← educatedguess.app Educated Guess
Privacy Terms Support
Privacy

Privacy Policy — Educated Guess

Last updated: 18 August 2026

This Privacy Policy explains how Educated Guess handles data in the Android app (an iOS release is planned) and on educatedguess.app.

Summary

  • You can play without creating an account.
  • The app automatically collects pseudonymous product analytics and technical diagnostics.
  • If you sign in, your progress is synchronized and analytics may be associated with a pseudonymous account UUID.
  • Rewarded ads are optional, but an ad may be preloaded before you press the ad button.
  • Purchases are processed by Google Play or the Apple App Store. We do not receive full payment-card details.
  • The website uses privacy-focused Plausible Analytics without cookies or persistent visitor identifiers.
  • If you join an early-access list, we store your email with MailerLite. Android and iOS are separate lists.
  • We do not sell personal data.

1. Controller

The controller is:

Bartłomiej Nycz, sole trader operating under the business name Kvalito Solutions Bartłomiej Nycz, registered in CEIDG, Poland.

  • Address: ul. Blokowa 39, 43-316 Bielsko-Biała, Poland
  • Tax ID (NIP): 5492189944
  • Contact: contact@educatedguess.app

2. Website and Plausible Analytics

The website uses Plausible Analytics to understand aggregate traffic, such as page views, referring sites, countries, browsers, devices, and configured page events. On a successful waitlist submit the site records a non-identifying custom event named waitlist_signup. That event does not include your email address or other personal data.

Plausible does not use cookies or persistent visitor identifiers. It processes an IP address transiently to produce aggregate measurements and location statistics, then discards it rather than storing the IP address. The website may also generate standard hosting, network, and security logs needed to deliver and protect the site.

Purpose: operate, secure, and improve the website and understand aggregate use.

Legal basis: our legitimate interests in operating and measuring the website, Article 6(1)(f) GDPR.

Retention: analytics data is aggregate and does not identify individual visitors; it is retained for as long as we use the analytics service, currently up to 5 years under our provider’s plan. Hosting and security logs are retained according to the provider’s operational schedule.

Website hosting — Vercel

Vercel hosts and delivers the website and may process request data such as IP address, request URL, timestamp, user agent, response status, request identifiers, and security or diagnostic information.

Purpose: deliver, secure, and troubleshoot the website.

Legal basis: our legitimate interests in providing and protecting the website, Article 6(1)(f) GDPR.

Retention: short-term operational request logs per our hosting plan.

2.1 Early-access waitlist — MailerLite

If you join an early-access list on educatedguess.app, we collect your email address, which list you chose (Android or iOS), and your explicit consent.

  • Provider: MailerLite Limited (EU). The address is stored in MailerLite, not in this website’s hosting, in the group that matches the form you submitted (eg_android_early_access or eg_ios_early_access).
  • Purpose: send early-access notices for that platform (Google Play launch or later iOS availability). Not used for unrelated marketing. Submitting one form does not add you to the other list.
  • Legal basis: consent, Article 6(1)(a) GDPR. Withdraw via the unsubscribe link or contact@educatedguess.app.
  • Consent: an active tick of an unticked checkbox is required to submit. We record a consent timestamp and policy version on the subscriber record (consent_record field). A submission without JavaScript records the policy version without a timestamp. Double opt-in is not used. You can withdraw consent through the unsubscribe link or by writing to contact@educatedguess.app.
  • Retention: until you unsubscribe or we delete the list, and no longer than 24 months after the last message, unless you ask us to delete sooner.

3. Data handled by the app

3.1 Product analytics — PostHog

The app automatically sends the allowlisted pseudonymous events to PostHog Cloud EU. Events are pseudonymous (an Educated Guess account UUID after sign-in), contain no email or message content, and are processed on PostHog Cloud EU.

Data may include:

  • a PostHog identifier and, after sign-in, an Educated Guess account UUID;
  • app version, platform, build channel, and authentication status;
  • game phase, question ID and category, answers and streak-related events;
  • app sessions, screen and feature interactions;
  • share, advertising, subscription, and purchase-funnel events; and
  • defined anomaly events and technical result codes.

We do not intentionally send your name, email address, precise or approximate location, question text, free-form content, or payment-card details to PostHog.

The UUID is pseudonymous, not a real-world name. When an account is deleted, we remove the account and its mapping from our systems. Retained historical events are identified only by a pseudonymous UUID that is no longer connected to any Educated Guess account, and they expire with the retention period below.

Purpose: understand game use, improve design and reliability, measure conversion, and investigate product anomalies.

Legal basis: our legitimate interests in understanding aggregate product usage and improving the game, Article 6(1)(f) GDPR.

