MSG Privacy Center
How MSG sign-in handles your data.
MSG sign-in is the single Google sign-in shared by the MSG
apps: Lea the game, Sabine and Tasty Crousty. You sign in once at
auth.msg.community with your Google account, and each app knows
it is you. Some apps also let you play as a guest, without an account.
This center publishes what MSG sign-in collects, why, where it is kept,
for how long, and how to reach us.
Read the sign-in privacy policy
Operated in Singapore by BERNAYS AND BERNAYS SINGAPORE PTE. LTD..
Questions: privacy@michel-simon.com.
MSG sign-in: privacy policy
Version 1.0 · Effective 29 September 2026 ·
Operated in Singapore by BERNAYS AND BERNAYS SINGAPORE PTE. LTD. ·
Contact privacy@michel-simon.com
This policy covers MSG sign-in: the page at
auth.msg.community where you sign in with Google, and the guest
access that lets you use an MSG app without signing in. It does not cover what
each app does with its own data once you are in. Each app describes that
itself.
What we collect
When you sign in with Google. We ask Google for three things
only: openid, email and profile. Google then
gives us:
- your Google account identifier, a number that never changes;
- your email address;
- your name;
- if your Google account belongs to an organisation's Google Workspace, the
domain of that Workspace (for example
example.com).
We never see your Google password.
What we create from it. An MSG account, which holds the
items above, the date it was created and updated, and the groups you belong
to. The staff group is added automatically when your Workspace domain
is one of ours. Other groups, such as access to Sabine, are added by a
person.
When you use an app as a guest. We create a random guest
identifier for that app on your device, with no name, email or account behind
it. If you later sign in on that device, the guest identifier is linked to
your MSG account, so what you did as a guest stays yours.
Records of sign-in activity. Each sign-in, sign-up and
session refresh is recorded to help us keep the service secure and fix
problems. These records may include your IP address and details of your device
and browser. When an account is created, the full sign-in event is recorded,
including the email address, name and Workspace domain.
Cookies on the sign-in page. The sign-in page at
auth.msg.community, run by Amazon Cognito, sets cookies that keep
your sign-in session and protect the form against forged requests. They are
needed for sign-in to work. This privacy center sets no cookie and stores
nothing in your browser.
Why we use it
- To let you in: to check with Google who you are.
- To recognise you as the same person across the MSG apps, so you have one
account.
- To recognise members of our own organisations as staff.
- To let you use an app as a guest, and keep what you did when you sign
in.
- To keep the service secure and to investigate problems.
We do not sell this data. We do not use it for advertising.
Who else handles it
- The MSG apps you sign in to receive your account
identifier, email address, name and groups, so they know who you
are.
- Amazon Web Services hosts MSG sign-in and stores
everything above.
- Google handles the sign-in on its side, under its own
privacy policy. Google knows that you signed in to MSG.
Where it is kept
In Amazon Web Services' Asia Pacific (Singapore) region. The sign-in page is
delivered through Amazon's worldwide content delivery network.
How long we keep it
We keep it with no end date: your MSG account, guest identifiers, and the
records of sign-in activity are kept for as long as MSG sign-in runs.
Questions and requests
To ask about your data, or to make a request about it, write to
privacy@michel-simon.com.
You can stop using MSG sign-in at any time. You can also remove MSG's
access from your Google account settings, under Third-party apps and
services.
Changes to this policy
When this policy changes, the version and the effective date above change,
and the previous version stays on record.
MSG Privacy Center