At a glance: core play is local-first and needs no account. Your full learning history, Knowledge DNA, interests, and review schedule stay on your device. If you intentionally create a social identity, trivolivia sends the limited Daily results and profile information needed for challenges, Braintrusts, channels, and anonymous answer distributions. There are no ads or cross-site trackers.
Scope
This Privacy Policy applies to the trivolivia website at trivolivia.com, the trivolivia app, the optional social API at social-us-central1-m1rif45.uc.gateway.dev, the social share service at trivolivia-social-prod.web.app, and official challenge, Braintrust, and channel links. In this policy, “we” and “us” refer to trivolivia.
Local-first information on your device
trivolivia uses app or browser storage to save information such as:
- current sessions, answers, question history, Daily Five results, and skipped questions;
- interests, cached Topic Sprint decks, recent supported topic selections, and followed-channel preferences;
- review timing, progress, and the bounded answer ledger used to calculate Knowledge DNA on the device;
- cached Daily editions and immutable challenge manifests; and
- preferences, data-version information used for safe recovery, and—only after you enable social features—a random social identifier and secret access credential. Native apps place that credential in platform-protected Keychain or Keystore storage; the web app uses origin-scoped encrypted browser storage protected with Web Crypto.
Core play does not upload your complete answer history, Knowledge DNA profile, interests, review schedule, or ordinary non-Daily rounds to trivolivia. You can remove individual sessions from History, clear Knowledge DNA in the app, or remove all local information by clearing trivolivia site data or uninstalling the app. Clearing Knowledge DNA keeps saved quest and Daily history but records a local reset boundary so those older answers do not recreate the profile; only future answers begin a new profile. Clearing all local data erases progress and may also erase the only copy of your secret social credential.
Optional social identity and information sent to trivolivia
You do not need social features to play. If you choose to enable them, the app creates a pseudonymous guest identity without asking for an email address, phone number, password, contacts, or real name. We receive and store:
- a random guest identifier, your chosen display name (or the default “Curious player”), a one-way hash of the secret credential held on your device, and creation, update, and recent-use timestamps;
- verified Daily result data: edition and content identifiers, the five card identifiers, selected answer positions, correctness outcomes, categories, score, and completion time;
- challenge records and responses, including the challenger or respondent display name, edition, selected challenge question, score and correctness pattern, response count, and timestamps;
- Braintrust names, membership, role, display names, Daily results copied into that group, standings, streaks, category crowns, and computed recaps;
- for player-created channels, the channel name, description, selected categories, owner display name, and timestamps; and
- social product-interaction information linked to the random guest identifier, including record creation and update times and participation in the social features you choose; and
- safety reports, blocks, and security and rate-limiting records needed to protect people and the service, as described below.
We use this information only to provide and secure the social features you request: verify scores against the published edition, prevent answer tampering and abuse, show comparisons, calculate group summaries, choose channel rounds, and maintain the service. We do not use it for advertising or behavioral analytics.
For App Store privacy disclosures, the guest-linked social timestamps and participation records are Product Interaction linked to a user. “Linked” here means linked to the app’s pseudonymous guest identifier—not that trivolivia asks for or knows your real-world identity. This information is not used to track you across other companies’ apps or websites.
The app may fetch the public channel catalog before you create a social identity. That request carries ordinary connection information, such as an IP address and request headers, but no social credential, answer history, Knowledge DNA, interests, or review schedule.
To limit automated identity creation and Daily-result abuse, the service derives one-way, action- and time-window-specific identifiers from the gateway-observed IP or network address. The persistent rate-limit record contains only a hash-based key, an action name, a counter, update time, and expiry—not the raw IP address—and is not joined to a guest record. Shorter per-instance counters remain only in memory for about one minute. We conservatively disclose the persistent network-derived identifier as an unlinked Device ID used for app functionality and security. Cloud providers may separately process ordinary request metadata and logs as described under “Service providers and technical information.”
Who can see social information
- Read the Room: a distribution is available only to a pseudonymous identity that has already submitted the same exact Daily edition. It remains unavailable until at least 10 verified pseudonymous submissions exist. Returned percentages are rounded to five-percentage-point buckets and do not include guest identifiers or display names.
- Challenges: anyone with an active challenge link can see the challenger’s display name, edition, target question, expiration, and response count. The challenger’s score and answer pattern stay hidden from a recipient until that recipient submits the same verified edition. A challenger can see responses to their challenge; a respondent sees their own comparison.
