Privacy Policy
Last updated: 5 October 2026
Table of Contents
- Introduction and scope
- Data controller identity and contact
- Summary of data practices
- Information we collect
- How we use your information
- Legal bases for processing under GDPR
- Third-party service providers
- International data transfers
- Data retention
- Your rights under GDPR (EU/UK)
- Your rights under CCPA/CPRA (California)
- Your rights under LGPD (Brazil)
- Other regional rights
- Children's privacy
- Security measures
- Apple App Privacy Nutrition Label disclosures
- Cookies and similar technologies
- Changes to this policy
- How to contact us and exercise your rights
1. Introduction and scope
This Privacy Policy explains what data Gossipy collects, why it is collected, and the rights you have. The solo game works without an online account. An anonymous account is created only when you use multiplayer, leaderboards, or another online feature.
This Privacy Policy (the "Policy") describes how personal data is handled in connection with the mobile application Gossipy (the "App"), an iOS narrative investigation game. The App is published and operated by KOFY, a French société par actions simplifiée unipersonnelle (SASU) (the "Developer", "we", "us", or "our").
The practices described here cover version 2.3.0 and later. Data flows can differ on earlier installed versions.
This Policy applies exclusively to the App and to the limited data flows triggered by your use of the App. It does not apply to the Apple App Store itself, to your iOS device, or to any third-party website or service that is not operated by the Developer, even when accessed from a link inside the App. Apple's processing of your data as the App Store operator is governed by Apple's Privacy Policy.
This Policy explains our data practices. Reading it or continuing to use the App does not constitute consent to processing for which your consent is required.
2. Data controller identity and contact
KOFY is the data controller for the personal data processed through Gossipy.
The data controller for any personal data processed in connection with the App is:
- KOFY, société par actions simplifiée unipersonnelle (SASU), SIREN 108 387 283, represented by its President Charly Klopfenstein
- Registered office: 47 rue Vivienne, 75002 Paris, France
- Contact email: contact@gossipyapp.com
Throughout this Policy, references to "the Developer", "we", "us", and "our" refer to KOFY. The Developer has not appointed a Data Protection Officer because the processing carried out does not require one under Article 37 of the General Data Protection Regulation (GDPR).
3. Summary of data practices
The solo game does not require a login. Online play uses a pseudonymous account and generated public alias. We also process limited data to deliver the App, manage subscriptions, understand App use, and measure advertising.
| Topic | Position |
|---|---|
| Name and login | The first name or pseudonym entered for conversations stays on your device. No email or password is requested. Online features use an automatically generated account identifier and public alias. |
| Multiplayer and leaderboards | Supabase stores the generated alias, selected avatar and style, game statistics, leaderboard entries, duel membership, progress and results. |
| Subscription processing | Apple and RevenueCat manage purchases and access. Subscription events also support product analytics and advertising measurement. |
| Product analytics | PostHog receives selected usage events and technical metadata. Session replay and automatic screen capture are disabled. |
| Advertising measurement | Singular measures installations, sessions, purchases and selected events. Configured events can be shared with TikTok for campaign measurement and optimisation. |
| iOS advertising identifier (IDFA) | Available only if you grant Apple's App Tracking Transparency permission. Refusing does not stop all analytics or privacy-preserving attribution. |
| Account deletion | If an online account exists, you can delete it and its associated player data directly in Profile > Account. App Store subscriptions must be cancelled separately with Apple. |
| Children | The App is intended for users aged 17 or older and is not directed at children. |
| Advertising data sharing | We share limited identifiers, technical data, purchase information and events with TikTok through Singular for advertising measurement and campaign optimisation. |
Creator-programme exception. A person who voluntarily applies to the paid creator programme provides the professional identity, address, tax and bank details described in Section 4.1. Ordinary game use still requires no email, password or legal identity.
4. Information we collect
4.1 Information you provide
The first name or pseudonym used to personalise conversations remains on your device. Online surfaces show a server-generated alias instead.
