Legal
Privacy Policy
The short version: we collect as little as possible, and we can't read what you sync.
This Privacy Policy explains what information TicTease ("we", "us") collects when you use the TicTease app and website (the "Service"), how we use it, and the choices you have. By using the Service you agree to this policy.
Our privacy principles
- Data minimization. We collect the least we can to run the Service.
- No email required. Accounts use a username and password. You may add an email if you want to; if you do, we use it for two things only: recovering your account if you forget your password, and one reminder three days before a free trial ends.
- Encrypted by default. Anything you choose to sync is encrypted on your device before it reaches our servers, so even we can't read it.
- No selling your data. We do not sell or rent your personal information to anyone.
Information we collect
Information you provide.
- Account details (optional). If you create an account to sync across devices, we store a username and a securely hashed password. We do not collect your phone number or real name. If you start a free trial, we also store when it started and when it ends (and when we sent the one reminder, if you added a recovery email), and, if you came to us through ClickBank, a note that your purchases go through ClickBank. These are kept for as long as your account exists.
- Recovery email (optional, off by default). If you choose to add an email address, we store the address, the time you agreed to it, and a wrapped (encrypted) copy of your encryption key that only your recovery key can open. See "Account recovery" below for exactly what that means. If you never add one, we do not have your email address.
- Purchases. If you make a purchase, payment is handled by ClickBank or CCBill, each under its own privacy policy. They collect your payment and billing details; we never see your card number. We keep only an order or subscription reference, the amount paid, any influencer code you applied, and the account the purchase unlocked.
- Messages you send us. If you contact support, we keep your message and any details you include so we can help.
Information collected automatically.
- Your synced game state. If you sign in, the app stores a slice of your in-app state (such as preferences and progress). This is encrypted on your device with a key derived from your password; our servers only ever store ciphertext. If you forget your password, this data can be recovered only if you added a recovery email (see "Account recovery" below); without one it cannot be, by design.
- Product analytics (privacy-first). Where enabled, we use PostHog to understand which features are used. Analytics run on EU-hosted infrastructure, automatic event capture and session recording are turned off, on-screen text is masked, and we never log the content of dares, prompts or anything you type. What we do count is the shape of a night: how many turns it had, which level it reached, how many timers ran and cards were skipped, whether Settings were opened and how the night ended (put down, or played to the end), plus which screens and unlock steps were reached. None of it carries a card, a name, who did what, or an identifier for you or your device. We do not build advertising profiles. IP-based geolocation is not persisted.
- Essential technical data. Like any website, our hosting provider (Cloudflare) processes basic request information to deliver pages and protect against abuse.
- Abuse limits. When you start a free trial or send us feedback, we keep a keyed hash of your IP address (a code we can compare but cannot turn back into the address) for up to 30 days, only to cap how many trials or reports can start from one connection. The address itself is never stored.
Information we do not collect. We do not collect your contacts, photos, microphone or camera data, or precise location. Unless you add a recovery email, we do not collect your email address either.
Account recovery
Your synced data is encrypted with a key that is never stored on our servers, so a normal "reset your password" would leave it unreadable forever. If you add a recovery email, the app instead draws a random recovery key on your device and uses it to wrap (encrypt) your encryption key. It sends us the wrapped copy, which we store. So that we can email the recovery key to you, the app sends it to our server in the same request: it passes through our server once, in memory, on its way to the mail service, and is never written to storage or logs. During that one request our server has both the recovery key and the wrapped copy; we do not keep the first, so afterwards what we hold cannot open your data. If our email service is not set up, the app does not send the recovery key at all and shows it to you once on screen instead. When you ask for a reset, we email a link that works once and for one hour. On that page your device uses your recovery key to open the wrapped copy, re-encrypts your data under your new password, and sends us the result along with the new password, over HTTPS, so our server can store a salted hash of it, exactly as when you sign up or sign in. We never store your password, your recovery key, or readable data.
Said plainly: what we hold cannot open your data on its own. What this does not protect against is someone who controls both your inbox and our servers, because that is exactly what a recovery is. That is the trade you make by adding an email, and it is why the address is optional and off by default. You can remove it at any time in Settings, which also deletes the wrapped copy.
If you added an email and started a free trial, we send one reminder three days before the trial ends. That is the only other email you will ever get from us at that address.
How we use information
- To provide and maintain the Service, including optional cross-device sync.
- To keep accounts secure and prevent fraud and abuse.
- To understand aggregate usage and improve the product.
- To respond to your support requests.
- If you added a recovery email: to send you the recovery key, a reset link when you ask for one, and one reminder before a free trial ends. Nothing else is ever sent to it.
Cookies and local storage
We use local storage and a session cookie to keep you signed in and to remember your preferences. If you arrive through a ClickBank link, or sign in to an account that did, we also set a small cookie that remembers it, so your purchase goes through ClickBank; it holds no identifier. Analytics, where enabled, set no cookie and store nothing on your device: each visit is counted on its own, with no identifier carried between visits. When we test two versions of a screen, the version your device shows is chosen on the device and kept in local storage as a plain label (such as "control" or "b") with no identifier attached, so we can compare the versions without knowing who saw which. We do not use third-party advertising cookies.
Sharing and disclosure
We share information only with service providers who help us run the Service (such as our hosting and analytics providers, acting under contract), or where required by law. We may disclose information if necessary to protect the rights, safety or security of our users or the public.
Data retention
We keep account data for as long as your account exists. Encrypted synced state is kept until you delete it or your account. A recovery email and the wrapped key that goes with it are kept until you remove them in Settings or delete your account; a reset link is kept only as a hash and only for an hour. Support messages are kept only as long as needed to resolve your request.
Your rights and choices
- Access and deletion. You can delete your synced data from within the app, or ask us to delete your account and associated data.
- Opt out of analytics. Analytics are aggregate and privacy-preserving; contact us if you'd like to opt out entirely.
- Regional rights. Depending on where you live (for example, the EEA/UK under the GDPR, or California under the CCPA/CPRA), you may have additional rights to access, correct, port or erase your data. Email us to exercise them.
To make a request, email privacy@tictease.com.
Children
TicTease is for adults aged 18 or older. We do not knowingly collect information from anyone under 18. If you believe a minor has used the Service, contact us and we will remove the data.
International transfers
We operate globally and may process data in countries other than your own. Where we do, we rely on appropriate safeguards for any transfer of personal data.
Security
We use industry-standard measures including encryption in transit (HTTPS), client-side encryption for synced state, and salted password hashing. No method of transmission or storage is perfectly secure, but we work to protect your information.
Changes to this policy
We may update this policy from time to time. We'll revise the "Last updated" date above and, for material changes, provide a more prominent notice.
Contact
Questions about privacy? Email privacy@tictease.com. See also How we handle data for a plain-language summary.