What data do games collect about players?
Considerably more than most players realise, and for reasons that range from legitimate engineering to targeted monetisation — with the distinction rarely visible from inside the game.
Technical and operational data: device model, operating system, hardware specification, driver versions, crash reports with diagnostic context, frame rate and performance metrics, and network quality. This is genuinely necessary to support a wide device range and to diagnose problems.
Gameplay telemetry: what you played, for how long, at what times, where you died, which levels you abandoned, which items you used, which settings you changed, and where you stopped playing. This drives balance changes, difficulty tuning and design decisions, and is one of the reasons modern games are better tuned than older ones.
Account and social data: friends, party membership, messages in some contexts, voice chat where moderation applies, and cross-platform identity linking.
Commercial data: every purchase, what you looked at and did not buy, when you were offered something and declined, and your response to discounts. This is where the sharper practices live — pricing and offers can be personalised, offers timed to moments of frustration or engagement, and spending patterns used to identify players likely to spend heavily, who are then targeted differently. Regulators in several countries have examined exactly this.
Advertising identifiers in free-to-play and mobile titles, frequently shared with advertising networks and analytics providers embedded in the game.
Anti-cheat data, which on kernel-level systems can be extensive and is a legitimate source of discomfort.
What your rights are, where data protection law applies: to know what is held, to obtain a copy, to correct it, to object to profiling and direct marketing, and frequently to have it deleted — though deleting an account usually deletes your progress and purchases too.
What you can do: read what the privacy policy says about sharing with third parties rather than what it says about security; limit advertising identifiers at the operating system level; decline optional analytics where offered; and check settings on children's accounts specifically, where stricter defaults are legally required in several jurisdictions.