Privacy policy
This is a translation; if it differs from the Serbian version, the Serbian version applies.
In short
- You play right away, with no sign-up: the server gives you a random identifier and a nickname. We never ask for your name, email or phone number.
- Signing in with Google Play Games is optional. Once you do, your Play Games profile name stands in your seat instead of the nickname.
- Players in your room see your name, animal, level, answers and points. Nobody outside the room sees them.
- No ads. We never sell your data or give it to advertisers, or to anyone for advertising or marketing.
- You turn analytics off with the Statistics switch on the About screen.
- You delete your account yourself, in the app, or by email (Account deletion).
1. Who the controller is
The controller of the data processed in Kvizić, under Serbia's Law on Personal Data Protection, is:
Nikola Tokić (toleapps)
Slavka Rodića 11, 11000 Belgrade, Serbia
Email: application.eili@gmail.com
Here "we" is the controller and "you" the player. The game is available on Android through Google Play; versions for iPhone and the browser come later. This policy covers every version of the game and this site.
2. What we process and why
Playing as a guest
The first time you open the game, the server creates a player with a random identifier, a nickname (an adjective and an animal, such as "Брзи јеж", the quick hedgehog) and an animal for a picture. The device gets two session tokens: an access token valid for 15 minutes and a refresh token valid for 30 days, replaced every time it is used. The tokens are kept in the app's storage on the device (in a browser, its localStorage).
For each session the server keeps a hash of the current and the previous refresh token (never the tokens themselves), when the session was opened and when the tokens expire. It keeps nothing else about the device, neither its model nor its operating system.
Only on the device, never on the server, we keep the game's language, whether sound is on and your analytics choice.
With every request the app sends its platform (Android, iOS, web or desktop) and its version number, so the server can ask an outdated version to update. The server does not keep them.
Why: so the game knows it is you without a sign-up, and keeps your statistics.
Signing in with Google Play Games (optional)
Google Play Games (Google Play Games Services) is Google's service for games on Android. If you are signed in to Play Games on your phone, the game signs you in through it by itself. The app gets a one-time code from Play Games, and the server exchanges it with Google for your Play Games player identifier and your profile name. We keep that identifier, with when it was linked to your player, and the profile name, which replaces your nickname in the game and is refreshed at every sign-in. We do not keep the tokens Google issues in the process.
Signing in links the profile to the guest you are playing as, so you keep everything you did as a guest. If the profile is already linked to another player in the game, signing in switches you to that player and the guest stays behind (see how long we keep data). The link is permanent and for now can only be undone by deleting the account.
Why: so you can carry on with the same statistics on another device, and players know you by name.
Rooms and games
While you are in a room, the server holds in memory what the room needs: who is in it, who hosts, its settings and its name if the host gave one, your answers to the current question, when you answered and your points, kick votes and who was kicked. All of it is gone when the room closes; none of it is written to the database.
When a game ends, the server writes to the database:
- the game: when it started and ended, how many questions it had, the time to answer, its topics and how many players; no player is in it;
- your result in it: your points, how many answers you gave and how many were right, your place and whether you played it to the end;
- your statistics: games played and won, answers given and right, overall and per topic, experience (level), solo games and your best solo score at each difficulty, with its date;
- the questions you have seen: which, when last and how many times.
How players answered a question is counted only in total, never who answered what, to tell how hard the question is.
Why: so the game works. The server picks questions you have not seen yet, counts points and places, and shows you your statistics and level.
What other players see
Players in the same room see your name (the nickname or your Play Games profile name), your animal, level, whether you host, which answer you picked once answers are locked in, your points, your place and the reactions you send. The other players' apps also receive your player's random identifier, to tell players apart; it is not shown on screen.
In the list of public rooms, anyone playing sees a room's name if it has one, its host's name and animal, and its settings. A private room is not listed; anyone who knows its six-digit code sees the same before joining. The server cleans a room's name and refuses offensive ones, as it does players' names.
Question reports
When you report a question, we keep which question and which revision, the reason from the list (wrong answer, typo, ambiguous, offensive, other), when and by whom it was reported, and when and how a moderator resolved it. No free text is sent. The moderator sees reports in total, by reason, never who sent them.
Why: to fix or remove wrong questions.
IP address and server logs
The game's server runs at Render, in Frankfurt. Render puts Cloudflare's network in front of its services, so every request from the game passes through it: Render and Cloudflare see your device's IP address and the request's technical details (time, address requested, app or browser version). Cloudflare was engaged by Render, as its provider, not by us.
We use the IP address only in the server's memory: to limit how many requests and connections one address may make, and to stop room codes being guessed. Those counters vanish when they expire and at every server restart. We never write the IP address to the database or to our logs.
Server logs record each request's method, address (which may contain a room code), response and duration, and technical errors. Where an event needs tracking they name identifiers only, such as a player's when we refuse a request over a limit or when they delete their account. We never log tokens, names or question text.
Why: security and the game working properly.
Analytics (PostHog, EU)
To see what works in the game and what confuses, the app sends usage events to PostHog, to its servers in the European Union: when you open and leave the app, screens opened and left and how long you spent on them, taps on buttons (with what you chose on them, such as the number of questions, the time, the difficulty, a topic or a reaction), errors shown, entering and leaving a room and how, games finished (your place, the number of players and questions, whether solo), changes of language and sound, signing in with Play Games and deleting the account. With them go the app's version, the platform, the operating system and its version, the device type and the game's language.
