We do not sell data
We do not trade personal data or use it for cross-service advertising profiles.
Privacy without the fine print
This policy explains what data WitLoop needs, why we use it, and what rights you have. It covers the published website, playtest signup, and contact form. Information about the app and online gameplay applies to the features you actually use after obtaining access.
We do not trade personal data or use it for cross-service advertising profiles.
A guest can start without an account. We ask for an account, email, or extra details only when a selected feature needs them.
You can withdraw consent, request access, correction or deletion, and object to certain uses of your data.
The public website provides project information, a Word Hunt demo, playtest signup, and a contact form. Visiting the website or playing the demo does not create an app account or join an online room. Information about account and match data applies when you use those app features.
This policy applies to witloop.app, the waitlist form, the WitLoop app, guest and registered profiles, rooms, matches, and messages sent to us.
WitLoop is an evolving platform for short games. Features may change, so we update this policy before using data in a new and material way.
WitLoop is the name of a project developed by individuals, not a separate incorporated company. The controller identified in this document is responsible for personal data.
The data controller is controller details to be completed, address: address to be completed.
For privacy matters, use the contact form below or in the website footer. We have not appointed a data protection officer. If we appoint one, their contact details will be published in this document.
The email address submitted at signup and the time the submission was received. Request handling also involves technical data such as IP address, browser information, and timestamps. Cookie preferences are a separate browser record described in section 6.
Client and session identifiers stored in Google Analytics 4 cookies, page addresses and titles, referrer, language, approximate location, device type, operating system, browser, screen resolution, and events relating to section views, clicks, the demo, waitlist form, and website performance. We do not send email addresses, message content, or words entered in the game to Google Analytics.
Profile identifier, nickname, tag, selected avatar, optional country code, verified email address, and creation and update dates.
Cryptographic hashes of guest secrets, one-time codes and session tokens, expiry dates, attempt counts, last use, revocations, and service security events.
Room and match identifiers, game and mode, rules and content versions, players, scores, rank, experience points, starts, finishes, abandoned matches, and rematches.
App and system version, language, settings, error diagnostics, and technical identifiers needed for connections and sessions. Credentials are stored locally in the device's secure storage.
The name or identifier entered in the form, reply email address, subject, message, and time received. Do not send sensitive data, passwords, or login codes. The form does not support attachments.
We create profiles, maintain accounts and sessions, run rooms and matches, calculate scores, save progress, and deliver features you request.
Under Article 6(1)(a) GDPR and your electronic communications consent, we send test, launch, and important product updates. You can withdraw at any time without affecting earlier processing.
Under Article 6(1)(f) GDPR, we prevent abuse, limit automated submissions, investigate failures, analyse essential gameplay events, and verify that features work. We balance this interest against your privacy, and you may object.
We comply with legal obligations under Article 6(1)(c) GDPR and establish, exercise, or defend claims under Article 6(1)(f) GDPR.
Where Google Analytics 4 is active in a deployment, we use it only after you consent, under Article 6(1)(a) GDPR. It is loaded through Google Tag Manager and used to measure traffic, use of sections and the demo, waitlist effectiveness, and website performance. Refusing or later withdrawing consent does not restrict the website's or game's core functions.
The website uses essential local storage to record the version, date, and expiry of your choice and whether you consent to optional analytics. This record contains no unique identifier and is not sent to the server on its own. Without it, we would have to ask on every visit.
The website is prepared to use Google Analytics 4 (GA4), loaded and managed through Google Tag Manager (GTM). In a given deployment, these tools operate only when WitLoop has configured them and the user has consented. They help us understand how visitors use the website, which sections and actions are useful, whether the demo and form work correctly, and how to improve performance. We do not use them for advertising, remarketing, or cross-service profiling.
We use basic Consent Mode: before consent, the GTM and GA4 scripts are not downloaded and no analytics requests are sent to Google. After consent, we grant analytics_storage only; ad_storage, ad_user_data, and ad_personalization remain denied.
