Privacy Policy
This policy explains what data the Wordker mobile app ("Wordker", "we") collects, why, and what you can do about it. Wordker is a multiplayer word game available on Android and iOS.
1. Who is responsible
The data controller is Jakub Szymion, the developer of Wordker. Contact: wordker@szymion.dev.
2. What we collect
Playing without an account
You can play without registering. In that case the app generates a random identifier on your device and we create an anonymous player profile for it, with an automatically generated nickname. We store:
- the random device identifier,
- the generated nickname and a generated avatar,
- your gameplay: words you submit, scores, game history, streaks and daily-challenge progress.
Registered account
If you create an account, we additionally store:
- your e-mail address (used to verify the account and to reset your password),
- your password, stored only as a salted hash,
- the nickname you choose,
- an avatar photo, only if you decide to upload one from your camera or photo library.
Anonymous gameplay recorded before you registered is merged into your account.
Push notifications
If you allow notifications, we store a push token issued by Firebase Cloud Messaging for your device and your notification preference. We use it to send reminders about your streak, daily challenges and game events. You can turn notifications off in the app's settings or in your device settings at any time.
Crash and error reports
When the app crashes or hits an error, a report is sent to Sentry. It contains technical details such as the device model, operating system version, app version and the stack trace. We configure Sentry not to include personal data by default.
Server logs
Our servers keep short-lived technical logs, including IP addresses, which we use for security, rate limiting and abuse prevention.
We do not use advertising, analytics or tracking SDKs, and we do not collect precise location, contacts or any data unrelated to the game.
3. Why we use it and on what legal basis
- Providing the game (rounds, scores, leaderboards, challenges, account management): performance of the contract with you.
- Security, abuse prevention and fixing crashes: our legitimate interest in keeping the service working and fair.
- Push notifications: your consent, given through the notification permission on your device; you can withdraw it at any time.
- E-mails about account verification and password reset: performance of the contract. We send no marketing e-mails.
4. What other players can see
Your nickname, avatar and scores are visible to other players on leaderboards and in game results. Please do not use a nickname or photo you would not want to be public.
5. Who processes data on our behalf
We do not sell personal data and we do not share it with advertisers. The following providers process data for us, under their own data-processing terms:
- Railway – application and database hosting (European Union region),
- Amazon Web Services (S3) – storage of avatar images and static files (EU, Ireland),
- Google Firebase Cloud Messaging – delivery of push notifications,
- Sentry – crash and error reporting,
- Resend – sending transactional e-mails (verification, password reset).
Some of these providers may process data outside the European Economic Area; in that case transfers rely on the European Commission's standard contractual clauses or an adequacy decision.
6. How long we keep it
- Finished games, together with the words submitted in them, are deleted after 30 days.
- Daily-challenge progress is deleted after 30 days.
- Anonymous player profiles that have not played for 30 days are deleted.
- Registered accounts are kept until you delete them.
- Crash reports are kept by Sentry for 90 days.
- Server logs are kept for a short period needed for security.
7. Deleting your account
You can delete your account in the app: Account → Delete account. Deletion removes your e-mail address, password, nickname and avatar, and unlinks your device from the profile. Aggregate gameplay statistics (such as the number of games played) are kept without any link to you. You can also ask us to delete your account by e-mail.
8. Your rights
Under the GDPR you have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, and to receive a copy of it in a portable format. To exercise these rights, write to wordker@szymion.dev. You also have the right to lodge a complaint with a supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO).
9. Children
Wordker is not directed to children under 13 and we do not knowingly collect data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Security
All traffic between the app and our servers is encrypted (HTTPS). Passwords are stored as salted hashes. Account sessions use short-lived tokens. Access to production systems is restricted to the developer.
11. Changes
We may update this policy as the game evolves. The current version is always available at wordker.app/privacy, with the date of the last change at the top.
12. Contact
Questions about privacy: wordker@szymion.dev.