Plain language

How we handle data

No email needed, no tracking of what you do together, and end-to-end encryption for anything you sync.

This is the plain-language companion to our Privacy Policy. If anything here seems to conflict with the policy, the policy is the authoritative version.

You can play without an account

TicTease works without signing in. When you play without an account, your choices stay in your browser's local storage on that device. Where product analytics are enabled, the only thing a night sends us is its shape: how many turns it had, which level it reached, how many timers ran and cards were skipped, whether Settings were opened, and how it ended (put down, or played to the end). Never a card, a name, or who did what, and nothing that identifies you or the device.

An email is optional, and used for two things

Accounts use a username and password. There's no phone number and no real name. You can add an email if you want one, and if you do we use it for exactly two things: recovering your account if you forget your password, and one reminder three days before a free trial ends. Nothing else, ever, and you can remove it in Settings whenever you like.

The trade-off without one is real: with no email, there's no password reset. If you forget your password, your synced data can't be recovered.

How recovery works without us keeping your key

Your synced data is locked with a key made from your password, and that key is never stored on our servers. So when you add an email, your phone draws a random recovery key and uses it to lock up a copy of your encryption key. It sends us that locked copy, which we keep. To email you the recovery key, your phone sends it to our server too: it passes through once, in memory, on its way to your inbox, and we never store or log it. For that one moment our server has both pieces; afterwards we keep only the locked copy. If our email service isn't set up, your phone doesn't send the recovery key at all and shows it to you once instead. Forget your password, and the reset link we email opens a page where your phone uses the recovery key to unlock the copy, re-locks everything under your new password, and sends us the result together with the new password, over HTTPS, so we can store a salted hash of it, just like at sign-up. We never store your password, your recovery key, or readable data.

Plainly: what we hold can't open your data. Someone who had both your inbox and our servers could, which is what a recovery is; that is the trade you make by adding an email, and why it is off by default.

What "sync" actually stores

If you create an account to carry your progress between devices, here's exactly what happens:

  1. The app turns a small slice of your state into data.
  2. It encrypts that data on your device using AES-GCM with a key derived from your password (the key never leaves your device).
  3. Only the resulting ciphertext is sent to and stored on our servers.
  4. If you added a recovery email, a copy of that key, locked with your recovery key, is stored next to it. It is as unreadable to us as the data.

Because we never receive your password or your encryption key, we cannot read your synced data: to us it's an opaque blob.

The free trial and feedback

Starting a free trial or sending us feedback keeps one more thing, briefly: a keyed hash of your IP address, a code we can compare but cannot turn back into the address, kept for up to 30 days so one connection cannot start trials or send reports without limit. The address itself is never stored, and the code is deleted when the window ends. The trial itself is recorded on your account: when it started and when it ends, and, if you came through ClickBank, a note that your purchases go through ClickBank. Those stay for as long as the account does.

Analytics, done carefully

If product analytics are enabled for a build, we use PostHog configured for privacy:

  • Hosted in the EU.
  • No automatic click/scroll capture and no session recording.
  • On-screen text is masked, so dares, prompts and anything you type are never collected.
  • We don't persist IP-based location.
  • We never build advertising profiles or sell data.

We use this only to see, in aggregate, which features people use so we can make TicTease better. When we compare two versions of a screen, your device picks its version itself and keeps only a plain label for it (such as "control" or "b") in local storage, with no identifier, so the comparison never knows who saw which.

What we don't touch

We don't access your contacts, photos, camera, microphone, or precise location. We don't track which dares you draw, who did what, or anything that happened between you: the counts above (turns, level, timers, skips, how it ended) are the only trace a night leaves, and they carry none of its content. That's yours.

Deleting your data

You can clear your synced data from inside the app, or email privacy@tictease.com to delete your account entirely.

Want the full legal detail? Read the Privacy Policy and Terms of Service.