Retention: retained for as long as we use the analytics service; we periodically review and delete older analytics data.

The current product decision is to collect this analytics automatically and not provide a PostHog opt-out.

3.2 Crash and diagnostic reporting — Sentry

The app uses Sentry to detect and diagnose crashes and reliability problems.

Data may include: crash logs, stack traces, error type, timestamps, app release and build, operating system, device model, technical breadcrumbs, performance context, and a pseudonymous Educated Guess account UUID after sign-in. A connection IP address is processed when the event reaches Sentry, but the organization-level Prevent Storing of IP Addresses setting is enabled so that Sentry does not store it or derive and store location from it.

We configure the app not to intentionally send email addresses, question content, payment details, or free-form user content. Sentry is not used as product analytics or advertising technology.

Purpose: detect, investigate, and fix crashes, security issues, and reliability defects.

Legal basis: our legitimate interests in maintaining a secure and reliable app, Article 6(1)(f) GDPR.

Retention: Sentry event data is retained for up to 90 days. Sentry may retain infrastructure backups for up to 90 days after creation under its service security practices.

3.3 Anonymous app and purchase identifiers

Before sign-in, the app and its providers may create pseudonymous identifiers, including:

  • a RevenueCat anonymous App User ID;
  • an app/device identifier used for the onboarding experiment assignment stored in Supabase; and
  • the PostHog identifier described above.

These identifiers support app functionality, purchase continuity, experiment integrity, analytics, and fraud prevention. They do not by themselves contain your name or email, but they can still be treated as pseudonymous personal data.

3.4 Rewarded advertising — Google AdMob

Educated Guess offers an optional rewarded-ad button. Ads never play automatically. When you select Watch ad, the app attempts to display an available ad and awards the stated in-game benefit after the required completion signal.

To reduce waiting, the app may initialize Google Mobile Ads and request or preload an ad before you tap the button, after any privacy state required for that request has been resolved.

Google Mobile Ads may process or share:

  • IP address, including for general location estimation;
  • app and advertising interactions, such as launches, taps, impressions, and video views;
  • crash, performance, and SDK diagnostics;
  • device, app-set, account, or advertising identifiers; and
  • information about ads shown.

Purpose: serve and measure ads, fund the free version, and prevent advertising fraud.

Advertising mode and choices: Before an ad request, the app uses Google’s User Messaging Platform (UMP) to determine whether ads may be requested and, when required, presents Google’s consent form. Depending on your choices, location, and Google’s applicable signals, Google may serve personalized, non-personalized, or limited ads. Educated Guess does not independently classify the serving mode. Where UMP requires privacy options, Profile → Ad privacy options lets you review or change those choices. An ad may be prepared in advance only after UMP reports that ads may be requested.

Provider: Google AdMob and participating advertising-technology providers.

Legal basis: consent where required for advertising personalization, device storage/access, or tracking; otherwise legitimate interests to fund the free service and prevent fraud where permitted.

3.5 Purchases and subscriptions

Google Play or the Apple App Store processes checkout and payment. We do not receive your full payment-card details.

We and RevenueCat receive purchase information needed to offer, activate, verify, and restore Unlimited, including:

  • pseudonymous app user or Educated Guess account ID;
  • store, platform, product, and entitlement identifiers;
  • purchase, renewal, cancellation, refund, and expiration status;
  • transaction or receipt information; and
  • limited locale, currency, and app-version information.

Available products are a monthly auto-renewing subscription and a yearly auto-renewing subscription on supported platforms.

Purpose: provide and restore Unlimited, prevent fraud, support purchases, and analyze purchase performance.

Legal bases: performance of the contract, Article 6(1)(b); legal obligations where applicable, Article 6(1)(c); and legitimate interests in fraud prevention and product measurement, Article 6(1)(f).

3.6 Account, sign-in, and synchronized progress

You can play without an account. Sign-in is currently offered with Google Sign-In. Sign in with Apple is planned for the iOS release.

When you sign in, we may receive:

  • email address and, where supplied by the sign-in provider, display name and profile-image URL;
  • sign-in-provider identity data, the provider user ID, and the Educated Guess account UUID;
  • authentication and session tokens handled by Google and Supabase Auth; and
  • synchronized answer history, current progress, lives, streaks, prologue state, and related account settings.

Purpose: create and secure an account, synchronize progress, and connect or restore purchases.

Legal basis: performance of the account service you request, Article 6(1)(b).

3.7 Local data

The app stores questions, game progress, lives, and settings in a local database on your device so gameplay can work offline. Data that never leaves the device is not collected by us. Signed-in progress is synchronized as described above.

