← Back to site

🔒 Privacy Policy — TriviAll

Last updated: June 2026 · Version 3.0

Your privacy matters to us. This Policy describes what data TriviAll collects, how it is used, where it is stored and what your rights are. Please read it carefully before using the App. This Policy is available at a public URL on the Google Play Store and also inside the App. Where we rely on consent, using the App after being asked does not replace that consent — you can withdraw it at any time as described in section 8.

1. Data We Collect

TriviAll collects the following data. This section matches the Google Play Data Safety form. ACCOUNT DATA: • Anonymous UID generated by Firebase Authentication • Email (only if you sign up with email/password or Google) • Authentication provider (anonymous, email, Google) PROFILE DATA: • Chosen nickname (public in the rankings) • Selected avatar index • Local path of the profile photo (stored on the device only) • Country/region detected from the device locale • Active profile frame and purchased frames GAME DATA: • Scores and records across all modes • Total XP and current level • Daily streak history and best streak • Unlocked achievements • Progress in themes and daily challenges • Virtual coins accumulated and shop transactions • Saved Endless mode sessions • Weekly missions and progress • Power-ups in stock DATA COLLECTED AUTOMATICALLY BY FIREBASE: • App instance identifier (Firebase Instance ID) • Android Advertising ID (AAID) — can be disabled in Android settings • Device model and manufacturer • Android operating system version • Device language and region • Session and app usage events (Firebase Analytics) • Crash and error logs (Firebase Crashlytics) WE DO NOT COLLECT: • Your real full name • Phone number • Precise GPS location • Device contacts • Data from other applications • Credit card or payment information (there are no real purchases)

1-A. Advertising, Party Mode and Invite Data

ADVERTISING (Google AdMob): • The Android Advertising ID (AAID), used to show ads (banner, interstitial and rewarded) and to measure performance • Consent for ads is requested via Google UMP (GDPR/LGPD) on first launch PARTY MODE (local connections): • Your nickname is broadcast to NEARBY devices so they can join the room • Game events (button presses, scores) travel directly between devices over the local network — they do NOT pass through our servers or the internet INVITE AND EARN: • Invite code (derived from your ID), a record of who invited whom, and pending reward coins — stored in Firestore

2. How We Use the Data

The data is used exclusively to: • Create and maintain your account and profile in the App • Display your statistics, achievements and game history • Publish your score in the global, weekly and country rankings • Enter you automatically into the Monthly Tournaments for your country • Reserve your unique nickname (availability check) • Detect and moderate inappropriate profile photos via ML Kit • Sync questions for offline use • Send local game notifications (daily reminders at 7pm, the weekly ranking notice and unlocked achievements) • Improve the App based on general anonymous usage patterns • Show ads (Google AdMob) to keep the App free • Connect you to nearby players in Party Mode (local network/Bluetooth) We show ads via Google AdMob according to your consent (Google UMP). We do not sell your data, nor use it for third-party marketing beyond serving ads.

3. Where the Data Is Stored

LOCAL (on your device only): • Room Database: full profile, achievements, theme progress, challenges, missions, Endless mode sessions, power-ups and recent history • Profile photo file (if uploaded) • SharedPreferences: app preferences (theme, notifications, tutorial state) CLOUD (Google Firebase/Firestore): • /nicknames/{nick}: unique nickname reservation → userId + creation date • /rankings/{userId}_survival: nickname, score, avatar and country for the global ranking • /weekly_rankings/: weekly ranking with the same data • /tournaments/{year-month}_{country}: tournament and match data • /questions/: synced question bank (no user data) • /referral_codes/, /referrals/, /referral_redemptions/: Invite and Earn system (invite code, who invited/was invited, pending reward coins) FIREBASE AUTHENTICATION: • UID, provider and email (if provided) managed by Google Firebase Auth

4. Public Data

The following information is visible to all players of the App: • Your nickname • Your highest Survival mode score • Your avatar index • Your country (for the country ranking and tournaments) This data appears in the global, weekly and country rankings and in the Tournament bracket. If you would rather not appear publicly, you can change your nickname or request deletion as described in section 9.

5. Third-party Services and Automatic Firebase Collection

The App uses the following external services: GOOGLE FIREBASE (policies.google.com/privacy): • Authentication: account and UID management • Firestore: cloud database • Cloud Messaging (FCM): integrated via the Firebase SDK (collects a device token) but not actively used to send messages — the App's notifications are local, generated by Android's AlarmManager • Firebase Analytics: automatically collects session events, device model, Android version, language and country • Firebase Crashlytics: crash and error logs for diagnostics (device model and system version) DEVICE IDENTIFIERS: Firebase may collect the Android Advertising ID (AAID) and app instance identifiers. You can reset or disable the AAID in: Android Settings → Google → Ads. GOOGLE ADMOB (support.google.com/admob/answer/6128543): • Shows ads (banner, interstitial and rewarded). May use the AAID and device data for advertising and performance measurement. Consent is managed by Google UMP (GDPR/LGPD). GOOGLE ML KIT (developers.google.com/ml-kit/terms): • Image analysis for profile photo moderation — 100% on-device processing, with no images sent to servers. OPEN TRIVIA DATABASE (opentdb.com): • Provides English questions under CC BY 4.0 — collects no user data. RETROFIT + OKHTTP: • Communication with the questions API over encrypted HTTPS/TLS. COIL: • Local image loading — processed on the device, with no external upload.

