This policy explains what Double Down Trivia (“we”, “the app”) collects and why. The controller is Elijah Silverman, a natural person in the United States, not a registered company. This page is meant to meet EU transparency standards in plain language. It is not legal advice.
Controller and contact
Controller: Elijah Silverman. Public identity: GitHub · elijahsilverman.com.
Contact for privacy, access, and erasure: the Support page. Signed-in players use in-app Feedback and should start the message with Privacy. There is no published personal inbox and no separate EU contact channel.
We are not established in the EEA or UK and have not appointed an Article 27 representative. You can still exercise the rights below through Support.
Who this applies to
Double Down Trivia is for players who are at least 13. If you are in the EEA, UK, or Switzerland you must also meet the digital-consent age in your country (GDPR Article 8 defaults to 16 unless that country set a lower age, not below 13). If you are under those ages, do not create an account or use the service. We do not knowingly collect personal data from children below those limits. If you believe a child has, use Support and we will delete what we can verify.
What we process
- Account identity from Google, Apple, or X via Firebase Auth: name, email when the provider shares one, profile photo, provider user id.
- Guest / anonymous Auth sessions: the display name you choose, and a Firebase uid. Guests generally cannot host or buy chips. Clearing site data or signing out can end the session.
- Profile and stats in Firestore: display name, photo URL, email when present, chip balance, games played, wins, streaks, answer-speed summaries, leaderboard opt-in.
- Live rooms: codes, host, status, settings, question ids, timers, scores, wagers, answers, submission timing, presence / last-seen.
- Match history under your account, custom packs you create, optional chip ledger and checkout session metadata.
- Feedback you send (message, optional email, category, rating, page path, user agent).
- Anagram finder telemetry (pasted text, category, match flags, scramble, timing). That collection is not attached to your player profile. Anagram Play solves, skip counts, and Daily streak live in this browser and, when you are signed in, on your account.
- Public anagram MCP tool calls: the scramble or title you send. No player profile.
- Technical data: Firebase Auth session in the browser, App Check / reCAPTCHA-style abuse checks when configured, and Firebase Analytics identifiers when analytics is on.
Scores, wagers, and chips are virtual points only. There is no cash-out, withdrawal, or prize payout through the app.
Purposes and lawful bases (GDPR Article 6)
Where GDPR applies, we rely on these bases. We do not sell personal data.
- Contract (Art. 6(1)(b)). Create and keep your account, run rooms, score games, host custom packs, credit chips you bought, show your stats, and delete the account when you ask in the app.
- Legitimate interests (Art. 6(1)(f)). Prevent spam and abuse, keep rooms fair, debug outages, understand product usage at a coarse level, and defend legal claims. You may object through Support. We will stop unless we have compelling grounds or need the data for a legal claim.
- Consent (Art. 6(1)(a)). Public leaderboard listing (off until you turn it on). Optional reply email on Feedback. You can withdraw in the app (hide from the board) or by omitting email next time. Withdrawal does not undo processing already done.
- Legal obligation (Art. 6(1)(c)). Keep or disclose records when tax, accounting, or a lawful request requires it. Stripe also keeps payment records as a processor / independent controller for its own obligations.
We do not use special-category data on purpose. We do not make solely automated decisions that produce legal or similarly significant effects.
Payments (Stripe)
The chip shop uses Stripe Checkout. Card details are handled by Stripe. We do not store full card numbers. We may store your user id, SKU, Stripe session or event ids, and chip credit amounts so the webhook can update your balance. Stripe processes payments under its own privacy notice.
Analytics
When a measurement id is configured, we use Firebase Analytics for product events (sign-ins, room creates and joins, game starts, shares, rematches). Events may include technical identifiers and room codes. They do not include live-game answer text.
There is no cookie-consent banner. Auth storage is necessary to stay signed in. Analytics is optional product measurement. Turn it off on Support (this browser only). That is also how you object to analytics as a legitimate-interest activity.
The anagram finder records what you paste or search, the category, whether it matched, generated scrambles, and lookup time. Firebase Analytics only gets counts and timing, not the full strings. Anagram Play solves, skip counts, and Daily streak stay in this browser and copy onto your account when you log in.
Anagrams lists
Titles in Anagrams come from public catalogs we compile when we build the site (Wikipedia film data, TVmaze, Project Gutenberg, and GeoNames / DataHub world cities). Those lists are not collected from your account. Licenses and third-party names are in the Terms of Use.
Cookies, local storage, and similar tech
- Necessary. Firebase Auth session persistence so you stay signed in. sessionStorage for a short-lived pending invite code across sign-in.
- Preferences. localStorage for display name keyed to your user id, last pack choice, a local cache of anagram Play solves and Daily streak, tour dismiss flags, and the analytics opt-out flag.
- Analytics (optional). Firebase Analytics cookies / local identifiers when analytics is enabled and you have not opted out.
Google / Firebase Authentication may run security checks (including reCAPTCHA-style challenges) as part of sign-in abuse prevention. App Check is optional infrastructure and is not claimed as active for every deploy.
Recipients and processors
We share data with providers that make the app work:
- Google Firebase / Google Cloud (Auth, Firestore, Analytics when configured, Hosting, Cloud Functions)
- Stripe (checkout and payment processing for chip packs)
Other players in your room can see your display name, photo, scores, wagers, and submitted answers during a game. If you opt in to the public leaderboard, it may show your display name and win-related stats. You can hide yourself again at any time.
We may disclose information if required by law or to protect the safety, integrity, or availability of the service.
International transfers
The app runs on Google Cloud and Stripe infrastructure, commonly including the United States (our Cloud Functions region is us-central1). If you play from the EEA, UK, or Switzerland, your data is transferred to the United States and any other country where those providers operate. Google and Stripe rely on their own transfer tools, including Standard Contractual Clauses where they offer them. We do not operate a separate EU region for this product.
Retention
- Account, stats, packs, ledger, and checkout metadata: until you delete the account in the app, or we close the service.
- Live rooms and in-room player state: about one hour after create, then cleaned up. A player doc in a live room may linger until that cleanup if you delete mid-game.
- Feedback tied to your uid: deleted with the account. We may keep a copy of a support thread if it is still needed to finish a dispute.
- Anagram finder events: not keyed to your account, so account deletion does not wipe them. We keep them only as long as they help debug the finder, then rotate or drop them.
- Stripe payment records: kept by Stripe as required for tax, fraud, and accounting. Deleting the app account does not currently instruct Stripe to erase checkout history. Ask via Support if you need us to pass that request on.
- Backups and logs: a limited window after deletion, then they age out. We will not restore a deleted account from backup to put it back into production.
Your rights
If GDPR, UK GDPR, or a similar law applies, you can ask to access, rectify, erase, restrict, or port personal data we hold, and to object to processing based on legitimate interests. You can withdraw consent where we rely on it (leaderboard, optional feedback email).
- Erasure: Delete account on home or Support. That wipes the Firestore profile tree, custom packs, feedback under your uid, and the Auth user.
- Rectification: edit your display name and leaderboard listing in the app.
- Access / portability: we do not offer an automated export file. Request a copy through Feedback (start with Privacy). We will send the profile and stats fields we hold when we can verify it is you.
- Analytics objection: the opt-out on Support.
You also have the right to complain to a supervisory authority in the EEA country where you live, work, or where you think a breach happened. A directory is on the European Data Protection Board site. In the UK, that is the ICO.
Changes
We may update this policy as the product changes. The date at the top will change when we do. Material changes will also be noted on this page. Keep using the app after the new date only if you accept the update. You can delete the account if you do not.