Privacy Policy
Your privacy matters. Here's exactly what we collect, store, and why.
Last updated: February 2026
TL;DR — We respect your privacy
No account required to play — guests can enjoy Kwazoo with no sign-up. Optional accounts let you sync stats and unlock Premium features. We only collect what's needed to provide the service. No tracking without your consent. You can export or delete your data at any time.
What We Collect
Kwazoo collects the minimum data needed to provide the service. What we collect depends on how you use Kwazoo:
All players (including guests)
Player name — Chosen by you when joining a room. Stored in sessionStorage (cleared when you close the tab) so you don't have to re-enter it.
Session ID — A random identifier stored in sessionStorage so you can reconnect if disconnected. Cleared when you close the tab.
Game state — Your in-game actions (drawings, guesses, votes) are held in server memory during the game session only. They are not stored in any database.
Preferences — Theme, sound, favorite games, and custom packs are stored in your browser's localStorage. This data never leaves your device.
Registered accounts (optional)
Email address — Used for authentication and account recovery. Stored securely via Supabase Auth. We do not send marketing emails without your consent.
Display name & avatar — Your chosen display name, avatar icon, and color. Stored in your user profile.
Game history — Records of which games you played, when, and with how many players. We do not store win/loss records or individual scores.
Premium subscribers
Payment information — Handled entirely by Stripe. We never see, store, or process your card number, CVV, or billing address. We store only your Stripe customer ID, subscription status, and payment history (amounts and dates).
Subscription status — Whether your subscription is active, cancelled, or expired, along with billing period dates. Used to determine your Premium features.
What We Don't Collect
No credit card numbers, CVVs, or billing addresses (Stripe handles all payment processing)
No IP addresses stored in our database
No tracking cookies without your explicit consent
No analytics without your consent
No win/loss records or individual game scores
No personal data sold to third parties — ever
Cookies & Storage
We use sessionStorage to store data essential for gameplay. This data is automatically cleared when you close your browser tab:
Session ID — random identifier for reconnecting if you lose connection
Room code — the room you're currently in
Player ID — your identifier within the room
Player name — the name you chose when joining
We use localStorage to remember your preferences and game statistics across visits. This data persists until you clear your browser data:
Cookie consent — whether you accepted or rejected the consent banner
Theme preference — dark or light mode
Sound preference — whether sound effects are on or off
Favorite games — which games you marked as favorites
Player stats — your game history and performance statistics (wins, scores, streaks). You can clear this anytime from the stats panel
Achievements — badges you've unlocked by reaching game milestones. Cleared alongside player stats
Custom game packs — any custom question packs you created
Install prompt dismissed — whether you dismissed the app install prompt
We use authentication cookies if you create an account:
Supabase auth token — a secure, HTTP-only cookie used to keep you signed in. This is essential for account functionality
Advertising cookies are only set if you give explicit consent via the cookie consent banner. You can change your preferences at any time by clicking "Cookie Preferences" in the footer or in your account settings.
Data Retention
We retain data only as long as necessary:
Game rooms — Held in server memory only. Automatically deleted after 3 hours of inactivity or when all players leave. No game data is written to a database.
Account data — Retained for as long as your account is active. When you delete your account, all personal data is permanently removed within 30 days.
Game history — Retained for as long as your account is active. Deleted when you delete your account.
Payment records — Anonymized payment history is retained for 7 years after account deletion to comply with financial regulations and tax requirements. Your personal information is removed from these records.
Third-Party Services
Kwazoo uses the following third-party services to operate:
Supabase (Authentication & Database) — Handles user authentication, profile storage, and game history. Supabase is GDPR-compliant and processes data in accordance with their privacy policy. Data is stored securely with row-level security.
Stripe (Payment Processing) — Handles all payment processing for Premium subscriptions. Stripe is PCI DSS Level 1 compliant (the highest level of payment security certification). We never see or store your card details. See Stripe's privacy policy for details.
Google AdSense (Advertising) — Displays advertisements to non-Premium users. Advertising cookies are only set after you give explicit consent via our cookie consent banner. You can revoke this consent at any time. Premium subscribers do not see ads and no advertising cookies are set.
Each of these services has their own privacy policy. We encourage you to review them:
Your Rights
Regardless of where you are located, you have the following rights regarding your data:
Right to access — You can view all data associated with your account from your Settings page.
Right to data portability — You can export all your data (profile, game history, subscription info) as a JSON file from Settings > Export My Data.
Right to deletion — You can permanently delete your account and all associated data from Settings > Delete My Account. This action is irreversible.
Right to withdraw consent — You can change your cookie and advertising preferences at any time via the cookie consent banner or from Settings > Cookie Preferences.
Right to rectification — You can update your profile information (display name, avatar) at any time from your Settings page.
Guest players: Your game stats and achievements are stored only in your browser's localStorage — we never have access to them. You can clear this data anytime from the stats panel.
These rights apply globally, including under the EU General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA), Canadian PIPEDA, and Australian Privacy Act.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date.
Contact
Questions about this policy? Reach out at croxa@hotmail.no. See also: Terms of Service · Refund Policy.