Privacy Policy
Effective date: 14 June 2026 · Last updated: 6 July 2026
1. Who we are
Gaspr ("Gaspr", "we", "us", "our") is a mobile social party game in which small groups of friends respond to comedy prompts and vote on the funniest answers.
For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), the data controller is Deivis Jankauskas, operating Gaspr as a trading name.
Contact for privacy matters: support@gaspr.io.
This policy explains what personal data we collect when you use the Gaspr app, why we collect it, how we use and share it, and the rights you have over it.
2. A note on our approach
We try to collect as little about you as we reasonably can:
- You play under a generated pseudonym — there's no free-text display name and we don't ask for your real name to show to other players.
- We do not use MAC-address fingerprinting or similar device-tracking techniques.
- We treat your IP address as a weak signal for safety, abuse-prevention, and approximate traffic-origin analytics only, not as a direct identity key or account gate.
- Marketing use of player Responses is anonymised by default.
3. What we collect
We collect the following categories of personal data.
You give us:
- Account details — the email address you sign up with (used for authentication, account recovery, and important service messages).
- Date of birth — required at signup to verify that you meet Gaspr's minimum age of 16 and to keep compliance evidence for successful accounts.
- Legal acceptance/acknowledgement records — timestamps and versions showing that you accepted the Terms of Service and read the Privacy Policy.
- Content you create — your responses to prompts ("Responses"), the votes you cast ("Gasps"), and any comments you're able to post. This content is shared with other members of the group you're playing in.
- Reports, blocks, feedback, and support requests — if you block another player, report content, send feedback, or contact support, we record the information needed to handle that request.
We collect automatically:
- Group activity — which groups ("Houses") you belong to, your score/standing, and your in-app balance.
- Device and technical data — device type, operating system, app version, and a push-notification token if you enable notifications.
- Approximate network data — your IP address and approximate location inferred from it, used only as a soft signal to help detect abuse, fraud, and vote manipulation, and to understand broad traffic origin such as country, region, or city.
- Product analytics data — limited, non-content usage events such as app opens, login/signup outcomes, group creation/joining, round screen views, approximate traffic geography, and whether actions such as answering, voting, reporting, or blocking succeeded or failed. We do not send Response text, prompt text, vote choices, author identity, invite codes, emails, raw user/group/round IDs, tokens, report details, date of birth, or free-text user content as analytics events. Launch analytics are anonymous-only: we do not ask our analytics provider to identify you unless a future privacy-reviewed backend contract adds a separate analytics subject that is not your auth, provider, user, or email identifier.
- Website analytics data — if you accept analytics cookies on our website, Microsoft Clarity may collect interaction data such as page views, clicks, scrolling, browser/device information, approximate location, and session recordings. We use this to understand whether the website is clear and working properly.
We do not collect:
- Real names for public display, free-text usernames, precise location, or special-category data (such as health, ethnicity, or religious belief). Please don't put sensitive personal information into your Responses or comments.
4. Why we use it, and our legal bases
| What we use it for | Legal basis (UK GDPR) |
|---|---|
| Running the game — accounts, groups, prompts, voting, scoring | Performance of a contract with you |
| Checking age eligibility and keeping DOB/legal acceptance evidence | Legal obligation and/or legitimate interests in operating an age-gated, compliant service, subject to legal review |
| Blocking underage registrations and deleting failed underage signup data | Legal obligation and/or legitimate interests in preventing underage access, subject to legal review |
| Keeping the app safe — preventing abuse, harassment, cheating, and vote farming | Our legitimate interests in a safe, fair service |
| Sending push notifications | Your consent (you can turn these off any time) |
| Account and security emails (e.g. password resets) | Performance of a contract / legitimate interests |
| Product analytics, improving and fixing the app | Our legitimate interests in maintaining and improving a working product, with data minimisation |
| Website analytics cookies and Microsoft Clarity session insights | Your consent |
| Featuring anonymised in-game Responses in marketing and promotional material | Legitimate interests in promoting Gaspr, with anonymisation and eligibility safeguards, subject to legal review |
| Responding to support, data-rights, legal, or removal requests | Legal obligation / legitimate interests |
| In-app purchases (when available) | Performance of a contract |
Where we rely on legitimate interests, we've considered whether those interests are outweighed by your rights, and we've limited what we process accordingly.
5. Age gate and underage users
Gaspr is intended for users aged 16 and over. Date of birth is mandatory during account creation and is checked before a Gaspr account/session is completed.
