Privacy Policy
Effective date: 26 August 2026
This policy covers the websites at rock.paperscissors.online and taskagitmakas.online, together with the iOS and Android apps (together, the "Game"). The data controller is Özgür Özalp, the developer of the Game.
In short
- You can play without an account. In that case we collect no identifying information; your match runs under a temporary in-memory identity that disappears when the match ends.
- We do not store chat messages. They are relayed between the two players in real time. A message is only saved if you report it.
- If you create an account, we store your name, email address, profile photo and match statistics.
- You can delete your account and all of your data yourself, from inside the app.
- The website uses advertising and measurement cookies; the mobile app shows no advertising. On both, we measure which ad brought you here; on iOS we ask your permission first and you can decline, and on Android you can reset or switch off your device's advertising identifier in the device settings.
1. Data we process
When you play without an account
We do not ask for a name, an email address or any similar identifier. The game server assigns you a temporary connection identifier (socket id) that is valid for that match only. The result is not added to your statistics or to the leaderboard ("unranked"); it is kept only as a record with no player attached.
When you create an account
When you sign in with Google or Apple, we store the information the provider sends us:
- First and last name
- Email address (if you choose to hide your address when signing in with Apple, the relay address Apple generates)
- Profile photo URL
- Provider account id and session tokens
For the security of your session we also store your IP address and browser/device information (user agent) alongside the session record.
Game data
- Your win and loss counts
- Match results (winning and losing user, whether the match counted towards rankings, date)
- Friend requests and your friend list
- Rematch requests and their status
Notifications
If you allow notifications, we store your device's push token and your language preference. We use them only to deliver game-related notifications such as rematch and friend requests. You can withdraw permission at any time in your device settings.
Profile photo
If you upload your own photo, the image is stored on Cloudflare R2 and shown to your rivals through a publicly accessible URL.
Chat
In-match chat messages are never written to the database; they are relayed between the two players through the server in real time and disappear when the room closes. The single exception is the reporting mechanism: when you report a message, the message text, the room code, the sender's connection identifier and the reporting and reported user ids are saved so the report can be reviewed. When you block a player, that choice is stored only on your own device.
2. Cookies, measurement and advertising
The following third-party services run on the website. They may set their own cookies and process data such as your IP address and browser information under their own policies:
| Service | Purpose | Provider |
|---|---|---|
| Google AdSense | Serving ads (may be personalised) | |
| Google Analytics / Tag Manager | Visit and usage measurement | |
| PostHog (EU servers) | Product analytics, error tracking, session recording | PostHog |
| Rybbit | Visit measurement | Rybbit |
| Meta Pixel | Measuring ads we run on Meta (Facebook/Instagram) | Meta |
The Meta Pixel is for measurement only: no Meta advertising is shown on the site. It reports whether visitors coming from ads we run on Meta reached the site and went on to play. The events sent to Meta are page views, creating a room, starting a game, sharing an invite, and clicking the tip link; your gameplay, your chat and your email address are not sent.
The mobile app shows no advertising. It uses PostHog: events such as which screens were opened and which buttons were tapped, crash reports, and session replay. In session replay all text and images are masked, so your chat content, your name and your profile photo never appear in a recording. In web recordings, form fields are masked using PostHog's default settings.
The app also includes the Meta SDK, again for measurement only: it reports to Meta whether you installed the app through one of our Meta ads, and whether you then reached steps such as installing, creating an account, completing a match or leaving a tip. On iOS the app asks for tracking permission (App Tracking Transparency). If you decline, your device's advertising identifier (IDFA) is not read and measurement is limited to Apple's anonymous SKAdNetwork reporting. You can withdraw this permission at any time under Settings → Privacy & Security → Tracking on iOS.
The app also includes the TikTok SDK, with the same purpose: it reports to TikTok whether you installed the app through one of our TikTok ads, and whether you then reached steps such as creating an account, completing a match or leaving a tip. Unlike the Meta SDK it runs on both iOS and Android. What is sent to TikTok is those events plus device and app information (device model, operating system version, IP address, app version). On iOS the tracking permission above applies here too: if you decline, the IDFA is not read. The Android equivalent is the device's advertising identifier (Google advertising ID); you can delete it or turn off personalisation under Settings → Google → All services → Ads.
For both in-app SDKs, if you are signed in, only your account's identifier within the Game is sent; your name, email address and phone number are not. Your chat and gameplay content is not sent either.
You can manage ad personalisation through Google's Ads Settings, your Meta preferences through Meta ad preferences, and your TikTok preferences in the TikTok app under Settings and privacy → Ads.
3. Why we process data, and on what legal basis
- To run the Game (performance of a contract): creating rooms, matching players, resolving matches, keeping you signed in.
- Legitimate interests: preventing abuse (reporting and blocking), finding bugs, improving the service, measuring usage — on Android, ad measurement also rests on this basis and can be switched off in the device settings.
- Consent: notification permission, the advertising/measurement cookies on the website, and the tracking permission in the iOS app.
- Legal obligation: where the law requires it.
We do not sell your data to third parties for advertising.
4. Who we share data with
Your data is only processed by the infrastructure providers needed to run the service: Google and Apple for authentication, Vercel for hosting, Cloudflare for file storage, Apple Push Notification service and Expo for notification delivery, and the analytics and ad-measurement services listed in the table above together with Meta and TikTok. Some of these are located outside your country; PostHog processes data on servers in the European Union.
On screens such as the leaderboard and match history, your name and profile photo are visible to other players. Your email address is never shown to other players.
5. Retention
Your account data and game statistics are kept until you delete your account. When you delete it, the records attached to your account (statistics, friendships, rematch requests, push tokens, sessions) are deleted. Reports are kept until the moderation process is complete, so that abuse can be followed up. Records held by analytics services are subject to that provider's retention period.
6. Your rights
Under the GDPR and Turkey's Personal Data Protection Law No. 6698 (Article 11), you have the right to learn whether your personal data is being processed, to access it, to ask for it to be corrected or erased, to object to processing, and to request portability.
The most practical route is the app itself: choose "Delete Account" on the Profile screen to erase your account and your data yourself. For any other request, write to us at the address below; we respond within 30 days at the latest.
7. Children's privacy
The Game is not directed at children under 13 and we do not knowingly collect data from that age group. If you believe we hold data belonging to your child, contact us and we will delete it.
8. Security
Connections are encrypted with HTTPS, and session credentials are held in the operating system's secure storage on mobile devices (Keychain / Keystore). Even so, no system can be guaranteed to be completely secure.
9. Changes
We may update this policy from time to time. When something meaningful changes we update the effective date at the top of this page, and for substantial changes we also notify you inside the app.
10. Contact
For questions and data requests: mail@ozgurozalp.com