- Braintrusts: a valid invite page displays the group name. Members can see other members’ display names and the group’s recent Daily standings, streak, crowns, and recap. Invite links contain a secret token and are valid for seven days unless the owner replaces the link, ownership transfers and rotates it, or the group closes. A full group does not accept another member, but the unexpired invite may accept a request later if a seat becomes available. An expired or invalid invite page does not reveal the group name.
- Channels: player-created channel names, descriptions, category selections, owner display names, and share pages are public. A channel chooses from reviewed trivolivia questions; it does not publish custom question text.
Stable random guest and owner identifiers used to target report and block actions are returned only with authenticated social requests or inside authenticated member and comparison contexts. They are omitted from unauthenticated challenge previews, channel catalogs and details, and public share pages.
Please use a pseudonym and do not place sensitive personal information in a display name, Braintrust name, channel name, or channel description. Information that another person copies, screenshots, or shares outside trivolivia is outside our control.
Safety reports, blocks, and content screening
Display names, Braintrust names, and channel names and descriptions are checked against automated safety rules before publication. The checks are designed to reject clearly abusive, hateful, threatening, sexually explicit, or evasively encoded text. They do not replace user reports or human review and may make mistakes.
If you submit an in-app report, we store the reporter’s random guest identifier for internal accountability; the reported user, channel, or Braintrust identifier and target owner’s random guest identifier; your selected reason and optional report details of up to 500 characters; a snapshot of the reported text and categories; a content hash; internal priority and review status; and creation and update timestamps. This information is used only to investigate safety, abuse, rights, and service-integrity concerns. The report response shows the reporter only an opaque receipt and status. Report contents and the reporter’s identity are not made public or disclosed to the reported person through the app.
If you block another social identity, we store the blocker and blocked random guest identifiers and a timestamp. Blocking hides that person and their user-created content from your social views, prevents challenge interaction in either direction, and can remove one of you from a shared Braintrust. Unblocking does not restore prior Braintrust membership. The blocked person is not told who blocked them. Only you can retrieve your block list, which includes the current display names needed to manage it.
Topic Sprint and source links
Topic Sprint accepts only topics from a reviewed general-audience catalog. Exact bundled topics use the editorial question deck already included with the app and do not contact Wikimedia. For another supported topic without a safe cached deck, the app sends only the canonical reviewed topic directly to the English-language Wikipedia API to find an exact category and retrieve its introductory text and category labels. Unsupported, unsafe, and other free-form text is rejected on the device and is not sent to Wikimedia or trivolivia’s social service. The app checks each returned page’s title, introduction, and category labels against its general-audience safety rules. A page that fails is discarded in full, and no runtime deck is created unless at least five distinct safe pages remain.
Wikimedia receives the canonical topic request and ordinary connection information, including an IP address and request headers, under the Wikimedia Foundation Privacy Policy. Because trivolivia cannot guarantee that Wikimedia separates a topic search from that connection information, we conservatively disclose Search History as linked to a user or device. The resulting safe deck and canonical topic are cached on your device; trivolivia’s social service does not receive the topic selection.
Question explanations include links to third-party sources. If you open one, you leave trivolivia, and the destination receives the request and may collect information under its own privacy policy. Sharing through your device also gives the link—and any text you choose to add—to the operating system and destination service you select. trivolivia does not receive your address book or learn whom you contacted through the system share sheet.
Service providers and technical information
The public website is delivered through GitHub Pages. GitHub may process information needed to deliver and secure pages, such as IP address, device or browser information, requested URL, and time, under the GitHub General Privacy Statement. We do not receive a visitor-level analytics feed from ordinary GitHub Pages delivery.
The optional social API is delivered through Google Cloud API Gateway, and the social service and share pages run on Google Firebase and Google Cloud in the United States. Google processes stored social records and ordinary service data, including request metadata and logs, on our behalf under its applicable Firebase privacy and security terms. These providers may process information in countries other than the one where you live.
trivolivia does not add advertising SDKs, third-party visitor analytics, session recording, or tracking pixels. We may review limited operational logs when necessary to investigate reliability, security, or abuse.