5-A. Bluetooth and Local Connection Permissions (Party Mode)

Party Mode uses Google's Nearby Connections API to connect players in the same room, with NO internet and NO servers. PERMISSIONS REQUESTED: • Bluetooth (advertise, scan and connect) — Android 12+ • Nearby Wi-Fi Devices — Android 13+ • Approximate/precise location — required by Android 11 and earlier ONLY to scan for nearby devices IMPORTANT: • We do NOT collect, store or share your location • The location permission is used solely by the Android system to discover devices in Party Mode • In Party Mode only your nickname and match events are exchanged, directly between nearby devices

6. Data Security

We apply the following security measures: • All communication with Firebase uses HTTPS/TLS • User passwords are managed exclusively by Firebase Auth (we have no access to them) • Firestore security rules ensure each user can access only their own sensitive data • The profanity filter prevents offensive nicknames from entering the database • Profile photos are processed locally and never sent to external servers • Nickname reservation uses atomic Firestore transactions to avoid race conditions

7. Data Retention

We keep your data for the following periods: • Local data on the device: until the App is uninstalled or its data is cleared • Public ranking (Firestore): while the account is active; deleted on request • Reserved nickname: while the account exists; released when changed or when the account is deleted • Tournament data: history kept for 6 months after the tournament ends • Firebase Auth data (UID, email): retained according to Google Firebase policy • Diagnostic logs (Crashlytics): retained for up to 90 days by Firebase After the period ends or a deletion request is made, the data is permanently removed from our systems.

7-A. Legal Basis for Processing (GDPR Art. 6)

We process your data on the following legal bases: • CONSENT (Art. 6(1)(a)): creating an account with email, using a profile photo, sending notifications, and personalised advertising where you have agreed via the consent prompt • PERFORMANCE OF A CONTRACT (Art. 6(1)(b)): saving progress, rankings and the operation of the game you asked to use • LEGITIMATE INTERESTS (Art. 6(1)(f)): app security, content moderation, the profanity filter and fraud prevention — we have assessed that these do not override your rights • LEGAL OBLIGATION (Art. 6(1)(c)): responding to requests from competent authorities Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand. If you are in the United Kingdom, the same bases apply under the UK GDPR.

8. Your Rights (GDPR / UK GDPR)

If you are in the European Economic Area or the United Kingdom, you have the right to: • Be informed about how your data is processed (Arts. 13–14) • Access your data and obtain a copy of it (Art. 15) • Have inaccurate or incomplete data corrected (Art. 16) • Have your data erased — the 'right to be forgotten' (Art. 17) • Restrict processing in certain circumstances (Art. 18) • Receive your data in a portable, machine-readable format (Art. 20) • Object to processing based on legitimate interests (Art. 21) • Withdraw consent at any time, where consent is the basis (Art. 7(3)) • Lodge a complaint with your local supervisory authority (Art. 77) → In the UK: the Information Commissioner's Office (ico.org.uk) → In the EEA: the data protection authority of your country (edpb.europa.eu lists them) To exercise any right, contact: triviall.service@gmail.com We will respond within one month, as required by Art. 12(3). That period may be extended by two further months for complex requests, in which case we will tell you within the first month.

9. Account and Data Deletion

To request full deletion of your data: 1. Go to App Settings → account deletion option (where available) 2. Or email triviall.service@gmail.com with the subject 'Data Deletion — TriviAll' Once confirmed, we will remove: • Your entry in the public ranking • Your reserved nickname in Firestore • Your tournament data • Your records in the invite system (Invite and Earn) • Your Firebase Auth account Data stored locally on the device is removed when you uninstall the App.

10. Minors

The App is not intended for children under 13. We do not knowingly collect data from children under 13. In the EEA, the age of digital consent varies between 13 and 16 by country under GDPR Art. 8; below that age a guardian must give or authorise consent. If we learn that a child's data has been collected without parental consent, we will delete it immediately. Parents or guardians should contact us if they suspect misuse.

11. Cookies and Tracking

The App itself does not use cookies. Firebase may use device identifiers and cookies in its authentication and analytics services, as described in Google's privacy policy.

12. International Data Transfers

The App uses Google Firebase servers, which may be located outside the European Economic Area and the United Kingdom, including in Brazil and the United States. Where data leaves the EEA or the UK, Google relies on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures, to provide an equivalent level of protection. You may request a copy of the relevant safeguards using the contact address in section 14.

13. Changes to This Policy

We may update this Policy from time to time. Significant changes will be communicated inside the App. Continued use after the changes constitutes acceptance of the new version. The date of the last update is shown in the header.

14. Contact and Data Controller

Data controller: TriviAll — Trivia Application 📧 triviall.service@gmail.com For privacy questions, data subject rights or complaints, contact the address above with the subject 'Privacy — TriviAll'. We have not appointed a Data Protection Officer, as the App does not meet the criteria in GDPR Art. 37; the contact address above handles all privacy requests.