Privacy
Rummy Kompis
Draft — not yet published. This text is a working draft. It has not been reviewed, it is not yet the policy that applies, and the open questions at the foot of the page are still open.
Effective date: [to be set on publication] · Version: draft
The short version
Rummy Kompis keeps score for a card game played on a real table. It stores the games you play — scores, rounds, the names of the people at the table — and, if you claim an account, your email address — typed in, or given by Sign in with Apple. There are no ads, no analytics SDKs and no tracking of any kind. You can erase everything from inside the app, at any time, whether or not you ever gave an email address.
Who is responsible
Rummy Kompis is made by Romain Perron, an individual, who is the data controller for the purposes of the GDPR. Contact: [email protected].
What is stored
- Your games
- Every score of every round of every game, the order people sit in, who dealt, when each round was saved and by whom, the room code while it is live, and whether the game is in a lobby, being played, finished or abandoned. Totals, ranks and records are never stored — they are computed from the scores each time they are shown.
- The names you enter for other players
- When you keep score for someone who does not have the app, you type their name into your own list of players; that name and a generated cartoon avatar are stored as your data about them. Other people in the same game see that name and those scores.
- Your profile
- A display name you choose and a seed from which a cartoon avatar is drawn on your device. No photographs are ever collected.
- An email address, once you claim an account
- Claiming an account is optional and is not required to play. There are two ways to do it, and either one leaves an email address stored against your account.
- With a one-time code: you type your email address, and a six-digit code — valid for ten minutes — is sent to it each time you sign in that way.
- With Sign in with Apple: Apple asks you, and tells us an email address and an identifier for you. If you choose Hide My Email, the address is one of Apple's private relay addresses rather than your own; the app treats it like any other address, and it is the one shown in your profile. Apple's identifier is stored so that the same Apple Account signs you back into the same games, and your name is never requested. When you delete your data, the app asks Apple to disconnect it from your Apple Account — the deletion goes ahead either way.
- A username, if you choose one
- Usernames exist so friends can find each other, are unique, and are only available to accounts that have been claimed — with a one-time code or with Sign in with Apple.
- Links between people
- Friendships and the requests that created them, people you have blocked, invitations to a seat at a table, friend-invite links, and the standing permission you may give one person to seat you in their games without asking each time.
- Technical necessities
- An identity for the app on your device, created silently on first launch so that the app works without a sign-up, together with the sign-in tokens stored on the device itself; and a record of the day you last used the app, updated at most once a day, which is what the retention rule below is measured against.
What is not collected
- No advertising identifiers, no ad networks, no advertising of any kind.
- No analytics SDK, no usage tracking, no behavioural profiling.
- No photographs, no contacts, no address book, no location.
- No date of birth and no age check (see “Children” below).
- Nothing is sold, rented or shared for anyone else's marketing.
Why it is stored
To do the one thing the app is for: keep the scores of your games and show them back to the people who played them, on every phone at the table. The email address, however you give one, exists so that your games survive a new phone; the links between people exist so that invitations and friend lists work. There is no other purpose.
Legal basis under the GDPR: performance of the service you asked for (Art. 6(1)(b)). See the open questions below.
What other people can see
Rummy Kompis trusts the table. Anyone who is in a game — because they joined with the room code, or because they were seated there — can see and edit every score in it, including yours. That is deliberate: at a real table, whoever is holding a phone writes down the scores. Room codes stop working a day after a game finishes, and a game that is finished can never be changed again.
Where it is stored, and who else touches it
- Convex — the app's backend: database, server functions and real-time updates. The production deployment is in the European Union (Ireland region).
- Resend — delivers the one-time code email when you claim an account, and nothing else. Configured in the Ireland region, with click tracking and open tracking switched off.
- Apple — distributes the app through TestFlight and, later, the App Store, and, if you use Sign in with Apple, tells the app the email address and identifier described above and hides your real address behind a relay when you ask it to. Apple's own privacy policy governs what Apple learns about your download and your sign-in.
- Cloudflare — serves this website, which holds no personal data of its own and sets no cookies.
How long it is kept
- Never-claimed accounts are deleted after twelve months of inactivity. Inactivity means that account not opening the app; the deletion is the same complete erasure described below.
- Claimed accounts are kept until you delete them. They are never deleted automatically.
- Games you finished stay with the people who played them, for as long as those people keep their own accounts.
- Lobbies that were never started are swept away after a day, and a room code stops working a day after its game finishes.
Deleting your data
Settings → “Delete my data”, in the app. It is available to everyone, including accounts that never gave an email address, and it does not ask for a reason. The app signs the device out immediately and the erasure then runs to completion in the background: your profile, your list of players, and every game only you were in are deleted outright. If you claimed the account with Sign in with Apple, the confirmation offers one more line: tick it and sign in with Apple once more, and the app also asks Apple to disconnect it from your Apple Account. Leaving it untouched, dismissing that sign-in, or any failure to reach Apple does not stop or delay the deletion.
Games you played with other people stay with them — that is their history too — but your seat in them shows as “Deleted player”, with only the scores left behind. The names you had entered for other players disappear from those games as well, because they were your data about them.
You can also ask by email at [email protected], without opening the app.
Children
Rummy Kompis is rated 4+ and is a family scorekeeper: children play at the table alongside everyone else, usually on a grown-up's phone. It is not in Apple's Kids category, it asks for no date of birth, and there is no way to meet a stranger in it — there is no online play, no public profile and no discovery by phone number or email. A child's name in the app is whatever the person keeping score typed.
Your rights
Under the GDPR you may ask for a copy of your data, ask for it to be corrected, ask for it to be erased, ask for processing to be restricted, object to processing, and ask for your data in a portable form. Erasure is built into the app and needs no request. For anything else, write to [email protected]. You also have the right to complain to your national data protection authority.
Changes to this policy
If this policy changes, the effective date at the top changes with it, and a change that affects what is collected or why will be announced in the app before it takes effect.
Languages
The app itself speaks English, Swedish and French. This policy is in English for now; Swedish and French versions will follow, and the English text remains the reference version.
Contact
Romain Perron · [email protected]
Open questions (draft only — delete before publishing)
Not answered by the project documentation, and deliberately not invented here. Each one needs a decision before this page goes up.
- Controller's postal address. Art. 13(1)(a) expects identity and contact details. An email address alone is thin for a named individual; decide whether to publish an address or to rely on the email.
- The supervisory authority. Which one people should complain to depends on where the controller is established. The page currently says “your national data protection authority”, which is safe but vague.
- Legal basis. Art. 6(1)(b) is asserted above. Contract as a basis is awkward for an app with no sign-up and no terms; legitimate interests may fit better, and the names entered for other people (who never agreed to anything) are the part worth a second look.
- Server logs. Whether Convex, Resend or Cloudflare retain IP addresses or request logs on the owner's behalf, and for how long, is not recorded anywhere in the project docs. Check each provider and either say so here or say that none are kept.
-
Does
[email protected]receive mail? It is verified as a sending address; inbound forwarding is listed in the project notes as a follow-up that may not have been done. A contact address that bounces is worse than none. - An international-transfers sentence, if any provider processes outside the EU despite the EU regions chosen.
- A Google Play data-deletion page will be required as its own URL when an Android version ships; the in-app route and the email route above are what it would describe.