Privacy Policy
Last updated: May 31, 2026 · Effective on first install
Plain summary. Guess The Plate stores the minimum data needed to run the game — your Apple-anonymized user ID, your chosen nickname, the preset avatar you picked, and your in-game progress. There is no camera, no photo picker, and no image upload anywhere in the app — the only content you create is your public nickname (and reports/blocks of other players). We do not sell data. We do not run third-party advertising trackers. Account deletion is available from the app's settings, and we keep an auditable record proving the deletion ran.
1. Who we are
"Guess The Plate" (the "Service") is a mobile game published by Hole in the Roof Studios LLC, based in Houston, Texas, USA. References to "we," "us," or "our" mean Hole in the Roof Studios LLC. References to "you" mean the person using the Service.
For privacy questions or rights requests, write us at privacy@guesstheplate.com.
2. The data we collect, and why
2.1 Information you give us
- Game Center player identifier. If you are signed in to Game Center, Apple gives us a per-developer player identifier, which we exchange for your account session. For most players this is the default sign-in. Your score and your Game Center alias are also published to Apple’s Game Center leaderboards, where other Game Center players can see them.
- Anonymous sessions. If Game Center is unavailable we create an anonymous account for you instead, which carries no identifier from Apple at all. You can attach Sign in with Apple later to make that account recoverable across devices and reinstalls.
- Sign in with Apple identifiers. When you sign in, Apple gives us a privacy-relayed user identifier (an opaque string — not your real Apple ID, not your real email). We request no name and no email — only that opaque identifier. Because we ask for no scopes, Apple never even shows you a “Share My Email / Hide My Email” choice for this app, and we hold no email address and no real name for you. We use the identifier only to recognise your account across launches and reinstalls.
- Your public player card. A 3–16-character nickname you choose, plus your preset avatar, your country flag, the plate you have equipped, your skill rating and your lifetime gameplay stats. These are visible to other players on leaderboards and profile cards. Your country is a country-level label pre-filled from your device’s region setting, which you can change in your profile — it is not a location fix. If you leave “Show my coin balance” on, your coin balance also appears on our public Richest Players board; turning it off removes you from that board. Stored alongside a normalized lowercase form so we can enforce uniqueness without leaking your exact capitalization, and screened against a banned-term filter before it is accepted.
- Preset avatar. You pick an avatar from a fixed set we provide. We store only your selection (an identifier for which preset you chose). There is no camera, no photo picker, and no image upload — you cannot submit a photo or any other image, so no image moderation applies.
- Reports you file or are filed against you. When you report another player, we store the report alongside the reason you selected and any optional 500-character free text you wrote. Reports target a user/nickname, not an image.
2.2 Information your device sends automatically
- Game progress. Coin balance, current streak, completed plates, trophies unlocked, current week's quest plate, settings preferences. Stored so you don't lose progress when you re-install or change phones.
- Purchase receipts. Apple sends us transaction identifiers when you buy a coin pack or VIP — we never see your card number. Used to grant your purchase and honor refunds.
- App Check device attestation. A per-device cryptographic token from Apple's App Attest framework that proves the requests are coming from a genuine, unmodified copy of the app. We don't get a device serial number from it; we only see "pass" or "fail."
- Crash logs. If the app crashes, an anonymized stack trace and the iOS version may be sent so we can fix the bug. No personal content is included.
2.3 What we don't collect
- We do not collect your phone's location. The privacy nutrition label declares NO Location data, and because there is no photo or image upload there is no metadata for us to receive in the first place.
- We do not embed any third-party advertising SDKs, and the app shows no ads at all — no banners, no interstitials, no rewarded video. Because there is no advertising, there is no ad-related tracking, no IDFA use, and no App Tracking Transparency prompt.
- We do not collect your contacts, calendar, photos, camera roll, microphone (except in real time during voice mode — see §2.4), or any health data. The app has no camera or photo-picker access at all.
2.4 Voice mode is on-device
When you enable voice answers, your spoken words are processed by Apple's on-device speech recognition engine. Your audio is not sent to our servers. We never receive recordings.
3. How long we keep it
- Account data (Apple ID hash, nickname, preset avatar selection, progress): for the life of your account, or until you delete it.
- Reports against your account: deleted when your account is deleted. Reports you filed against other players are kept with your identity removed — your identifier is replaced with a placeholder — under Article 17(3)(e) GDPR, so the moderation record survives.
- Cascade audit records: when your account is deleted, we write a pseudonymized record (your user ID is salted-hashed, not stored in clear) of which tables were swept and which retentions invoked which legal basis. Audit retained 7 years; receipt to you retained 24 hours.