3.8 Data we do not intentionally collect

The app is not designed to collect precise GPS location, contacts, calendar data, photos, videos, audio recordings, health data, or payment-card details. Permissions and SDK behavior must be rechecked for every release.

4. Recipients and service providers

We use:

  • Plausible — aggregate website analytics;
  • MailerLite — early-access waitlist email storage and sending;
  • PostHog — app product analytics;
  • Sentry — crash and diagnostic reporting;
  • Supabase — authentication, database, and synchronized progress;
  • RevenueCat — purchase and entitlement management;
  • Google — Google Sign-In, Google Play, Google Mobile Ads, and UMP;
  • Vercel — website hosting, delivery, security, and operational logs; and
  • Apple — the App Store and Sign in with Apple only when the iOS version is released.

We do not sell personal data. AdMob data is shared within Google’s advertising ecosystem to serve and measure ads. Google and Apple also process store, account, and payment data under their own terms and privacy policies.

5. International transfers

Supabase is hosted in the EU. PostHog processes on PostHog Cloud EU. Plausible stores data in the EU. Where any provider (Google, Sentry, RevenueCat, Vercel, MailerLite) processes personal data outside the EEA, transfers rely on the mechanisms in our service agreements — the EU–US Data Privacy Framework where the provider is certified, otherwise Standard Contractual Clauses.

6. Retention

  • Plausible aggregate website analytics: aggregate and does not identify individual visitors; retained for as long as we use the analytics service, currently up to 5 years under our provider’s plan.
  • Early-access waitlist emails (MailerLite): until you unsubscribe or we delete the list, and no longer than 24 months after the last message, unless you ask us to delete sooner.
  • PostHog app analytics: retained for as long as we use the analytics service; we periodically review and delete older analytics data.
  • Vercel operational request logs: short-term operational request logs per our hosting plan.
  • Sentry error and diagnostic events: 90 days.
  • Account and synchronized progress: while the account exists, then deleted from active systems following a verified deletion request.
  • Supabase standard Pro daily backups: residual deleted data may remain for up to 7 days.
  • Local device data: until you delete the app, clear app data, or use an applicable in-app deletion/reset function.
  • Support emails: normally up to 24 months after the matter is closed, unless needed longer for a dispute or legal obligation.
  • Purchase and entitlement data: as needed to provide or restore the purchase, prevent fraud, resolve disputes, and meet legal obligations. Google and Apple apply their own retention rules to store records.

7. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, or a portable copy of personal data. Where processing relies on consent, you may withdraw consent without affecting earlier lawful processing.

Email contact@educatedguess.app. We may verify your identity before acting. You may also complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or another competent authority.

California note: we do not sell personal information. Google advertising may constitute “sharing” for cross-context behavioural advertising when personalized advertising is enabled. Where applicable, use the available advertising privacy choices to opt out.

For automatic PostHog analytics, you may object by email. Because historical events are identified only by a pseudonymous UUID, fulfilling a user-specific request may require the UUID still to be connected to an active account or otherwise supplied in a verifiable way.

Educated Guess does not make decisions based solely on automated processing that produce legal effects or similarly significant effects for you. Google may use automated systems to select advertisements as described in Google’s privacy information.

8. Account deletion

You can initiate account deletion:

  1. in the app through Profile → Delete account; or
  2. outside the app by following the instructions at https://educatedguess.app/support.

After verification, we delete the account and synchronized progress from active Supabase systems. Historical PostHog, Sentry, and RevenueCat records remain identified only by pseudonymous identifiers that are no longer connected to any Educated Guess account, and they expire with the retention periods above. You can additionally request targeted deletion by email (Section 7).

Residual account data may remain in standard Supabase backups for up to 7 days. Data that must be kept for purchase restoration, fraud prevention, legal obligations, or dispute handling may be retained only for those purposes.

Deleting the Educated Guess account does not cancel a Google Play or Apple subscription. Cancel it through the relevant store.

9. Children

Educated Guess is intended for a general audience and is not directed to children under 13. We do not knowingly create accounts for or collect personal data from children under 13. Contact us if you believe a child has provided account data.

10. Security

We use measures including encrypted network connections, access controls, platform authentication, row-level database security, data minimization, and restricted production credentials. No system can be guaranteed completely secure.

11. Changes

We may update this policy when the app, website, providers, or legal requirements change. We will update the date above and provide additional notice for material changes where appropriate.

12. Contact

Bartłomiej Nycz / Kvalito Solutions Bartłomiej Nycz
contact@educatedguess.app

Questions about this page? Write to contact@educatedguess.app.

© 2026 Educated Guess English