Legal
Privacy Policy
Privacy isn't a feature we bolted on. HoneyRoll is built local-first, encrypted end to end, and funded by subscriptions rather than advertising — so there is no business reason for us to want your data.
The short version. Your gameplay data stays on your devices. What you write, rate, pass on or play is not uploaded to us. We collect the minimum needed to make an account work and to fix crashes, we never sell or share it with data brokers, there are no ads, and you can delete everything from inside the app in three taps.
1. Who we are
HoneyRoll ("we", "us") operates the HoneyRoll mobile application and this website. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we are the data controller for the limited personal data described below. For California residents, we act as a business under the California Consumer Privacy Act (CCPA/CPRA).
Privacy questions, access requests and deletion requests can be sent to [email protected].
2. What we collect, and what we deliberately don't
2.1 Data you give us
- Account identifiers. If you create an account, an email address and a password hash. You may also sign in anonymously with no email at all — the app is fully usable that way, and anonymous accounts can be upgraded to email accounts later.
- Profile details. The display name or nickname you choose for yourself and your partner, and an optional avatar. Nicknames are free text and we do not require legal names or gender.
- Partner link data. A short pairing code, plus the identifier of the account you paired with. This is what makes a shared board possible.
- Age attestation. A yes/no confirmation that you meet the minimum age, and — only if you enable After Dark — a date of birth used to verify you are 18 or older. We store the resulting verification flag, not the raw date, once verification is complete.
- Support messages. Whatever you send us when you contact support, retained so we can resolve your issue.
2.2 Data generated by playing
- Session records (which cards appeared, what you chose, your private ratings, game outcomes) are stored on your devices in an encrypted local store. In long-distance mode, only the minimum state needed to keep a shared board in sync — whose turn it is, token positions, the identifier of the current card — transits our sync service, and it is encrypted in transit and at rest.
- Your private ratings and consent answers are never transmitted. The blind consent mechanism works by comparing hashed answers on-device and only ever sending a single boolean: whether both partners said yes.
- A Hard No list you create never leaves your device. It is applied locally when cards are drawn.
2.3 Data collected automatically
- Diagnostics. Crash reports and performance metrics, with a scrubbed stack trace. This is opt-in and off by default in the EU and UK.
- Subscription state. Purchase receipts and entitlement status, provided by the App Store or Google Play. We never see or store your card details — the platforms handle payment entirely.
- Server logs. IP address and request metadata for sync and account endpoints, retained for 30 days for security and abuse prevention.
2.4 What we do not collect
- We do not collect your contacts, photo library, microphone or camera — none of these permissions are requested.
- We do not collect precise or coarse location.
- We do not use advertising identifiers, and the app contains no advertising SDKs.
- We do not build behavioural profiles for marketing, and we do not sell or rent personal information to anyone. HoneyRoll has never sold personal information and has no plans to.
- We do not upload the content of your cards, your free-text answers or your After Dark activity.
3. After Dark data isolation
Content accessed in the 18+ After Dark mode is separated from everything else by design:
- After Dark session records are stored in a separate encrypted container with its own key, held in the device keychain or keystore and gated behind your device biometrics or passcode.
- They never appear in your regular history timeline, achievements, streak counters, shareable cards or any export you generate, unless you explicitly turn on "include After Dark" for that export — which is off by default and re-confirmed each time.
- Exiting After Dark immediately clears the in-session working data for that session.
- Backups: After Dark containers are excluded from iCloud and Google backups by default.
4. Why we process your data (legal bases)
- To provide the service — account creation, partner pairing, board sync, subscription entitlement. Legal basis: performance of a contract.
- To keep the service safe — abuse prevention, fraud detection, security logging. Legal basis: legitimate interests.
- To fix bugs — opt-in diagnostics. Legal basis: consent, withdrawable at any time in Settings.
- To meet legal obligations — tax, accounting and lawful requests. Legal basis: legal obligation.
