Privacy Policy
Last updated: 20 September 2026.
You'd Say is a two-player question game. This page explains, in plain language, what data we collect and why. For privacy questions or data requests, email youdsaygame@gmail.com. This is the same inbox we use for support and refund requests.
What we collect
- A session id, generated in your browser and stored in localStorage. It connects rounds and question skips from the same game session. If you later sign in and start your first game, the earlier rounds and skips can be linked to that game and account.
- Round results — which multiple-choice option was picked and guessed, tied to your session id. The game has no free-text answers.
- Question skips — when you ask to see another question, we record which question was replaced. These records are tied to your session and, when you are signed in, your game and account.
- Google account and session data, if you choose to sign in with Google. This includes the name, email address, profile image and Google account identifier returned for your account. We use your name and email address to send one transactional welcome email through Gmail after account creation. Authentication records can also contain OAuth tokens and scopes returned by Google, plus the session token used to keep you signed in. Session records can include IP address and browser user-agent information.
- Payment-related records for existing one-time purchases include identifiers connecting the browser session and account with the Stripe Checkout session, customer and payment intent, payment status and amount, and the purchaser email returned by Stripe. For subscriptions, we store internal account and browser-session identifiers, Stripe customer and subscription identifiers, subscription status, the base price and currency, purchaser email, the end of the current billing period and whether cancellation is scheduled. We also record when the app handles a full refund of the first subscription payment. Metadata sent to Stripe with checkout and the subscription includes internal account and browser-session identifiers plus limited product and attribution information used to confirm access and measure purchases. Card and billing-address details are handled by Stripe and Link and are not stored in our database.
- Cookieless product analytics. Umami receives page views and product-usage events supplied by the application. These events can contain session information, the language and product content shown, progress through the game, interaction outcomes and timing, and a purchase summary such as the product, price, discount use, amount and currency. We do not send player names, game answers, account or payment-provider identifiers, card details or email addresses to Umami.
- Cookieless product experiments. For signed-in accounts, GrowthBook processes our internal account identifier to assign and analyse paywall-copy experiments consistently. It receives an experiment-view event with the experiment and variation identifiers and, after a confirmed purchase, the amount, currency and paywall variant. This integration does not send player names, game answers, email addresses, card details or payment-provider identifiers to GrowthBook. GrowthBook's managed event warehouse for this app is in the United States.
- Hosting, security and performance data. Vercel handles ordinary web requests as the application host. Vercel Web Analytics always records page usage and aggregated device, browser, referrer and approximate location information, while Speed Insights always records web performance metrics. Sentry always receives browser, server and edge error diagnostics and 100% of performance traces. Sentry is configured not to send default personally identifiable information, and Session Replay is not enabled. In-memory IP rate-limit counters also protect the service from abuse.
Browser storage
localStorage holds the browser session ID, game progress (including round, question IDs and selected vibe), player names and language preference. During a Google sign-in redirect, sessionStorage temporarily holds the current game state so the game can resume on return. Signing in also uses an authentication cookie. The analytics and monitoring providers do not set an analytics cookie through this app.
What we don't collect
No password-based login, no free-text game answers, and no full card or billing-address details — those payment details go directly to Stripe and Link and are not stored in our database. The player names you enter are used in your browser and are not sent to the game database or analytics; analytics records only whether each name field was filled in. Choosing the spicy vibe clears saved player names from that browser and the game uses the generic labels Player 1 and Player 2. Accounts are created only when you choose to continue with Google.
Who we share it with
Google is used for optional sign-in and Gmail sends the one-time transactional welcome email. Sold through Link, LLC acts as merchant of record through Stripe Managed Payments; Stripe and Link operate checkout and subscription billing, handle payment and billing data, provide billing management, receipts and transaction support, and receive the limited transaction metadata described above. Subscription status and billing-period information are returned to You'd Say to keep paid access up to date. Supabase hosts our database. Vercel hosts the web application and provides the analytics and performance services named above. Umami receives the cookieless page views and product-usage data described above. GrowthBook receives the cookieless experiment-assignment and purchase-measurement data described above and stores those events in its managed warehouse in the United States. Sentry receives technical error diagnostics and performance traces as described above. Depending on the provider account configuration, these providers may process data outside the EEA; contact us for the current processing locations and transfer safeguards.
We don't sell personal data and we don't share it with advertisers.
Stripe Privacy PolicyLink Privacy CenterWhy we use the data
Game and browser-session records operate and resume the game. Account and authentication records provide optional Google sign-in, keep your game history connected to your account and let us send one transactional welcome email. Payment and subscription records confirm and maintain paid access, keep subscription status, renewals and scheduled cancellations in sync with Stripe, and support refund requests. We use a subscriber's Stripe customer identifier to open the billing portal for subscription management. Buyers with an existing one-time purchase can still open Link order history for receipts and transaction support. Technical counters protect the service from abuse. Analytics is used to understand game progress, improve questions and features, measure purchase performance and compare paywall-copy variants.
Your choices
Umami, GrowthBook, Vercel Web Analytics, Speed Insights and Sentry operate automatically as described above. They do not depend on a cookie-consent choice in this app. You may object to processing based on our legitimate interests by contacting us.
You can clear localStorage to remove the session ID, saved game progress, player names and language preference from that browser. sessionStorage is removed by the browser when the tab session ends, and the sign-in flow normally removes its saved return state after reading it. This does not delete records already held in our database or by a provider.
For privacy questions or to request access, correction, deletion, restriction, portability or to object to processing, contact youdsaygame@gmail.com. Include the email address for a signed-in account, or the session ID if your request concerns an anonymous game session. These rights apply subject to the conditions and exceptions in data-protection law. You may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO).
President of the Personal Data Protection Office (UODO)Changes
If this policy changes in a meaningful way, we'll update the date at the top of this page.