The App has no email-and-password signup or login screen. The first name or pseudonym entered during onboarding does not need to be real and is not sent to Supabase, opponents, or leaderboards. If you choose an online feature, the App creates a pseudonymous guest account without asking for an email, password, phone number, or photo. Other players can see only a generated alias such as “Detective-AB12CD”, your selected avatar and style, and game or duel results. You may also enter a creator code in Settings; it identifies a referral campaign, not your real-world identity.
If you voluntarily apply to the paid creator programme, Gossipy collects your public TikTok or Instagram username, follower count and temporary bio-verification code; legal name; professional address; tax residence and registration country; business form and registration number; VAT status and optional VAT number; signed collaboration agreement; bank-account holder name, IBAN and optional BIC; submitted video links; public view counts; calculated earnings; and payment status. Bank details are encrypted before storage. This information is used only to assess eligibility, administer the collaboration, track submitted content and make or document manual bank transfers.
If you choose to contact the Developer by email at the address listed in Section 2 or Section 19, the email content you send will be received and read by the Developer and may be retained as needed to respond to your request and to comply with applicable record-keeping obligations.
4.2 Information collected automatically
Technical data and selected events are collected for content delivery, referrals, product analytics, and advertising measurement. Your game save and the text you enter are separate from this telemetry.
The following categories of data may be collected automatically when you use the App:
- Online player account and gameplay. When you first use multiplayer, leaderboards, the creator programme, or another online feature, Supabase creates a random account ID. We store a generated public alias, avatar, style, aggregate statistics and selected progress, case completion times, leaderboard entries, duel room membership, progress, winner and timestamps. Answers submitted for the weekly timed ranking are validated by the server but are not stored after validation.
- Content delivery logs. When the App downloads assets from Cloudflare at
cdn.gossipyapp.com, the CDN processes IP address, user-agent, requested URL, timestamp, and response metadata for delivery, security and performance. - First-party creator-referral telemetry. A creator link or code creates a random installation identifier and sends the creator code, event type, timestamp, platform, installation date and optional click identifier to our endpoint.
- Creator-programme account and Premium activation. Applicants use the same pseudonymous account to retrieve their programme state. The programme also processes the professional information described in Section 4.1.
- Product analytics through PostHog. A random installation identifier connects selected events such as sessions, onboarding, gameplay progress, question attempts, hints, paywall views, purchase actions and technical errors. Search events contain query length and result count, not the search text. Session replay, automatic screen capture and IP-based geolocation enrichment are disabled.
- Advertising measurement through Singular. The SDK processes installs, sessions, pseudonymous device and installation identifiers, the RevenueCat app user identifier, purchase and selected in-app events, device and App information, network information and tracking-permission status. Network information can provide an approximate country, region or city.
- iOS tracking permission. IDFA is available only if you authorise tracking through Apple's ATT prompt. You can use the App without granting permission. Other pseudonymous identifiers, analytics and SKAdNetwork measurement can still operate without IDFA.
- Local game data. The entered name, full save, notes and preferences remain in local App storage. Selected statistics and milestones are separately processed as described above.
4.3 Information from third parties
Apple and RevenueCat provide purchase and subscription information. Our measurement providers also report App usage and campaign attribution.
When you purchase or restore an in-app subscription, the following information is transmitted to RevenueCat, which acts as a data processor on behalf of the Developer:
- A pseudonymous app user identifier generated by RevenueCat. It is not your name or Apple ID, but it can link subscription records to App analytics and measurement identifiers.
- The Apple in-app purchase receipt provided by the App Store, which RevenueCat validates with Apple.
- The resulting subscription status (active / expired / in grace period / in billing retry / etc.), product and transaction identifiers, trial or renewal status, purchase amount and currency, country of purchase, purchase and renewal dates, and refund information where applicable.
- Coarse technical metadata: device type, operating system version, App version, and a randomised installation identifier.
The Developer accesses this data through RevenueCat to manage subscription access, restore purchases, and analyse subscriptions. The App supplies RevenueCat with its PostHog installation identifier and Singular device identifier, together with App/device metadata and ATT status. RevenueCat sends subscription lifecycle events to PostHog, where they can be connected to App usage through the installation identifier. Singular also receives the pseudonymous RevenueCat app user identifier to connect measurement for the same App user. These links do not require an account or your real name. RevenueCat's privacy practices are described at revenuecat.com/privacy.