Events are tied to a random identifier made on the device and, once you sign in with Play Games, to your player's identifier in the game, which is random too. They never contain your name, a room code, a room name, a question's text or anything you type. Requests reach PostHog from your device's IP address: PostHog derives an approximate location from it (country and city), so we can see where players come from.
Analytics is on by default. You turn it off with the Statistics switch on the About screen, under Data (Home, the settings icon, then About): while it is off the app sends no event at all, and your choice is kept on the device.
Why: to fix bugs and make the game better.
When you write to us
If you email us, we use your address and message only to answer you and settle your request. We receive email through Google's Gmail.
This site
This site uses no cookies or analytics and loads nothing from other services. It is hosted by Render, which may record visitors' IP addresses in its technical logs.
What we do not collect
We never ask for your full name, email, phone number, contacts or photos. There is no chat in the game: players cannot write to each other, and reactions are fixed. We do not determine your precise location or use GPS; only analytics (PostHog) derives an approximate location from the IP address, as described above. The game has no ads, no advertising identifiers and no purchases: nothing is paid for and we process no payment data.
3. Legal basis
- Performance of a contract (Article 12(1)(2) of the Law on Personal Data Protection; Article 6(1)(b) GDPR): playing as a guest, sessions, signing in with Play Games, rooms, results and statistics. Without them the game cannot work the way you use it.
- Legitimate interest (Article 12(1)(6); Article 6(1)(f) GDPR): security and rate limits, server logs, question reports, and analytics to improve the game. You may object to this processing, and you can turn analytics off yourself with the Statistics switch.
- Legal obligation (Article 12(1)(3); Article 6(1)(c) GDPR): when the law requires us to keep data or hand it to an authority.
4. Who else sees the data
We never sell or rent data, give it to advertisers, or share it for advertising or marketing. Apart from the players in your room (above), only these providers have access:
- Render
- hosting of the server, the database and this site; the server and database are in Frankfurt, Germany. Render puts Cloudflare's network in front of its services, which therefore sees IP addresses and requests. Render's privacy policy · Cloudflare's
- PostHog
- analytics, on servers in the European Union. Privacy policy
- Google Play, where you get the game, Google Play Games, for signing in, and Gmail, through which we receive email. Privacy policy
Render, with the Cloudflare it engages, and PostHog process data on our behalf, as processors. Google Play and Google Play Games are Google's own services: the data they process, Google processes under its own terms and privacy policy. When the iPhone version comes out, Apple's services will be listed here too.
The moderator sees questions and reports in total, never who sent them. We give data to public authorities only when the law requires it.
5. Transfers to other countries
The server and database are in the European Union. Render, PostHog and Google are based outside Serbia and the EU, and some of their networks, as well as Cloudflare's, run worldwide, so data may be transferred to other countries, above all the United States. We base such transfers on the safeguards the law provides, such as standard contractual clauses or an adequacy decision.
6. How long we keep data
- A player linked to Google Play Games: until you delete it.
- A guest: until you delete it. A guest no device has used for 90 days (the app was removed, has not been opened for long, or you signed in to another player on that device) is deleted by itself, with all its data.
- Sessions: while the player exists. A refresh token stops working after 30 days unused.
- Results, statistics and questions seen: while the player exists.
- Games: for good, but no player is in them; once you delete your account, no record links a game to you.
- Question reports: for good, as a question's history; once you delete your account, a report stays without its reporter.
- A room's state (who is in it, answers to the current question, its name, votes and kicks): in the server's memory, until the room closes.
- Rate-limit counters: in the server's memory, until they expire.
- Server logs: as long as Render keeps them, at most 30 days.
- Analytics: at most two years from when an event was sent, then deleted.
- Email correspondence: until the request is settled, then at most three years, the limitation period for damage claims.
Removing the app from a device does not by itself delete the account.
7. Security
The connection to the server is HTTPS, and during a game an encrypted socket (WSS); to enter a room the app gets a one-time pass valid for 30 seconds, so nothing secret is in the connection's address. We keep refresh tokens only as SHA-256 hashes, so even someone who reached the database could not use them. On the device the tokens are kept in the app's ordinary storage, not in the operating system's vault, because the game keeps nothing sensitive: whoever has your unlocked device can play as you. No measure is perfect, so if you notice anything suspicious, write to us.
8. Your rights
Under the Law on Personal Data Protection (Official Gazette of the Republic of Serbia, No. 87/2018) and, if you live outside Serbia, under your country's law, you have the right:
- of access: to learn what data about you we process and get a copy;
- to have inaccurate data corrected;
- to erasure: you delete your account yourself, in the app, or by email (how);
- to restrict processing;
- to portability: to get your game's data in a machine-readable form;
- to object to processing based on legitimate interest, analytics included;
- to withdraw consent, where any processing rests on it;
- to complain to the Commissioner for Information of Public Importance and Personal Data Protection (www.poverenik.rs) and, if you live in another country, to its supervisory authority.
Send your request to application.eili@gmail.com with your account ID: in the game it is on the About screen, under Data, where one tap copies it. We answer without delay, within 30 days at most.
9. Age
The game is meant for people aged 13 and over. If you are under 13, please do not use it. If we learn an account belongs to someone younger, we may delete it. A parent or guardian can write to us at application.eili@gmail.com.
10. Changes to this policy
If we change this policy, we publish the new version on this page and change the date at the top. We may also tell you about important changes in the game.
Questions? Write to us.