Privacy Policy
Effective date: September 20, 2026
Applies to: Who's That? version 1.0 and later.
1. Introduction
This Privacy Policy explains how Leah Stewart, trading as Penny Labs ("we", "us", "our") collects, uses, and discloses information in connection with the mobile application Who's That? (the "App").
For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), we are the data controller for the information described in this Policy. Our contact details are in Section 14.
By downloading or using the App, you acknowledge the practices described in this Policy.
2. Summary
The App is a two-player guessing game played with photographs you supply. It has no user accounts and no advertising.
Photographs you add to the App stay on your device unless you choose to do one of two things: play a game across two devices, or send a group of people to someone else using a code. Those are the only circumstances in which a photograph leaves your device, and Section 3.1 describes exactly what happens in each. The App tells you what is about to happen, and lets you decline, before either one begins.
The names you give the people in a group travel with their photographs in both of those cases.
The card you are secretly dealt is never transmitted, to us or to the other player, in any mode of play.
We collect a limited set of anonymous gameplay records for analytics purposes, described in Section 3.2. These records contain no photographs, no names, and no text you have typed. They do not contain your name, contact details, location, or any device identifier.
3. Information we collect
3.1 Photographs and the people in them
The App is built around photographs of people you know. You add them by taking a photograph inside the App, or by selecting one from your photo library.
Where photographs are stored.
When you add a photograph, the App creates a copy inside its own private storage on your device, resized for display. The App does not retain a reference to the original in your photo library, so moving or deleting the original does not affect the App. Each copy is named after a SHA-256 hash of its own contents.
When photographs leave your device.
If you play on a single device, passing it between players, photographs are never transmitted anywhere.
There are two circumstances in which they are uploaded.
Hosting a game across two devices. The photographs in the group you are playing with are uploaded to our storage provider so that the second device can display them. This happens after you confirm a notice on screen that says so, and before a room code is created.
Sending a group to someone else. You can give another person a copy of a group you have built, so that they can use it without assembling it themselves. If you choose to, the App uploads the group's photographs together with a small record listing the group's name, each person's name, and the address of each photograph. It then gives you a six-character code. This happens after you confirm a notice on screen that says so.
In both cases every photograph in the group is uploaded each time, including any that have been uploaded before.
How uploaded photographs are stored.
Uploaded photographs are stored in a storage bucket configured for public read access. The address of each image is derived from the SHA-256 hash of the image itself. That address is not published, indexed, or linked from anywhere, and it cannot be guessed from any information about you. It is, however, not protected by an access-control check: anyone who obtains the address can retrieve the image. You should take this into account when deciding whether to host a two-device game or send a group.
What a code means.
A code is not a request that we approve. Anyone who has the code can download their own permanent copy of that group's photographs and names, as many times as they like. Codes do not expire, and once somebody has downloaded a copy we cannot retrieve or delete it — it is on their device, exactly as your own copy is on yours. Treat giving somebody a code as equivalent to handing them the photographs.
Deleting uploaded photographs.
Deleting a group in the App deletes both the local copies and the uploaded copies of any photographs that no group still refers to. Because photographs are stored by content, an image used in two groups is deleted only when the last group referring to it is deleted.
Deleting a group therefore also stops any code you have given out for it from working. The small record listing the group's name and the names of the people in it is not deleted automatically; if you would like one removed, contact us under Section 14 with the code.
Photographs of other people.
The App is designed for photographs of friends and family. If you photograph another person, or add a photograph in which another person appears, you are responsible for having their agreement to do so, and for telling them what you intend to do with it. We would encourage you in particular to ask before hosting a two-device game or sending a group, since those are the points at which the image is uploaded — and, in the case of a code, at which somebody else acquires a copy you cannot recall.
3.2 Information collected automatically
As you use the App, it transmits records describing your interaction with it. These records contain information about your progress and navigation within the App, including:
| Data | Description |
|---|---|
| Event type | Which action occurred, such as opening a screen, starting a game, finishing one, or sending a group to someone |
| Screen | Which screen of the App was opened |
| How you are playing | Whether the game is set to one device or two, and whether questions are asked out loud or typed |
| Group size | How many people are in the group being played with, or being sent, as a number |
| Rounds or questions | How many turns a completed game took |
| Outcome | Whether a game was finished or abandoned |
| Walkthrough progress | How far through the introductory screens you progressed |
| Time of the event | The date and time recorded by your device |
| App version | The version of the App installed on your device |
| Installation identifier | A randomly generated value, described below |
These records contain no photographs, no names of people in your groups, no group names, no player names, no room codes, no group codes, and no text you have typed. Where questions are typed rather than spoken, the content of those questions is never included in these records.
