# Privacy Policy — Tug of Thought
**Effective date:** [DATE]
**Last updated:** [DATE]
Tug of Thought ("the app") is an educational quiz game for children, published
by [COMPANY LEGAL NAME], [REGISTERED ADDRESS] ("we", "us").
We built this app for a small group of children and we collect as little as we
can get away with. This policy explains exactly what that is.
## The short version
- There are **no accounts, no sign-up, no email addresses and no passwords.**
- We collect **a display name and an emoji** that the child chooses, and nothing
else that could identify them.
- We show **no advertising**, use **no analytics**, and have **no third-party
trackers** of any kind.
- We **never sell or share** anything with anyone.
## What we collect
Only what the game needs to let children play together:
| What | Why | Who chooses it |
|---|---|---|
| A display name (up to 12 characters) | So teammates can tell who answered | The child. It is optional and need not be a real name |
| An emoji avatar | To identify players on screen | The child, from a fixed list |
| A randomly generated player ID | To keep a player's friends list between sessions | Generated on the device |
| A randomly generated 6-character friend code | So a friend can add them | Generated on the device |
| A "last seen" timestamp | To show which friends are available to invite | Automatic |
| Friends list, friend requests, game invitations | To run the friends and invitation features | The child, by adding friends |
| In-game scores, streaks and team | To run and score a match | Automatic during play |
## What we do not collect
We do **not** collect or request: real names, email addresses, phone numbers,
passwords, dates of birth, postal addresses, location data, contacts, calendar,
photos, camera or microphone access, advertising identifiers, device
identifiers (such as IMEI, MAC or Android ID), or any biometric data.
The app requests exactly one device permission: **internet access**. Nothing
else.
We do not use Google Analytics, Firebase Analytics, Crashlytics, advertising
SDKs, or any third-party analytics or attribution service.
## Where the data is stored
Game and friend data is stored in **Google Firebase Realtime Database**, on
servers operated by Google in the **United States**. Google processes this data
on our behalf as a service provider. See Google's privacy policy at
<https://policies.google.com/privacy>.
The display name, emoji and player ID are also stored locally on the device so
the child does not have to set them up again.
## How long we keep it
- **Matches, invitations and open-room listings** are temporary and are deleted
automatically when a game ends or shortly afterwards.
- **Display name, emoji, player ID, friend code and friends list** are kept
until the data is deleted (see below) or the account becomes inactive.
- Uninstalling the app removes the local copy from the device.
## Deleting the data
To have a child's profile and friends list deleted, email
**[PRIVACY CONTACT EMAIL]** with the child's **friend code** (shown on the
Friends screen). We will delete it within 30 days and confirm by reply.
## Children's privacy
This app is **intended for children** and is used under the supervision of a
parent, guardian or teacher.
- We do not knowingly collect personal information beyond the display name and
emoji described above.
- A child is never required to provide a real name. We ask supervising adults
to encourage a first name or nickname only.
- There is **no chat, no free-text messaging between players, no user-uploaded
images, and no way for a child to send arbitrary text to another child.** The
only thing one player sees of another is their chosen name and emoji.
- There are no in-app purchases and no advertising.
- Parents and guardians may request access to, correction of, or deletion of
their child's data using the contact address above.
## Sharing
We do not sell, rent or trade any data. We share it only with Google as the
hosting provider described above, and only where required by law.
## Your rights
Depending on where you live you may have the right to access, correct, delete
or export the data we hold, and to withdraw consent. Contact
**[PRIVACY CONTACT EMAIL]** and we will respond within the period required by
applicable law.
## Security
Data is transmitted over encrypted connections (HTTPS/TLS) and stored with
access rules that restrict what any one device can read or write. No system is
perfectly secure, and we do not claim otherwise.
## Changes
If we change this policy we will update the date at the top and, for
significant changes, notify users in the app.
## Contact
[COMPANY LEGAL NAME]
[REGISTERED ADDRESS]
Email: **[PRIVACY CONTACT EMAIL]**