Knowtilus: Trivia Quiz Game

Privacy Policy

Last updated 5 October 2026

This policy explains how FREEDOM LLP ("we", "us") handles personal data when you play Knowtilus: Trivia Quiz Game (the "app"). It is written to be read. If anything is unclear, write to us at office@freedomgaming.co.

Effective date: 5 October 2026.

In short.

  • You can play as a guest, with no email address, name or password. If you save your player, we store the email address and a scrambled form (a hash) of the password you chose, or the ID of the Google, Apple, Game Center or Google Play Games account you signed in with. We never ask for your name, phone number, date of birth, contacts, photos, camera, microphone or location, and the app does not ask your device for them.
  • Opening the app for the first time creates nothing. When you tap I agree on the first screen, our server creates a player with a random ID and a generated nickname such as "Brave Narwhal 42". You cannot type a nickname. Logging in never makes a player, and nothing else does: every player is made by your own tap on I agree.
  • We store the answers you type, with their scores and how long you took.
  • An answer that is new to us is checked by an AI model run by OpenAI. What is sent is the prompt and the answer only, with nothing that identifies you or your device.
  • The app contains no advertising, no analytics or tracking software, no crash-reporting software and no purchases today. Section 12 says what would change if we add any of these.
  • You can delete your data yourself, in the app, at any time. That deletes your sign-in details too.

1. Who is responsible#

The controller of your personal data is FREEDOM LLP, the publisher of Knowtilus: Trivia Quiz Game.

2. What we collect#

A guest player does not tell us who you are. The data below is still personal data under laws such as the GDPR, because it is tied to an identifier that lives on your device. A saved player is also tied to an email address or to an account at Google, Apple, Game Center or Google Play Games, which can tell us which player is yours. We treat all of it as personal data.

DataWhat it is and where it comes fromWhat we use it for
Player ID and sessionsWhen you tap I agree on the Terms screen (the first screen of the app, and the screen the app shows again before it makes any new player), our server creates a player and sends back a random player ID and two signed sign-in tokens: an access token that lasts 1 hour, and a refresh token that lasts up to 60 days and is replaced every time it is used. The app keeps them in your device's secure storage (the iOS Keychain, or the Android Keystore) and sends the access token with each request. Of a refresh token we store only a one-way hash (SHA-256) with the time it was made and when it ends, never the token itself. If an old refresh token is used again, we treat it as stolen and end every session of that player.To recognise your device from one day to the next, keep your progress and rank, keep other people's requests away from your data, and end your sessions: on this device when you log out of a saved player, and on every device when you reset your password or delete your data.
Account detailsWhether your player is a guest or saved, when it was saved, and a credential counter that ends old sessions when a password is reset.To run accounts and keep them secure.
Email addressOnly if you save your player by email, or sign in with Google or Apple. The address you typed, or the address that Google or Apple vouches for (Apple may give a private relay address that forwards to you). Stored in lower case with the time it was confirmed. An address counts only once it is confirmed.To sign you in, to send the one-time codes you ask for (section 5) and to protect the account. We do not use it for marketing and send no newsletters.
PasswordOnly if you chose email and password. We store a salted bcrypt hash, from which the password cannot be read. We do not store the password itself.To check your password when you log in.
Sign-in IDs from Google, Apple, Game Center and Google Play GamesOnly for the services you use. The ID that the service gives your account for our app: Google's account ID (we ask Google only for it and for your email address, not for your name, picture or contacts); Apple's user ID for Sign in with Apple; the Game Center player ID, which Apple scopes to a developer team, so the same person has the same Game Center ID in every title published by FREEDOM LLP (our Apple developer team); Google's Play Games player ID. We do not read your Game Center or Google Play Games name, picture, friends or achievements.To recognise the same account on another device, and so that one account cannot be attached to two players. We use these IDs only to recognise your player in this app.
Emailed codesWhen you ask to save your player by email or to reset a password, a short-lived record: a hash of the 6-digit code, the address, the time, and, when you save by email, a bcrypt hash of the password you chose. A Google link, or a Google log in to a player that exists, leaves a similar record, with the Google account ID and email address, that lives for minutes. A Google log in that finds no player keeps nothing at all: no record is stored and no player is made.To check that you control the address, and to attach a Google account to the player that asked.
Generated nicknameChosen by our server when the player is created: an adjective, a sea creature and two digits. Nicknames are not unique and say nothing about who you are. Other players see yours on the daily leaderboard.To show your place on the leaderboard.
Activity timesWhen the player was created and when it was last seen (refreshed at most every ten minutes while you use the app).To run the service, to delete inactive players (section 7) and to count how many players we have.
Your answersFor every prompt: the text you typed (the first 100 characters), a normalised form of it (lower case, no punctuation or accents, typos and plurals merged with known answers), which prompt and day it belongs to, whether you skipped it, whether it fitted the prompt, and the result: depth in metres, the estimated share of players who gave the same answer, and the rarity tier. Also the time you took, as measured by the app.To score your dive, work out how rare an answer is, build the daily leaderboard and the "what others said" lists, keep the game fair, and handle reports.
Anonymous answer statisticsPer prompt: how many players gave each answer, and whether an answer fits the prompt (the verdict of section 4). Neither is linked to a player.To estimate how rare an answer is, and to avoid asking the AI model the same question twice.
Technical dataYour IP address and the usual details of a network request (time, address requested, result, the app's user-agent text). The app does not send an advertising ID or any other device identifier. Your IP address is used for rate limiting, held in memory in windows of up to 15 minutes (the limits on emailed codes use the longest), and appears in the access logs of our web server. Our software does not store it in the game database or attach it to your player.To answer your request, to stop flooding and abuse, and to diagnose faults.
ReportsIf you report an answer: which answer, the reason you chose, the time, and your player ID.To review the report and act on it, as the Terms of Service describe.
What you send usIf you write to us: your email address, your message, and anything you attach or tell us.To answer you and to handle your request.