GA4 may set the first-party cookies _ga and _ga_<identifier> to distinguish users and persist session state. Their default lifetime is up to 2 years and may be shortened by browser settings. Google receives the IP address during the connection; according to Google, for EEA traffic it is used to derive approximate location and then discarded before it is logged in Analytics.
You can accept, reject, or later change consent through the cookie settings button in the footer. Withdrawal does not affect the lawfulness of earlier processing and does not restrict the website's or game's core functions.
The app stores settings and session data locally as required to provide the service. The device's secure storage holds the guest secret and refresh token. We do not access other device data without a legal basis and the appropriate permission.
Essential server events such as profile creation, room entry, match start, and match result help operate and assess the service. If we introduce additional analytics or marketing tools, we will update the information and provide the appropriate, separate consent choices before activation.
We disclose only what is needed to run WitLoop. Recipients may include hosting and cloud, database, email, error monitoring, logging, and support providers, as well as legal or accounting advisers.
Where GA4 is active and the user has consented, analytics data is received by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, the provider of Google Analytics 4 and Google Tag Manager, and Google's approved subprocessors. Google processes the data under the applicable data processing terms for measurement services.
We may also disclose data to public authorities when required by law. We do not share user lists with advertising partners and do not sell data.
We prioritise processing in the European Economic Area. Some technology providers may nevertheless process data in the United States or other countries.
According to Google, Analytics data from users in the EEA is first collected through domains and servers based in the EU, but Google and its processors may then process it outside the EEA, particularly in the United States.
Where this happens, the transfer relies on a legally recognised mechanism, in particular an adequacy decision under the EU-US Data Privacy Framework where applicable, or European Commission Standard Contractual Clauses with supplementary safeguards. We will provide information about the applicable safeguard on request.
Until consent is withdrawn or no later than 12 months after we send the public launch notice, whichever happens first.
The local record remains valid for 12 months. We will ask again sooner if the scope of consent changes, or the record will be removed when you clear the website data in your browser.
Where GA4 is active, we retain user-level and event-level data in the service for 14 months. Aggregated reports may remain available for longer. The _ga and _ga_<identifier> cookies may remain valid for up to 2 years unless you withdraw consent, delete them, or your browser limits their lifetime sooner.
A one-time code is valid for 10 minutes and its challenge record is removed within 24 hours. Access sessions last 15 minutes. Refresh sessions expire after 30 inactive days and no later than 90 days.
For as long as the account is used. Following a valid deletion request, we delete or anonymise active-system data within 30 days unless law or claims require longer. Backups are overwritten in their normal cycle, no later than 90 days.
We generally keep logs for up to 90 days and longer only to investigate an incident. Support cases are deleted or anonymised within 12 months after closure.
Data needed for a legal obligation or claims is retained for the period required by applicable law and limitation periods.
To exercise a right, send a request through the contact form. You can use “Privacy” as the subject and describe your request in the message. To withdraw consent to playtest messages, identify the email address used at signup. We may ask only for information needed to confirm that the request concerns the right person. We generally respond within one month.
WitLoop is intended to work for family play, but the service is not designed to collect children's consent independently. In Poland, where consent is the legal basis for processing a child's data in an online service, a person under 16 needs a parent or guardian to give or authorise that consent.
If you believe a child provided data without the required consent, report it through the contact form. We will investigate and delete the data unless another legal basis requires us to retain it.
We do not make solely automated decisions about you that produce legal or similarly significant effects. Automatic scoring, ranking, and progress are game mechanics, not decisions under Article 22 GDPR.
We use safeguards appropriate to risk, including encrypted connections, hashed secrets and tokens, limited session lifetimes, access control, request limits, backups, and service monitoring. No method is completely secure, so we review safeguards and respond to incidents regularly.
We publish the current version at a stable address with its revision date. If a change materially affects how we use data, we will notify you in the app, on the website, or by email depending on its importance and the contact details available.
Send privacy questions, requests, and comments through the contact form available in this document and in the website footer. The address entered in the form is used to reply to your request; sending a message does not sign you up for playtests or give marketing consent.