Privacy Policy
Short, because there is very little to say.
Last updated 4 August 2026
Who is responsible
The data controller is the Viridite project, an open-source project maintained by volunteers and operated from the United Kingdom. Contact: legal@aaronworld.uk, or an issue on GitHub. The project is below the threshold at which a statutory Data Protection Officer is required, and has not appointed one.
The website
No cookies are set. No local storage or session storage is used to track you. There is no analytics package, no tag manager, no advertising, no social embeds, and no fonts or scripts fetched from third-party servers.
The site is served by a hosting provider (Vercel) and some requests pass through Cloudflare. Like any web host, these process your IP address and request metadata in order to deliver the page and to protect against abuse. That processing is theirs, under their own policies; the project does not receive, store or have access to those server logs.
The software
Viridite running on your console does not phone home. It has no telemetry, no crash
reporting, no update check that identifies you, and no account system. Logs it writes
(compat_log.txt, launcher_log.txt) stay on your SD card until
you choose to do something with them.
Games run through Viridite are a separate matter. A game may contain its own analytics, advertising or network code, and if your console is online that code may run. Viridite does not add that, cannot fully prevent it, and has no visibility into what a given game sends. Its network activity is logged locally so you can see it.
Compatibility reports
If you submit a report through the form, it collects:
- the game you tested and the source you obtained it from;
- your description of what happened and any notes you add;
- the log files you choose to attach;
- your GitHub username, if you supply one — this is optional and used only for credit.
The logs contain the Viridite version, your console's firmware and Atmosphère versions, the game's package name, file paths on your SD card, performance measurements and a trace of the calls the game made. They do not contain your Nintendo account, your console's serial number, your network details or your profile name. They may contain in-game values such as save-file keys. Read a log before you attach it.
Where it goes
Submissions are written to the public compat-reports repository on GitHub. They are public from the moment they are accepted, are indexed by search engines, and are copied by GitHub's own forking and archiving. Publication is the entire purpose of the form: the compatibility list is built from it.
Legal basis and retention
Where UK/EU data protection law applies, the basis for processing a report is your consent (Article 6(1)(a)), given by submitting the form, together with the project's legitimate interest in maintaining a public compatibility record (Article 6(1)(f)). No special-category data is sought and none should be submitted.
Reports are kept indefinitely, because a compatibility record is only useful as a history. You can ask for yours to be removed — see below — though note that anything already public may persist in forks, caches and archives outside the project's control.
Who else sees it
GitHub, Inc. (a Microsoft company) hosts the repository. Cloudflare operates the worker that relays submissions. Both are processors for this purpose and both are located in, or transfer data to, the United States. Transfers rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses as incorporated into those providers' terms, and on the EU-US and UK-US Data Privacy Framework where the provider participates.
Your rights
Depending on where you live you may have some or all of the following rights. The project applies them to everyone, regardless of jurisdiction, because maintaining two standards for a form this small would be absurd.
- Access
- Ask what the project holds about you. In practice: everything is already public.
- Rectification
- Ask for inaccurate data to be corrected.
- Erasure
- Ask for a report to be deleted. Granted on request for your own submissions.
- Restriction and objection
- Ask that processing stop while a dispute is resolved, or object to processing based on legitimate interests.
- Portability
- Receive your data in a machine-readable form. Reports are already JSON and plain text in a public git repository.
- Withdraw consent
- At any time, without affecting processing already carried out.
- Complain
- To your supervisory authority. In the UK that is the Information Commissioner's Office; in the EU, your national authority.
For California residents under the CCPA/CPRA: the categories above are the only personal information collected. It is not sold and not shared for cross-context behavioural advertising, and never has been. You have the right to know, delete, correct and opt out, and you will not be treated differently for exercising any of them. There is no financial incentive programme.
Equivalent rights under other regimes — PIPEDA in Canada, the LGPD in Brazil, the APPI in Japan, POPIA in South Africa, the Australian Privacy Principles, and comparable US state laws — are honoured on the same terms. Write to the contact address above and say what you want done.
Children
Viridite is not directed at children and the project does not knowingly collect personal data from anyone under 16. If you believe a child has submitted a report, tell us and it will be removed.
Automated decision-making
Submitted APK metadata is parsed automatically to fill in the compatibility list. That produces no legal or similarly significant effect on any person, and no profiling of individuals is performed.
Changes
Changes to this policy are made in public, in the website's git history. The date at the top is the date of the last change.