Privacy Policy

Guilty Party · last updated 17 August 2026

Guilty Party is a party game for one evening. It has no accounts, no profiles and no sign-up. This policy describes the little data it does handle and why.

What we never collect

We do not collect your name, email address, phone number, contacts, photos or location. We do not ask you to create an account, and there is nothing to log into.

Nothing from inside a game is sent to our analytics: not the name you type in the lobby, not who anyone accused, not which role anyone was dealt.

Game data

To let several phones share one table, a room lives briefly in Google Firebase Realtime Database (Google Ireland Limited, EU). A room holds the nickname you type, which character each seat plays, votes, and the case being played. It is anonymous: sign-in is Firebase Anonymous Authentication, which issues a random identifier tied to no personal detail.

Rooms are one evening long. We delete rooms older than 30 days.

Analytics

We use PostHog (EU hosting) to see where people get stuck — for example how many tables finish a case, or which screen loses people. Events carry a random identifier stored on the device, the case being played, player counts and purchase steps. They never carry text you or your friends wrote.

On this website the same applies: we record which pages were viewed and which buttons were pressed, against a random identifier kept in your browser's local storage. There are no advertising cookies and no third-party trackers, and we do not sell or share any of it.

Purchases

We never see your payment details, wherever you buy.

In the iPhone app, purchases are handled by Apple. The app asks Apple what this Apple ID owns in order to unlock the cases you paid for.

On this website, payments are processed by Stripe, which collects your card details and your email address and is the seller of record. Stripe's handling of that data is covered by their privacy policy.

What we keep from a website purchase is: which case or subscription was bought, when, and an irreversible SHA-256 hash of your email address — not the address itself. The hash is how a purchase finds you again when you sign in on a new device: we hash the address you sign in with and look for a match. It cannot be turned back into an address.

If you then sign in — with an email link or with Apple — Firebase Authentication holds your address so that it can send that link and recognise you next time. You can ask us to delete that account and everything attached to it at info@theguiltyparty.app; deleting it also gives up access to what you bought, so we will say so before we do it.

If you sign in with Apple and choose «Hide My Email», we only ever see Apple's relay address, which is the point of the feature and works fine here.

Notifications

If you allow notifications, we store a device push token so we can tell you when a new case is published. Nothing else is sent to that token. You can revoke this at any time in iOS Settings.

Children

The game is written for adults and older teenagers. It is not directed at children under 13, and we do not knowingly collect data from them.

Your rights

Because we hold no identifying data, we usually cannot connect data to a person. If you want the device identifiers associated with your copy of the app deleted, write to us and we will remove them.

Contact

info@theguiltyparty.app