Privacy Policy
This policy explains how FREEDOM LLP ("we", "us") handles personal data when you play Knowtilus: Trivia Quiz Game (the "app"). It is written to be read. If anything is unclear, write to us at office@freedomgaming.co.
Effective date: 5 October 2026.
In short.
- You can play as a guest, with no email address, name or password. If you save your player, we store the email address and a scrambled form (a hash) of the password you chose, or the ID of the Google, Apple, Game Center or Google Play Games account you signed in with. We never ask for your name, phone number, date of birth, contacts, photos, camera, microphone or location, and the app does not ask your device for them.
- Opening the app for the first time creates nothing. When you tap I agree on the first screen, our server creates a player with a random ID and a generated nickname such as "Brave Narwhal 42". You cannot type a nickname. Logging in never makes a player, and nothing else does: every player is made by your own tap on I agree.
- We store the answers you type, with their scores and how long you took.
- An answer that is new to us is checked by an AI model run by OpenAI. What is sent is the prompt and the answer only, with nothing that identifies you or your device.
- The app contains no advertising, no analytics or tracking software, no crash-reporting software and no purchases today. Section 12 says what would change if we add any of these.
- You can delete your data yourself, in the app, at any time. That deletes your sign-in details too.
1. Who is responsible#
The controller of your personal data is FREEDOM LLP, the publisher of Knowtilus: Trivia Quiz Game.
- Company registration: company number OC407608, registered in England and Wales
- Address: 101 King's Cross Road, London WC1X 9LP, United Kingdom
- Privacy requests and questions: office@freedomgaming.co
- Data-protection contact: no data protection officer is appointed; write to office@freedomgaming.co
2. What we collect#
A guest player does not tell us who you are. The data below is still personal data under laws such as the GDPR, because it is tied to an identifier that lives on your device. A saved player is also tied to an email address or to an account at Google, Apple, Game Center or Google Play Games, which can tell us which player is yours. We treat all of it as personal data.
| Data | What it is and where it comes from | What we use it for |
|---|---|---|
| Player ID and sessions | When you tap I agree on the Terms screen (the first screen of the app, and the screen the app shows again before it makes any new player), our server creates a player and sends back a random player ID and two signed sign-in tokens: an access token that lasts 1 hour, and a refresh token that lasts up to 60 days and is replaced every time it is used. The app keeps them in your device's secure storage (the iOS Keychain, or the Android Keystore) and sends the access token with each request. Of a refresh token we store only a one-way hash (SHA-256) with the time it was made and when it ends, never the token itself. If an old refresh token is used again, we treat it as stolen and end every session of that player. | To recognise your device from one day to the next, keep your progress and rank, keep other people's requests away from your data, and end your sessions: on this device when you log out of a saved player, and on every device when you reset your password or delete your data. |
| Account details | Whether your player is a guest or saved, when it was saved, and a credential counter that ends old sessions when a password is reset. | To run accounts and keep them secure. |
| Email address | Only if you save your player by email, or sign in with Google or Apple. The address you typed, or the address that Google or Apple vouches for (Apple may give a private relay address that forwards to you). Stored in lower case with the time it was confirmed. An address counts only once it is confirmed. | To sign you in, to send the one-time codes you ask for (section 5) and to protect the account. We do not use it for marketing and send no newsletters. |
| Password | Only if you chose email and password. We store a salted bcrypt hash, from which the password cannot be read. We do not store the password itself. | To check your password when you log in. |
| Sign-in IDs from Google, Apple, Game Center and Google Play Games | Only for the services you use. The ID that the service gives your account for our app: Google's account ID (we ask Google only for it and for your email address, not for your name, picture or contacts); Apple's user ID for Sign in with Apple; the Game Center player ID, which Apple scopes to a developer team, so the same person has the same Game Center ID in every title published by FREEDOM LLP (our Apple developer team); Google's Play Games player ID. We do not read your Game Center or Google Play Games name, picture, friends or achievements. | To recognise the same account on another device, and so that one account cannot be attached to two players. We use these IDs only to recognise your player in this app. |
| Emailed codes | When you ask to save your player by email or to reset a password, a short-lived record: a hash of the 6-digit code, the address, the time, and, when you save by email, a bcrypt hash of the password you chose. A Google link, or a Google log in to a player that exists, leaves a similar record, with the Google account ID and email address, that lives for minutes. A Google log in that finds no player keeps nothing at all: no record is stored and no player is made. | To check that you control the address, and to attach a Google account to the player that asked. |