4. Account deletion
You can delete your account from Settings → Account → Delete Account (you'll be asked to sign in if you aren't, then to type DELETE to confirm) inside the app at any time.
- The deletion request is recorded immediately. You're signed out instantly.
- A 30-day grace window starts. During those 30 days your account is locked and you cannot sign back in — the grace period is a delay before permanent deletion, not an undo. If you change your mind, email privacy@guesstheplate.com before it elapses.
- At the 30-day mark, a server-side cascade runs and: clears your account record, releases your nickname back to the pool, pseudonymizes any reports you filed (so the safety record survives), and writes the audit entry.
- Optional: the deletion is recorded in a tamper-evident audit entry. We cannot email you a confirmation, because we hold no email address for you.
5. Sharing — who else sees this data
We share data only with the service providers that make the app work. Specifically:
- Apple Inc. — Game Center (sign-in and leaderboards; your score and Game Center alias are published to Apple’s leaderboards, visible to other Game Center players), Sign in with Apple, App Store payments, App Attest, on-device speech recognition. Governed by Apple's privacy policy.
- Google Cloud Platform (Firebase) — our backend hosting, database (Firestore), and Cloud Functions. We also use Firebase Crashlytics for crash and error diagnostics (see §2.2) — it receives crash traces, the build and language you were on, and peak memory, never your nickname or user ID. We do not use Firebase Analytics, advertising, or any cross-app tracking SDK. Governed by the Google Cloud Data Processing Addendum. Our default region is us-central1 (Iowa, USA).
We do not sell your data to anyone. We do not transfer your data to third parties for behavioral advertising. If we ever change this we will obtain affirmative consent first and clearly state it here.
6. Your rights
6.1 If you are in the European Economic Area, the UK, or Switzerland (GDPR)
You have the right to access, rectify, port, restrict, object to the processing of, and erase your personal data. Most of these you can exercise directly in-app (your profile, your nickname, account deletion). For others, email privacy@guesstheplate.com — we will respond within 30 days. The legal bases we rely on are: performance of a contract (running the game for you), legitimate interest (security, anti-abuse, basic moderation), and legal obligation (REPORT Act / lawful requests). You also have the right to lodge a complaint with your national data-protection authority.
6.2 If you are in California (CCPA / CPRA)
You have the right to know what we collect, request deletion, correct inaccurate information, and not be retaliated against for exercising any of these rights. We do not "sell" or "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA. Use the in-app deletion flow or email privacy@guesstheplate.com.
6.3 If you are anywhere else
You have the same rights. Email privacy@guesstheplate.com and we will respond.
7. Children
The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). The App Store age rating for Guess The Plate is 4+ for content suitability, but We do not verify age. The age requirement is stated in the Terms you accept before playing, and enforced by that acceptance rather than by any automated check. We do not knowingly collect data from anyone under 13. If we learn that we have, we will delete the account and the associated data promptly. Parents who believe their child has signed in despite the Apple-side gate can write us at privacy@guesstheplate.com for an expedited deletion.
8. International data transfers
Our backend runs in us-central1 (Iowa, USA). If you use the Service from outside the United States, your data is transferred to and processed in the United States. For transfers from the EEA / UK / Switzerland we rely on the European Commission's Standard Contractual Clauses with Google as our processor.
9. Security
All transit is HTTPS / TLS 1.2+. All at-rest storage is encrypted by Google Cloud's default AES-256 with Google-managed keys. Authentication uses Game Center or an anonymous device account, with Sign in with Apple as an optional upgrade, and every request additionally carries Apple's App Attest (device cryptographic proof). Server-side endpoints require a valid Firebase authentication token and a valid App Check attestation token; missing or invalid attestation returns HTTP 401. No security control is unbreakable, but we use industry-standard defenses and minimize what we hold so a worst-case leak is minimally harmful.
10. Cookies / tracking on this website
This marketing website (guesstheplate.com) sets no analytics cookies and no advertising cookies. The site is static HTML on Firebase Hosting; the only third-party connection is to Google Fonts to load the typefaces. We do not track which pages you read or how long you stay.
11. Changes to this policy
If we materially change how we collect or use data we will update the "Last updated" date above and surface a notice in the app the next time you launch. Continued use after a change means you accept the updated policy.
12. Contact
Email: privacy@guesstheplate.com
Postal: Hole in the Roof Studios LLC, Houston, Texas, USA (full mailing address on request).
This document is provided for transparency and ease of reading. Where this summary conflicts with applicable law, applicable law controls.