PostHog and Singular provide event reports and derived information such as usage patterns and acquisition source. Singular and TikTok provide advertising-performance and attribution information, including whether an installation or action is associated with a campaign.
Apple may also independently collect aggregated, non-identifying analytics about the App through App Store Connect (App Analytics), in accordance with Apple's Privacy Policy. The Developer can view aggregated charts in App Store Connect but does not receive raw personal data from this source.
5. How we use your information
We use the data described above to operate Gossipy, understand its use, and measure and improve our advertising.
The Developer processes the data categories listed in Section 4 for the following purposes:
- Providing online features. Authenticating pseudonymous players, running multiplayer rooms, synchronising selected stats, operating leaderboards and awarding eligible prizes.
- Delivering App content. Serving game assets through Cloudflare.
- Managing your subscription. Verifying and restoring in-app subscriptions through RevenueCat.
- Measuring creator referrals. Crediting campaign milestones and preventing duplicate or fraudulent credit.
- Product analytics. Understanding onboarding, gameplay, feature use, technical issues, retention and conversion through PostHog.
- Advertising measurement and campaign optimisation. Using Singular and TikTok to measure installs, sessions, purchases and selected actions.
- Maintaining and securing the App. Detecting abuse, diagnosing issues and improving performance.
- Responding to requests and complying with law.
Paid creator collaborations. Creator-programme data is used to verify eligibility and account ownership, form and retain the collaboration agreement, track public videos and view counts, calculate remuneration, make manual bank transfers, document payments, prevent fraud, and grant the promised creator Premium benefit.
The Developer does not carry out automated decision-making that produces legal or similarly significant effects on you.
6. Legal bases for processing under GDPR
Data protection law and rules on access to information on your device apply separately. Pseudonymous identifiers remain personal data when they can distinguish a user or device.
| Purpose | Data category | Legal basis (GDPR Art. 6) |
|---|---|---|
| Online gameplay, multiplayer and rankings | Pseudonymous account ID, generated alias, avatar, style, stats, progress and results | Art. 6(1)(b), performance of the service requested by the player |
| Delivering and securing the App | IP address, request and technical metadata | Art. 6(1)(b) for delivery; Art. 6(1)(f) for security and fraud prevention |
| Managing subscriptions | Pseudonymous user ID, receipt, subscription and purchase metadata | Art. 6(1)(b), performance of the subscription contract |
| Creator referrals | Installation ID, creator code, referral events and timestamps | Art. 6(1)(f), campaign administration and fraud prevention |
| Product analytics | Pseudonymous identifiers, usage, purchase and technical events | Consent under Art. 6(1)(a) where required; otherwise Art. 6(1)(f), App improvement |
| Advertising measurement | Identifiers, purchases, selected events, device and network metadata | Consent under Art. 6(1)(a) where required |
| Support and legal compliance | Correspondence and legally required records | Art. 6(1)(b) and Art. 6(1)(c) |
The optional creator programme processes professional identity, social-profile and public-video data, the agreement, tax and bank details, earnings and payment records under Art. 6(1)(b) to take steps at the creator's request and perform the collaboration agreement; Art. 6(1)(c) for applicable tax and accounting duties; and Art. 6(1)(f) for fraud prevention and programme security.
You may object to processing based on legitimate interests by contacting us. Where processing relies on consent, you may withdraw it without affecting processing lawfully carried out before withdrawal.
ATT controls iOS tracking permission and access to IDFA. It does not by itself provide a separate consent choice for every analytics or data-sharing purpose. The current App does not offer a separate general analytics or advertising-sharing switch. Sections 4.2 and 7.4 describe the flows that can continue without IDFA; Section 10 explains the available controls and how to contact us about them.
7. Third-party service providers
We use service providers for content, subscriptions, analytics, and advertising measurement. Apple and advertising partners also process data under their own applicable terms and privacy notices.