| Generated nickname | Chosen by our server when the player is created: an adjective, a sea creature and two digits. Nicknames are not unique and say nothing about who you are. Other players see yours on the daily leaderboard. | To show your place on the leaderboard. |
| Activity times | When the player was created and when it was last seen (refreshed at most every ten minutes while you use the app). | To run the service, to delete inactive players (section 7) and to count how many players we have. |
| Your answers | For every prompt: the text you typed (the first 100 characters), a normalised form of it (lower case, no punctuation or accents, typos and plurals merged with known answers), which prompt and day it belongs to, whether you skipped it, whether it fitted the prompt, and the result: depth in metres, the estimated share of players who gave the same answer, and the rarity tier. Also the time you took, as measured by the app. | To score your dive, work out how rare an answer is, build the daily leaderboard and the "what others said" lists, keep the game fair, and handle reports. |
| Anonymous answer statistics | Per prompt: how many players gave each answer, and whether an answer fits the prompt (the verdict of section 4). Neither is linked to a player. | To estimate how rare an answer is, and to avoid asking the AI model the same question twice. |
| Technical data | Your IP address and the usual details of a network request (time, address requested, result, the app's user-agent text). The app does not send an advertising ID or any other device identifier. Your IP address is used for rate limiting, held in memory in windows of up to 15 minutes (the limits on emailed codes use the longest), and appears in the access logs of our web server. Our software does not store it in the game database or attach it to your player. | To answer your request, to stop flooding and abuse, and to diagnose faults. |
| Reports | If you report an answer: which answer, the reason you chose, the time, and your player ID. | To review the report and act on it, as the Terms of Service describe. |
| What you send us | If you write to us: your email address, your message, and anything you attach or tell us. | To answer you and to handle your request. |
We do not collect your name, phone number, postal address, date of birth, precise or approximate location, contacts, photos, files, audio, health data, payment details, advertising ID or browsing history, and the app requests no such permission from your device. We collect an email address only in the cases of the table above, and when you write to us.
What other players can see#
- The daily leaderboard shows the nickname, total depth and rank of every player who finished the day's dive. It never shows a player ID.
- "What others said" lists the most common answers to a prompt and how many players gave each. It names nobody. An answer typed by players is shown to others only if it is on our list for that prompt or has passed the check of section 4 and our safety check for offensive text. If the safety check cannot run, the answer is still scored but is not shown.
- Sharing. The Share button opens your device's share sheet with a short text (your total depth and your rarest answer). It contains neither your nickname nor your player ID, and it goes only where you send it.
- Your sign-in details. Nobody else sees your email address, your password hash or your sign-in IDs.
What stays on your device#
Only the session and what the sign-in screens need, in secure storage: your player ID, nickname and the two sign-in tokens; the version of the Terms you accepted; the guest players you logged out of on this device, so that you can continue them from the welcome screen; the last Game Center or Google Play Games player ID the app saw, to notice when you switch game account; and whether you logged out on purpose. The app uses no cookies and no other persistent identifiers.
Signing in with Google, Apple, Game Center or Google Play Games#
- When your player is made. Opening the app for the first time creates no player and no sign-in. The first screen shows our Terms of Service, and until you tap I agree the app does not sign you in, does not contact Game Center, Google Play Games, Apple or Google, and asks our server only for its public settings (a request that, like every request, appears in the access log described under "Technical data" in section 2). On Android the Google Play Games component built into the app is not started before that tap either. Tapping I agree is what creates your player, and a player can do nothing until it has agreed to the Terms. Every player is made by your own tap on I agree, and nothing else makes one or agrees for you. After you log out, after we end a session or after you delete your data, the welcome screen's Continue as guest only shows you the Terms again, whatever the app remembers of an earlier agreement; the player is made when you tap I agree there. Log in only opens a player that already exists. If you log in with a Google, Apple or game account that has no player, no player is made, our database keeps no record of the attempt, and the app tells you so; you start from the Terms screen. When the app signs you in again without a tap (see below) it only opens the player that account already has; it never makes one. If our server has deleted your player, for example after 400 idle days, the app does not make a new one: it shows the Terms again, as on a first launch, and nothing is made until you tap I agree.
