Last updated: 24 September 2026
This Privacy Policy sets out the rules for collecting, processing and protecting Users' personal data when using the Privé game in the browser version (privegame.com), as well as the rules for storing and reading data on Users' Devices (Cookies).
This Privacy Policy is an integral part of the Terms of Service.
§1 Definitions
Service - the Privé platform: the browser version available at https://privegame.com (freemium game: first game free, one-time Privé+ and Privé Max packages).
Administrator - "bidibidibambam sp. z o. o.", ul. Puszkarska 7M, 30-644 Krakow, Poland.
User - a natural person using the Service.
Couple - two Users connected in the game via a private link.
Share link - a short identifier used to pair the second User with the game without creating an account or providing contact details.
Guest session - an anonymous token kept in the browser’s local storage (localStorage) and attached to game requests, which allows using the browser version without an account. It is not a cookie. It is valid for 30 days, and if the User plays during the last day of that period, it is extended by another 30 days.
Device identifier - a random string created in the User’s browser the first time the game is used and kept in the browser’s local storage (localStorage). It is not derived from browser or hardware characteristics and carries no information about the User.
Device - electronic equipment with software through which the User accesses the Service (computer, smartphone, tablet).
Cookies - text data stored as files on the User's Device.
GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
Personal data - any information relating to an identified or identifiable natural person.
Special category data - data listed in Article 9 GDPR; in the context of Privé this concerns information about Users' sexual preferences expressed in their quiz answers and dare interactions.
Anonymisation - an irreversible process making it impossible to attribute a record to a specific person.
Pseudonymisation - processing data so that they can no longer be attributed to a specific person without additional information held separately.
§2 Data Protection Officer
Pursuant to Article 37 GDPR, the Administrator has not appointed a Data Protection Officer. For matters related to data processing, please contact the Administrator directly (§17).
§3 Types of Cookies
First-party cookies - placed by the Service (e.g. language preference, cookie consent status).
Third-party cookies - placed by external services integrated with the Service (list in §7).
Session cookies - removed when the browser is closed.
Persistent cookies - remain on the Device until manually removed or expired (for example, one year for the language preference and the cookie consent status).
§4 Cookie security and control
Mechanism - Cookies use built-in browser mechanisms; they cannot fetch other data from the Device or execute code.
Security - cookies set by the Service’s server carry the httpOnly attribute, so JavaScript cannot read them. The guest session token is not a cookie (§1), so this protection does not cover it.
User control - Users may change cookie settings at any time in their browser (Chrome, Safari, Firefox, Edge, Opera) or in our consent banner.
Consequences of disabling - disabling cookies may prevent use of the browser version of the game (loss of guest session, no quiz answer persistence).
§5 Purposes of cookies
- Maintaining the guest session in the game (a token in the browser’s local storage, not a cookie; necessary - no consent required)
- Remembering language preferences and cookie consent status (necessary cookie)
- Product analytics - anonymous usage measurement (consent cookie)
- Marketing and remarketing on third-party services (consent cookie)
§6 Purposes of personal data processing
Users' data are processed for one of the following purposes:
- Providing the Privé game service - freemium model: first game free, one-time Privé+ and Privé Max packages.
- Sending an invitation to the partner - Users may share a private link with their partner via SMS or email. We do not attach the recipient address to the couple and we do not use it for anything beyond that single send; it only enters the outgoing message log described in §15, which covers every message we send.
- Payments - Stripe Checkout (one-time Privé+ / Privé Max).
- Real-time communication - Mercure Server-Sent Events synchronising the couple's game state across devices.
- Product and marketing analytics - understanding User behaviour (anonymous), product optimisation, advertising campaigns.
- Research and aggregate statistics - analysing anonymous answers from the post-quiz survey to understand trends in couples' preferences, and publishing findings as aggregate statistical summaries (details in §8.4).
- Security and abuse prevention - see §13 (Anti-abuse).
- Crash reporting - anonymous application error reports (Sentry).
- Pursuing the Administrator's legitimate interests.
