Last updated: 2 October 2026.
1. Controller
adimeiss Ltd.Limnaria 1
Westpark Village, Shop 20
8042 Paphos, Cyprus
Email: hello@zackdu.com
Further provider details are in the Legal notice. We have not appointed a data protection officer because we are not required to do so.
2. Key points
- The app does not need a user account. Player names, free-form or spoken answers, secret words and voice recordings stay on your device. Choices in “Would You Rather?” may be sent to the server for the community comparison (see section 6.9).
- For purchases and creator codes, we use a random installation identifier (not an advertising ID).
- Usage analytics are only enabled with your explicit consent. We count pages, predefined button actions and game flows, without screen recordings. You can turn analytics off in Settings at any time.
- Feedback messages stay private; we review public ideas before publishing them. Voting uses a separate identifier (section 6.7).
- We do not include advertising SDKs or track you across other apps or websites, so we do not ask for the iOS App Tracking permission.
3. Website zackdu.com and hosting
When you visit zackdu.com, the web server processes connection data that is technically necessary, such as your IP address, time, requested address, browser information and HTTP status. This serves delivery, stability and security of the website (Art. 6(1)(f) GDPR). The website is hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, which acts as our processor (Art. 28 GDPR). We keep server logs only as long as necessary for operation and security; they are then deleted or their IP addresses anonymised.
Without your consent, the website does not use analytics cookies. We do not use advertising cookies, external fonts or social media embeds. Your browser may create technically necessary caches.
Creator invitation links: When you open an invitation page under zackdu.com/r/ or zackdu.com/en/r/ with a creator code, your browser sends a request to our app backend (section 5). We count the visit for each code with a timestamp, without an IP address, cookie or device ID in this count. To prevent abuse, we briefly process a hash of the IP address (section 6.4). The legal basis is our legitimate interest in fair, traceable creator accounting (Art. 6(1)(f) GDPR). Link visits are deleted after 13 months.
Google Analytics on the website
We load Google Analytics 4 only when you choose “Allow analytics”. Without consent, no connection to Google Analytics is made. With consent, we measure page views and clicks to the app download, App Store and creator profile. Google processes a random cookie identifier, browser and device information, language, the page visited without URL parameters and technical connection data. We do not send creator codes, names, email addresses or free text as analytics parameters. According to Google, Google Analytics 4 does not store IP addresses; your IP address is processed for the technical connection and approximate location.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC in the United States is possible. Google explains its international transfer mechanisms, including the EU-US Data Privacy Framework and Standard Contractual Clauses, in its data transfer information. Further information is in the Google Privacy Policy.
The legal basis is your consent (Article 6(1)(a) GDPR; for access to your device, Section 25(1) of the German TDDDG). Google signals and advertising personalisation are disabled. Analytics cookies last no longer than 180 days; we also store your consent choice locally in your browser for no longer than 180 days. User and event data are retained in Analytics for two months; aggregated standard reports may remain available longer. You can withdraw consent for future processing at any time using “Privacy settings” in the footer. We then remove analytics cookies and reload the page without Google Analytics.
4. App: data that stays on your device
The app stores player names, ongoing rounds, crew scores, card history, private Imposter words and sound, vibration and reminder settings locally on your device. These data are not transferred to us or third parties. “Delete progress and names” in Settings removes player names, game progress, crew scores, card history and custom words from the device; your settings, installation identifier, creator code and consent choices remain. Deleting the app removes all local data.
Microphone in Sound Flip: Only when you play Sound Flip and allow microphone access in iOS or Android does the app record short voice recordings of up to six seconds to play them backwards. The recordings are stored temporarily on the iPhone or Android device, are not transferred and are deleted when you leave the game, start a new round and no later than the next app start. The legal basis is providing the game you selected (Art. 6(1)(b) GDPR). On Android, recordings are held only temporarily in the app process’s memory; no audio file is created. You can revoke access in your device settings at any time.
Daily reminder: The daily Imposter reminder is scheduled as a local notification on your device. Nothing is transferred to us for this.
The app does not access your camera, location, contacts or photos and does not require a user account.
5. App backend (Supabase)
Supabase, Inc. operates our app backend (database and server functions) as our processor (Art. 28 GDPR). The database is in Frankfurt am Main, Germany (AWS eu-central-1). Requests from the app and invitation page are received by Supabase server functions running at a data centre near you, generally in Europe when used in the EU. Supabase technically processes your IP address and briefly stores it in server logs. Supabase is a US company; where access from the US or processing outside the EU cannot be ruled out, it takes place under the EU Standard Contractual Clauses included in Supabase’s data processing agreement.
