hintrigue

Last updated 16 September 2026

Privacy Policy

Oleh Zasadnyy, trading as Hintrigue, is the controller of personal data described here. You can reach us at privacy@hintrigue.app, hello@hintrigue.app, or Heina 5/2, Apt. 2, Tallinn, 10611, Estonia.

Who this covers

This policy covers the Hintrigue website, our iOS and Android apps, and browser room join. Hintrigue is available worldwide. It is designed for people aged 16 or over. If you are 16 or 17, use it only with permission from a parent or guardian. We do not knowingly create accounts for children under 16.

Information we process

To run an account, we process authentication details supplied by Apple or Google, an account identifier, and the profile details you choose, such as a display name and avatar choice. To run a room, we process room and seat identifiers, game settings, gameplay records, scores, private room display names, hints, decoys, votes, and related connection data. Hints and decoys are private gameplay input shared only within the room as the game requires; they are not public posts or a persistent content service in V1.

We process purchase and entitlement information supplied by the app store and RevenueCat to provide Hintrigue Pro. Apple and Google handle payment details; we do not receive your full payment-card number. If you allow notifications, Expo and the relevant platform process a push token so we can send service notifications. If you choose to scan a room QR code, the app requests camera permission and uses the selected code to join the room; it does not use speech recognition in V1.

On the website, launch-update signup processes your email address, consent record, and confirmation time. An unconfirmed signup expires after 48 hours. We use cookieless PostHog measurement for limited website diagnostics, such as page activity, device and browser information, anonymous funnel events, Web Vitals, and public 404 paths. We do not intentionally send email addresses, confirmation tokens, deletion-form contents, or a persistent analytics identifier to that website analytics service.

In the app, PostHog may process app and device activity, diagnostic information, and session replay data to help us understand reliability and use. Do not enter personal or sensitive information into gameplay fields. We will verify and publish the final production replay, masking, retention, and provider settings before release.

Why we use it

We use account, room, and gameplay information to provide the service you ask for and perform our contract with you. We use purchases and entitlements to provide paid features. We use limited security, operational, and diagnostic information for our legitimate interests in keeping the service secure, reliable, and understandable. We send launch updates only with your consent; you can unsubscribe at any time. Where the law requires it, we process information to meet legal obligations or establish, exercise, or defend legal claims.

Service providers and international transfers

We use Supabase for account and application data, Cloudflare for site delivery, spam protection, and temporary request-rate limiting, Resend for email delivery, PostHog Cloud EU for analytics, RevenueCat for purchase entitlements, Expo for push delivery, and Apple and Google for sign-in and app-store transactions. These providers may process data outside Estonia or the EEA. Where required, we rely on an adequacy decision, the European Commission’s standard contractual clauses, or another lawful transfer mechanism. Provider settings and agreements are verified before production release.

Retention and your choices

We retain account and room information for as long as it is needed to provide the service, then delete or anonymize it under our operational retention rules. We retain entitlement and transaction-related records as required for accounting, tax, fraud prevention, and legal claims. Confirmed launch-update contact data is retained until you unsubscribe, apart from a minimal suppression record needed to honour that choice. We retain account-deletion request messages only as long as needed to verify and complete the request and document the result.

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal data, and to withdraw consent. You may complain to the Estonian Data Protection Inspectorate or your local supervisory authority. We may need to verify your identity before acting on a request.

Delete your account

You can delete your account in the app from Settings. If you cannot access the app, use our account-deletion request page. Sending a request does not delete an account automatically: we verify identity first. We aim to acknowledge, complete, or explain why more time is needed within one month after verification; where the law permits an extension, we will tell you within that first month. Some records may be retained where law allows or requires it.

Deleting an account removes access to account features and can remove associated profile and gameplay data as described above. It does not cancel an App Store or Google Play subscription; manage subscriptions through the store where you bought them.

Security and changes

We use reasonable technical and organisational safeguards, but no online service can promise absolute security. We will update this policy when our practices or the service changes materially. Before enabling public or persistent player-created content, uploads, chat, custom decks, player-triggered generation, or broader sharing, we will separately assess and publish the necessary safety and privacy controls.