Privacy Policy
Effective date: 13 August 2026 · Last updated: 13 August 2026
ZIPPER ("the App", "we", "us") is a party drinking game for iOS made by Niels Marinus Rens van Brussel. This policy explains what data the App collects, why, and how it's handled.
ZIPPER is intended for adults aged 18 and over. Do not use ZIPPER if you are under the legal drinking age in your location.
1. Data We Collect
ZIPPER does not require an account, a username, or an email address to play. We collect the minimum needed to run the game and understand how it's used:
a) Anonymous session identity
When you open the App, it silently creates an anonymous, unique session (via Supabase Authentication) so we can attribute gameplay data to a single device without collecting your name, email, phone number, or any other personal identifier. This session is protected by a bot-check (Cloudflare Turnstile) the first time it's created, then reused on future launches. It contains no personal information — it's a random identifier, not tied to your identity.
b) Gameplay analytics
To understand how the game is played and improve card balance, we log:
- Session data: player count, selected game mode and intensity, deck size.
- Card events: which cards were shown, in what order, and their outcome (played, skipped, won, lost) — identified only by internal card ID and type.
- Game results: the display names you typed in for players during setup, final scores, win/loss counts, and zip (drink) counts, for each completed game.
Player display names are whatever you type into the app at setup — they are not verified and are not linked to any external identity, account, or contact. Don't enter anyone's full legal name if you'd rather not have it stored.
c) Microphone access (Music cards only)
Music cards use Apple's ShazamKit to identify the song playing in the room, so the app can reveal the title and artist instead of relying on the game master to know it. This requires microphone access, which iOS will ask you to grant the first time a Music card comes up — you can decline, and the card falls back to deciding manually.
The audio itself is processed on-device and by Apple's ShazamKit matching service; we never receive, record, or store it. Once a match is found, the app makes one additional lookup to Apple's iTunes API to fetch extra track details (album art, release info). Neither the audio nor the identified song is sent to our servers — the only thing logged to our analytics is that a Music card was played and its outcome, exactly like any other card.
Outside of Music cards, the app never accesses the microphone.
d) Locally stored game state
Your in-progress game (players, scores, current card) is saved on your device only, using standard app storage, so you can resume a session after closing the app. This data never leaves your device.
e) What we do NOT collect
- No location data
- No contacts, photos, or camera access
- No advertising identifiers
- No third-party analytics or ad SDKs (no Facebook SDK, Google Analytics, AdMob, etc.)
- No payment card data is stored by us — subscription purchases are handled entirely by Apple's App Store; we never see your payment details
2. How We Use This Data
We use the data described above to:
- Operate core game functionality (deck generation, scoring, save/resume)
- Understand which cards, modes, and intensities are popular or unpopular, to improve future card content
- Diagnose bugs and imbalances in gameplay
We do not sell your data. We do not use it for advertising or share it with data brokers.
3. Where Data Is Stored
Analytics and session data are stored with Supabase (a hosted PostgreSQL database provider) on servers operated by Supabase. Access is protected by Row Level Security: the App can only insert new records tied to its own anonymous session — it cannot read, modify, or delete other players' data, and neither can any other player's copy of the app.
4. Third-Party Services
| Service | Purpose | Data involved |
|---|---|---|
| Supabase | Backend database (auth + analytics storage) | Anonymous session ID, gameplay analytics described above |
| Cloudflare Turnstile | Bot/abuse protection on first launch | Device signal used only to verify you're not a bot; no profile is built |
| Apple ShazamKit | Song identification for Music cards | Microphone audio, processed on-device/by Apple — never sent to us |
| Apple iTunes API | Track detail lookup (title/artist/artwork) after a Shazam match | Song identifier only; not linked to you |
| RevenueCat | Subscription entitlement management | An anonymous purchase identifier and your subscription status; no payment details |
| Apple App Store / StoreKit | Subscription billing | Handled entirely by Apple; we never receive your payment details |
We do not use any advertising or cross-app tracking SDKs, so ZIPPER does not require App Tracking Transparency permission.
5. Data Retention & Deletion
Analytics data is retained to inform ongoing game balance. Because it is tied only to an anonymous session ID (not your identity), we generally have no way to look up "your" data specifically unless you contact us with your session details. If you'd like your gameplay data deleted, contact us at team.zipper.2026@gmail.com and we will remove any records associated with the session identifiers you provide.
Locally stored game state can be deleted at any time by deleting the App.
6. Children's Privacy
ZIPPER is not directed at, and must not be used by, anyone under the legal drinking age in their jurisdiction. We do not knowingly collect data from children.
7. Changes to This Policy
We may update this policy as the App evolves (e.g. new features, new backend providers). Material changes will be reflected in the "Last updated" date above, and significant changes will be noted in the App Store release notes.
8. Contact
Questions about this policy or your data: team.zipper.2026@gmail.com
Subscriptions are billed by Apple and governed by the Apple Standard End User License Agreement.