7.1 RevenueCat
RevenueCat, Inc., a Delaware corporation headquartered in the United States, provides the subscription management infrastructure that validates Apple receipts and exposes your subscription status to the App. RevenueCat acts as a data processor on behalf of the Developer. Categories of data processed are listed in Section 4.3. RevenueCat publishes data-processing terms, including provisions for international transfers. RevenueCat's privacy practices are described at revenuecat.com/privacy.
7.2 Cloudflare
Cloudflare is operated by Cloudflare, Inc., a company headquartered in the United States, with edge servers distributed worldwide. Cloudflare stores the App's static assets in its R2 object storage and delivers them over its content delivery network, processing the standard access logs described in Section 4.2. Cloudflare acts as a data processor on behalf of the Developer. Because of the global edge architecture, your requests are typically served by the geographically closest edge node, which may be located outside the European Union, see Section 8. Cloudflare's privacy practices are described at cloudflare.com/privacypolicy.
7.3 Apple
Apple Inc. and its affiliates (collectively, "Apple") operate the App Store, the in-app-purchase infrastructure, and push notification delivery. Apple acts as an independent data controller with respect to its own processing of your data as an App Store customer. The Developer has no access to your Apple ID, your Apple payment information, or your Apple account. Apple may also collect aggregated App Analytics (anonymous funnel and crash metrics) which the Developer can view in App Store Connect. Apple's practices are governed by Apple's Privacy Policy and the App Store & Privacy notice.
7.4 Advertising and attribution partners
Singular is our mobile measurement provider. It processes the identifiers, technical information, sessions, and selected events described in Section 4.2 on our behalf and provides campaign-attribution reports. Its service privacy notice describes its role as a processor for data supplied by its business customers: Singular Privacy Policy.
TikTok receives configured measurement data through Singular to measure and optimise Gossipy campaigns. Our integration is configured for all users, rather than only installations attributed to TikTok. It includes installation or re-engagement measurement, App sessions, investigation and paywall views, checkout starts, and confirmed purchases. Depending on the event, fields include App and device identifiers (such as IDFV, and IDFA when authorised), the pseudonymous RevenueCat user identifier, device and operating-system details, tracking-permission status, IP address, approximate country/region/city, event type and time, product or offer context, and campaign context. Events can be shared when an installation was not attributed to TikTok and when IDFA is unavailable. This is separate from Apple's SKAdNetwork postbacks.
TikTok's processing is governed by the applicable advertising terms and its privacy notices. Information is available through TikTok's privacy resources. Section 11.4 describes advertising-sharing choices for California residents.
7.5 PostHog
PostHog provides product analytics, processing pseudonymous usage events and subscription events from RevenueCat on our behalf. Gossipy uses PostHog's EU ingestion endpoint. Session replay, automatic screen capture, and IP-based geolocation enrichment are disabled in the App configuration. The data remains linkable through installation identifiers. See the PostHog Data Processing Agreement and PostHog Privacy Policy.
7.6 Online and creator infrastructure
Supabase provides anonymous authentication, multiplayer, leaderboard and database hosting. It processes the online player and creator-programme data described above on the Developer's behalf. Vercel hosts first-party APIs and the private creator dashboard. TikHub is queried only for public TikTok or Instagram profile and video information needed to verify a submitted creator account and public view counts; legal, tax and bank details are not sent to TikHub. RevenueCat processes the pseudonymous identifier needed to grant a creator Premium benefit.
8. International data transfers
The Developer is based in France. Some providers are based in the United States or use infrastructure and support teams in other countries.
- RevenueCat and Singular are based in the United States and process App data as described in their service terms and privacy notices.
- Cloudflare is based in the United States and operates a global delivery network. Requests and technical logs may be processed outside the European Economic Area.
- PostHog receives Gossipy analytics through its EU endpoint. This endpoint does not imply that every provider operation, subprocessor, or support activity takes place exclusively in the EU.
- Apple and TikTok process data internationally under their applicable terms and privacy notices.
Supabase, Vercel and TikHub may process the online-player, creator-programme and public social-media data described in Sections 4 and 7 in the locations covered by their applicable service terms and data-processing arrangements.