- Age verification for 18+ content — protecting minors is a legal and safety requirement. Legal basis: legal obligation and vital interests.
We do not use your data for automated decision-making that produces legal or similarly significant effects.
5. How we protect it
- Encryption in transit (TLS 1.3) and at rest (AES-256) for anything that reaches our servers.
- Local-first architecture: the sensitive part of your data simply has nowhere to leak from, because it never leaves your devices.
- End-to-end encryption for paired sync payloads — sync content is encrypted with keys derived from your pairing, and our servers relay ciphertext they cannot read.
- Optional biometric app lock (Face ID, Touch ID or fingerprint) and an optional passcode.
- Least-privilege internal access, mandatory 2FA for staff, and an annual third-party penetration test.
- If a breach affecting your personal data occurs, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.
6. Cookies and this website
This website uses a strictly necessary session cookie only where needed to remember your cookie preference. We do not run advertising cookies, cross-site trackers or third-party analytics on this site. If we ever introduce optional analytics, it will be consent-gated and off by default in the EU and UK.
The HoneyRoll app itself is not a browser and does not use cookies. Embedded web views that display our own help content use the same strictly necessary policy.
7. Sharing with third parties
We share the minimum necessary with a small set of processors, all under written data processing agreements:
- Apple and Google — app distribution and subscription billing.
- Cloud infrastructure providers — hosting our account and sync endpoints, in the EU and US.
- Crash reporting — only if you opted in to diagnostics.
- Support tooling — to handle tickets you open.
- Law enforcement — only where legally compelled, and we will tell you unless prohibited by law.
There are no advertising networks, no data brokers, no social media SDKs and no "marketing partners" in our stack.
8. International transfers
Where personal data is transferred outside the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with a transfer impact assessment, and we minimise transfers in the first place by keeping gameplay data on your device.
9. How long we keep it
- Account data — while your account exists, and deleted within 30 days of account deletion.
- Gameplay data — it's on your devices; deleting the app or using "Erase all data" ends it immediately.
- Server logs — 30 days.
- Diagnostics — 90 days, then aggregated or deleted.
- Billing records — as long as tax law requires (typically 7 years), stored by the platform and our payment processor.
- Support tickets — 24 months.
10. Your rights
Depending on where you live, you have some or all of the following rights. We honour all of them for everyone, regardless of jurisdiction:
- Access — get a copy of the personal data we hold about you.
- Correction — fix anything inaccurate.
- Deletion — have your data erased. You can do this yourself in Settings → Privacy → Erase all data, which takes three taps. You do not need to email anyone.
- Portability — export your history as a machine-readable file.
- Objection and restriction — object to processing based on legitimate interests, or ask us to restrict it.
- Withdraw consent — for diagnostics at any time, without losing access to the service.
- Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of. The link in the footer exists to make that explicit.
- Non-discrimination — we will not degrade the service for exercising any right.
- Complaint — you may lodge a complaint with your local supervisory authority. If you're in the EU or UK, you can find yours via the EDPB. We'd appreciate the chance to resolve it first.
We respond to verified requests within 30 days, or 45 days for CCPA requests where an extension is needed.
11. Children
HoneyRoll is not directed to children. The core game is intended for users aged 13 and over (16 and over in parts of the EU where the digital age of consent is higher), and After Dark content is strictly 18 and over. We do not knowingly collect personal data from children below the applicable age. If we learn we have, we delete it promptly.
We do not use the app's age attestation as a marketing signal, and we never serve age-inappropriate content to accounts that have not completed 18+ verification.
12. Changes to this policy
If we make a material change, we will tell you in the app before it takes effect and, where the law requires it, ask for your consent again. The "last updated" date at the top always reflects the current version, and previous versions are available on request.
13. Contact
Privacy: [email protected]
Data Protection Officer: [email protected]
General support: [email protected]
Postal: HoneyRoll, Data Protection Office, 1 Example Street, Dublin, Ireland