Legal & Privacy

Privacy Policy

We believe good privacy is good design. Here's exactly what we collect, why we collect it, and how you stay in control.

πŸ“… Effective: May 1, 2025
πŸ”„ Last updated: May 1, 2025
🌍 Applies to: smartassfacts.com
βœ… GDPR Compliantβœ… CCPA Compliantβœ… COPPA Compliant
πŸ™…

We never sell your data

Your personal information is never sold to third parties. Ever.

πŸ”’

Minimal collection

We only collect what's needed to run the game and improve it.

πŸ—‘οΈ

You can delete everything

Request full account and data deletion at any time, no questions asked.

βœ‰οΈ

We respond in 48 hrs

Privacy requests are handled by a real person within 2 business days.

πŸ’Who we are

The data controller responsible for your information.

Smartass Facts is a gamified fact-guessing app operated by Smartass Facts Ltd. ("we", "us", "our"). When you use our website at smartassfacts.com or our mobile apps, you're sharing information with us, and this policy explains how we handle it.

🏒

Data Controller

Smartass Facts Ltd.
Registered in Ukraine
Company No. 12345678

πŸ“¬

Registered Address

Kyiv, Ukraine
privacy@smartassfacts.com

πŸ‘€

Data Protection Officer

Appointed in accordance with GDPR Art. 37
dpo@smartassfacts.com

πŸ‡ͺπŸ‡Ί

EU Representative

For EEA-based data subjects with GDPR queries
eu@smartassfacts.com


πŸ“‹Data we collect

We collect only what's necessary to provide, improve, and protect the service.

2.1 Data you give us directly

  • Account registration β€” name, email address, username, and password (hashed) when you create an account.
  • Profile information β€” optional avatar, display name, and bio you choose to add.
  • User-submitted content β€” facts, ratings, comments, or reports you submit within the app.
  • Support communications β€” messages you send to our support team, including any attachments.
  • Payment data β€” billing name and address. Card numbers are processed directly by Stripe and never stored by us.

2.2 Data collected automatically

  • Usage data β€” pages visited, features used, game sessions played, facts swiped, correct/incorrect answers, time spent in-app.
  • Device & technical data β€” IP address, browser type and version, operating system, device identifiers, screen resolution, language settings.
  • Log data β€” server logs including timestamps, error reports, referrer URLs, and HTTP response codes.
  • Cookies & similar technologies β€” as described in our Cookie Policy.

2.3 Data from third parties

  • Social login providers β€” if you sign in via Google or Apple, we receive your name, email, and profile picture from that provider.
  • Analytics providers β€” aggregated, anonymised behavioural data from Google Analytics (with IP anonymisation enabled).
  • Fraud prevention β€” risk signals from Stripe Radar to prevent fraudulent transactions.
ℹ️
We don't collect sensitive data

We do not intentionally collect special category data (health, race, religion, biometrics, etc.). Please don't share this type of information in the app.


βš™οΈHow we use your data

We use your information for specific, documented purposes only.

PurposeData usedLegal basis
Create & manage your accountName, email, passwordContract
Deliver the game experienceUsage data, game progress, preferencesContract
Process payments & subscriptionsBilling name, address, Stripe tokensContract
Improve & personalise the appUsage data, game historyLegitimate interest
Analytics & performance monitoringAnonymised usage & device dataConsent
Send transactional emailsEmail addressContract
Send marketing & product updatesEmail address, preferencesConsent
Fraud prevention & securityIP address, device data, Stripe signalsLegitimate interest
Comply with legal obligationsAs required by applicable lawLegal obligation
Respond to support requestsName, email, support messagesContract
πŸ“£
Marketing emails

We only send promotional emails with your explicit consent. You can unsubscribe at any time using the link in any email, or by updating your account preferences.



πŸ”—Sharing & international transfers

We share data only with trusted partners who help us run the service, under strict data processing agreements.

5.1 Service providers we work with

ProviderRoleData sharedLocation
Firebase (Google)Authentication & database hostingAccount data, game dataEU & US
Google AnalyticsUsage analytics (anonymised)Anonymised usage dataUS
StripePayment processingBilling info, device dataUS & EU
SendGridTransactional & marketing emailsEmail address, nameUS
SentryError tracking & monitoringAnonymised error & device dataEU
VercelWeb hosting & CDNIP address, request logsGlobal

5.2 Other circumstances where we may share data

  • Legal requirements β€” if required by a court order, government authority, or applicable law, we may disclose your data. We will notify you unless legally prohibited from doing so.
  • Business transfers β€” in the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity under the same privacy protections.
  • Protecting rights β€” to investigate, prevent, or act on suspected fraud, security incidents, or violations of our Terms of Service.
  • With your consent β€” we may share data for other purposes if you've explicitly agreed.

5.3 International data transfers

Some of our service providers are based outside the EEA (primarily the US). Where this occurs, we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Binding Corporate Rules for intra-group transfers
πŸ›‘οΈ
We never sell your data

We do not sell, rent, or trade your personal information to any third party for their own commercial purposes. This is unconditional.


πŸ—“οΈData retention

We keep your data only as long as necessary for its original purpose, or as required by law.