6. App: data transferred to us
6.1 Installation identifier
On first launch, the app generates a random installation identifier (UUID). It contains no name and is not your device’s advertising ID. At each start, the app uses it to ask our backend whether a creator code is active for this installation. It also serves as a pseudonymous customer identifier with RevenueCat (section 7). The legal bases are providing the app and Plus (Art. 6(1)(b) GDPR) and our legitimate interest in correct creator attribution (Art. 6(1)(f) GDPR). Storing the identifier on your device is technically necessary for these functions you use.
6.2 Creator codes and purchase attribution
You can enter a creator code or open a creator link. We then store the installation identifier, code, entry method (manual or link) and timestamp. A code is considered confirmed once our server has checked that it exists and is active and assigned it to your installation. If you buy Plus within 30 days of entering it, we attribute the purchase to this creator, who receives a share of our revenue. You pay nothing extra, and a creator code does not unlock Plus or any content. Creators see only aggregate figures, not who you are. We also send the code to RevenueCat as the “creator_code” attribute.
The legal basis for attributing your installation and purchase to a creator is our legitimate interest in contractual, verifiable commission accounting (Art. 6(1)(f) GDPR). We process creators’ own data to perform their contracts (Art. 6(1)(b) GDPR). Attributions without a purchase are deleted 30 days after the last entry. A free trial that does not convert to a paid subscription is not a purchase: code entries are deleted after 30 days in that case. A provisional trial attribution record (installation identifier, code, transaction ID) is retained to account for possible later conversions, like other accounting data (section 11). Once a paid purchase has been made through the installation, its attribution and previous code entries remain stored for commission accounting and evidence (section 11).
6.3 Usage analytics — only with your consent
Only when you explicitly consent to usage analytics in the app or enable it in Settings do we send pseudonymous events to our backend: random event and session identifiers, installation identifier, timestamp, game mode, app version and platform, viewed pages, predefined button actions, intro steps, duration of a page visit, player count without names, completed rounds, leaving and resuming a round, purchase attempts and their results, and predefined types of technical errors. In an A/B test, we also record the test run, variant and its display. If a creator code is assigned, we link the event to that code. We do not transfer screenshots, screen recordings, player names, answers, words, audio recordings or entered free text as usage data. The purpose is aggregate analysis of game flows, clarity, return visits, technical problems and creator campaigns, and comparison of two app versions. Earlier consent to previous analytics is not carried over to this expanded analysis; we ask again.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time in the app under Settings → Data & privacy → Usage analytics. No further events will then be sent, and unsent events on the device will be deleted. Already transferred events remain stored until the retention period expires; we will delete them sooner on request (section 14). Events are automatically deleted after 13 months.
Additional analytics with PostHog (EU): In app versions that explicitly mention PostHog in the consent request, the predefined usage events described above are also sent with your consent to PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114. We use PostHog Cloud EU with servers in Frankfurt and a separate random analytics identifier that is neither your purchase nor your installation identifier. Events contain no creator codes, transaction identifiers, player names, answers, words, recordings, screen recordings, URLs or free text. During technical transmission, PostHog processes your IP address; location analytics are disabled in our integration. The analytics identifier is stored locally until withdrawal of consent or deletion of the app. Prior consent to our own analytics does not enable PostHog; we ask again. On withdrawal, the local PostHog identifier and unsent PostHog events are also deleted. The analysis serves the same purposes described above and is also based on your consent. Information about the provider is available in its privacy documentation.
6.4 Abuse prevention
To prevent artificial inflation of creator figures or overload of our interfaces, we count requests per sender. For each request type, we store counters with hashes of the IP address, or the IP address together with an installation identifier or creator code, and a total counter per creator code; we do not store the IP address itself in plain text. These entries are deleted no later than approximately two days after the last request. The legal basis is our legitimate interest in security and fair accounting (Art. 6(1)(f) GDPR).
6.5 News by push notification — iPhone, only with your consent
The Android app currently uses no server push notifications; it only has the local daily reminder. If you enable “News about new games” on iPhone (a separate switch, independent of the daily reminder) and allow notifications, we occasionally send ZACKDU! news, such as new games, through Apple Push Notification Service (APNs). We store the installation identifier, Apple device token, technical push environment, your consent with timestamp and text version, and the delivery status of individual notifications. Apple processes the token and notification content to deliver the notification to your device.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can turn off news in the app under Settings → Notifications independently of the daily reminder. Without an internet connection, withdrawal is completed at the next app start; you can also block iOS notifications in iPhone settings at any time. Device tokens are deleted 30 days after withdrawal. Delivery status is deleted after 90 days. We keep consent records while your consent is active and delete them 13 months after withdrawal.