§7 Cookies and scripts of external services
The browser version integrates scripts and components from the following partners (some may place their own cookies):
- Payments:
- Stripe (USA) - Stripe Checkout for Privé+ and Privé Max packages.
- Security / Anti-abuse:
- Cloudflare Turnstile (USA / EU) - invisible challenge protecting against bots (CAPTCHA alternative).
- Product analytics:
- Marketing:
- Meta (Facebook) Pixel + Conversions API (USA) - measuring conversions of advertising campaigns.
- Email:
- Mailjet (EU) - partner invitation relay (fire-and-forget) and transactional email (purchase confirmation, report link).
- Crash reporting:
- Sentry (EU host) - anonymous error reports.
Services provided by third parties are outside the Administrator's control. These entities may change their terms, privacy policies and cookie usage at any time without the Administrator's consent.
§8 Types of data collected
8.1 Anonymous data collected automatically:
- IP address (used, among other things, in the anti-abuse limits described in §13)
- Browser type (User-Agent), operating system, version
- Browser / device language
- Screen resolution
- Approximate location (based on IP - country/region)
- Pages visited, time spent
- Referrer URL
8.2 Data collected in the browser version (Web):
- Partner names (optional - solely for report personalisation, not required to play)
- Couple profile (fm / mf), chosen intensity level (discover / explore / unleash)
- Quiz answers (sexual preferences - special category data, Article 9 GDPR)
- Device identifier (§1) - sent with game requests and used as the identifier in analytics tools (§7). On the player profile we keep the most recent identifier and the device type (phone, tablet, computer) read from the User-Agent, solely to handle support requests. We delete the identifier stored on the player profile when data is deleted on request (§15); automatic anonymisation does not delete it. The copy in the browser stays until the User clears the site’s data in the browser settings.
- Guest session token (§1) - kept in the browser’s local storage and sent in the header of game requests
- SHA-256 hash of email address (optional - only if the User opts in for an email reminder; we do not store the raw address)
- Email address from the „Send me the report link" form on the blurred report (optional - entered manually). The raw address is stored for a maximum of 7 days (to enable a resend of the link) and is then automatically purged by a scheduled job. Until the couple is anonymised (§15) we keep only the SHA-256 hash of the address - for potential advertising audience matching (Facebook CAPI, Google Customer Match). Legal basis: Art. 6(1)(b) GDPR (service performance - sending the link) and (f) (legitimate interest - campaign measurement). Right to deletion of the hash: contact by email (§18).
- Email address given at payment (couples who bought access only). We keep it in plain form for as long as the access lasts and delete it together with the rest of the couple's data at anonymisation (30 days after access expires, §15). It serves service messages about the purchased service only: purchase confirmation, a notice that report access is about to end, and a notice that it has ended. We send no commercial messages to it - those need separate consent, which we do not collect today. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
- Messages about new challenges (couples who bought access only). We send them to couples who bought access and have not opened their report for a while, on an opt-out basis: we do not ask for separate consent, but every such message carries one-click unsubscribe, and the unsubscribe link also works pasted into a browser. We store the date the permission was granted and what it rests on. Objecting is permanent: once unsubscribed, a couple stays out even after buying again. Legal basis: Art. 6(1)(f) GDPR (legitimate interest - direct marketing of our own services to our own customers), with the right to object at any time (§16). Notices about access running out are sent regardless of this, as they concern performance of the contract, and there is no opting out of those.
- A record of how the report is used - we note when a couple opened their report and what they did there (expanded an activity, jumped to a section, opened the summary). The record holds no text written by the user and is tied to an anonymous couple identifier, not to a person. We use it to answer support requests („I can't see my report"), to account for access, and to improve the game. Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and (f) (legitimate interest - diagnostics and product development). This record does not require cookie consent, because it is created on our side and does not touch storage on your device; the separate statistical measurement in analytics tools runs only after you consent (§7).
- We do not collect: phone number, identifying data, payment data (these are processed exclusively by Stripe).
8.3 Payment-related data:
- Stripe - the Administrator does not store card data or other payment data. From Stripe we receive only: Stripe customer ID, payment status, transaction metadata (amount, currency, package).