If a signup attempt shows the person is under 16:
- account creation is blocked;
- the app shows: "You must be 16 or over to use Gaspr.";
- the person cannot retry date of birth in the same session;
- for email signup, Gaspr does not create or keep a Gaspr user, device, session, email, or date-of-birth record for that failed attempt;
- for Google/Apple/provider signup, Gaspr deletes Gaspr-controlled backend, session, device, email, date-of-birth, and provider/Auth user data created for that failed attempt where Gaspr has control over deletion.
We avoid storing underage DOB values in logs, analytics, crash reports, or support payloads.
6. UGC and marketing use
Gaspr may feature or promote in-game Responses externally, for example on social media, app-store/listing material, websites, press, paid ads, and other owned or paid promotional channels.
Marketing use is anonymised by default. MVP marketing attribution is anonymous only. If optional credit is introduced later, it may use only the user's generated Gaspr display name and never a personal/legal name.
Only content from users who have verified that they meet the 16+ age requirement is eligible for UGC/marketing use. Content should not be used for marketing if it is hidden, unresolved in moderation, tied to an ineligible account, or cannot be safely anonymised.
Truly anonymised answers used in marketing are no longer personal data under UK GDPR and are treated accordingly. Content may still be personal data if it is pseudonymised rather than anonymous, or if it includes a display name, House context, dates, IDs, metadata, or wording that could reasonably identify someone.
You can request removal of content from marketing material after publication by using the in-app Contact Us route or contacting support@gaspr.io. We will remove or request takedown from channels we control where practical. We may not be able to remove copies already shared or republished by others.
7. Who we share it with
We don't sell your personal data. We share it only with service providers who help us run Gaspr, and only as needed:
- Authentication and database hosting (e.g. Supabase) — to store your account and game data.
- Push-notification delivery (Apple Push Notification service and Firebase Cloud Messaging) — to send notifications you've opted into.
- Product analytics (e.g. PostHog US Cloud, if enabled) — to understand whether core flows are working, where users get stuck, and broad traffic geography, using limited event data rather than Response text or vote choices.
- Website analytics (Microsoft Clarity) — only if you accept analytics cookies on the website, to understand site usability through limited interaction analytics and session recordings.
- Media hosting (e.g. Cloudinary) — to store and serve any images used in the app.
- App stores (Apple, Google) — they handle any future in-app purchases; we never receive your card details.
- Publishing, marketing, and creative service providers/platforms — only as needed to publish or manage approved anonymised marketing material.
- Other players — your pseudonym, Responses, votes, and any comments are visible to members of your group, by design.
We may also disclose data where the law requires it, or to protect the safety of users or our rights.
8. International transfers
Some of our service providers are based outside the UK (for example, in the United States or EU). Where we transfer personal data abroad, we rely on an appropriate safeguard such as the UK Government's adequacy regulations, or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
9. How long we keep it
We keep your personal data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we need to keep limited records for legal, safety, moderation, audit, or fraud-prevention reasons.
Date of birth is retained for now for age-verification and compliance evidence. Legal-review note: the owner will run a GDPR retention review and introduce an enforceable retention/deletion policy before production release or before any longer-term retention commitment is finalised.
Marketing-publication records may be kept so we can track where anonymised content was published and handle removal requests.
10. Security
We use technical and organisational measures to protect your data, including running all game logic on our servers and limiting access to data. No system is perfectly secure, but we take reasonable steps to protect your information and to respond to incidents.
11. Children and younger users
Gaspr is intended for users aged 16 and over. We don't knowingly collect personal data from anyone under that age. If you believe a child under 16 has provided us with personal data, please contact us at support@gaspr.io and we'll take steps to remove it.
Because Gaspr may still be accessed by 16- and 17-year-old users, we account for age-appropriate design expectations, including data minimisation, clear explanations, high-privacy defaults, visible reporting/blocking tools, and accessible ways to exercise rights.
12. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- ask us to correct inaccurate data;
- ask us to delete your data ("right to erasure");
- object to, or ask us to restrict, certain processing;
- ask for a copy of certain data in a portable format;
- withdraw consent (e.g. for notifications) at any time.
To exercise any of these, use the in-app Contact Us route or contact us at support@gaspr.io. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we'd appreciate the chance to address your concern first.
13. Changes to this policy
We may update this policy from time to time. If we make a significant change, we'll let you know in the app or by email. The "Last updated" date at the top shows the current version.
14. Contact
Questions about this policy or your data:
Gaspr, a trading name of Deivis Jankauskas — support@gaspr.io.