Installation identifier.
On first launch, the App generates a random value and stores it locally on your device. This value is not derived from, and cannot be used to obtain, any device identifier, hardware identifier, advertising identifier, or account identifier. Its sole function is to allow gameplay records originating from the same installation to be counted together. The value is deleted when the App is uninstalled. A subsequent reinstallation generates a new value that cannot be associated with the previous one.
Under GDPR, this identifier may constitute personal data notwithstanding that it does not identify you by name. We treat it accordingly.
We use this information to understand which ways of playing are actually used, how often games are finished, and which parts of the App are used. Sections 4 and 7 describe how it is used and how long it is kept.
3.3 Information transmitted during two-device play
When two devices play together, they exchange messages over a real-time channel identified by the four-character room code shown on screen. Those messages carry the state of the game in progress: the people in play and their names, the addresses of their photographs, whose turn it is, how many cards each player has eliminated, questions and their yes/no answers where questions are typed, and the result of a guess.
If you choose to enter a name for yourself on the setup screen, that name is also sent to the other device, so that their screen can say whose turn it is. Entering a name is optional; leaving it blank means both screens say "Player 1" and "Player 2", which is what the App does if nobody types anything.
These messages pass through our provider's real-time service in order to reach the other device. They are not written to a database and we do not store them. A room exists only while the two devices are connected to it.
The card you were secretly dealt is never included in these messages. Each device deals its own card and keeps it. When a guess is made, it is sent to the device holding the card, which replies only that the guess was right or wrong.
Which cards you have eliminated on your own board is likewise never transmitted. Only the number of cards you have remaining is shared, because in the physical game your opponent can see that across the table.
3.4 Information collected in the ordinary course of transmission
When the App transmits the records described in Sections 3.1 to 3.3, the internet protocol ("IP") address of your device is visible to our hosting provider, as it is to any server receiving an internet request. IP addresses are not stored alongside gameplay records and are not used to identify individuals. They may appear in our hosting provider's standard server logs, which are retained according to that provider's log retention practices.
3.5 Information you provide
If you contact us by email, we receive your email address and the contents of your message.
3.6 Information we do not collect
The App does not collect:
- names, email addresses, postal addresses, or telephone numbers, except where you provide them under Section 3.5;
- precise or approximate location data;
- contacts, calendar entries, or microphone input;
- your photo library, or any photograph other than the ones you specifically select or take within the App;
- the Apple Advertising Identifier (IDFA), the Identifier for Vendors (IDFV), device names, device models, operating system versions, or serial numbers.
The names you give to the people in your groups, the names you give to groups, and any name you enter for yourself are not collected as analytics and never appear in the records described in Section 3.2. They are stored on your device. They leave it only in the two circumstances described in Section 3.1 and in Section 3.3 — that is, when you host a game across two devices, or when you send a group to someone using a code.
The App contains no advertising, and no third-party advertising, attribution, or analytics software development kits. The records described in Section 3.2 are sent to our own database, hosted by the provider named in Section 5; no third-party analytics product receives them.
Permissions. The App requests access to your camera so that you can photograph people directly inside it, and access to your photo library so that you can select existing photographs. Both are requested only at the point you first use the corresponding feature, and the App functions without either if you decline, provided you can supply photographs by the other route.
4. How we use information, and our legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| To display the people in your groups on your own device | Section 3.1 | Performance of a contract (Art. 6(1)(b)), providing the App you have chosen to use |
| To make the people in your group visible on a second device during a game you have chosen to host | Section 3.1 | Performance of a contract (Art. 6(1)(b)) |
| To give a copy of a group to a person you have chosen to send it to | Section 3.1 | Performance of a contract (Art. 6(1)(b)), at your request |
| To carry the state of a game between two devices while it is being played | Section 3.3 | Performance of a contract (Art. 6(1)(b)) |
| To understand which ways of playing are used, how often games are finished, and where players stop, in order to improve the App | Section 3.2 | Legitimate interests (Art. 6(1)(f)), our interest in understanding and improving the App, balanced against the minimal and non-identifying nature of the data |
| To operate and secure the services receiving this data | Section 3.4 | Legitimate interests (Art. 6(1)(f)) |
| To respond to your enquiries | Section 3.5 | Legitimate interests (Art. 6(1)(f)), or performance of a contract where applicable |
We do not use this information for automated decision-making or profiling, and we do not use it to serve advertising. We do not perform facial recognition, face detection, or any other biometric processing on photographs, and we do not analyse their content.
