Privacy Policy — Noggin!
Effective date: 18th November 2025
This Privacy Policy explains how Dun Cow Productions Ltd., trading as “Noggin!” (“we”, “us”, “our”), collects, uses, and shares information when you use the Noggin! mobile app (the “App”) and related services.
By using Noggin!, you agree to this Policy. If you do not agree, please do not use the App.
Information we collect
- Account information. Email, display name, avatar, and dates created/updated. Stored in our database (users table in Supabase).
- Authentication and session. Supabase-auth user ID and session tokens to keep you signed in.
- Gameplay and usage. Quiz participation, answers, scores, leaderboards, points, reward redemptions, and show joins.
- Transactions. In‑app purchase receipts and subscription details to validate purchases (via Apple’s StoreKit on iOS and Google Play on Android). We store minimal transaction metadata required for validation, fraud prevention, and accounting.
- Security/fraud prevention. Device fingerprints such as IP address, user agent, and similar signals to detect suspicious activity and protect the service.
- Advertising identifiers. On iOS, if you grant permission, Apple’s Identifier for Advertisers (IDFA) may be collected for rewarded ads (via Google AdMob). If you deny permission, we request non‑personalized ads.
- Device and diagnostics. Basic device/OS info and error logs to improve stability. Approximate location may be inferred from IP for regional compliance and ad delivery.
We do not intentionally collect sensitive categories of data.
How we use your information
- Provide and improve the App. Authenticate you, run shows, compute scores, award points, display leaderboards, and deliver support.
- Process purchases. Validate subscriptions, ticket packs, and redemptions with the relevant stores and our backend.
- Show rewarded ads. Display and verify completion of rewarded ads via Google AdMob to grant in‑app points.
- Safety and enforcement. Prevent fraud, abuse, and violations of our Terms.
- Legal compliance. Satisfy tax, accounting, and regulatory obligations.
Legal bases (EEA/UK)
- Performance of a contract (to provide the App and purchases).
- Legitimate interests (fraud prevention, security, and service improvement).
- Consent (personalized advertising and tracking via ATT/IDFA).
- Legal obligations (transaction records and accounting).
Sharing of information
We do not sell your personal information. We share data only with:
- Service providers: Supabase (hosting/database and auth), Google AdMob (rewarded advertising), Apple (in‑app purchases), and similar vendors who process data on our behalf under contracts and appropriate safeguards.
- Legal and safety: If required by law or to protect rights, safety, and property.
- Business transfers: In connection with a merger, acquisition, or sale of assets.
Data retention
- Account and gameplay data: kept while you maintain an account and for a reasonable time thereafter.
- Transaction/receipt data: retained as required for tax, accounting, and anti‑fraud (often up to 6 years in the UK).
- Logs/diagnostics: retained for a limited time for stability and security.
Your choices and rights
- Access, correction, deletion: Email us to request access to, correction of, or deletion of your personal data. Deleting your account removes your profile and gameplay data, subject to legal retention (e.g., transaction records).
- Advertising and tracking: On iOS, you can allow/deny tracking via the system prompt and device settings. You can also reset your advertising identifier in device settings.
- Subscriptions and purchases: Manage or cancel auto‑renewing subscriptions in the App Store settings on your device.
Children’s privacy
Noggin! is not directed to children under 18, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us to delete it. For users in the EEA/UK under 16, parental consent may be required for certain processing (e.g., personalized ads).
International transfers
We may process data in countries outside your own. Where required, we use appropriate safeguards (e.g., SCCs) for international data transfers.
Security
We use reasonable administrative, technical, and organizational measures to protect your information. No system is 100% secure.
Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new “Effective date.”
Contact