Privacy Policy — What's That Game

Last updated: 25 July 2026

Applies to: the "What's That Game" mobile app (iOS and Android) and its backend API.

1. Who we are

What's That Game ("we", "us", "our") is an independent project run by its founding team. We are not yet incorporated as a legal entity — the project is currently operated privately by its founders. If and when we incorporate, this policy will be updated with the company details.

For any privacy question or request, contact us at whatsthatgameteam@gmail.com.

The project founders act as joint data controllers for the purposes of the UK GDPR / EU GDPR.

2. Summary

What's That Game lets you create, store, search and discover party/board games. To do that we store an account for you, the games you contribute (including photos), and your activity — favourites, comments, aliases suggestions, and achievements. We use a small number of third-party providers (Google, Apple, OpenAI, Amplitude, Railway, Cloudflare, Resend, Expo) to sign you in, power semantic search and AI text suggestions, moderate uploaded content, measure how the app is used, host the service, store photos, send account emails, and deliver push notifications. We do not sell your personal data.

3. Data we collect

3.1 Account data (you give us this when you register)

DataRequired?Why
First nameYesDisplay, personalisation
Last nameYesDisplay, personalisation
UsernameYesPublic identity on the platform
Email addressYesLogin, account recovery, service notices
PasswordOnly for email/password sign-upAuthentication — stored only as a bcrypt hash, never in plain text
Date of birthYesAge-appropriate content (age ratings, adult-content gating)
Country of originYesPersonalisation / regional context (stored as a 2-letter ISO code)
Avatar imageOptionalProfile picture (see §3.6 for how images are handled)

We also automatically record an account role, an active/inactive flag, and account created/last updated timestamps.

3.2 Sign-in provider data (if you choose "Sign in with Google" or "Sign in with Apple")

You can create or access your account using a third-party identity provider. We do not receive your Google or Apple password.

Sign in with Google — under the openid email profile scopes, Google gives us your:

Sign in with Apple — Apple gives us your:

We store these to create and identify your account.

3.3 Content you create

Anything you mark public is visible to other users. Anything you mark private is visible only to you.

3.4 Photos and images

When you upload a photo (for a game or your avatar), it is first placed in a private quarantine storage area and screened by our AI moderation provider (see §3.5) before it becomes publicly visible. Approved images are copied to public storage and served via a public URL; rejected images are discarded. We store the image file itself, its storage location, and, for game photos, its display position.

3.5 Content moderation

Text you submit (e.g. comments, game descriptions) and images you upload are automatically checked with an AI moderation model before being made public, to detect content such as hate speech or graphic/sexual imagery. This is an automated screening step, not a decision that produces legal effects on you — see §4.

3.6 Analytics data (Amplitude)

Our app uses Amplitude to understand how the app is used (for example: which screens are viewed and key in-app actions/moments). Amplitude may process a device identifier, app/usage events, and technical data such as device type, OS version and approximate location derived from IP. This helps us improve the product. See Amplitude's privacy policy.

3.7 Push notification data

If you enable notifications, we store a device push token and platform (iOS/Android) so we can deliver notifications (e.g. achievement unlocks, announcements) via Expo's push service. We keep a record of notifications sent to you and their delivery status.

3.8 QR / short-link data

Some marketing/social links route through short codes we host (e.g. qr.whatsthatgame.co.uk/<code>). We record an aggregate scan count per link. We do not tie individual scans to your account.

3.9 Technical data

When the app calls our backend, our hosting provider processes standard request metadata (IP address, timestamps, user-agent) for security and reliability. Authentication uses a JWT token stored in a secure, HTTP-only cookie and/or sent as a bearer token from the app.

4. How we use your data (purposes & legal bases)

PurposeLegal basis (GDPR)
Create and run your account, authenticate youPerformance of a contract
Store and display the games, photos, comments, aliases and favourites you createPerformance of a contract
Semantic search and AI text suggestions (see §5)Performance of a contract / legitimate interest
Automated content moderation of text and images (see §3.5)Legitimate interest / legal obligation
Age-appropriate content gatingLegitimate interest / legal obligation
Push notificationsConsent (notification permission)
Transactional emails (e.g. password reset)Performance of a contract
Product analytics and improvement (Amplitude)Consent, where required, otherwise legitimate interest
Security, fraud/abuse prevention, debuggingLegitimate interest
Service and security communicationsPerformance of a contract / legitimate interest

We do not use your data for automated decisions that produce legal effects on you. Automated content moderation (§3.5) only screens content before publication; it does not affect your account status, and rejected content can be appealed by contacting us.

5. AI features and how your content is processed

When you create or edit a game, the game's text is sent to OpenAI to:

  1. Generate a semantic-search embedding (text-embedding-3-small), stored so your game can be found by meaning-based search.
  2. Optionally improve a field's wording when you use the AI optimiser (gpt-4.1-nano) or the "brain dump" free-text-to-fields feature.
  3. Screen text and uploaded images for policy violations using an AI moderation model, before the content is made public.

Only the content you submit (game text, comments, images) is sent — not your account credentials. OpenAI processes this as our service provider. See OpenAI's privacy policy. We recommend not putting personal or sensitive information into game text, comments, or photos.

6. Third parties we share data with

We share data only with providers that help us run the service:

ProviderRoleWhat they receive
GoogleSign-in (OAuth)Authentication exchange; we receive your basic profile (§3.2)
AppleSign in with AppleAuthentication exchange; we receive your Apple ID, email (or relay address) and name (§3.2)
OpenAIEmbeddings, AI text suggestions, content moderationGame/comment text and images you submit (§5)
AmplitudeProduct analyticsUsage events and device/technical data (§3.6)
RailwayHosting + managed PostgreSQL databaseAll data needed to run the service, stored at rest
Cloudflare (R2)Photo and avatar storageUploaded image files, in quarantine and public storage (§3.4)
ResendTransactional emailYour email address, for account emails such as password resets
ExpoPush notification deliveryYour device push token and notification content (§3.7)

We do not sell your personal data or share it with advertisers.

7. International transfers

Our backend and database are hosted on Railway, and our processors (Google, Apple, OpenAI, Amplitude, Cloudflare, Resend, Expo) may process data in Europe or the United States. Where data leaves the UK/EEA, transfers are protected by appropriate safeguards such as Standard Contractual Clauses.

8. How long we keep data

9. Your rights and choices

Depending on your location, you have the right to access, correct, delete, restrict, or object to processing of your personal data, and to data portability.

To exercise any right, email whatsthatgameteam@gmail.com. You also have the right to complain to your data protection authority (in the UK, the ICO).

10. Children

What's That Game is not directed at children under 13. You must be at least 13 to create an account. We do not knowingly collect data from children under that age. If you believe a child has given us data, contact us and we will delete it. Some games are gated as adult content and require an appropriate age.

11. Security

Passwords are stored only as bcrypt hashes. Authentication uses signed JWT tokens over HTTPS in HTTP-only cookies. Uploaded images pass through a private quarantine area and automated moderation before becoming public. Access to production data is restricted. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.

12. Changes to this policy

We may update this policy. We will post the new version with an updated "Last updated" date and, for material changes, notify you in the app.

13. Contact

What's That Game (founding team)
Email: whatsthatgameteam@gmail.com