8.4 Anonymous post-quiz survey:
- After completing the quiz we may offer you a short, voluntary survey. We store its answers anonymously - we do not link them to your name, email address or a specific couple.
- We reserve the right to use the findings from these surveys publicly - for example in press materials, on our blog, on social media or in marketing communications - solely in the form of aggregate statistical summaries.
- We publish such statistics only once the aggregate covers at least 1,000 couples, so that no individual person or couple can be identified from them. Data prepared in this way are fully anonymised and do not constitute personal data within the meaning of the GDPR.
§9 Third-party access to data
Users' data are not sold to third parties. Access to data - usually under a Data Processing Agreement (DPA) - is granted to the following entities necessary to operate the Service:
- Hosting / Infrastructure - Amazon Web Services EMEA SARL (eu-central-1, Frankfurt) - databases, application, Mercure SSE, Redis.
- Payments - Stripe Payments Europe.
- Invitation SMS - SMSPlanet (Poland).
- Invitation and transactional emails - Mailjet (EU).
- Anti-abuse:
- Cloudflare Turnstile (USA / global network).
- Analytics: PostHog (EU host), Mixpanel (USA).
- Marketing: Meta (USA) - Pixel + Conversions API.
- Crash reporting: Sentry (EU host).
§10 Transfer of data outside the European Union
Some partners listed in §9 are based outside the EU (mainly USA): Stripe, Meta, Mixpanel. Data transfers are based on:
- Standard Contractual Clauses (SCC) approved by the European Commission,
- Adequacy decisions for transfers to the USA (EU-US Data Privacy Framework - for certified entities).
The Administrator prefers EU-hosted partners wherever possible (PostHog, Sentry, Mailjet, AWS Frankfurt).
§11 Legal bases for processing
- Article 6(1)(b) GDPR - performance of a contract (providing the game service, executing payments).
- Article 6(1)(f) GDPR - Administrator's legitimate interests (anti-abuse, analytics, security, own marketing).
- Article 6(1)(a) GDPR - User consent (marketing cookies, optional reminder email).
- Article 9(2)(a) GDPR - User's explicit consent to processing of special category data (sexual preferences - necessary to provide the game service; see §12).
- Polish Act of 10 May 2018 on Personal Data Protection.
- Polish Telecommunications Act of 16 July 2004.
§12 Special category data (Article 9 GDPR)
Given the nature of the service, the Privé game processes information about Users' sexual preferences, expressed in their quiz answers and dare interactions. These are special category data within the meaning of Article 9 GDPR.
- Legal basis - User's explicit consent (Article 9(2)(a) GDPR) given before starting the game. Without this consent, the service cannot be provided.
- Security measures:
- Encrypted SSL/TLS connection for every transmission,
- Pseudonymisation - answers linked to an anonymous couple identifier, not to a person,
- Data are never sold to third parties,
- Partner answers are revealed only when there is mutual agreement - rejected preferences remain secret from the other User,
- Retention as per §15 - the access term set by the package, anonymisation 30 days later, deletion on request at any time.
- User rights - the User may withdraw consent at any time (by contacting the Administrator), which results in immediate cessation of processing and deletion of data.
§13 Anti-abuse and security
To protect the Service against abuse (bots, scrapers, artificial repeated use of the free game), the Administrator employs the following mechanisms in the browser version:
- Cloudflare Turnstile - invisible challenge verifying that the visitor is human, not a bot.
- Per-IP limits - a cap on attempts at points exposed to abuse (for example opening a report from a link, deleting data, sending invitations), counted in Redis over windows of one hour to one day. The Administrator may also switch on a limit of free games per IP address (up to 3 in 30 days).
Legal basis: Article 6(1)(f) GDPR - Administrator's legitimate interest in protecting the Service against abuse.
IP addresses used in these limits are kept only in Redis, with an expiry (TTL) of up to 30 days, and are never combined with data that could identify the User.
§14 Payments
- First game - completely free.
- One-time packages Privé+ and Privé Max - Stripe Checkout. The Administrator never has access to card data.