Transfers subject to EU or UK data protection law require an applicable transfer mechanism, such as an adequacy decision or Standard Contractual Clauses with any necessary supplementary safeguards. The mechanism depends on the recipient, destination, and applicable contractual arrangements; the location of a provider's headquarters alone does not establish it.
You can contact the Developer using Section 19 to request information about the transfer safeguards applicable to your data. Provider data-processing terms and privacy notices are linked in Section 7.
9. Data retention
We keep data only as long as needed for the purposes listed above, with the longer periods driven by legal obligations (especially accounting).
| Data category | Retention period |
|---|---|
| Online account, profile, stats, multiplayer and leaderboard data | Until you delete the online account in the App, or until the account is removed after an appropriate period of inactivity. Non-personal prize ledgers and accounting records may be retained where legally necessary. |
| RevenueCat subscription records | For the subscription duration and as required for accounting, tax, fraud prevention and dispute handling. |
| Cloudflare access logs | A short rolling period under Cloudflare's policy, unless needed for a security incident. |
| Pseudonymous creator-referral events | Up to thirteen (13) months, then deleted or irreversibly aggregated, unless needed for fraud or legal compliance. |
| PostHog and Singular records | For the period configured to analyse App use, conversion and campaign performance, subject to deletion or restriction requests. |
| Data disclosed to TikTok | Under the applicable advertising terms, TikTok retention practices and privacy requests. |
| Local game data | Until you uninstall or reset the App. |
Creator application, agreement, earnings and payment records are kept for the collaboration and then only for applicable limitation, tax and accounting periods. Encrypted bank details are kept while needed to pay outstanding earnings and then deleted or restricted unless a legal obligation or dispute requires longer retention.
When retention periods expire, the relevant data is deleted or irreversibly anonymised.
Deleting an online account in Profile > Account > Delete online account deletes the Supabase authentication record and associated player profile, statistics, multiplayer membership and leaderboard records. It does not cancel an Apple subscription, erase local progress, or automatically delete records held separately by Apple, RevenueCat, PostHog, Singular or TikTok. You can request deletion or restriction of those records through Section 19, subject to legal exceptions.
10. Your rights under GDPR (EU/UK)
If you are in the EU, EEA, or the United Kingdom, you have the rights listed below. You can exercise them by emailing us.
If you reside in the European Union, the European Economic Area, or the United Kingdom, you have the following rights under the GDPR (Regulation (EU) 2016/679) and the UK Data Protection Act 2018:
- Right of access (Art. 15), obtain confirmation of whether personal data concerning you is processed, a copy of that data, and information about the processing.
- Right to rectification (Art. 16), request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17, "right to be forgotten"), request deletion of personal data in the cases set out by the GDPR.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20), receive a structured, machine-readable copy of data you have provided and have it transmitted to another controller where technically feasible.
- Right to object (Art. 21), object to processing based on legitimate interests, including profiling, at any time.
- Right to withdraw consent (Art. 7(3)), where processing relies on consent, withdraw consent at any time without affecting the lawfulness of past processing.
- Right not to be subject to automated decisions producing legal or similarly significant effects (Art. 22), the Developer does not carry out such automated decision-making.
- Right to lodge a complaint with a supervisory authority (Art. 77).
To exercise these rights, use the in-App deletion option for the online account or contact contact@gossipyapp.com for other records. The Developer may request proportionate information, such as the user code visible in the App, to locate and verify a request.
iOS control. You can change Gossipy's tracking permission in Settings > Privacy & Security > Tracking. Turning it off removes access to IDFA; it does not delete existing records or switch off all analytics and measurement described in this Policy. For access, deletion, objection, withdrawal of consent, or other data-sharing requests, email contact@gossipyapp.com. No Gossipy account is required. See Apple's instructions for tracking permissions.
The competent supervisory authority for France is:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
cnil.fr
If you reside in another EU or EEA Member State, or in the United Kingdom, you may alternatively lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available on the European Data Protection Board website at edpb.europa.eu. For the United Kingdom, the competent authority is the Information Commissioner's Office (ICO), ico.org.uk.
11. Your rights under CCPA/CPRA (California)
Where the CCPA/CPRA applies, California residents have the rights described below, including the right to opt out of sale or sharing. Our advertising data flows are described in Section 7.4.