We do not collect your name, phone number, postal address, date of birth, precise or approximate location, contacts, photos, files, audio, health data, payment details, advertising ID or browsing history, and the app requests no such permission from your device. We collect an email address only in the cases of the table above, and when you write to us.

What other players can see#

What stays on your device#

Only the session and what the sign-in screens need, in secure storage: your player ID, nickname and the two sign-in tokens; the version of the Terms you accepted; the guest players you logged out of on this device, so that you can continue them from the welcome screen; the last Game Center or Google Play Games player ID the app saw, to notice when you switch game account; and whether you logged out on purpose. The app uses no cookies and no other persistent identifiers.

Signing in with Google, Apple, Game Center or Google Play Games#

This website#

The legal and support pages are static web pages. They set no cookies and load no scripts, fonts or images from other sites. The company that hosts them, DigitalOcean, may keep ordinary access logs.

If the GDPR or the UK GDPR applies to you, these are the legal bases we rely on.

PurposeLegal basis
Creating your player (guest or saved), signing you in with the method you chose, running the daily dive, scoring, the leaderboard and the answer listsPerformance of our contract with you: the Terms of Service (Article 6(1)(b))
Keeping accounts secure: checking passwords, sending codes, limiting sign-in attempts and emails, ending sessionsPerformance of the contract, and our legitimate interest in keeping accounts safe (Article 6(1)(b) and (f))
Checking whether a new answer fits its prompt (section 4)Performance of the contract, and our legitimate interest in scoring fairly (Article 6(1)(b) and (f))
Keeping the game secure and fair: rate limiting, preventing cheating and abuse, moderating answers, handling reports, enforcing the Terms, defending legal claimsOur legitimate interests in a safe and fair game (Article 6(1)(f)); a legal obligation where the law requires it (Article 6(1)(c))
Counting daily and returning players, finding and fixing faults, improving the gameOur legitimate interest in running and improving the service (Article 6(1)(f))
Answering your messages and requestsOur legitimate interest in supporting you, and legal obligations for rights requests (Article 6(1)(f) and (c))
Complying with legal requestsLegal obligation (Article 6(1)(c))
Optional features that ask your permission (section 12)Your consent, which you can withdraw at any time (Article 6(1)(a))

We do not make decisions about you that have legal or similarly significant effects. The AI check of section 4 decides only whether an answer counts in the game.