6.6 Creators as in-app hosts
If you confirm a code for a creator who appears as a host in ZACKDU!, the app shows that creator’s character with their name and short texts, labelled as advertising. The images are loaded from our backend through time-limited links; your installation identifier is not passed to third parties.
6.7 Ideas and feedback
When you send feedback, we store the message, category and timestamp. Messages are initially visible only to our team. We may combine similar requests into a public idea that we have reviewed; please do not include names, contact details or other private information in your message. The board shows only the title, description, status and total vote count. You can cast one vote per idea and withdraw it. The app generates a separate random feedback identifier, distinct from the installation identifier used for analytics. We store only a hash of this identifier created with a secret key on the server. This feature is also available when analytics are disabled.
We process these data to receive your feedback and provide the voting function you use (Art. 6(1)(b) GDPR). Private messages are deleted after no more than 180 days, and rejected messages after 30 days. Individual votes and their hash identifiers are deleted after 13 months; displayed totals are then recalculated. Reviewed idea texts we publish remain visible until the idea is removed. Reporting an idea sends a private report to our team. You can reach us through the support page for enquiries and privacy concerns.
6.8 App store reviews
The review button opens the review page of the respective store (Apple App Store or Google Play). You submit your review to the store; this button does not tell us whether or how you reviewed the app. The provider’s privacy notice applies to its processing. We count opening the review page as a button action only when usage analytics are enabled.
6.9 Community voting in “Would You Rather?”
When you tap an answer, the app sends the card number, your choice (A or B) and a separate random voting identifier to our server. This identifier is separate from analytics, feedback voting and creator attribution. We store the total vote count per card. To prevent the same installation counting more than once per card, we also store a hash of the voting identifier created with a separate secret key and the vote timestamp. The daily deletion process removes these entries after 30 days; aggregate votes remain. The same installation can then vote again. Percentages appear once a card has 50 votes. This function is also available when usage analytics are disabled.
The legal bases are providing the selected voting function (Art. 6(1)(b) GDPR) and our legitimate interest in preventing manipulated votes (Art. 6(1)(f) GDPR). To prevent abuse, we count requests using hashes of the IP address and voting identifier; these entries are removed by the daily deletion process after one day. Names, free-text answers and audio recordings are not transferred.
Protected content updates
The iPhone app downloads new game content through protected access. The Android app currently uses only bundled game content; it does not generate App Attest evidence or request protected content downloads. Apple’s App Attest generates a dedicated device key on your iPhone. The private key stays on the device. We send the public key identifier, Apple attestation evidence and signed responses to short-lived challenges to our backend. We store the public key, evidence, technical environment, a counter against repeated requests and the registration timestamp. These data verify the app and prevent unauthorised downloads; we do not link them to player names, game progress, creator codes or usage analytics.
Challenges are valid for two minutes, and download access for no more than 15 minutes. On the server, we store only a hash of the access token. A daily deletion process removes expired challenges after one hour, expired access tokens after one day and rate-limiting entries after one day. The public key identifier and attestation evidence remain stored for later device checks until the key is blocked or deleted. Content updates also work with usage analytics disabled; they do not require an account or password.
7. Purchases with Apple, Google Play and RevenueCat
Apple handles in-app purchases in the iPhone app, and Google Play in the Android app, including payment, subscription management and refunds. We do not receive payment card details or contact details for your store account. We receive purchase and accounting data through RevenueCat and statements from the respective store. The privacy notices of Apple and Google also apply. Plus purchases are disabled in test versions without configured Google Play purchases.
We use RevenueCat, Inc. (USA) as our processor to unlock and restore Plus. RevenueCat receives our random, persistent installation identifier as a pseudonymous customer identifier, product, purchase and transaction data, Apple purchase receipts or Google Play purchase evidence where applicable, the creator code, and technical device and usage information required by the RevenueCat SDK for purchase verification and operation (such as device type, operating system, language, store country and currency, and last app contact). No advertising ID is collected. We do not send player names to RevenueCat. RevenueCat reports purchase events to our backend; we store selected fields there (event type and ID, transaction IDs, installation identifier as app user ID, product, store and environment, timestamp, subscription phase and any cancellation reason, price, currency, country, and tax and store commission shares) for accounting, refunds and creator commissions. If a purchase event cannot be processed, we store the same selected fields for follow-up: resolved cases for up to 90 days after resolution, and open cases for up to 13 months after the last processing attempt.
The legal basis is performance of the Plus purchase contract (Art. 6(1)(b) GDPR), with statutory retention obligations also applying to accounting records (Art. 6(1)(c) GDPR). Transfers to the US take place under the EU Standard Contractual Clauses included in RevenueCat’s data processing agreement.