This section describes our practices and the rights available where the California Consumer Privacy Act of 2018 applies, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA/CPRA"), codified at California Civil Code §§ 1798.100 et seq.
11.1 Categories of personal information
The categories of personal information ("PI") covered by the App data flows described in this Policy, mapped to Cal. Civ. Code § 1798.140, are:
| Statutory category (§ 1798.140) | Collected? | Examples | Recipients, according to the flow in Sections 4 and 7 |
|---|---|---|---|
| Identifiers | Yes | IP address; installation, device, and subscription identifiers; IDFA when authorised | Cloudflare, RevenueCat, Apple, PostHog, Singular, TikTok, referral hosting provider |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Only if provided in a support request | Email address and correspondence | Developer and email service provider |
| Characteristics of protected classifications | Not requested | — | — |
| Commercial information | Yes | Purchase and subscription records; offer views and checkout starts | Apple, RevenueCat and PostHog for subscription records; Singular and TikTok for the selected offer or checkout events described above |
| Biometric information | No | — | — |
| Internet or other electronic network activity information | Yes | Content requests, referral events, sessions, selected gameplay and purchase actions | Cloudflare, referral hosting provider, PostHog, Singular, TikTok, according to the event |
| Geolocation data | Approximate | Network-derived country, region, or city; country of purchase. The App does not request GPS location. | Cloudflare, RevenueCat, PostHog for purchase country, Singular, TikTok |
| Sensory data (audio, electronic, visual) | No recording through analytics | Session replay and screen capture are disabled | — |
| Professional or employment-related information | Not requested | — | — |
| Education information | Not requested | — | — |
| Inferences drawn from PI | Limited analytics | Acquisition source, usage and subscription patterns | PostHog, Singular, TikTok |
| Sensitive Personal Information | Not requested for these flows | No precise GPS location, payment-card details, or account password is requested by Gossipy | — |
For optional creator applicants, the additional categories include customer records, professional or business information, financial information and payment records: legal name, professional address, business and tax identifiers, collaboration agreement, bank-account details, earnings and payment status. Gossipy discloses these only to the Developer and the creator-programme infrastructure providers described in Section 7.6.
11.2 Sources of personal information
The Developer collects personal information (a) from you when you contact us or enter a creator code; (b) from your device through the App, its SDKs, creator links, and content requests; and (c) from Apple, RevenueCat, PostHog, Singular, and advertising partners for subscriptions, analytics, and campaign attribution.
11.3 Purposes for collection
The purposes for which personal information is collected are described in Section 5 of this Policy.
11.4 Sale or sharing of personal information
The Developer does not exchange personal information for money. However, the advertising integration described in Section 7.4 discloses identifiers, technical data, approximate location, and selected activity to TikTok for advertising measurement and campaign optimisation. Advertising disclosures can constitute "sharing" for cross-context behavioural advertising, or a "sale" for other valuable consideration, under California law. The absence of a payment for data does not by itself exclude those definitions.
You can submit a Do Not Sell or Share My Personal Information request by email. No account is required. The iOS tracking control is also available as described in Section 10, but is not a general opt-out from every flow described here.
11.5 Sensitive Personal Information
The analytics and measurement flows described here do not request sensitive personal information such as precise GPS location, account passwords, or payment-card details. Please do not include unnecessary sensitive information in support messages. Apple handles payment information under its own privacy notice.
The optional creator programme separately collects the bank and tax information described in Section 4.1 solely to administer and pay the collaboration. It is not used to infer characteristics about a creator or for advertising.
11.6 Your CCPA/CPRA rights
Subject to applicable exceptions, you have the right to:
- Know what personal information is collected, used, disclosed, and (if applicable) sold or shared.
- Access the specific pieces of personal information collected about you.
- Delete personal information collected from you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information.
- Limit the use and disclosure of Sensitive Personal Information.
- Non-discrimination for exercising any of these rights.
To exercise these rights, contact the Developer at contact@gossipyapp.com. You may also use an authorised agent to submit a request, in which case the Developer will verify the agent's authorisation. For requests to access, correct, or delete records, we may need proportionate information to locate the records and verify the request. An opt-out of sale or sharing does not require an account or verification of your identity; we may need enough information to identify the records to which it applies.