- Game Center and Google Play Games. On a device that is already signed in to one of them, the app uses that game identity when you tap I agree: it opens the player that game account already has, or creates one if it has none, and asks you nothing more for that. The app asks Apple to sign your Game Center player ID for our app and sends us the signature, which our server checks by downloading Apple's public certificate. For Play Games the app gets a one-time code from Google, and our server asks Google whom the code belongs to. Without such an identity, the tap on I agree creates a guest player. Once you have agreed and the game is open, the app also checks, when it starts, when you come back to it and (on iPhone) when Game Center reports a change, which game account is signed in on the phone. If it is a different account from the one your player was made for and that account already has a player, the app switches to that player; if the account has none, nothing is made and you stay where you are. If your sign-in ends (for example after a password reset on another device) and your player was made with a game account, the app signs you back in to the same player through that game account without a prompt; it asks our server for that one player only, and if another game account is on the phone, or none, nothing is opened or made and you log in again. If the app cannot reach our server for that, it keeps trying later and does not sign you out. The Log in screen also has a button for your game account, which opens the player that account already has and, if it has none, makes nothing.
- Google. The app opens Google's own sign-in page in a secure system browser window. You type your Google password there, never in the app. Google tells our server your account ID and your email address, and Google learns that you signed in to our app.
- Apple. Sign in with Apple uses Apple's own dialog, where you choose what to share. Apple gives our server your Apple ID for our app and, the first time, your email address or a private relay address.
This website#
The legal and support pages are static web pages. They set no cookies and load no scripts, fonts or images from other sites. The company that hosts them, DigitalOcean, may keep ordinary access logs.
3. Why we use your data, and our legal bases#
If the GDPR or the UK GDPR applies to you, these are the legal bases we rely on.
| Purpose | Legal basis |
|---|---|
| Creating your player (guest or saved), signing you in with the method you chose, running the daily dive, scoring, the leaderboard and the answer lists | Performance of our contract with you: the Terms of Service (Article 6(1)(b)) |
| Keeping accounts secure: checking passwords, sending codes, limiting sign-in attempts and emails, ending sessions | Performance of the contract, and our legitimate interest in keeping accounts safe (Article 6(1)(b) and (f)) |
| Checking whether a new answer fits its prompt (section 4) | Performance of the contract, and our legitimate interest in scoring fairly (Article 6(1)(b) and (f)) |
| Keeping the game secure and fair: rate limiting, preventing cheating and abuse, moderating answers, handling reports, enforcing the Terms, defending legal claims | Our legitimate interests in a safe and fair game (Article 6(1)(f)); a legal obligation where the law requires it (Article 6(1)(c)) |
| Counting daily and returning players, finding and fixing faults, improving the game | Our legitimate interest in running and improving the service (Article 6(1)(f)) |
| Answering your messages and requests | Our legitimate interest in supporting you, and legal obligations for rights requests (Article 6(1)(f) and (c)) |
| Complying with legal requests | Legal obligation (Article 6(1)(c)) |
| Optional features that ask your permission (section 12) | Your consent, which you can withdraw at any time (Article 6(1)(a)) |
We do not make decisions about you that have legal or similarly significant effects. The AI check of section 4 decides only whether an answer counts in the game.
4. Answer checking with OpenAI#
Rarity is only fair if an answer really fits its prompt: "papaya" is a rare answer to "Name a type of pasta", but it is not pasta. So when an answer is new, an AI model checks it.
When. Only when the answer is not on our prepared list for that prompt and we have no stored verdict for it yet. Every distinct answer to a prompt is judged once, ever, and the verdict is stored and reused. Most answers never leave our servers.