8. Creator hosts: AI-generated characters
This section concerns creators who have agreed to appear as hosts in the app. Only after the creator contract including this permission has been signed do we send a photo selected by the creator to OpenAI’s image generation service to create an illustrated 3D character. The photo is submitted for two image edits per creation, and again if a character is recreated. We do not store the original photo in our database; only the generated character images, display name, approved texts, label and a reference to the approval are stored. The legal basis is the creator contract (Art. 6(1)(b) GDPR), including its permission to use the creator’s likeness.
The image service provider is OpenAI Ireland Ltd., Dublin, Ireland; processing by OpenAI group companies in the US is possible and takes place under the EU Standard Contractual Clauses. Under OpenAI’s contract terms, content submitted through the API is not used for training; abuse monitoring logs may generally contain content for up to 30 days, or longer in exceptions described by OpenAI (for example, for legal reasons). The creator approves the character and texts in text form before activation. When their appearance ends, we deactivate the character and automatically delete the images within 30 days.
9. Digital creator contracts
For creator agreements, we store names, company and contact details, addresses, individual terms, the contract version and electronic signatures (name and drawn signature) with server-side timestamps and checksums. The purposes are preparing, performing and evidencing the contract (Art. 6(1)(b) GDPR), complying with statutory retention obligations (Art. 6(1)(c) GDPR) and, where necessary, asserting or defending claims (Art. 6(1)(f) GDPR). Unsigned contract drafts are deleted 30 days after the link expires.
The personal contract link contains confidential access in the URL fragment and must only be shared with the intended person. There is no identity-document check, qualified electronic signature or automatic email delivery.
10. Creator applications and contact
For a creator application, we store the requested code, public channel name, invitation reference and processing status. Rejected applications are deleted after 90 days and pending applications after 180 days; accepted applications remain stored to perform the contract. We also store commission rates, payouts and bank references for commission accounting.
When you email us, we process your address and message to reply (Art. 6(1)(b) or (f) GDPR). ALL-INKL.COM also operates our email inbox as our processor. Please do not send secret game content or payment details by email.
11. Retention overview
- Creator attribution without a purchase: 30 days after the last entry.
- Usage events and link visits: 13 months.
- Abuse-prevention hashes: approximately two days after the last request.
- Unprocessable purchase events: 90 days after resolution, or for open cases 13 months after the last processing attempt.
- Push: tokens 30 days after withdrawal, delivery status 90 days, consent records while consent is active and for 13 months afterwards. The titles and texts of news sent contain no personal data.
- AI-generated creator character images: no later than 30 days after the appearance ends.
- Purchase, refund and commission data and purchase attribution: for the duration of commission claims and then until statutory retention periods expire; under Cypriot tax law, six years from the expiry of the tax return deadline. Our daily deletion process removes these data once the transaction predates 1 January of the eighth preceding year (in 2026, transactions before 2018). Open or later corrected accounts and linked evidence may be kept longer until resolved. Aggregate balances per creator remain for ongoing accounting.
- Signed creator contracts: for the contract term and then until statutory retention and limitation periods expire. Automatic deletion is not currently configured for these; we manually review deletion after a contract ends.
- Local data on iPhone: until you delete them in the app or remove the app.
12. Required or optional?
Usage analytics and push news are optional; without your consent, only these functions are unavailable. Purchases require the identifiers and transaction data needed to process them; without these, we cannot unlock or restore Plus. Withdrawal takes effect for the future and does not affect lawful processing before withdrawal. You can request a copy of the EU Standard Contractual Clauses used for transfers to third countries at hello@zackdu.com.
13. No automated decisions or sale of data
We make no automated individual decisions within the meaning of Art. 22 GDPR, create no advertising profiles and sell no personal data.
14. Your rights
You have the rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and withdrawal of consent at any time with effect for the future (Art. 7(3)). Where we process data based on legitimate interests, you can object at any time on grounds relating to your particular situation (Art. 21 GDPR).
To exercise your rights, email hello@zackdu.com. We do not maintain player accounts or know players’ names, so we often cannot link app data to a person (Art. 11 GDPR). The Apple or Google Play order number from the purchase confirmation is particularly helpful. We will tell you what information is needed for secure identification. We can identify creators and contact data by name.
You can lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Office of the Commissioner for Personal Data Protection, Kypranoros 15, 1061 Nicosia, Cyprus (postal address: P.O. Box 23378, 1682 Nicosia) (dataprotection.gov.cy). You can also contact the supervisory authority where you live or work in the EU (Art. 77 GDPR).
15. Changes
We update this notice when the app, website or legal situation changes. The version published here applies.