11.7 California "Shine the Light"
California Civil Code § 1798.83 ("Shine the Light") entitles California residents to request, once per calendar year, information regarding the disclosure of personal information to third parties for the third parties' direct marketing purposes. You may send this request to the email address in Section 19. Advertising disclosures are described in Section 7.4.
12. Your rights under LGPD (Brazil)
If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD). You can exercise them by emailing us.
If you reside in Brazil, the processing of your personal data is subject to Federal Law No. 13.709 of 14 August 2018, as amended (the "Lei Geral de Proteção de Dados", or "LGPD"). The Developer is the controller (controlador) of your personal data within the meaning of Art. 5(VI) LGPD.
The legal bases relied upon under Art. 7 LGPD mirror those described in Section 6 of this Policy: performance of a contract to which you are a party (Art. 7(V)), compliance with a legal or regulatory obligation (Art. 7(II)), the legitimate interests of the controller (Art. 7(IX)) where permitted, and consent (Art. 7(I)) where required. The available controls and their limits are described in Sections 6 and 10.
You have the rights set out in Art. 18 LGPD, including:
- Confirmation that your data is being processed and access to it.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymisation, blocking, or deletion of unnecessary or excessive data, or of data processed in non-compliance with the LGPD.
- Portability to another service or product provider, subject to commercial and industrial secrets.
- Deletion of personal data processed on the basis of consent.
- Information about public and private entities with which the controller has shared your data.
- Information about the possibility of not granting consent and the consequences thereof.
- Withdrawal of consent.
To exercise these rights, contact the Developer at contact@gossipyapp.com. You may also lodge a complaint with the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD), gov.br/anpd.
13. Other regional rights
Residents of Canada, South Africa, Japan, Australia, and other jurisdictions retain the privacy rights granted by their local laws. The Developer will honour those rights to the extent applicable.
The Developer respects the privacy rights granted by your local law, including:
- Canada, PIPEDA. The Personal Information Protection and Electronic Documents Act provides rights of access, correction, and complaint. Complaints may be addressed to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
- South Africa, POPIA. The Protection of Personal Information Act 4 of 2013 provides rights of access, correction, deletion, and objection. Complaints may be addressed to the Information Regulator (inforegulator.org.za).
- Japan, APPI. The Act on the Protection of Personal Information (APPI) provides rights of disclosure, correction, and suspension of use. Inquiries may be addressed to the Personal Information Protection Commission (PPC), ppc.go.jp.
- Australia, Privacy Act 1988. The Australian Privacy Principles provide rights of access and correction. Complaints may be addressed to the Office of the Australian Information Commissioner (oaic.gov.au).
- Other jurisdictions. Where local law grants rights equivalent to those above, the Developer will honour them upon receipt of a verified request.
To exercise any of the rights above, contact the Developer at contact@gossipyapp.com.
14. Children's privacy
The App is intended for users aged 17 or older and is not for children. We do not knowingly collect data from children.
The App is intended for users aged 17 or older due to mature narrative content (investigations involving infidelity, suggestive themes, simulated communications). The App is not directed at children and is not intended for use by children. The Developer does not knowingly collect personal data from children under 17, and where applicable does not knowingly collect personal data from children under 13 within the meaning of the United States Children's Online Privacy Protection Act ("COPPA", 15 U.S.C. §§ 6501–6506) or from children under 16 within the meaning of Article 8 of the GDPR.
If you are a parent or guardian and believe a child has provided personal data to the Developer through the App, please contact contact@gossipyapp.com. The Developer will promptly investigate and delete the data unless retention is required by law.
15. Security measures
We minimise the data collected, rely on industry-standard processors for everything that leaves the device, and depend on Apple's platform security for the data on your device.
The Developer implements technical and organisational measures appropriate to the nature of the processing, the limited categories of data involved, and the risks they present:
- Data minimisation. The local name, notes and free-text answers are excluded from online profiles and analytics. Public online names are generated aliases.