5. Disclosure of information
We do not sell, rent, or trade information. We do not share information with advertising networks, data brokers, or third-party analytics providers.
Photographs, gameplay records, and real-time game messages are handled using Supabase, Inc., which acts as our data processor and processes the data only on our instructions and only to provide hosting services.
Where you give somebody a code under Section 3.1, you are disclosing that group to them directly. We do not control what they do with it.
We may disclose information where required to do so by law, or where necessary to establish, exercise, or defend legal claims.
6. International transfers
Uploaded photographs and gameplay records are stored on servers located in us-west-2.
Where information is transferred outside the EEA or UK, that transfer is made under the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, as incorporated into our agreement with our hosting provider.
7. Data retention
| Data | Retention period |
|---|---|
| Photographs stored on your device (Section 3.1) | Until you delete the group containing them, or uninstall the App |
| Uploaded photographs (Section 3.1) | Until no group on your device refers to them and that group is deleted, at which point they are deleted from our storage |
| The record behind a group code — its name, the names in it, and photograph addresses (Section 3.1) | Retained until you ask us to delete it. Deleting the group stops the code working, but does not remove this record |
| A copy somebody else downloaded using a code (Section 3.1) | On their device, under their control. We cannot delete it |
| Gameplay records (Section 3.2) | 90 days from the date of the event, after which they are deleted automatically |
| Real-time game messages, including player names (Section 3.3) | Not stored; they exist only in transit |
| Hosting provider server logs (Section 3.4) | As determined by that provider's standard practices |
| Correspondence (Section 3.5) | For as long as necessary to resolve your enquiry, and thereafter as required for our records |
Data stored locally on your device, including your groups, the names you have given people, and the photographs themselves, is retained until you delete it within the App or uninstall the App.
8. Security
Photographs, gameplay records, and real-time messages are transmitted over encrypted connections (HTTPS and secure WebSockets). Gameplay records are stored in a database configured to prevent the App from reading any records back.
As described in Section 3.1, uploaded photographs are stored at addresses derived from their own contents, in a bucket that permits public read access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children
The App is a general-audience puzzle game. It is not directed at children, is not offered in the App Store Kids Category, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data under Section 3.5, please contact us and we will delete it.
10. Your rights in the EEA and the UK
Subject to the limitation described below, you have the right to request access to your personal data, to request its rectification or erasure, to request restriction of processing, to object to processing carried out on the basis of legitimate interests, and to data portability.
Photographs.
Photographs on your device are under your control: deleting the group containing them deletes them, and deletes any uploaded copy no longer referred to by another group. If you are unable to do this, or believe an uploaded image has not been removed, contact us under Section 14 and we will delete it. If you can supply the image itself we can locate the corresponding object directly, since objects are addressed by their contents.
If you have sent a group using a code and would like the record behind that code removed, contact us with the code and we will delete it. We cannot recover copies already downloaded by whoever you gave the code to.
Limitation on rights in respect of gameplay records.
The gameplay records described in Section 3.2 do not contain information enabling us to identify you, and we do not retain additional information for the purpose of identifying you. In accordance with Article 11(2) GDPR, the rights of access, rectification, erasure, restriction, and portability do not apply to that data unless you provide additional information enabling your identification. We are unable to locate records relating to a specific individual on request.
Right to object.
You may object at any time to the processing described in Section 4. You may give effect to this by uninstalling the App, which halts all further transmission and deletes the installation identifier from your device.
You have the right to lodge a complaint with your national data protection supervisory authority.
11. Your rights in the United States
We do not sell personal information and do not share personal information for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws. We do not process sensitive personal information, and we do not use photographs for any biometric purpose.
Residents of California, Virginia, Colorado, Connecticut, and other states with comparable legislation may have rights to know, delete, correct, and appeal in respect of personal information. The limitation described in Section 10 applies equally to gameplay records: we are unable to associate them with an identified individual.
12. Tracking and App Tracking Transparency
We do not track you. Specifically, we do not link information collected through the App with information collected by other companies' applications or websites for advertising or advertising measurement purposes, and we do not share information with data brokers. The App therefore does not request App Tracking Transparency permission and does not access the Apple Advertising Identifier.
We do not respond to Do Not Track browser signals, as the App is not a web browser and does not use cookies.
13. Changes to this Policy
If we change the information the App collects, we will update this Policy and the corresponding App Store privacy disclosures before the change takes effect, and we will revise the effective date above.
14. Contact
Leah Stewart, trading as Penny Labs