What is sent. Our fixed instructions, the text of the prompt (for example "Name a type of pasta"), and the normalised form of the answer (at most 40 characters and five words). The request is made by our server to OpenAI's chat completions service (api.openai.com).
What is not sent. Your player ID, nickname, email address, IP address, sign-in tokens, device details, the time you took, or anything else about you. OpenAI sees the network address of our server, not of your device.
What comes back. A yes-or-no verdict: the answer fits the prompt or it does not. We store the verdict with the prompt, the normalised answer, the model's name and the date, with no link to you.
OpenAI's role and retention. OpenAI processes this data for us as a service provider under its own API terms. When we wrote this policy, OpenAI's published terms said that it may keep API inputs and outputs for up to 30 days to provide the service and to detect abuse, and that it does not use API data to train its models unless the customer opts in. Our service does not opt in, and it does not use OpenAI's optional zero-data-retention or modified abuse-monitoring controls. We therefore cannot promise that OpenAI deletes a request immediately. Read OpenAI's current terms and privacy policy at https://openai.com/policies/ for the details, which OpenAI can change.
If the check is not possible. When OpenAI cannot be reached, the app tells you to try again or to type a different answer. We do not store or score that answer in the meantime.
Your choices. There is no switch to turn the check off, because it is what decides whether a new answer counts. If you do not want a particular answer to be sent, skip that prompt: an empty answer scores 0 m and sends nothing. Please do not type personal information into an answer.
Mistakes. The model can be wrong. If you think an answer was judged wrongly, write to us with the prompt and the answer. A person can correct the stored verdict, and it then applies to everyone.
5. Who we share data with#
- Hosting. Our servers and database are run by DigitalOcean, in Frankfurt, Germany (EU). It stores and processes the data described in section 2 on our behalf.
- OpenAI. Only what section 4 describes.
- Email. If you write to us, the provider of the mailbox behind office@freedomgaming.co handles your message on our behalf.
- Email delivery. Resend (sending from Ireland, EU) sends the emails that carry your codes. It receives your email address and the text of the message, and keeps delivery logs for the provider's own retention period for delivery logs (we do not control it).
- Google. If you sign in with Google, Google receives your sign-in and tells us your account ID and email address. If you use Google Play Games, our server asks Google whom a one-time code belongs to. Google's privacy policy applies to what Google collects.
- Apple. If you use Sign in with Apple or Game Center, Apple tells us your Apple ID for our app, or signs your Game Center player ID for us. Our server downloads Apple's public certificate to check that signature. Apple's privacy policy applies to what Apple collects.
- Apple and Google as stores. They distribute the app and, if you have chosen to share diagnostics with app developers, may pass us reports that do not contain your player ID. Their own privacy policies apply to what they collect.
- Other players. Only what section 2 lists under "What other players can see".
- Authorities and advisers. When the law requires it, to answer a valid legal request, or to establish, exercise or defend legal claims, and to our professional advisers under a duty of confidentiality.
- A successor. If we sell or reorganise the business, the data may move to the new owner, who must respect this policy.
We do not sell your personal data. We do not share it for cross-context behavioural advertising.
6. Transfers outside your country#
Your data may be processed in countries other than the one where you live.
- OpenAI may process answer checks in the United States: we use OpenAI's standard endpoint and have not selected a regional data-residency option.
- Google, Apple and our email delivery provider may process what they receive from you or from us in other countries, including the United States, under the safeguards they provide.
- Our hosting is in Frankfurt, Germany (EU).
- The app connects to our servers from wherever you are.
Where the GDPR or the UK GDPR requires a safeguard for a transfer, we rely on one that the recipient provides: an adequacy decision or a certification under the EU-US Data Privacy Framework, or standard contractual clauses, with the UK addendum where needed. Ask us for a copy of the safeguards at the address in section 14.