- Access control. Supabase row-level security limits player access; sensitive creator administration uses authenticated server-side access.
- Transport security. Network communications use HTTPS / TLS.
- Processor security. We rely on the controls of the providers listed in Section 7.
- Device-side data. Local progress and preferences use sandboxed App storage.
Creator bank details are encrypted at rest with a server-only key, are never returned to the mobile App in full, and are exposed only through the authenticated private founder dashboard.
No system is perfectly secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, the Developer will notify the competent supervisory authority and, where required, affected users in accordance with Articles 33 and 34 of the GDPR.
16. Apple App Privacy Nutrition Label disclosures
Apple's privacy categories include information linked to a device or pseudonymous identifier, even when an app has no named account.
The App data flows described above include the following categories. The App Store's privacy label is a separate disclosure; this section does not mean that all transmitted data is anonymous.
16.1 Data Used to Track You
Identifiers and selected usage events are used for advertising attribution and shared with TikTok as described in Section 7.4. Apple's tracking definition concerns links between App or device data and data from other companies for advertising or advertising measurement. IDFA requires ATT authorisation. Apple's SKAdNetwork postbacks are a separate privacy-preserving measurement mechanism.
16.2 Data Linked to You
- Contact and financial information: legal name, professional address, bank details, earnings and payment information for optional creator applicants.
- Location: approximate location derived from network or purchase information.
- Identifiers: online account, device, installation and RevenueCat identifiers.
- Purchases: subscription, transaction and renewal information.
- User content and gameplay: generated alias, avatar, style, game statistics, multiplayer and leaderboard records, plus creator-submitted video links.
- Usage and diagnostics: product interactions, selected gameplay milestones, technical errors and related metadata.
- Other data: professional, registration and tax information supplied by creator applicants.
For optional creator applicants, linked data also includes contact information (legal name and professional address), financial information (bank-account details), identifiers (social username and Gossipy user ID), submitted video links, professional and tax information, public view counts, earnings and payment records.
These categories are used for App functionality, analytics, and, for the limited fields described in Section 7.4, the Developer's advertising or marketing.
16.3 Data Not Linked to You
Apple also provides aggregated App Analytics reports and privacy-preserving advertising reports. These are separate from the pseudonymous event records above. We do not describe all identifiers or purchase records as "not linked" merely because we do not ask for a name or email address.
If you notice an inconsistency with the App Store privacy label, contact contact@gossipyapp.com.
17. Cookies and similar technologies
The native App uses local storage and SDK identifiers. These technologies can support measurement even without browser cookies.
Game saves, preferences, referral state, SDK identifiers, and queued events use native application storage. The App does not use browser cookies for its native gameplay. The analytics, subscription, and advertising flows that transmit data are described in Sections 4 and 7.
When the App opens an external URL, your browser's cookie and storage behaviour applies. The relevant website's privacy and cookie notices govern those interactions.
18. Changes to this policy
The "Last updated" date identifies the revision of this Policy.
The Developer may update this Policy to reflect changes in the App, data flows, law, or provider practices. Additional notice or consent is required where applicable law requires it. Continued use of the App does not replace any required consent.
19. How to contact us and exercise your rights
Email the Developer at contact@gossipyapp.com. We will respond within the statutory timeframes.
For any question concerning this Policy or the data practices described in it, and to exercise any of the rights described in Sections 10 to 13, please contact:
- KOFY, SASU, SIREN 108 387 283, represented by its President Charly Klopfenstein
- Registered office: 47 rue Vivienne, 75002 Paris, France
- Email: contact@gossipyapp.com
When contacting the Developer, describe the request precisely. We may ask for the Gossipy user code, approximate dates, country or a store receipt to locate the relevant pseudonymous records and verify the request.
The Developer will acknowledge your request promptly and respond within the timeframes set by applicable law (one month under GDPR, extendable by two months for complex requests; forty-five days for CCPA/CPRA access, correction, or deletion requests, extendable by forty-five days, and as soon as feasible within fifteen business days for applicable sale or sharing opt-outs; fifteen days under the LGPD, extendable as provided by law).
Gossipy © 2026 · Privacy Policy · Terms of Use