- Coupon ladder system X→Y - credit of the amount paid for upgrading from Privé+ to Privé Max (TTL 30 days from Privé+ purchase).
- Refunds - pursuant to the Terms of Service; in case of a refund we revoke access to the package.
§15 Data retention period
- Report access has a term set by the package: 14 days from the creation of the report for a free game, 30 days from purchase for Privé+ (buying Privé+ again adds another 30 days on top of the paid access you have left, rather than starting the period over), and 365 days from purchase for Privé Max (a renewal adds another year on top of the access that is left). Couples who bought Privé Max before 31 August 2026 have access without an end date.
- Outgoing message log: every message we send by email is recorded in an internal operational log: recipient address, subject, body, time and delivery status. We use it for accounting and to answer reports such as "we never got the message" or "it arrived twice". After 365 days the
app:mail-log:anonymizecommand, which runs daily, permanently removes the body and the subject from such an entry and replaces the address with an irreversible digest. Only the date, the message type and the delivery status remain. - Anonymisation: 30 days after access ends we remove the couple's personal data: names, contact data and its hashes (including the email address given at payment) and the IP addresses stored with the game. This is done by the
app:web:anonymize-expiredcommand, which runs daily. Couples that never reached a report are anonymised 30 days after the game started. Anonymisation does not remove access tokens (report links, game sessions), device identifiers (§8.2) or data on where the couple came from (country, advertising campaign). Only deletion on request removes those. - Game answers remain after anonymisation, without names or contact data, and feed aggregate statistics only.
- Deletion on request: immediate, on any package, through the link in the report footer and, for paying couples, in the footer of the purchase email. On top of what anonymisation removes, it also deletes access tokens (report access ends at once), device identifiers and data on where the couple came from. It covers both partners and does not entitle you to a refund for a package you bought.
- Privé Max: personal data is removed 30 days after access ends, on the same terms as the other packages; for couples who bought before 31 August 2026 access has no end date, so removal happens on request only. Financial data (invoices) - 5 years pursuant to tax law.
- IP addresses in Redis (anti-abuse): TTL up to 30 days.
- Server logs: 30 days.
- Sentry / PostHog: 30-90 days according to the operator's policy.
§16 User rights
Each User has the following rights under the GDPR:
Right of access (Article 15 GDPR) - information about the data being processed.
Right to rectification (Article 16) - correcting inaccurate data.
Right to erasure ("right to be forgotten") (Article 17):
- on your own - the "delete our data" link in the report footer works on every package and takes effect straight away,
- automatically - anonymisation 30 days after report access ends,
- Paid couple - by email request to the Administrator.
Right to restrict processing (Article 18) - temporary suspension of processing in cases listed in the GDPR.
Right to data portability (Article 20) - receiving data in a structured format (JSON / CSV).
Right to object (Article 21) - to processing based on legitimate interest (analytics, marketing).
Right to withdraw consent (Article 7(3)) - at any time; applies, among other things, to consent for processing special category data (Article 9) and marketing cookies.
Right to lodge a complaint with a supervisory authority - Polish President of the Personal Data Protection Office (uodo.gov.pl) or the supervisory authority in your country of residence.
All requests should be sent to the Administrator's email address (§17). We respond within 30 days.
§17 Contacting the Administrator
Postal address - bidibidibambam sp. z o. o., ul. Puszkarska 7M, 30-644 Krakow, Poland
Email - prive@privegame.com
§18 External links and User-generated content
The Service may contain links to external sites with which the Administrator does not cooperate. These links and any pages or files referenced may pose a risk to your Device. The Administrator is not responsible for content located outside the Service.
§19 Changes to the Privacy Policy
The Administrator reserves the right to amend this Privacy Policy.
Material changes (concerning processing purposes, third parties or User rights) are announced by publishing the updated version on this page at least 7 days before it takes effect. The Service has no accounts and no mailing list, so there is no channel for notifying Users individually.
The current version of the Privacy Policy is always published on this page with the date of last update.
Continued use of the Service after the introduction of changes constitutes acceptance of those changes. If the User does not accept the changes, they should stop using the Service.