7. How long we keep data#
| Data | How long |
|---|---|
| Player record (ID, nickname, times), the sign-in details (email address, password hash, sign-in IDs) and the scores, answer keys and timings linked to it | While you keep playing. Deleted automatically 400 days after your last activity, a saved player included, or earlier when you ask. |
| Sessions (refresh tokens) | Each lasts up to 60 days from the last time it was used. Logging out of a saved player ends the session on that device at once; a password reset or deleting your data ends your sessions on every device at once. A guest that you log out of keeps its session on your device, so that you can continue it from the welcome screen: that session ends when its 60 days run out, or when you delete your data. The record of an ended session is removed when its 60 days run out (deleting your data removes the records at once). |
| Emailed codes and pending requests | A code and its pending request (the address you typed and, when you save by email, the bcrypt hash of the password you chose) are marked as used when you use them, and are removed by the database when they expire: 15 minutes after they were made, plus the minute or so the database takes to sweep expired records, so at most about 16 minutes. A pending Google link lasts 5 minutes and a Google sign-in code 2 minutes, and they are removed the same way. |
| The text you typed, exactly as you typed it | 12 months from the day you submitted it, then erased. The score, normalised answer and timing stay with the player record. |
| Anonymous answer statistics and AI verdicts | Indefinitely. They contain no player ID. |
| Reports and moderation records | 24 months after the case is closed. A report you filed is deleted sooner if you delete your data. |
| Web server access logs (these hold IP addresses) | 30 days |
| Application logs (these hold normalised answers and prompt IDs, never a player ID) | 30 days |
| Backups | Rolling 30 days. Data you delete leaves the backups when they expire, at most 30 days later. If we ever restore a backup, we delete again what has been deleted since. |
| Emails you send us | 24 months after the last message in the conversation |
| Delivery records of the emails we send you (codes) | the provider's own retention period for delivery logs (we do not control it), at the email provider |
| The record that a deletion or rights request was made (date, player ID, outcome) | 24 months, to show that we answered it and to re-apply it after a backup restore |
| The copy at OpenAI | Up to 30 days, under OpenAI's terms at the time of writing (section 4) |
We may keep data longer when the law requires it, or when we need it to establish, exercise or defend a legal claim.
8. Security#
- All traffic between the app and our servers uses HTTPS.
- On your device, the session is kept in secure storage (the iOS Keychain or the Android Keystore).
- Sign-in tokens are signed and short-lived (an access token lasts 1 hour). Refresh tokens are stored only as hashes. A password reset ends every session of the player, on every device.
- Passwords are stored only as bcrypt hashes. The API limits how many requests, sign-in attempts and emails one address can make.
- Access to the database and the admin tools is limited to the people who run the service, needs a login with a role, and every change made in the admin tools is written to an audit log.
No system is perfectly secure. If a breach puts your rights at risk, we will tell the people concerned and the authorities as the law requires.
9. Your rights#
If the GDPR or the UK GDPR applies to you, you have the right to:
- ask whether we hold data about you and get a copy (access);
- have wrong data corrected (rectification). The nickname cannot be edited, but you can delete your data and start again;
- have your data deleted (erasure);
- ask us to restrict how we use it;
- receive the data you gave us in a common electronic format (portability);
- object to processing that rests on our legitimate interests;
- withdraw a consent at any time, without affecting what was done before;
- complain to a data-protection authority: in the UK the Information Commissioner's Office (https://ico.org.uk), in the EU the authority of the country where you live, work or believe the problem happened.
How to use them.
- The fastest way to delete: open the app and choose Delete my data. See Delete your data.
- For anything else, write to office@freedomgaming.co and include the player ID shown in the app (the About and support screen, reached with About on the home screen). Because we hold no name for you, the player ID is how we know the data is yours. If you saved your player with an email address, write from that address. A nickname alone is not enough: nicknames are public and can be shared by several players.
- We answer within one month. We can extend that by two months for complex requests, and we will tell you why.
- It costs nothing, unless a request is clearly unfounded or excessive.
10. California and other US states#
This section is for residents of California and of other US states whose laws give similar rights.
