1. Who we are and what this covers
NameGOAT is a friendly game for learning the names and faces of the families in your group. In this policy, “we” means NameGOAT. Our first launch is in Spain, in the European Union. This policy explains our data practices and your rights under the EU General Data Protection Regulation (GDPR).
2. What we collect and why
For grown-ups, Firebase Authentication holds an account identifier and sign-in details: an email address or the identifiers from linked Google or Apple sign-in methods. Your game profile has your first name, family name, photo and fun fact. These let you sign in and help your group get to know you. Apple sign-in is implemented but its live setup is still pending.
A grown-up creates kid profiles in their family, with a name and photo and an optional fun fact. Kids do not create sign-in accounts or passwords. A paired kid device gets its own technical authentication identity. We store its family and profile links, device label, who paired it, pairing time, last-seen time and revocation status.
We save learning progress and answer history to schedule practice and improve the learning algorithm. Answer records include profile IDs, choices, hints, timing, learning state, app and scheduler versions, time zone and whether play used a grown-up account or kid device. We also store group membership, family links, invitation records and joining times.
To protect groups, we store keyed hashes of blocked sign-in identities, reasons and dates. Rate limits use hashed IP addresses and account IDs, counters and expiry times. Joining records link an account to a family. App Check and reCAPTCHA process security signals; our cloud services also generate operational logs. The app has no ads, analytics SDK or crash-reporting SDK, and no data-selling or marketing-sharing integration.
3. Photos and face detection
Uploaded photos are processed in a Cloud Function in europe-west1. A bundled detector finds a face to help crop the image; it does not recognise who you are. Detection is transient: pixels and boxes stay in the function’s memory. No biometric templates, landmarks or detector results are stored or logged, and photos are not sent to an external face-detection service.
We keep a square photo and a tiny, heavily blurred teaser. Processing strips image metadata such as EXIF and GPS. The upload and previous photo version are deleted after processing. Until you add your own photo, you receive only blurred teasers of other families, not their real photos. Paired kid devices can see playable group photos.
4. Who can see what
Active group members and paired kid devices can read published profiles: names, family connections and fun facts. Real photos require the photo access described above. Draft profiles are readable only by grown-ups in that family and the group admin for moderation; the admin also needs their own photo to read draft photos. Profiles and photos are not a public directory.
Grown-ups can read their own learning progress and their kids’ progress. A kid device can read its own player’s progress. The admin role gives no access to other players’ progress or answer history. Answer logs cannot be read through the app, even by the player. The NameGOAT team can use them server-side to tune learning; pseudonymous analysis copies are still personal data.
Anyone holding a family invitation can preview the inviter’s name and group name. A pairing-code preview shows the kid’s display name to help confirm the device setup. These limited previews do not expose group photos or the full roster. Please share invitations only with the intended people.
5. Children and grown-ups
The game is designed for grown-ups first, and kids around six and older can play too. A grown-up adds the kids, manages their profiles and pairs or removes devices. Adding a kid shares their published profile with the group. Please only add a child you are authorised to represent, and explain this sharing to them in a way they understand.
Kids do not sign up themselves. A paired device lets a kid play, browse the group and add their own fun fact, not manage family settings or other players. The legal consent requirements for children in Spain still need review before use by real families.
6. Where data is stored
Our group database is in Firestore’s EU eur3 location. Photo storage and Cloud Functions are in europe-west1. This EU storage choice does not mean all processing happens in the EU. Firebase Authentication, Firebase Hosting’s content-delivery network, Google or Apple sign-in and reCAPTCHA can also process data outside the EU.
Their processing is subject to the providers’ terms and data-protection arrangements. We do not promise EU-only processing for those services. Contact us if you need information about the applicable international-transfer arrangements.
7. Services we use
Google Firebase and Google Cloud provide authentication, the database, photo storage, server functions and website hosting. Google reCAPTCHA Enterprise and Firebase App Check help protect the app against misuse. Google sign-in, and Apple sign-in once configured, handle the sign-in method you choose. These services receive the information needed for their role. App stores may provide their own crash reports; there is no crash-reporting SDK in the app.
8. How long we keep data
Group data is kept while the group exists, unless a profile or account is removed earlier. Removing a profile starts cleanup of its photos, progress and answer records, including records about that person in other players’ history. Account deletion also deletes the grown-up’s sign-in and profile. Access changes take effect when removal is accepted; background cleanup is retried if interrupted.
Kids stay if another grown-up remains in the family. Otherwise, account deletion requires you to add another grown-up first or explicitly include all the kids in the deletion. Completed deletion jobs and account tombstones have a seven-day expiry. Some removal identifiers, revoked-device records and blocklist hashes remain for access control; account deletion does not add you to the blocklist. Rate-limit and invitation records have expiry times.
Our documented retention policy requires backups and analysis copies to be purged within 30 days. Production database backups and point-in-time recovery are documented with seven-day retention. We cannot recall photos that another device has already downloaded.
9. Your rights and your choices
Under the GDPR, you can request access, correction, deletion, restriction of processing or a portable copy of your data, and object to processing where these rights apply. Where processing relies on consent, you can withdraw it. Withdrawal does not change the lawfulness of earlier processing. You can complain to your national data protection authority, such as the AEPD in Spain.
In the app, edit your own profile or manage a kid’s profile in Family. You can remove a kid or revoke a paired device there. Delete your account from Settings or the account-deletion page linked below. You must sign in again to confirm. For access, portability, other requests or help with a child’s data, email us. We may need to check your identity and authority to act before releasing or changing private data.
Delete your account10. Cookies and device storage
The web app uses persistent browser storage for your sign-in session. Local storage remembers language, appearance and sound choices, pending email sign-in or method-linking details, return paths, a linking-session check and a paired-device marker. Game navigation remembers player IDs and mode in app memory; sign-out clears the remembered selections. These support app functions, not advertising.
The product website remembers language and appearance without loading the game’s authentication or group data. On the web, Firestore data and downloaded photos are cached in memory, not a persistent roster or photo database. Native apps use device storage for sessions and preferences and private cache files for photos. Sign-in and reCAPTCHA services may use their own browser storage or cookies.
11. How we protect data
Firestore and Storage rules use active membership or a live paired device to restrict access to group profiles, progress and processed photos. Privileged changes run on the server. Callable functions require App Check, and code guessing is rate-limited. Photo downloads use authenticated access rather than public download links. Hosted web connections use HTTPS. These controls reduce risk, but no system can guarantee absolute security. Keep devices and invitations safe.
12. Changes to this policy
We will update this page when our practices change. The date at the top identifies this version. Please check it when deciding whether to use a new feature or share more information.