4. Answer checking with OpenAI#

Rarity is only fair if an answer really fits its prompt: "papaya" is a rare answer to "Name a type of pasta", but it is not pasta. So when an answer is new, an AI model checks it.

When. Only when the answer is not on our prepared list for that prompt and we have no stored verdict for it yet. Every distinct answer to a prompt is judged once, ever, and the verdict is stored and reused. Most answers never leave our servers.

What is sent. Our fixed instructions, the text of the prompt (for example "Name a type of pasta"), and the normalised form of the answer (at most 40 characters and five words). The request is made by our server to OpenAI's chat completions service (api.openai.com).

What is not sent. Your player ID, nickname, email address, IP address, sign-in tokens, device details, the time you took, or anything else about you. OpenAI sees the network address of our server, not of your device.

What comes back. A yes-or-no verdict: the answer fits the prompt or it does not. We store the verdict with the prompt, the normalised answer, the model's name and the date, with no link to you.

OpenAI's role and retention. OpenAI processes this data for us as a service provider under its own API terms. When we wrote this policy, OpenAI's published terms said that it may keep API inputs and outputs for up to 30 days to provide the service and to detect abuse, and that it does not use API data to train its models unless the customer opts in. Our service does not opt in, and it does not use OpenAI's optional zero-data-retention or modified abuse-monitoring controls. We therefore cannot promise that OpenAI deletes a request immediately. Read OpenAI's current terms and privacy policy at https://openai.com/policies/ for the details, which OpenAI can change.

If the check is not possible. When OpenAI cannot be reached, the app tells you to try again or to type a different answer. We do not store or score that answer in the meantime.

Your choices. There is no switch to turn the check off, because it is what decides whether a new answer counts. If you do not want a particular answer to be sent, skip that prompt: an empty answer scores 0 m and sends nothing. Please do not type personal information into an answer.

Mistakes. The model can be wrong. If you think an answer was judged wrongly, write to us with the prompt and the answer. A person can correct the stored verdict, and it then applies to everyone.

5. Who we share data with#

We do not sell your personal data. We do not share it for cross-context behavioural advertising.

6. Transfers outside your country#

Your data may be processed in countries other than the one where you live.

Where the GDPR or the UK GDPR requires a safeguard for a transfer, we rely on one that the recipient provides: an adequacy decision or a certification under the EU-US Data Privacy Framework, or standard contractual clauses, with the UK addendum where needed. Ask us for a copy of the safeguards at the address in section 14.

7. How long we keep data#

DataHow long
Player record (ID, nickname, times), the sign-in details (email address, password hash, sign-in IDs) and the scores, answer keys and timings linked to itWhile you keep playing. Deleted automatically 400 days after your last activity, a saved player included, or earlier when you ask.
Sessions (refresh tokens)Each lasts up to 60 days from the last time it was used. Logging out of a saved player ends the session on that device at once; a password reset or deleting your data ends your sessions on every device at once. A guest that you log out of keeps its session on your device, so that you can continue it from the welcome screen: that session ends when its 60 days run out, or when you delete your data. The record of an ended session is removed when its 60 days run out (deleting your data removes the records at once).
Emailed codes and pending requestsA code and its pending request (the address you typed and, when you save by email, the bcrypt hash of the password you chose) are marked as used when you use them, and are removed by the database when they expire: 15 minutes after they were made, plus the minute or so the database takes to sweep expired records, so at most about 16 minutes. A pending Google link lasts 5 minutes and a Google sign-in code 2 minutes, and they are removed the same way.
The text you typed, exactly as you typed it12 months from the day you submitted it, then erased. The score, normalised answer and timing stay with the player record.
Anonymous answer statistics and AI verdictsIndefinitely. They contain no player ID.
Reports and moderation records24 months after the case is closed. A report you filed is deleted sooner if you delete your data.
Web server access logs (these hold IP addresses)30 days
Application logs (these hold normalised answers and prompt IDs, never a player ID)30 days
BackupsRolling 30 days. Data you delete leaves the backups when they expire, at most 30 days later. If we ever restore a backup, we delete again what has been deleted since.
Emails you send us24 months after the last message in the conversation
Delivery records of the emails we send you (codes)the provider's own retention period for delivery logs (we do not control it), at the email provider
The record that a deletion or rights request was made (date, player ID, outcome)24 months, to show that we answered it and to re-apply it after a backup restore
The copy at OpenAIUp to 30 days, under OpenAI's terms at the time of writing (section 4)