Cookies, caching, and tracking
trivolivia does not set cookies for accounts, advertising, or analytics. Browser storage and cached site files support local progress and faster loading. The social service uses the secret credential stored by the app rather than a tracking cookie. On the web, encrypted credential storage is still part of the same website origin: clearing browser data can erase it, and malicious code running with that origin’s privileges could access it. Native Keychain or Keystore storage provides a stronger platform boundary but cannot protect an unlocked, compromised device.
The app does not track you across other companies’ websites or apps, sell personal information, or share personal information for cross-context behavioral advertising. We have not sold or shared personal information for those purposes.
Because trivolivia does not perform cross-site tracking, it does not respond differently to browser “Do Not Track” signals.
Retention and deletion
Local information remains until the app removes it under its bounded-history rules or you clear it. Attributable Daily result rows and their Braintrust copies are scheduled for automatic deletion 31 days after submission. Challenges and challenge-response records stop working and are scheduled for automatic deletion 14 days after challenge creation. Safety reports are scheduled for automatic deletion 180 days after creation and may be deleted earlier when either the reporter or reported social identity deletes its data. A block remains until the blocker unblocks the other identity or either identity is deleted. Firestore’s deletion process can occur after the scheduled time, and limited provider backups may take longer to cycle out.
You can use Delete social data in the app while your credential is available. The service deletes your guest profile, individual Daily results, challenge responses you wrote, responses to challenges you owned, memberships and Braintrust result copies, channels and challenges you own, blocks involving your identity, and safety reports in which your identity is the reporter or target. A populated Braintrust you own transfers to its longest-tenured remaining member and receives a new invite; a sole-member Braintrust and its artifacts are deleted.
Aggregate Daily answer totals are not reversed and may remain because they contain no guest identifier. Leaving a Braintrust or deleting social data removes attributable Braintrust result copies that still exist within the 31-day retention window and adjusts their frozen round counts. After those result rows expire, an older anonymous frozen-round record may retain an already-counted play because it can no longer be linked to you. That record keeps only the Braintrust ID, edition, frozen member count, participation threshold, anonymous participant count, quorum timing, and timestamps—not your guest identifier or answer. Rate-limit counters are scheduled to expire at the end of their one-hour or 24-hour window. After social deletion, a minimal tombstone containing the credential hash and deletion timestamps remains for 24 hours so a lost deletion response can be retried safely. Limited provider logs, backups, and records required for legal obligations may remain for a reasonable period and are isolated or deleted under operational retention cycles.
Deleting social data does not clear local learning history, and clearing local app data does not send a server-deletion request. To erase both, use the in-app controls before clearing or uninstalling. If you lose the only copy of your social credential, contact us; we may request enough information to locate and verify a deletion request, and in some cases may be unable to reconnect an otherwise pseudonymous record to you.
Your choices and rights
You can play without a social identity, choose or change a display name, report or block another social identity or its content, review and remove your blocks, leave a Braintrust, replace a Braintrust invite if you are its owner, unfollow a channel locally, and delete your social data. You may also ask to access, correct, or delete information associated with you, or object to or restrict processing where local law provides those rights.
Where applicable, we process social information to provide the features you request, to pursue legitimate interests in service security and integrity, to respond with your consent or at your direction, and to comply with law. You may contact us to exercise a privacy right or appeal a decision. We will not discriminate against you for making a valid request.
Contacting us
If you email us, we receive the email address, message, and any information you choose to include. We use it to respond, address safety or support issues, and maintain necessary business records. We do not sell it or use it for advertising. We retain correspondence only as long as reasonably needed for those purposes or legal obligations.
Children
trivolivia is intended for people age 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Do not create a social identity if you are under 13. A parent or guardian who believes a child sent personal information to us may contact us to request deletion.
Security
Core learning data remains on your device. Social requests use HTTPS; the service stores a one-way hash rather than the secret credential itself; native apps use platform-protected credential storage; Android backup and device-transfer extraction are disabled for app data; and direct client access to the social database is denied. Treat your device-held credential and Braintrust invite links like passwords. No internet service is perfectly secure, so we cannot guarantee absolute security. Please do not include sensitive personal information in names, descriptions, or support emails.
Changes to this policy
We may update this policy when the app or its services change. The effective date above will change when revisions are posted. If a change materially affects how we handle information, we will provide a prominent notice where reasonably practical.
Contact
For privacy questions or deletion requests, contact trivolivia.