- What we collected in the last 12 months. Identifiers (player ID, generated nickname, IP address in server logs, and for a saved player the email address and the Google, Apple, Game Center or Google Play Games ID); account log-in credentials (the hash of a password); internet or other electronic network activity (your answers, their scores and timings, activity times). The account log-in (email address with a password hash) is the one item that California law may class as sensitive personal information: we use it only to give you the service and to keep the account secure. We collect the rest directly from your device, and the sign-in IDs and a vouched email address from Google or Apple at your request.
- Why, and who receives it. For the business purposes in section 3. Our service providers (hosting; OpenAI, which receives no personal identifiers; the mailbox provider; the email delivery provider) receive it under contracts that limit their use.
- Sale and sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. If that ever changes, section 12 will say so first and we will offer the opt-out.
- Your rights. To know what we collected, to have it deleted, to have it corrected, and not to be treated worse for using these rights. Use the routes in section 9. An authorised agent can write on your behalf; we will ask for the player ID and for proof of the agent's authority.
- Signals. The app does not track you, so it has nothing to switch off when your device sends Global Privacy Control or Do Not Track.
- We give residents of other US states the same rights.
11. Children#
Knowtilus: Trivia Quiz Game is for people aged 13 and over and is not directed to children. We do not ask for your age and we do not knowingly collect data from anyone under 13. If we learn that a player is under 13, we will delete their data. If you are a parent or guardian and think your child is playing, write to us and we will delete it. Where the age of majority is above 13 in your country, you need the permission of a parent or guardian to accept our Terms.
12. Features that are not in the app yet#
The app today has none of the features below. Each one is described here so that you can see what would change before it does. We will update this policy, and where the law requires it ask for your permission, before a feature goes live.
When enabled: daily reminders and push notifications. A reminder that you set up in the app is a local notification: your device shows it at the time you chose, and no data leaves your device. If we later add notifications sent from our servers (for example a challenge from another player), we will store a push token that Apple or Google gives your device, linked to your player ID, and use it only to send notifications you allowed. The token is deleted when you turn notifications off, when Apple or Google reports it as invalid, or when you delete your data. Legal basis: your consent.
When enabled: advertising. If we show ads, we will use an advertising service, which we will name here, with a link to its privacy policy, before any ad appears. It may receive your IP address, device and ad-interaction data and, only if you allow it, your advertising ID. On iOS we will ask for your permission through Apple's tracking prompt, and in the EEA, the UK and Switzerland through a consent prompt, before any personalised ad. You will be able to change your choice in the app. Rewarded ads will be optional and will never change what an answer scores or what you can win.
When enabled: purchases. If we sell anything, Apple or Google will take the payment and we will never see your card or account details. We will receive a confirmation of what was bought, tied to your player ID, so that we can unlock it and restore it. Anything sold will have fixed contents and a fixed price. Nothing sold for real money will be random.
When enabled: crash reports. If we add crash reporting, we will name the service here, and it will receive technical details of a crash (app version, operating system version, device model, what the app was doing) and will not receive your player ID or your answers. We will state how long it is kept before it is switched on.
When enabled: progression, collections and streaks. We will store, linked to your player ID, your level and depth record in each category, your daily streak, your collection (trophies, chests, in-game currency and cosmetics), and a ledger of what you earned. When you are the first player ever to give a valid answer, we may record you as its discoverer and show your nickname next to that answer. This data is deleted with your player.
When enabled: playing against other people. In a match, your opponent sees your generated nickname and, after each round, your answer. Bots may fill seats and are always labelled as bots. We may store a recorded match so that another player can later face a replay of your answers, under your generated nickname and labelled as a replay. You will be able to report and block players. A block is stored on our server against your player ID. Matches use the same player, guest or saved; there is no chat and no free-text name.
13. Changes to this policy#
We will change this policy when the app or the law changes. The date at the top shows when it was last updated. If a change matters to you, for example a new kind of data or a new recipient, we will tell you in the app before it takes effect and, where the law requires it, ask for your permission.
14. Contact and complaints#
Write to office@freedomgaming.co, or by post to 101 King's Cross Road, London WC1X 9LP, United Kingdom. For help with the game itself, see Support. If you are not happy with our answer, you can complain to the data-protection authority named in section 9.