We may keep data longer when the law requires it, or when we need it to establish, exercise or defend a legal claim.

8. Security#

No system is perfectly secure. If a breach puts your rights at risk, we will tell the people concerned and the authorities as the law requires.

9. Your rights#

If the GDPR or the UK GDPR applies to you, you have the right to:

How to use them.

10. California and other US states#

This section is for residents of California and of other US states whose laws give similar rights.

11. Children#

Knowtilus: Trivia Quiz Game is for people aged 13 and over and is not directed to children. We do not ask for your age and we do not knowingly collect data from anyone under 13. If we learn that a player is under 13, we will delete their data. If you are a parent or guardian and think your child is playing, write to us and we will delete it. Where the age of majority is above 13 in your country, you need the permission of a parent or guardian to accept our Terms.

12. Features that are not in the app yet#

The app today has none of the features below. Each one is described here so that you can see what would change before it does. We will update this policy, and where the law requires it ask for your permission, before a feature goes live.

When enabled: daily reminders and push notifications. A reminder that you set up in the app is a local notification: your device shows it at the time you chose, and no data leaves your device. If we later add notifications sent from our servers (for example a challenge from another player), we will store a push token that Apple or Google gives your device, linked to your player ID, and use it only to send notifications you allowed. The token is deleted when you turn notifications off, when Apple or Google reports it as invalid, or when you delete your data. Legal basis: your consent.

When enabled: advertising. If we show ads, we will use an advertising service, which we will name here, with a link to its privacy policy, before any ad appears. It may receive your IP address, device and ad-interaction data and, only if you allow it, your advertising ID. On iOS we will ask for your permission through Apple's tracking prompt, and in the EEA, the UK and Switzerland through a consent prompt, before any personalised ad. You will be able to change your choice in the app. Rewarded ads will be optional and will never change what an answer scores or what you can win.

When enabled: purchases. If we sell anything, Apple or Google will take the payment and we will never see your card or account details. We will receive a confirmation of what was bought, tied to your player ID, so that we can unlock it and restore it. Anything sold will have fixed contents and a fixed price. Nothing sold for real money will be random.

When enabled: crash reports. If we add crash reporting, we will name the service here, and it will receive technical details of a crash (app version, operating system version, device model, what the app was doing) and will not receive your player ID or your answers. We will state how long it is kept before it is switched on.

When enabled: progression, collections and streaks. We will store, linked to your player ID, your level and depth record in each category, your daily streak, your collection (trophies, chests, in-game currency and cosmetics), and a ledger of what you earned. When you are the first player ever to give a valid answer, we may record you as its discoverer and show your nickname next to that answer. This data is deleted with your player.

When enabled: playing against other people. In a match, your opponent sees your generated nickname and, after each round, your answer. Bots may fill seats and are always labelled as bots. We may store a recorded match so that another player can later face a replay of your answers, under your generated nickname and labelled as a replay. You will be able to report and block players. A block is stored on our server against your player ID. Matches use the same player, guest or saved; there is no chat and no free-text name.

13. Changes to this policy#

We will change this policy when the app or the law changes. The date at the top shows when it was last updated. If a change matters to you, for example a new kind of data or a new recipient, we will tell you in the app before it takes effect and, where the law requires it, ask for your permission.

14. Contact and complaints#

Write to office@freedomgaming.co, or by post to 101 King's Cross Road, London WC1X 9LP, United Kingdom. For help with the game itself, see Support. If you are not happy with our answer, you can complain to the data-protection authority named in section 9.