the one field you did not type, so it is the one that is filtered.

The dialog lists all of it before you press send, with the real values in it rather than a description. Nothing from your copy of the game and nothing from your mod project is included — reports are text.

Legal basis. Article 6(1)(f) GDPR: our legitimate interest in finding out what is broken in software you are testing for us, and yours in it being fixed. Nothing is sent unless you fill in the form and press send.

Where it goes. The same Azure Table Storage account in West Europe. A report marked as a bug is also emailed to the operator immediately through Azure Communication Services; anything else waits for the daily digest described above. If you gave an address, it is set as the reply address on that mail so an answer reaches you.

How long. Until the bug is fixed and the beta is over. Ask and the row is deleted.

Signing in through Steam

Signing in is optional everywhere it is offered. It sends you to steamcommunity.com, where Valve authenticates you and sends you back with a claimed identity. No password ever reaches us. What comes back is your 17-digit SteamID.

We then ask Valve's Web API a single question — does this account own Final Fantasy VII (app 39140)? Valve answers that only for accounts whose game details are public, which is why a real owner with a private profile looks the same to us as somebody who does not own it.

What is kept. The SteamID itself: on the early-access list, so we can tell whether you are through, and as the name of the private storage container your projects live in. Nothing else about your Steam account is stored — not your name, not your avatar, not the rest of your library.

The session. What proves you are signed in is a short signed token carrying your SteamID and an expiry. On openmidgar.com it is held in your browser's sessionStorage and is gone when you close the tab.

Signing in also sets cookies, and these are all of them:

  • om_owner — the signed session itself, set by the service that performs the ownership check. HttpOnly, Secure, SameSite=Lax, valid for an hour at a time and renewable for up to fourteen days.
  • om_gate — on workshop.openmidgar.com only. It records that your account is on the early-access list, because that has to be known on the server before the page is drawn. Valid for six hours.

Both are strictly necessary for a service you asked for, within the meaning of § 25(2) TDDDG, which is why there is no consent banner: neither has anything to do with advertising or analytics, and nothing else sets a cookie here at all. If you never sign in, no cookie is ever set.

Valve Corporation is in the United States. Choosing the Steam route means personal data reaches them, and what happens to it there is governed by Valve's own privacy policy rather than this one. Every tool here also has a route that never touches Steam.

Projects you save

If you are signed in, a project is stored as a small JSON recipe — which parts, which colours, which values — in a private container named after your SteamID. Never a byte of the game, and never a baked mesh, because both of those rebuild from the recipe and the archives you already have.

If you are not signed in, projects live in your own browser's storage and never reach us at all. Clearing your site data clears them, which is also the only deletion needed.

Ask and a stored container is deleted. The storage account keeps deleted blobs recoverable for 7 days before they go for good, which is a safety net against mistakes rather than a copy kept on purpose.

Who else touches any of this

  • Microsoft — hosting, storage, the digest email and the platform monitoring, all in the West Europe region, as a processor under Microsoft's data protection terms.
  • GitHub — the scheduled job that composes the daily digest of new applications, contact messages and Workshop reports runs there.
  • Valve — only if you choose to sign in through Steam, and only your SteamID and the one ownership question.

Data is held in the EU. Microsoft may involve support staff outside it under the standard contractual clauses in its data protection addendum, and Valve, as above, processes in the United States.

What is never done

No analytics or tracking of any kind. No advertising, no advertising identifiers, no tracking pixels. No profiling and no automated decision-making that produces legal effects for you within the meaning of Article 22 GDPR — who gets an invitation is decided by a person reading applications. Nothing is sold, and nothing is passed to anybody for their own purposes.

Your rights

Under the GDPR you may ask for access to your data (Article 15), correction of it (16), deletion of it (17), restriction of its processing (18), a copy of it in a portable form (20), and you may object to processing based on legitimate interests (21). Where processing rests on consent, you may withdraw it at any time with effect for the future (Article 7(3)).

Email kontakt@growforge.dev and it will be done. A deletion request needs no justification.

You also have the right to complain to a data protection supervisory authority (Article 77). That may be the authority for the country you live in, the one where you work, or the one where you believe something has gone wrong. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenPostfach 20 04 4440102 DüsseldorfGermanypoststelle@ldi.nrw.dehttps://www.ldi.nrw.de

Children

This is not a service aimed at children, and the early-access form is not meant to be filled in by anybody under 16. If you believe a child has sent us something, say so and it will be deleted.

Changes

This notice describes what the software does today. When that changes, this changes with it, and the date below changes too.

Last updated 28 August 2026.