Data typeRetention periodReason
Account & profile dataDuration of account + 30 daysService delivery; deletion grace period
Game history & progressDuration of accountPersonalisation & leaderboards
Payment records7 yearsTax & accounting obligations
Support communications3 yearsDispute resolution & quality assurance
Server & access logs90 daysSecurity monitoring & debugging
Analytics data (anonymised)26 months (Google Analytics default)Product improvement
Marketing consent recordsUntil consent withdrawn + 1 yearGDPR accountability
Deleted account data30-day recovery window, then purgedAccidental deletion recovery

When data reaches the end of its retention period, it is either securely deleted or irreversibly anonymised. We conduct quarterly data audits to ensure compliance.


βœ‹Your rights

You have meaningful control over your personal data. Here's what you can do and how to exercise each right.

πŸ‘οΈ

Right to Access

Request a copy of all personal data we hold about you (a "Subject Access Request").

✏️

Right to Rectification

Ask us to correct any inaccurate or incomplete personal data we hold.

πŸ—‘οΈ

Right to Erasure

Request deletion of your data ("right to be forgotten") where no legal basis for retention exists.

⏸️

Right to Restriction

Ask us to pause processing your data while a dispute about accuracy or lawfulness is resolved.

πŸ“¦

Right to Portability

Receive your data in a structured, machine-readable format (JSON/CSV) to transfer to another service.

🚫

Right to Object

Object to processing based on legitimate interest, including profiling and direct marketing.

πŸ€–

Automated Decisions

Not be subject to decisions made solely by automated processing that significantly affect you.

↩️

Withdraw Consent

Withdraw any consent you've given (e.g. marketing emails, analytics) at any time without penalty.

πŸ›οΈ

Right to Complain

Lodge a complaint with your local data protection authority if you're unhappy with how we handle your data.

How to exercise your rights

  1. Email us at privacy@smartassfacts.com with "Privacy Request" in the subject line.
  2. Describe your request and include your registered email address so we can verify your identity.
  3. We will respond within 30 days (we usually respond within 48 hours).
  4. We may need to verify your identity before processing some requests β€” we'll let you know if so.
πŸ›οΈ
Supervisory authorities

If you're in the EU/EEA and believe we've mishandled your data, you have the right to lodge a complaint with your national data protection authority. For example, in the EU you can contact the relevant national DPA β†’


πŸ§’Children's privacy

Smartass Facts is designed for adults and older teenagers. We take children's privacy seriously.

Smartass Facts is intended for users aged 13 and over (or 16+ in certain EU member states). We do not knowingly collect personal information from children under these ages.

  • Our registration process requires users to confirm they meet the minimum age requirement.
  • We do not direct marketing at users under 18.
  • If we discover we have inadvertently collected data from a child under the applicable minimum age, we will delete it promptly.
  • Parents or guardians who believe their child has provided us with personal data should contact us at privacy@smartassfacts.com.
⚠️
For parents

If you believe your child under 13 has created an account without your knowledge, please email us at privacy@smartassfacts.com and we will delete the account and all associated data within 24 hours.


πŸ”Security

We implement industry-standard technical and organisational measures to protect your data.

Technical safeguards

  • Encryption in transit β€” all data transmitted between your device and our servers uses TLS 1.2+.
  • Encryption at rest β€” stored data is encrypted using AES-256 on Firebase's infrastructure.
  • Password hashing β€” passwords are hashed using bcrypt with per-user salts. We never store plaintext passwords.
  • Two-factor authentication (2FA) β€” available and encouraged for all accounts.
  • Access controls β€” internal access to production data is role-based, logged, and limited to essential personnel.

Organisational safeguards

  • Annual security training for all staff with access to personal data.
  • Signed data processing agreements with all third-party processors.
  • Regular internal security reviews and third-party penetration testing.
  • Documented incident response procedure for data breaches.

Data breach notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of discovery (GDPR Art. 33).
  • Notify affected users without undue delay where the breach poses a high risk (GDPR Art. 34).
  • Provide clear information on what happened, what data was affected, and steps you can take.
πŸ›
Found a security vulnerability?

We take security reports seriously. Please email security@smartassfacts.com with details. We aim to acknowledge all reports within 24 hours.



πŸ“Policy changes

We keep this policy up to date. Here's how we notify you of changes.

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we update the "Last updated" date at the top of this page.

For material changes β€” those that significantly affect how we use your data or your rights β€” we will notify you through:

  • A prominent notice on the Smartass Facts website and in-app
  • An email to your registered address (at least 30 days before changes take effect)
  • A prompt to review and re-accept updated terms where required by law

Version history

May 1, 2025 β€” v1.2 (Current)
Added EU Representative details. Expanded security section. Updated third-party provider list to include Vercel.
February 10, 2025 β€” v1.1
Added CCPA section for California residents. Clarified retention periods for support communications.
November 3, 2024 β€” v1.0
Initial Privacy Policy published at launch of Smartass Facts.

πŸ“¬Contact & Data Protection Officer

We're here to help with any privacy questions, requests, or concerns.

If you have any questions about this Privacy Policy, want to exercise your rights, or have a concern about how we handle your data, please get in touch. All privacy requests are handled by a real person β€” not a bot.

Privacy team & DPO πŸ”’

For general queries, data requests (SAR, deletion, portability)
and GDPR / CCPA compliance matters.

⏱️
Response times

We aim to acknowledge all privacy requests within 48 hours and resolve them within 30 days as required by GDPR. Complex requests may take longer β€” we'll keep you informed.